Business Student Society
Privacy
What a member account holds, who can see it, and what this site knows about a visitor who never signs in, which is only that somebody came.
Last updated 22 September 2026
In short
Browsing this site asks nothing of you. No account, no form, no advertising, and the only measurement is the site counting its own visitors, with no cookie and nothing that identifies you.
Making a member account asks for three things: your name, your email address and a password. The password never leaves your browser, and we never see it.
The member list is read by the society committee and by nobody else. Ask us to delete your account and it goes.
Who we are
The Business Student Society is the student society of the Suliman S. Olayan School of Business at the American University of Beirut, founded in 1965.
This page covers this website and the member accounts made on it. It does not cover Instagram, an email thread, or an event run with a partner, each of which is handled by whoever runs it.
Reach us at [email protected] or on Instagram at @businessstudentsociety. Either one is enough to ask what we hold, to correct it, or to have it deleted.
If you never make an account
Nothing about you is collected. There is no contact form on this site, no newsletter box and no comment field.
There is no Google Analytics, no Meta pixel and no session recorder, and nothing measures what you read here. The site does count how many people open it, by itself: the first time a page opens in your browser it tells the site once, and the site adds one to that day's number of visitors. No cookie is set, no page address or referrer is sent, and no network address or identifier is kept for it, only how many people came each day. With Do Not Track switched on, nothing is sent at all.
The one thing the site writes into your browser before you sign in is a small mark saying your browser has been counted, so it is never counted twice. The cookies page describes it.
What a member account holds
Five fields, and no sixth:
- Your name, exactly as you type it, because it is what the card shows and what the committee searches by.
- Your email address, which is how you sign in and how we reach you about the card.
- A search key built from your name, lowercased and without accents, so a committee member looking you up finds you by any part of it.
- An expiry date for the membership, set by the committee when the card is issued or renewed.
- The date the account was made.
Your password is not in that list and never reaches us. Your browser turns it into a one way proof before anything is sent, and the site keeps only a keyed fingerprint of that proof, which cannot be turned back into the password.
While you are signed in, the site also keeps a record of the session: when it began and when it was last used, so it can end it on time. It holds no address and no device detail.
What we do not ask for
No student ID number, no date of birth, no phone number, no address, no payment detail and no photograph.
Nothing is asked for that the card does not need, and the card needs a name and a way to reach you.
Who can read it
You can read your own record, and we correct your name when you ask. You cannot move your own expiry date, and neither can anybody else who is not on the committee.
The committee account can read the member list, set expiry dates, clear a forgotten password so you can make a new one, and delete an account. That is enforced by the site's own server on every request rather than by the screen, so a modified page cannot get past it. The committee never sees a password, yours or a new one.
Nobody else. The list is not sold, shared with a sponsor, handed to a recruiter, or used for anything but the membership card and the society's own communication about it.
Sponsors and discounts
A discount is honoured in person, by showing the card. The sponsor sees the card and your name on it, in the way any shop sees a customer.
No sponsor receives your details from us. There is no list handed over, no code that reports back, and nothing that tells us or them which offers you used.
Where it is kept
With Cloudflare, in a database that belongs to this site alone and is reached only through the site's own server. Cloudflare serves the website too, and keeps the member accounts and the daily visitor count as our processor: it stores what we put there and does not use it for anything of its own. It also keeps the ordinary server records any web host keeps while serving a page.
Until 22 September 2026 member accounts were kept in Google's Firebase. That database has been deleted, and the accounts made there were not carried over: anybody who had one makes a new one.
How long it is kept
While your account exists. A lapsed membership is not a deleted account: the card simply stops showing, and renewing brings it back without retyping anything.
A session ends after thirty days without use or six months in all, whichever comes first, and at once when you sign out.
The visitor count keeps one number per day. The key that stops a browser being counted twice in one day is deleted two days later.
Ask us to delete the account and we delete the record, the account and every session with it. Email [email protected] from the address you signed up with.
Your rights
You can ask us at any time to:
- tell you what we hold about you and send you a copy,
- correct anything wrong in it,
- delete your account,
- stop using it for something you object to.
Lebanon's Law 81 of 2018 on electronic transactions and personal data gives you these rights here, and the GDPR gives you the same ones if you are reading this from Europe. Asking costs nothing and we do not ask why.
Security
The site is served over HTTPS. The account and committee pages carry a content security policy that blocks any script from an origin that is not ours and lets them talk to nobody but this site, and neither page contains an inline script for that policy to have to allow.
Passwords are stretched in your browser before anything is sent, and a run of wrong guesses at one account is held off for fifteen minutes.
The committee screen ships as encrypted code rather than as a readable page, so what it looks like and which address opens it are not published beside the site.
If something goes wrong with data we hold about you, we will tell the people affected rather than hope nobody notices.
Changes
If this page changes, the date at the top changes with it, and the version badge in the footer tells you which build of the site you are reading.