Privacy First

Privacy Policy

KS HackZone (“we”, “us”, “our”) is a CTF archive platform. We preserve Capture The Flag challenges from around the world with organizer permission, and we link back to the organizer’s website or event page for attribution. Users can join for free, solve challenges, publish/read writeups, and react (“love”) to writeups, challenges, and events.

Controller
KS HackZone
Scope
Website, challenge archive, and community features
Effective
August 31, 2025

Overview

We collect the minimum information needed to run the platform, provide community features, fight abuse, and comply with the law.

This policy explains what we collect, why, how long we keep it, and the choices you have.

Information we collect

Account & profile

  • Username, email address, password (stored using industry-standard hashing).
  • Optional profile details you add (name, bio, links, profile picture).

Platform activity

  • Challenge interactions (solves, attempts), writeups you publish, comments, and love reactions.
  • Event follows or bookmarks, and any reports you file (e.g., abuse reports).

Organizer submissions

  • Challenge data we host with permission from organizers, with credits and links back to their event/website.
  • Organizer contact details and correspondence related to permissions.

Device & technical

  • IP address, device/browser metadata, and basic logs for security, spam prevention, and service reliability.
  • Cookies or similar technologies (see Cookies & tracking).

How we use data

  • Provide the service: account access, challenge play, writeups, reactions, and community pages.
  • Preserve learning materials: host CTF challenges with organizer permission and attribution.
  • Safety & integrity: detect fraud/abuse, secure accounts, and enforce our Terms.
  • Communication: account-related emails (verifications, security, changes). You control optional notifications.
  • Improvement: diagnose issues, understand feature usage, and improve performance.
  • Legal: comply with applicable laws and valid legal requests.

Lawful bases (GDPR/UK GDPR): consent (e.g., optional cookies), contract (providing the service), legal obligation, and legitimate interests (platform security, abuse prevention, basic analytics). Where we rely on consent, you can withdraw it at any time.

Cookies & tracking

We use necessary cookies for login, session continuity, CSRF protection, and basic functionality.

  • Strictly necessary: required for sign in and core features.
  • Preference: e.g., theme, UI choices (where applicable).
  • Analytics (optional): privacy-respecting metrics to improve the site’s reliability and UX.

You can control cookies in your browser settings. Some features may not work without required cookies.

Sharing & third parties

  • Service providers: infrastructure, storage, email delivery, anti-abuse, and analytics vendors who process data on our behalf under agreements.
  • Organizers & attribution: public challenge pages include credits and links to organizer websites/event pages.
  • Legal & safety: we may disclose information to comply with law, respond to legal process, or protect users and the platform.

We do not sell personal information.

Data retention

We keep personal data only as long as needed to operate KS HackZone and meet legal obligations.

  • Account data persists while your account is active. If you delete your account, we will remove or anonymize personal data, except where we must keep limited records (e.g., legal, security, anti-abuse).
  • Public content you post (e.g., writeups) may remain visible or be attributed as “deleted user”, unless you remove it beforehand or request removal (subject to moderation and legal constraints).
  • Server logs are retained for a limited period to ensure security and reliability.

Security

We apply reasonable technical and organizational measures to protect your data (encryption in transit, hashed passwords, access controls). No internet service is 100% secure, so please use a strong, unique password and enable additional safeguards where available.

Your rights & choices

  • Access, correct, or delete your account information.
  • Export your data where supported or request an export.
  • Object to or restrict certain processing, and withdraw consent where processing is based on consent.
  • Opt out of non-essential emails.

Depending on your location (e.g., EEA/UK/California), you may have additional rights under GDPR/UK GDPR/CPRA. We will honor applicable requests subject to verification and legal limits.

To make a request, see Contact.

Children

KS HackZone is intended for individuals aged 13+. If you believe a child under the applicable age has provided personal data, please contact us and we will take appropriate action.

International data transfers

We may process and store data in countries other than where you live. When we transfer personal data, we use appropriate safeguards as required by law.

Changes to this policy

We may update this policy to reflect changes to our practices or for legal, operational, or regulatory reasons. We’ll adjust the “Last updated” date and, where appropriate, provide additional notice.

Contact

If you have questions about this policy, your data, or would like to exercise your rights:

You can also review our Terms and Why Ads? pages.