Privacy Policy

PRIVACY AND SECURITY

The Texas Tactical Police Officer's Association (TTPOA) is committed to protecting the privacy of its members and visitors. This page describes how the TTPOA collects data from its Web site and how the TTPOA uses this information.

WHAT INFORMATION DOES THE TTPOA COLLECT?

It is the TTPOA's general policy to collect only personal information that the member or visitor knowingly chooses to provide. The following information is collected from all visitors to the TTPOA Web site and is recorded in a log file:

  • Time and date of the visit
  • The IP address, browser, and operating system used
  • The page that is viewed
  • The previous page that was visited

If users choose to use Single Sign On through Google or Microsoft, TTPOA will receive: 

  • The name associated with that profile
  • The email address associated with that profile
  • A cyptographically signed token from the provider that the user sucessfully authenticated into the profile

Single Sign-On (SSO) Authentication

What is Single Sign-On (SSO)?

Single Sign-On (SSO) is a secure authentication method that allows you to access TTPOA using your existing work or personal email account from providers like Google or Microsoft. Instead of creating and remembering a separate username and password for TTPOA, you can use credentials you already trust and use daily. This technology, called OAuth 2.0, is the same secure authentication system used by thousands of organizations worldwide, including federal agencies, banks, and major corporations.

I already have a TTPOA account, can I use SSO?

Yes! If you login to our site via SSO with the same email address your TTPOA account was created with, SSO will be connected to your account automatically. If the system doesn't find your email address, it will prompt you to create a new account. If you want to preserve your old account or used a different email address for our site, login to our site with your normal TTPOA username and password, and then go to "My Profile" to connect any SSO credentials to your account. Read more about connecting your agency account below.

How Does SSO Work with TTPOA?

When you choose to sign in with Google or Microsoft:

  • Step 1: You click "Sign in with Google" or "Sign in with Microsoft" on the TTPOA login page
  • Step 2: You're securely redirected to your email provider (Google or Microsoft)
  • Step 3: You log in using your existing email credentials on your provider's secure website
  • Step 4: Your provider confirms your identity to TTPOA and sends us basic profile information
  • Step 5: You're automatically logged into TTPOA

Important: Your login credentials never pass through TTPOA's systems—you authenticate directly with Google or Microsoft, and they simply confirm to us that you are who you say you are.

What Information Does TTPOA Receive?

When you use SSO, TTPOA receives only the following information from your email provider:

  • Your name (as listed in your email account)
  • Your email address
  • A unique identifier (a cryptographic token that lets us recognize your account)

What Information Does TTPOA NOT Receive?

TTPOA does not and cannot receive:

  • Your password or login credentials
  • Your email messages or inbox contents
  • Access to your files or documents
  • Your browsing history or activity
  • Your contacts or calendar
  • Any private or sensitive information beyond name, email, and profile photo

The OAuth 2.0 protocol is specifically designed to prevent password sharing and limit data access to only what is explicitly necessary. Your email provider maintains complete control over your account security.

Is SSO Secure?

Yes, SSO is highly secure and often more secure than traditional passwords. Here's why:

  • No password storage: TTPOA never stores or sees your password, eliminating the risk of password theft from our systems
  • Single point of security: Your organization's IT security team already protects your email account with enterprise-grade security, multi-factor authentication (MFA), and monitoring
  • Reduced password fatigue: You don't need to create, remember, or change another password, reducing the risk of weak or reused passwords
  • Industry standard protocol: OAuth 2.0 is the gold standard for authentication, trusted by government agencies, financial institutions, and major technology companies
  • Immediate revocation: If you leave your organization, your SSO access to TTPOA is automatically disabled when your IT department deactivates your email account

Can I Use My Department or Agency Email on the TTPOA website?

Yes! If your department or agency uses Google Workspace (formerly G Suite) or Microsoft 365 (Outlook) for email, you can use those credentials to access TTPOA. Your organization's IT department already trusts these platforms with sensitive work communications and data—using them to access TTPOA does not introduce any additional cybersecurity risk. In fact, many IT security professionals prefer SSO because it centralizes authentication and reduces password-related vulnerabilities.

What Happens If I Change Agencies or Leave My Organization?

If you signed up for TTPOA using an organizational email address (such as @youragency.gov) and later leave that organization, you will lose access to your TTPOA account when your IT department deactivates your email. To regain access:

  • If you still qualify for membership and have changed agencies, contact us at [email protected] and send in your new agency credentials and we will migrate your account to your new agency email address. If you have not changed agencies but remain in good standing, email us with that information and we will confirm your status through TCOLE and migrate your account to a personal email address

This security feature ensures that only current members of your organization can access accounts tied to organizational email addresses.

Learn More About SSO Security

For more information about Single Sign-On security from trusted, authoritative sources:

SECURITY STATEMENT

TTPOA's online security program is aligned with the Payment Card Industry Data Security Standard (PCI DSS) and is reaffirmed through an annual self-assessment.

Card payments: TTPOA does not store, process, or transmit cardholder data on its own systems. All online card payments are processed by Authorize.net through a hosted payment form embedded directly from authorize.net—your card number, expiration date, and security code travel from your browser to Authorize.net and never touch TTPOA's servers or database. We retain only the Authorize.net transaction confirmation and the last four digits of the card. We will never ask you to send a card number to us by email, chat, or text message.

While we implement these and other security measures, you should be aware that 100% cyber security is not always possible. The TTPOA reserves the right to make modifications to these Policies without prior notice.