← Privacy Policy
Transparency review

Privacy & Security Audit

A plain-language record of the controls verified in CampusVerify as of 30 September 2026.

Scope and status

This is an internal product and code review, not an independent certification, legal opinion, penetration test, or claim of complete security. It covers the current website, authentication, database access rules, survey workflows, payments, and app-email triggers.

Verified controls

Account identity

Every account requires email confirmation. Student accounts additionally require a recognised academic email domain; General/Researcher accounts are email-confirmed but are not academically verified.

Data access

Database access rules separate private account data, survey ownership, responses, administrative tools, and public survey information. Sensitive profile and survey fields are protected from direct user changes.

Roles

Administrative, manager, and faculty permissions are stored separately from user profiles and checked by trusted backend functions.

Survey access

Survey owners control private invitations and progress access. Invitees must register and accept with the same confirmed email address. Super-admin assistance notifies the survey owner.

Payments

Payment confirmation is verified before credits or paid features are granted. CampusVerify does not store full payment-card details.

Transport and credentials

Traffic uses encrypted connections. Password handling is delegated to the authentication provider and passwords are not stored in readable form by CampusVerify.

Data minimisation

Public pages use limited survey information. Lecturer email addresses and sensitive account fields are not available through ordinary public or signed-in data access.

Important limitations

  • Email confirmation verifies control of an inbox; it does not prove how a person completes a survey or guarantee that every answer is truthful.
  • Academic-domain checks establish eligibility for a student account, not a permanent guarantee of enrolment or identity.
  • Survey creators control their questions and may ask respondents for identifying information. Respondents should review each survey before submitting.
  • No online service can promise that unauthorized access, human error, service interruption, or abuse will never occur.
  • Privacy and security controls require ongoing review as the service, its providers, and legal requirements change.

Data flow

  1. Account and profile information is collected during registration and stored in the protected database.
  2. Survey creators define questions and audiences; eligible respondents submit answers through signed-in accounts or authorised invitation paths.
  3. Responses are stored for the survey owner’s analysis. Access links and progress permissions are separately controlled.
  4. Paystack processes checkout details and reports payment status; CampusVerify records the transaction reference and resulting credits or service.
  5. Expected app emails are sent for account and feature events. The sending domain is not an incoming mailbox.

Contact and review

Operator: Vibe Tribe Organisation, Ghana. Privacy or security questions can be sent to campusverify996@gmail.com.

Read the Privacy Policy