🔒 Visitor and contributor privacy

Privacy should be proportionate, transparent and limited to what the service genuinely needs

This policy explains what information may be collected when you browse the site or submit research material, why it is used, how long it may be kept, and what choices are available to you.

Public browsing does not require a user account Contact details are used for review, not public display Spam prevention may use IP and technical logs
01

Scope and Privacy Approach

This policy covers public visitors, contributors and research submissions.

The public site can generally be browsed without creating a personal account. Personal information is mainly received when a visitor voluntarily sends a comment, correction, GPS or location suggestion, photograph, reference, contact message or other research contribution.

The project follows a data-minimization approach: collect only what is reasonably needed to operate the service, review contributions, prevent misuse, maintain research accountability and respond to the contributor.

Important notice

Do not include private, confidential or unnecessary personal information in a public comment, caption, correction description or uploaded file.

02

Information That May Be Collected

The information depends on how you use the website.

CategoryExamplesWhy it may be used
Information you provideName, email or contact detail; comment text; correction explanation; map link; reference; image caption; source or photographer credit.To review the submission, request clarification, provide attribution when requested and maintain a research record.
Submitted filesPhotographs, screenshots or other evidence, including file name, size, type and technical metadata.To assess relevance, authenticity, safety, copyright context and suitability for publication.
Technical dataDate and time, browser or device information, requested page, anonymous session identifiers, referrer, broad masked network prefix and locally resolved country; exact IPs may remain in limited server security logs.To deliver the site, understand anonymous visitor journeys and traffic sources, improve search and pages, diagnose errors, prevent abuse and maintain operational logs.
Preferences and local activitySelected language, session state, favourites or viewed-profile history stored in the browser where such features are enabled.To preserve language and interface choices and provide optional convenience features.
Editorial recordsSubmission status, moderator notes, approval or rejection outcome, associated shrine code and timestamps.To maintain a transparent internal review process and avoid repeatedly processing the same issue.
03

How Information Is Used

Information is not collected for unrelated commercial profiling.

  • Display requested pages, remember the selected language and operate essential website functions.
  • Review comments, corrections, location suggestions, references, photographs and other contributions.
  • Contact a contributor when clarification, permission or additional evidence is needed.
  • Prevent spam, automated abuse, malicious uploads, duplicate submissions and attacks on the service.
  • Maintain internal audit, moderation, backup and error records needed for research and technical accountability.
  • Credit an approved original photograph or field contribution when the contributor has requested public attribution.
  • Improve search, accessibility, page performance and the accuracy of published records using aggregated or non-identifying information.
04

Cookies, Sessions and Browser Storage

Some small data items are necessary for security and user preferences.

The site may use essential cookies or session identifiers to protect forms, maintain language and session state, prevent cross-site request forgery and support administrative authentication. These are operational rather than advertising cookies.

The site uses privacy-minimised first-party analytics identifiers to distinguish a visit, understand first and returning visits, page journeys, internal searches, referrers, devices and approximate country. Exact raw IP addresses are not stored in the analytics dashboard or sent to a third-party geolocation API. Clearing browser data resets the anonymous visitor identifier; browser Do Not Track is respected where configured.

05

Comments, Corrections, GPS and Image Submissions

Research submissions are private until an editorial decision makes specific content public.

Submitted material first enters an administrative review process. A pending comment, correction, GPS suggestion or photograph is not publicly visible merely because the upload succeeded. Administrators may review the content, source, location, copyright information, technical metadata and related record before approval.

If a submission is approved, only the relevant public content is displayed. Private email addresses, phone numbers, IP addresses, moderation notes and other unnecessary personal details are not included in the public shrine record.

Image metadata

Approved images may be resized, converted or stripped of unnecessary metadata, including embedded location data, before public display.

06

Sharing and External Services

Personal information is not sold to advertisers.

  • Personal information is not sold or rented for advertising purposes.
  • Hosting, email delivery, security, backup or technical service providers may process limited information only as needed to operate the service.
  • Information may be disclosed when reasonably necessary to investigate abuse, protect the service, comply with a lawful requirement or defend legal rights.
  • Public pages may link to Google Maps, OpenStreetMap, scholarly websites, social platforms or other external services. Visiting them is governed by their own privacy policies.
  • An embedded or linked map may cause the visitor’s browser to communicate with the relevant map provider; the exact behavior depends on the final implementation and provider configuration.
  • Research collaborators may receive non-public evidence only when necessary for verification and subject to appropriate confidentiality and source handling.
07

Retention and Deletion

Different records require different retention periods.

Spam and routine technical logs may be deleted or rotated when no longer needed. Pending submissions may be retained while they are reviewed. Approved evidence, correction history and moderation decisions may be kept longer because they explain the provenance and evolution of a historical record.

A contributor may request removal or correction of personal contact information, subject to the need to preserve a lawful, secure and understandable research audit trail. When possible, personal details can be removed while the non-personal historical evidence or published correction is retained.

Record typeGeneral approach
Session and security dataKept only as long as operationally or legally necessary, with routine rotation where configured.
Rejected spam or abusive submissionsMay be retained temporarily or in limited form to prevent repeated misuse.
Pending contributionsKept during review and for a reasonable period needed to resolve the submission.
Approved research evidenceMay be retained as part of the record’s provenance, attribution and revision history.
Public credit informationDisplayed until the material is removed, the credit is corrected, or a justified request is processed.
08

Security and Data Quality

Reasonable safeguards reduce risk but no internet service can promise absolute security.

  • Use secure hosting, HTTPS, strong administrative authentication and restricted access to non-public submissions when the site is deployed live.
  • Validate uploaded file type and size, generate safe file names and prevent direct execution of uploaded content.
  • Use rate limits, honeypots and duplicate checks to reduce automated spam and abuse.
  • Keep software, dependencies, backups and server configuration maintained and reviewed.
  • Avoid placing private credentials, raw database backups or environment files in the public web directory.
  • Limit administrative access to individuals who need it for research, moderation or technical maintenance.
No absolute guarantee

Reasonable technical and organizational precautions are used, but transmission and storage on the internet always carry some residual risk.

09

Your Choices and Requests

Visitors can browse with minimal disclosure and may contact the project about their submitted data.

  • Do not provide optional contact information when it is not needed for the type of submission.
  • Ask that public credit use a chosen name or that no public credit be displayed.
  • Request correction of inaccurate personal details connected to a submission.
  • Request removal of unnecessary personal contact information, subject to legal, security and research-record requirements.
  • Clear cookies or browser local storage through browser settings, understanding that language, session or viewed-history preferences may be lost.
  • Avoid following external links if you do not wish to interact with the external provider’s data practices.
10

Children and Sensitive Information

The website is a general research resource and does not seek sensitive personal profiles.

The public service is not designed to collect personal information from young children. A child should not submit contact information, private photographs or personal documents without the involvement of a parent or guardian.

Contributors should not submit medical, financial, identity, political, sectarian-affiliation or other sensitive personal data about living individuals unless there is a clear lawful and research necessity. Historical statements about public figures are handled as research content, but unnecessary private details about living persons should be avoided.

11

Policy Changes and Contact

The policy should evolve when website features or service providers change.

This policy may be updated when new forms, image uploads, email notifications, analytics, hosting arrangements, user accounts or other features are introduced. Material changes should be reflected on this page with an updated version or effective date.

Questions about privacy, public attribution, submitted data or removal requests can be sent through the project’s Contact and Feedback page once official contact details are published.

Deployment reminder

Before live launch, the final domain, hosting provider, official contact address, analytics choice and actual retention settings should be reviewed against this policy.