Privacy Policy
ConneCCS - Target Monitoring System · CSPC College of Computer Studies · Effective September 30, 2026
This policy explains how ConneCCS - Target Monitoring System ("ConneCCS") handles information when authorized faculty and staff use the web application. ConneCCS supports performance commitments and reviews, office and individual accomplishments, reportorial requirements, document submissions, and college coordination. The app is maintained by the College of Computer Studies of Camarines Sur Polytechnic Colleges (CSPC).
Summary
- What is collected: account and profile details (name, institutional email, role), performance records you enter or that reviewers enter about you, files you upload, messages and announcements you send, and basic device or browser data needed to keep you signed in and deliver notifications.
- Where Google data is used: Google sign-in is used only to authenticate your account. A Google Drive connection, available only to authorized administrators, is used to store and manage the system's documents. Google user data is never sold and is never used for advertising.
- Who can see your information: other authorized faculty, staff, reviewers, and administrators, but only within the role and workflow that concerns them.
- How long it is kept: for as long as the College needs the records for academic, performance-management, administrative, security, and records-management purposes.
- Your rights: you may request access to, correction of, or deletion of your information by contacting the CSPC Data Protection Officer. Some deletion requests may be limited by institutional recordkeeping obligations.
Information the system handles
Depending on the features used and the account’s assigned role, ConneCCS may process:
- Account and profile information: name, institutional email address, password credential (stored as a protected hash), profile image, phone number when supplied, department, position, and role or access tags.
- Performance and work records: OPCR/IPCR commitments, targets and indicators, accomplishments, ratings, comments, signatory details, review/approval status, and related dates.
- Documents and submissions: files and file details uploaded for reportorial requirements, templates, supporting records, and the submission history associated with them.
- Communications and support: messages, announcements, notification preferences, and any support report text, screenshots, or app context that a user chooses to send.
- Device and session data: authentication tokens, browser push subscriptions or device push tokens when notifications are enabled, and app preferences stored on the user’s device or browser.
Google data and Google APIs
Google sign-in. If a user chooses Google sign-in, ConneCCS sends the Google-issued sign-in token to Google for verification and uses the returned Google account identifier, verified email address, and available basic profile name or image to authenticate the user and associate the ConneCCS account. The app does not request Gmail or Google Contacts access for sign-in.
Exact permissions requested. ConneCCS requests only the following Google permissions:
| Permission | Where it is used |
|---|---|
openid email profile (Google Sign-In) |
Sign-in only: to confirm who is signing in and match the Google account to a ConneCCS account. |
https://www.googleapis.com/auth/drive (Google Drive) |
Administrator-only document storage: to create, list, read, upload, download, organize, share, and delete reportorial files in the repository configured for the College. It is not used to read the administrator's unrelated personal files outside that repository. |
Google Drive integration. Separately from sign-in, an authorized administrator can connect a Google Drive account for configured document workflows. The integration uses Google Drive API access to list relevant file metadata and to upload, download, or delete files in the configured repository as directed by system workflows. The server stores the administrator-authorized refresh credential so it can perform those operations. Drive file contents are used to provide those document features, not for advertising.
What ConneCCS does not do with Google data. Google user data is not sold, not shared with advertisers, not used to build advertising profiles, and not used to determine a person's eligibility for any benefit. It is not used for automated decision-making.
Some files uploaded through the current Google Drive document workflow may be assigned an “anyone with the link can view” permission when Google Drive allows it. Anyone who obtains such a link may be able to view that file. The link is used by the document workflow; users should upload only files approved for this sharing setting. This link-sharing behavior does not apply to Google sign-in profile data.
ConneCCS’s use and transfer of information received from Google APIs will be limited to providing or improving the user-facing features described here, and will comply with the Google API Services User Data Policy, including its Limited Use requirements.
Why information is used
- To create and authenticate accounts, verify institutional email addresses, and enforce role-based access.
- To record, review, route, and report performance commitments, accomplishments, ratings, and administrative submissions.
- To provide messaging, announcements, reminders, notifications, and user-requested support.
- To store, retrieve, or manage files through the configured document storage integrations.
- To protect account security, diagnose service issues, and maintain system operation.
How information is stored and shared
Account and system records are stored by the ConneCCS service and its configured hosting/database infrastructure. The web application is hosted on Railway (a Railway.app subdomain), and the API and database it connects to are also operated by the College. Files managed through the Drive integration are stored in the College's connected Google Drive repository. The app may use Google for sign-in, Google Drive for the authorized file workflows, and Expo or browser push services to deliver notifications when a user enables them. Information is transmitted over encrypted HTTPS connections.
Where data is stored may be processed in the country or region where that service operates. ConneCCS does not sell personal information and does not disclose it to third parties for their own marketing purposes.
Information is available to authorized faculty, staff, reviewers, and administrators according to their assigned role and the relevant workflow. Service providers process information only as needed to host or operate the features described above. ConneCCS does not sell personal information or use Google user data for advertising.
Local storage and notifications
The app stores the active session token and a cached account profile in device/browser storage to keep the user signed in. It also saves preferences such as the selected theme and last-visited screen. If a user grants notification permission, the app registers a browser subscription or device push token so that notifications can be delivered. Users can disable browser or device notifications in their operating-system or browser settings and can sign out to end the app session.
Retention and account requests
ConneCCS records are retained for as long as they are needed for the College’s academic, performance-management, administrative, security, and records-management purposes, including applicable institutional retention requirements. No fixed deletion period is represented here. Users may request access to or correction of their account information, or ask about deletion, through the College’s Data Protection Officer. A deletion request may be limited by institutional recordkeeping obligations. Signing out removes the active session from the device; it does not delete institutional records.
Security
The system uses authenticated accounts, access permissions, protected password credentials, and encrypted HTTPS connections for its public web service. No internet service can guarantee absolute security. Users should protect their credentials and avoid sharing a Drive link to a file unless its access setting is appropriate.
Children
ConneCCS is an institutional work application for authorized CSPC College of Computer Studies faculty and staff. It is not designed or directed to children.
Changes to this policy
This policy may be updated when the system’s features or data practices change. The current version and effective date will be published on this page. Material changes to Google user-data practices will be reflected here before the updated practices are used.
Contact and privacy rights
For questions, access/correction requests, deletion requests, or privacy concerns, contact the CSPC Data Protection Officer at dpo@cspc.edu.ph. You may also contact the College of Computer Studies at ccs@cspc.edu.ph.
See also the ConneCCS home page, the Terms of Service, and the CSPC Privacy Policy.
