Security at GreekHours
Verified against production on 2026-09-08.
GreekHours tracks study, service, and chapter hours for Greek organizations. Chapters trust us with member information and, during study sessions, with location. This page explains how we protect that data and how to reach us if you find a problem.
How we protect your data
No passwords, ever. You sign in with Apple, Google, or Microsoft. GreekHours never stores a password for your account.
Encrypted in transit and at rest. Connections use HTTPS with TLS 1.2 or higher in production. The database, file storage, and backups are encrypted at rest on Microsoft Azure using platform-managed keys.
Access is scoped by role and by chapter. Six roles control who can see and do what: student, admin, study admin, service admin, events admin, and global admin. Chapter data is scoped so one chapter cannot see another's.
Location is for verifying a session, not for tracking you. GreekHours checks your location when a session starts and while it is running. It does not collect location when no session is active. Location and place details are excluded from every shared compliance report.
We do not sell personal information. We use the data we collect to run hour tracking, reporting, and support.
Hosted on Microsoft Azure. Azure's infrastructure is independently audited by Microsoft. GreekHours' own application has not yet been independently reviewed; this page is a self-declaration, not a certification.
Report a security concern
If you believe you have found a security vulnerability or a data exposure in GreekHours, please tell us.
Email: security@greekhours.com
Machine-readable contact: greekhours.com/.well-known/security.txt
We begin assessing security reports within 1 business day, keep you informed while we investigate, and let you know when it is resolved. We do not pursue action against good-faith researchers who follow the guidelines below.
Good-faith research guidelines
- Do not access, modify, or delete data that is not yours. If you reach another chapter's data, stop and report it.
- Do not run denial-of-service tests or automated scanning that degrades the service.
- Do not use social engineering against GreekHours staff or users.
- Give us reasonable time to fix an issue before disclosing it publicly.
What we will not do
- We will not claim certifications we do not hold.
- We will not describe controls that are not running in production.
- We will not sell your personal information.
More detail
The GreekHours Trust Pledge covers data handling, retention, sharing controls, and incident response in depth, and is written for chapter officers, advisors, and campus stakeholders. Read the Trust Pledge or download a copy.
Privacy Policy: greekhours.com/privacy
Terms of Service: greekhours.com/terms