Privacy and retention policy
Last changed 2026-09-13
What this page is
QNN HQ is operated by the San Diego Amateur Radio Council (SANDARC) for amateur radio clubs to run their on-air nets. This page says what we store about you, who can see it, how long we keep it, and how to have it removed. Contact for anything on this page: [email protected].
1. Who this covers
- Visitors who read public pages without an account.
- Operators with an account.
- Roster participants: callsigns a club keeps on its roster, whether or not that person has an account.
- Stations logged during a net: any callsign a net control operator logs as checking in.
2. What we store
If you make an account: your username, email address, a hashed password (we never store the password itself), when you signed up, when you agreed to this policy, and when you last signed in, your callsign, your FCC Registration Number (FRN) and licence status and class as reported by the FCC licence database, the licensee name from that record, your Maidenhead grid square (a location about 5 km across, chosen by you), your time-format choice, and your notification choices.
If you turn on a second factor: the authenticator secret, encrypted under the site's key, and hashed recovery codes. If you add a passkey: its public key, credential id, the nickname you gave it, and when it was last used. Neither lets us sign in as you.
If a club seats you as a member: your role in that club (club admin, net control operator, viewer, or member), any officer title the club gives you, and when you were seated.
If you are on a club's roster: your callsign, name, licence class, and, if the club recorded them, an email address and phone number, plus your position in roll-call order and which nets you asked to be reminded about.
When you check into a net: your callsign, the name and licence class the net control operator recorded or looked up, your operating mode (mobile, portable, and so on), whether you had traffic, and any location (QTH), signal report, comment or club-defined field the operator typed, with the time it was logged. Corrections and voids are kept as a record rather than erased.
If you follow a club: which club and when.
If you link a Discord account: your Discord user id and username, and when you linked it. We ask Discord for nothing else.
If you post in a club's forum: your posts, when they were written, edited or removed, and which threads you subscribed to. A post a moderator removes is hidden from the page, but its text stays on the record and in the club's audit trail.
If a club invites you: the email address the invitation went to, the role offered, who sent it, and whether it was accepted, revoked or undeliverable.
If you request something: roster opt-in requests (callsign, name, email, phone, licence class), join requests raised by net control, and callsign-change requests (old and new callsign, the FCC lookup result, any note the deciding admin wrote).
Club records: a club's contact email, grid square, description, and whatever it chooses to publish on its public pages: an about text, founding year, website, meeting information, a public email address, a mailing address, and its officers.
Audit trail: clubs keep a record of who changed what: seating, role changes and removals, officer changes, roster edits and merges, check-ins logged and edited, session cancellations, club settings, invitations, CSV exports, callsign-change decisions, forum moderation, and announcements. These entries hold the before-and-after values, which can include a roster row's name, email and phone, a check-in's full details, and a removed post's text. SANDARC records who is granted or loses a staff role; other staff actions are written to the server log, not to an audit trail.
3. What we do not store
- We do not store your IP address in our database. Addresses are used briefly to rate-limit requests and sign-in attempts (section 6), and appear in server logs until they rotate (section 6).
- We do not read or store the mailing address from the FCC record.
- We do not store payment details; there is nothing to pay.
4. Who can see what
Anyone, without an account:
- Each listed club's public pages: club name, grid square, description, how many members and followers it has, its published nets with their schedules and frequencies, whether a net is on the air right now, and whatever the club has chosen to publish (about, officers by title, callsign and licensee name, schedule, contact). A club can ask not to be listed; its pages then still answer at their address but do not appear in the directory.
- A club's roster, callsign and name only, but only if that club's admins have chosen to publish it. Rosters are private by default. Email, phone, licence class and account details are never shown publicly.
- A public callsign record for each operator whose account is confirmed and whose licence the FCC record shows as active: the callsign, licence class and status from the FCC record, the licensee name, and earlier callsigns the FCC record proves. This is public FCC data, gathered in one place.
- Net schedules through JSON and calendar feeds and embeddable widgets that clubs may place on their own websites.
- Nothing about who checked into a net, who ran it, who follows a club, or what is said in a club's forum is public.
Club admins, net control operators and viewers: the club's roster (callsign, name, licence class), every net's check-in history, live check-ins during a net, attendance statistics, the club's forum and announcements. Club admins and net control operators additionally see roster email addresses and phone numbers. Members (the list-only role) see the forum and announcements.
Club admins: the members list (callsign, role, title), the callsigns and names of the club's followers, pending callsign-change requests from members, and the audit trail. They can download a net's or a session's check-in log as a CSV file.
You: your own check-in history across every club, your roster links, your callsign history, your second-factor and passkey settings, and your notification settings.
SANDARC staff: everything above for every club, plus usernames and invitation email addresses, through an administrative console. Staff do not run nets and do not read club data for any purpose other than operating the service and responding to requests.
