Privacy
Privacy Policy
Effective date: July 30, 2026. This page describes what the NextCollege codebase actually does — not aspirational or boilerplate language.
Who operates this site
NextCollege is operated by Lorenzo Ferrero. Contact: [email protected].
What we collect
- Standard server request metadata (IP address, request path, user-agent) used transiently for rate-limiting and abuse detection.
- One first-party cookie — see the table below.
- Information you voluntarily submit through the Data Correction & Removal form (name, email, description of your request).
What we do not collect
- No analytics, advertising, or tracking scripts of any kind (verified by code review — none are present).
- No payment information (no payment processing exists on this site).
- No account registration, and no browser local storage is used.
Purpose of processing
Request metadata is used only to keep the site available and to detect and slow down scraping/abuse. The cookie is used only for session continuity. Form submissions are used only to act on your request.
Providers
- Supabase — hosts the program and staff directory database.
- Upstash (Redis) — hosts distributed rate-limit counters; falls back to a temporary in-memory counter if not configured.
No analytics, advertising, or email-delivery providers are integrated at this time.
Cookies
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| nc_sid | NextCollege (first-party) | Anonymous session identifier used for rate-limiting and abuse/bot detection. Not used for advertising, profiling, or analytics. | 365 days |
This cookie is strictly necessary for the site to function and is set directly by NextCollege (not by any third party). Because no non-essential cookies, analytics, or advertising technologies are used, no cookie-consent banner is shown.
Analytics
No analytics of any kind are currently in use.
Security
Database credentials are used only on the server and never shipped to the browser. All directory and staff-lookup endpoints are rate-limited and monitored for abusive/automated traffic. Security response headers (Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-Frame-Options) are applied site-wide.
Retention
Rate-limit counters expire automatically (from seconds to 24 hours, depending on the counter). Server logs are retained according to the hosting platform's own log-retention settings. Data Correction & Removal submissions are retained only as long as needed to resolve the request.
Your rights: access, correction, and removal
To request access to, correction of, or removal of information about you or an institution you represent, use the Data Correction & Removal form.
International transfers
Our hosting and database providers may process data in the United States and/or other countries where they operate infrastructure.
Children's privacy
NextCollegeis not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us via the Data Correction & Removal form and we will remove it.
Changes to this policy
We may update this policy as the site changes. Material changes will update the effective date above.
Contact
Questions about this policy: [email protected].
Last updated: July 30, 2026