1. Scope
This Privacy Policy applies to the official We Are Loretto iPhone app and to public WeAreLoretto.com pages opened through the app. The app provides Loretto-area news, community events, weather, directories, jobs, sports information, app alerts, and links to public community resources.
No account is required to browse the main app or use the My Loretto website dashboard. Some optional website features—such as submitting community news, posting a job, or claiming a Business Directory listing—may ask for information needed to process that specific request. Those details are provided voluntarily through the applicable website form or service.
2. Information received
Push-notification information
The app uses Firebase Cloud Messaging, a Google service, to deliver optional push notifications. When notifications are configured, Firebase records the Apple Push Notification service token and associates it with an app-installation identifier used as the Firebase Cloud Messaging registration token. Firebase also receives technical information needed to manage notification subscriptions, such as device model, language, time zone, operating-system version, app identifier, and app version.
Notification preferences
Your choices for Community Alerts, Community News, Food Trucks, and LHS & SLS Sports Final Scores are stored on your device. The preference interface is served by WeAreLoretto.com inside the app, while the app itself applies each choice by subscribing or unsubscribing that installation from the corresponding Firebase notification topic. Community Alerts are enabled by default, while the other categories are optional. The web preference page does not receive your Firebase registration token.
To provide aggregate subscriber counts in the We Are Loretto administration panel, compatible app versions may report an anonymous installation identifier generated for the notification-preferences web view, the device platform, app version and build when available, notification permission status, selected notification categories, and first/last report times. The installation identifier is one-way hashed before it is stored on the server. This subscriber-count system does not store Firebase registration tokens, names, email addresses, phone numbers, or full IP addresses.
Firebase Analytics status
Firebase Analytics is currently disabled in the app’s Firebase configuration. The app does not currently use Firebase Analytics to collect app-usage events. The Firebase Analytics software package is present in the Xcode project, but the current Firebase configuration marks Analytics as disabled. If Analytics is enabled in a future release, this policy and the App Store privacy disclosures will be updated to describe that change.
Public website content and website analytics
The app retrieves public content from WeAreLoretto.com and may display public webpages inside the app. Like most web servers, the site receives standard technical request information needed to deliver a page. Public pages may also use We Are Loretto’s privacy-conscious website analytics system to record page views, sessions, traffic source, device or browser category, language, engagement time, and similar site-usage information.
The website analytics system uses randomly generated browser and session identifiers. Identifiers are privately hashed on the server. The analytics system does not store full IP addresses, names, email addresses, private message contents, form values, or private Trading Post conversation pages. Phone and email link clicks may be counted without storing the phone number or email address that was clicked.
Business Directory claims
If you ask to claim a Business Directory listing, we receive the business you selected, your name, email address, phone number, stated role with the business, and any optional verification details you submit. A privately hashed network identifier may also be stored to limit automated or repeated claim submissions. After a claim is approved, the claim record stores its verification status, access activity, and a one-way hash of the private owner-access token. The raw private token is not stored in the claim database.
Verified owners or managers may choose to publish business contact details, hours, services, a “From the Business” message, and Deals & Specials. Information intentionally entered into those public-profile fields is displayed publicly on WeAreLoretto.com.
My Loretto preferences
The optional My Loretto website dashboard stores your selected topics and favorite sports teams in your browser’s local storage. Those preference selections are read by your browser to customize the page and are not submitted to We Are Loretto or associated with an account. Clearing browser website data or using the Reset control removes those selections.
Weekly poll voting
The website’s optional weekly polls use a long-lived first-party browser cookie and a locally stored random browser identifier to limit voting to one response per browser or device. The server stores privately hashed versions of those random identifiers with the selected answer and voting time. Poll voting does not require a name or email address, and the poll system does not store full IP addresses.
Information you send to support
If you email us for help, we receive the information you choose to include, such as your email address, device details, screenshots, and description of the issue. We use that information only to respond, troubleshoot, protect the service, and maintain necessary support records.
3. How information is used
Information is used to:
- Deliver app alerts and honor your selected notification categories.