5. Third parties that receive data
- FCC licence data via exam.tools. When you sign up or change your callsign, we send the callsign or FRN you typed to the exam.tools licence lookup and receive the public FCC record for it. Results are cached for one day.
- callook.info. When a station not on the roster checks in, we send that callsign to callook.info to fill in the operator's name and licence class from public FCC data. Results are cached for one week.
- Cloudflare. Every request to this site passes through Cloudflare, which carries the connection to our equipment and screens for automated abuse. Cloudflare sees your IP address and the pages you request, and may set its own cookies to remember that you passed its check; its handling of that data is under Cloudflare's privacy policy. We also send email through Cloudflare's email service from the qnnhq.club domain: account verification, roster opt-in confirmation, club invitations, net reminders, follower notices, forum updates, announcements, and a security notice when a second factor or passkey changes. Your email address is shared with it only to deliver the message.
- Discord. If a club connects a Discord webhook, that club's net reminders, end-of-net summaries, new forum threads and announcements are posted to the club's Discord channel. A summary lists the callsigns that checked in (never names, locations or comments). This is each club's choice, not ours. If you link your own Discord account, the platform's bot can send you the same notices as direct messages; that is your choice, switched on your profile, and it works only from a server you share with the bot.
- Hosting. The service runs on equipment SANDARC operates in San Diego, California. Backups stay on that equipment (section 6).
We do not sell data, run advertising, or use analytics trackers.
6. How long we keep things
- Net history (sessions, check-ins, roll calls and the audit entries about them): kept until the club sets a retention horizon. A club admin can set one between 30 days and ninety years; with none set, history is kept indefinitely. Once set, older sessions are deleted nightly.
- Roster opt-in requests that were verified, and join requests that were declined: deleted under the same horizon as the club's net history. Opt-in requests that were never confirmed are deleted 28 days after their link was issued, again only for clubs with a horizon; otherwise they are kept.
- Account sign-ups whose verification link expired (username, email, callsign, hashed password) are kept until another sign-up claims that username, email or callsign.
- Club invitations are kept indefinitely, whether accepted, expired or revoked.
- Roster rows, memberships, follows, forum posts, announcements, the club audit trail, and accounts: kept until removed by the club or by you.
- Notices (on-site notifications, reminder and follower bookkeeping, forum and announcement deliveries): kept with the account or club they belong to; there is no separate expiry today.
- Backups: a database dump is taken nightly and kept for 30 days, and the storage holding it is snapshotted daily with snapshots kept for 4 weeks, all on the same equipment. A deleted record can persist in a backup until it expires.
- Rate-limit counters (which hold a hashed form of your IP address, username or email address): expire within one minute to 24 hours; the 24-hour ones are the daily budgets on how much email one address can ask us to send.
- Server logs (IP address, browser and page requested at the web server; a callsign when a licence lookup fails): each service keeps about 100 MB of log, oldest lines discarded first, which at our traffic is a few weeks. Cloudflare keeps its own logs under its policy.
7. Cookies and local storage
We set a session cookie when you sign in, a CSRF token that protects forms, and a short-lived cookie that carries a one-time status message. Public pages set no cookie of ours at all. Your theme (light or dark) is kept only in your browser's local storage and never sent to us; your clock format (12 or 24-hour) is saved on your profile and mirrored to local storage for public pages. Cloudflare may set its own cookie (section 5). There are no advertising or analytics cookies.
8. Your choices
- Notifications: turn email or on-site notices on or off from your profile; every reminder email carries an unsubscribe link that works without signing in.
- Following and forum updates: unfollow a club or unsubscribe from a thread at any time.
- Roster reminders: ask the club to change your opt-ins, or use the unsubscribe link.
- Callsign: request a change from your profile. If the FCC record matches your FRN it is applied at once; otherwise a club admin or SANDARC decides. Your earlier callsigns stay in your history.
- Delete your account: from your profile, with your password. This removes your account, profile, second factor and passkeys, Discord link, memberships, officer titles, follows, forum subscriptions, notification settings and notices. Roster rows, check-ins, forum posts and audit entries stay with the clubs that hold them, because they are the clubs' records, but they are no longer linked to any account. Reminders you opted into on a club's roster continue until you use the unsubscribe link or the club removes them. If you are the only admin of a club, seat another admin first.
- Anything else: email [email protected]. We answer within 30 days.
9. Security
Passwords are hashed. Connections use TLS. Each club's data is isolated from every other club's at the database level (row-level security). Sign-in attempts are throttled, and you can add a second factor or a passkey to your account. Only SANDARC staff have administrative access.
10. Children
Amateur radio licences are issued without a minimum age. The service does not ask for age and treats every licensee alike. If a parent or guardian wants a minor's data removed, email [email protected].
11. Changes
We note the date of the last change at the top of this page.