← Policies and legal

Privacy & data

Privacy Policy

What personal data the Society collects from members, applicants, candidates and website visitors, why we process it, how long we keep it, and the rights you can exercise.

Effective:
September 1, 2026
Last revised:
September 8, 2026
Reading time:
11 min

1.Who we are and how to reach us

The American Computer Society ("ACS", "the Society", "we") is a nonprofit membership corporation with its registered office at 600 Congress Avenue, Suite 1400, Austin, Texas 78701. For all privacy matters the controller of your personal data is the Society itself.

Privacy enquiries, access requests and complaints should be addressed to the Data Protection Officer at privacy@americancomputersociety.com. We answer substantive requests within 30 days.

2.Data we collect

  1. 2.1Account data: name, title and suffix, email address, password hash (Argon2/bcrypt-class one-way hash — we never store your password), and authenticator enrollment metadata for two-factor authentication.
  2. 2.2Membership application data: membership grade applied for, employment and education history, professional referees, supporting documents (CV, transcripts, references) and, for Student Members, the accredited institution and .edu email address used to verify enrollment.
  3. 2.3Identity photograph: the portrait you crop and upload, used solely to produce your membership card and to display your profile in the member portal.
  4. 2.4Assessment data: certification exam attempts, per-question responses, scores, pass/fail outcomes and CPD course progress and completions.
  5. 2.5Transaction data: subscription grade, renewal dates, payment status, invoice records, the last four digits and brand of the card used, and any discount code redeemed. Full card numbers, CVC values and bank credentials are never transmitted to or stored by ACS systems.
  6. 2.6Technical data: IP address, user agent, timestamps of authentication events and portal actions recorded in the Society's audit log, and functional cookie identifiers.

3.Why we process it and on what basis

  1. 3.1Contract: to assess your application, administer your membership, deliver certifications and CPD, issue membership cards, and take payment for subscriptions and examination fees.
  2. 3.2Legal obligation: to keep accounting records, meet tax reporting duties, and respond to lawful requests from competent authorities.
  3. 3.3Legitimate interests: to secure our systems, prevent fraudulent applications and payment abuse, maintain an audit trail of privileged actions in the executive portal, and improve our services. We balance these interests against your rights and document the assessment.
  4. 3.4Public task and professional standards: to maintain the register of members in good standing, verify post-nominal entitlement (AACS, MACS, FACS) on request, and administer complaints and disciplinary procedures under the Code of Conduct.
  5. 3.5Consent: for optional marketing email, chapter and specialist-group mailings, and any non-essential analytics. Consent can be withdrawn at any time in the member portal without affecting your membership.

4.Payment processing

Subscription and examination payments are processed by Stripe, Inc., a PCI DSS Level 1 service provider, acting as an independent controller for fraud prevention and as our processor for payment execution. Card details are captured inside a Stripe-hosted iframe on our checkout page; the card data never enters the ACS document object model, our servers, or our logs.

We receive from Stripe a payment identifier, the outcome, the card brand and last four digits, the billing country and any tax collected. Stripe's own privacy notice at stripe.com/privacy governs its independent processing.

5.Who we share data with

  1. 5.1Stripe, Inc. (payments, subscription billing, tax calculation and remittance).
  2. 5.2Our cloud infrastructure and managed database provider, which hosts application data in US regions with encryption at rest and in transit.
  3. 5.3Transactional email providers used to send account, application, examination and renewal notices.
  4. 5.4Printful, Inc. where you purchase merchandise; your shipping details are passed to fulfil that order only.
  5. 5.5Professional advisers, auditors and regulators where required by law or to establish, exercise or defend legal claims.
  6. 5.6We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use member data to train third-party machine learning models.

6.Retention

  1. 6.1Active member records: retained for the duration of membership.
  2. 6.2Lapsed or resigned members: core register entry (name, grades held, dates) retained for 7 years to verify past standing and post-nominal claims; supporting application documents deleted 24 months after lapse.
  3. 6.3Unsuccessful applications: retained 12 months, then deleted, except where a complaint or appeal is open.
  4. 6.4Examination scripts and CPD records: retained 5 years to support certificate verification and awarding-body integrity checks.
  5. 6.5Financial and tax records: retained 7 years as required by federal and Texas law.
  6. 6.6Audit log entries: retained 24 months, then aggregated and the identifying fields removed.

7.Your rights

  1. 7.1Access a copy of your data, including a machine-readable export of your profile, application and assessment history.
  2. 7.2Correct inaccurate data — most fields are directly editable in the member portal.
  3. 7.3Delete your data, subject to the retention obligations above; deletion terminates membership and forfeits post-nominal entitlement.
  4. 7.4Object to or restrict processing carried out under legitimate interests.
  5. 7.5Withdraw consent to marketing at any time.
  6. 7.6Residents of California, Colorado, Connecticut, Texas, Virginia and other states with comprehensive privacy statutes may exercise the equivalent state rights, including the right to appeal a refused request; appeals go to the Corporate Secretary.
  7. 7.7Where data is transferred outside the United States, we rely on Standard Contractual Clauses and apply supplementary technical measures including encryption in transit and at rest.

8.Security

Access to member data is governed by row-level authorization at the database layer, not merely in application code: a member can read only their own record, and executive access is granted by explicit role assignment that is itself audited. Privileged actions in the executive portal are written to an immutable audit log with the actor, timestamp and affected membership number.

Two-factor authentication with a TOTP authenticator app is available today and becomes mandatory for every account from January 1, 2027.

9.Children

Society services are intended for individuals aged 16 or over. Student Membership requires enrollment at an accredited institution. We do not knowingly collect data from children under 13; if we learn we have, we delete it promptly.

10.Changes

Material changes to this policy are announced to members by email at least 30 days before they take effect, and prior versions are retained on request so you can see what changed and when.

Questions about this policy?

Write to the Office of the Corporate Secretary, American Computer Society, 600 Congress Avenue, Suite 1400, Austin, Texas 78701.

Contact the Society →