- Estimate aggregate active-installation and notification-category subscriber counts for administrative reporting.
- Verify Business Directory ownership or management claims and provide approved owners with private listing-management access.
- Load public news, events, directories, weather, Alerts History, deals, and other community content.
- Operate, maintain, secure, and troubleshoot the app and website.
- Understand aggregate website usage and improve the usefulness of public pages.
- Respond to questions, problem reports, and support requests.
We do not sell personal information. The app does not use information for third-party targeted advertising or cross-app tracking.
4. Service providers and sharing
Information may be processed by service providers that help operate the app and website, including:
- Google Firebase, for Firebase Cloud Messaging and related app-installation services.
- Apple, for App Store distribution, iOS services, and Apple Push Notification service delivery.
- Website and infrastructure providers, for hosting, security, storage, and delivery of WeAreLoretto.com content.
We may also disclose information when reasonably necessary to comply with law, protect users or the public, investigate misuse, or defend the security and integrity of the service.
5. Your choices
- Notification permission: You may allow or deny notifications when iOS asks. You can change that choice later in the iPhone Settings app.
- Notification categories: In the app, open More → Notification Preferences. The web-based preference screen lets you enable or disable individual categories for that device.
- Business owner access: A verified owner or manager may ask We Are Loretto to revoke or replace the private management link. Revoking the claim immediately prevents the existing private token from creating a new owner session.
- My Loretto: Use Edit Preferences or Reset on the My Loretto page to change or remove the topic and team selections stored in that browser.
- Website storage: Clearing Safari or app website data may remove locally stored My Loretto choices, website analytics, notification-preference reporting, and weekly-poll identifiers and start new anonymous browser sessions.
- Support information: You may ask us to delete information you previously sent in a support email, subject to records we reasonably need for security, legal, or operational purposes.
- Stop all app collection: You may disable notifications and remove the app from your device.
6. Retention and deletion
My Loretto preferences remain only in the browser where you saved them until you reset the dashboard or clear that browser’s website data. Notification preferences remain on your device until they are changed, cleared, or the app is removed. The web-based preference page supplies the current category definitions, but it does not store the device’s Firebase registration token. Firebase manages app-installation and notification-token data according to its service operation and retention practices.
Business claim records may be retained while a claim is pending or approved and for a reasonable period afterward for security, dispute resolution, and ownership-change history. Private access tokens can be revoked or replaced at any time. Public business-profile information remains in the directory until it is updated or removed.
Anonymous notification subscriber records are considered active only when they have reported within the administrative reporting window. Records that have not reported for 365 days are automatically pruned from the subscriber-count store.
Public Alerts History entries are community content rather than user profiles. We Are Loretto administrators may hide, restore, or permanently delete those entries. Website analytics are retained for operational and historical reporting. Support correspondence is kept only as long as reasonably useful for responding, troubleshooting, security, recordkeeping, or legal obligations.
Former Trading Post account deletion: People who created an account before the Trading Post was discontinued can use the public Delete Trading Post Account page. After confirmation, the system removes the member profile and sign-in credentials, listings and listing photos, associated private buyer–seller conversations, and a Trading Post new-item email subscription using the same address. A limited non-identifying security record that a deletion occurred may be retained.
To request deletion of other information you directly provided to us, email admin@weareloretto.com and describe the information involved. We may need enough detail to identify the relevant record.
7. Children’s privacy
The app is a general community-information service and is not designed to collect personal information from children. We do not knowingly create profiles of children or knowingly collect personal information from a child through the main app. A parent or guardian who believes a child submitted personal information may contact us to request review or deletion.
8. Security
We use reasonable administrative and technical safeguards appropriate to the information handled, including restricted administration access, protected service credentials, private owner-access tokens stored only as one-way hashes, and encrypted network connections where supported. No internet or storage system can be guaranteed completely secure.
9. Changes to this policy
This policy may be updated when the app, website, service providers, or legal requirements change. The updated policy will be posted at this URL with a revised effective date. Material changes will also be reflected in the app or App Store disclosures when appropriate.
10. Contact
Questions about this policy or the app’s privacy practices may be sent to: