Privacy Policy

ConneCCS - Target Monitoring System · CSPC College of Computer Studies · Effective September 30, 2026

This policy explains how ConneCCS - Target Monitoring System ("ConneCCS") handles information when authorized faculty and staff use the web application. ConneCCS supports performance commitments and reviews, office and individual accomplishments, reportorial requirements, document submissions, and college coordination. The app is maintained by the College of Computer Studies of Camarines Sur Polytechnic Colleges (CSPC).

Summary

Information the system handles

Depending on the features used and the account’s assigned role, ConneCCS may process:

Google data and Google APIs

Google sign-in. If a user chooses Google sign-in, ConneCCS sends the Google-issued sign-in token to Google for verification and uses the returned Google account identifier, verified email address, and available basic profile name or image to authenticate the user and associate the ConneCCS account. The app does not request Gmail or Google Contacts access for sign-in.

Exact permissions requested. ConneCCS requests only the following Google permissions:

Google API scopes requested by ConneCCS
PermissionWhere it is used
openid email profile (Google Sign-In) Sign-in only: to confirm who is signing in and match the Google account to a ConneCCS account.
https://www.googleapis.com/auth/drive (Google Drive) Administrator-only document storage: to create, list, read, upload, download, organize, share, and delete reportorial files in the repository configured for the College. It is not used to read the administrator's unrelated personal files outside that repository.

Google Drive integration. Separately from sign-in, an authorized administrator can connect a Google Drive account for configured document workflows. The integration uses Google Drive API access to list relevant file metadata and to upload, download, or delete files in the configured repository as directed by system workflows. The server stores the administrator-authorized refresh credential so it can perform those operations. Drive file contents are used to provide those document features, not for advertising.

What ConneCCS does not do with Google data. Google user data is not sold, not shared with advertisers, not used to build advertising profiles, and not used to determine a person's eligibility for any benefit. It is not used for automated decision-making.

Some files uploaded through the current Google Drive document workflow may be assigned an “anyone with the link can view” permission when Google Drive allows it. Anyone who obtains such a link may be able to view that file. The link is used by the document workflow; users should upload only files approved for this sharing setting. This link-sharing behavior does not apply to Google sign-in profile data.

ConneCCS’s use and transfer of information received from Google APIs will be limited to providing or improving the user-facing features described here, and will comply with the Google API Services User Data Policy, including its Limited Use requirements.

Why information is used

How information is stored and shared

Account and system records are stored by the ConneCCS service and its configured hosting/database infrastructure. The web application is hosted on Railway (a Railway.app subdomain), and the API and database it connects to are also operated by the College. Files managed through the Drive integration are stored in the College's connected Google Drive repository. The app may use Google for sign-in, Google Drive for the authorized file workflows, and Expo or browser push services to deliver notifications when a user enables them. Information is transmitted over encrypted HTTPS connections.

Where data is stored may be processed in the country or region where that service operates. ConneCCS does not sell personal information and does not disclose it to third parties for their own marketing purposes.

Information is available to authorized faculty, staff, reviewers, and administrators according to their assigned role and the relevant workflow. Service providers process information only as needed to host or operate the features described above. ConneCCS does not sell personal information or use Google user data for advertising.

Local storage and notifications

The app stores the active session token and a cached account profile in device/browser storage to keep the user signed in. It also saves preferences such as the selected theme and last-visited screen. If a user grants notification permission, the app registers a browser subscription or device push token so that notifications can be delivered. Users can disable browser or device notifications in their operating-system or browser settings and can sign out to end the app session.

Retention and account requests

ConneCCS records are retained for as long as they are needed for the College’s academic, performance-management, administrative, security, and records-management purposes, including applicable institutional retention requirements. No fixed deletion period is represented here. Users may request access to or correction of their account information, or ask about deletion, through the College’s Data Protection Officer. A deletion request may be limited by institutional recordkeeping obligations. Signing out removes the active session from the device; it does not delete institutional records.

Security

The system uses authenticated accounts, access permissions, protected password credentials, and encrypted HTTPS connections for its public web service. No internet service can guarantee absolute security. Users should protect their credentials and avoid sharing a Drive link to a file unless its access setting is appropriate.

Children

ConneCCS is an institutional work application for authorized CSPC College of Computer Studies faculty and staff. It is not designed or directed to children.

Changes to this policy

This policy may be updated when the system’s features or data practices change. The current version and effective date will be published on this page. Material changes to Google user-data practices will be reflected here before the updated practices are used.

Contact and privacy rights

For questions, access/correction requests, deletion requests, or privacy concerns, contact the CSPC Data Protection Officer at dpo@cspc.edu.ph. You may also contact the College of Computer Studies at ccs@cspc.edu.ph.

See also the ConneCCS home page, the Terms of Service, and the CSPC Privacy Policy.