§01
What this covers
This policy applies to the SanghaPath mobile application (the “App”) and sanghapath.com (the “Site”). SanghaPath operates the service and is the controller of the account information described here. Apple, Google, Meta, Firebase, payment providers, email providers, and hosting providers process information under their own terms when the App or Site uses their services.
§02
Information we collect
- Account and profile. An email address and password hash are required for a password account. You may also provide a name, profile image, city, country, language, time zone, gender, date of birth, marital status, biography, interests, education, and profession. These fields support your profile, localization, search, and community features.
- Social sign-in. If you use Apple, Google, or Facebook sign-in, we receive the provider identity needed to authenticate you and any name, email, or avatar the provider shares. We store the linked provider record so you can sign in again. We do not receive your provider password.
- Practice and community activity. The service stores favorites, chant progress, connection requests and connections, conversations, messages, message receipts, and profile or message files that you upload. Public profile fields may be visible to other users according to the App’s connection and privacy rules.
- Notifications. If push notifications are enabled, we store the device token, platform, last-seen time, notification settings, and notification records so we can send and display account, connection, system, and billing notices.
- Subscriptions and payments. For a paid plan, we store the plan, provider (Apple or Google), subscription status and dates, provider transaction or subscription IDs, and billing webhook records. The server may retain signed provider payloads or purchase tokens for reconciliation and fraud review. Payment card numbers are handled by the payment provider; we do not store card numbers.
- Security and operations. Requests to the API and Site may create IP address, user-agent, device, timestamp, authentication, rate-limit, error, and audit records. We use these records to operate the service, prevent abuse, investigate incidents, and meet legal obligations.
Chants, calendar calculations, and place catalogue data are service content. Favorites and chant progress are account data when you use those features; profile and message files are uploaded only when you choose to submit them.
§03
Location and maps
The App asks for “When In Use” location permission only when you use the map’s location control or request a route. With permission, iOS Core Location provides the App with your current latitude and longitude. The coordinate is held in the App to center the map and calculate a route to a selected heritage place, and is used in memory by the map flow. The App does not send that coordinate to SanghaPath’s API or store it in your account.
MapKit and Apple’s mapping and directions services process the map, search, and route request under Apple’s privacy terms. Apple may receive location and technical information needed to return map or directions results. You can deny or revoke location permission in iOS Settings; the rest of the App remains available, but location centering and routes will not work.
A city, country, or time zone that you type into your profile is separate from device location. It is sent to SanghaPath and may be displayed in your profile or used to select calendar and language defaults.
§04
Why we use information
- create and secure accounts, authenticate sign-ins, and recover or delete accounts;
- provide profiles, search, connections, conversations, file uploads, chants, places, and calendar content;
- localize calendar results using your selected country, language, and time zone;
- send notifications you or another user’s interaction has enabled, including connection, message, system, and billing notices;
- verify purchases, provide subscriptions, prevent fraud and abuse, and keep financial records;
- debug, secure, maintain, and improve reliability of the App, Site, and API; and
- respond to support requests and comply with lawful requests.
We do not sell personal information or use it for behavioural advertising. We do not use precise device location to build a profile or target advertising.
§05
Who receives information
SanghaPath personnel and contractors may access information only to operate, secure, support, or administer the service. Other recipients are DigitalOcean and the providers listed in §04, people you communicate with in the App, and authorities or professional advisers when disclosure is required by law, needed to protect rights or safety, or necessary for a transaction such as a reorganization or sale. We require service providers to protect information and process it for the agreed purpose.
§06
Retention
We keep account, profile, practice, community, notification, and uploaded-file data while your account is active and for as long as needed to provide the feature, resolve disputes, enforce terms, prevent abuse, or meet legal and accounting duties. Expired access tokens and short-lived verification or idempotency records are automatically removed. Deleted messages and conversations are purged by the service after 30 days where the retention job can do so. Payment and financial audit records can remain longer because they are retained for accounting, fraud, refunds, and legal requirements. Backups and provider systems follow their own retention cycles.
API and security log retention depends on operational rotation and incident or legal holds. We do not use those logs to create an advertising profile.
§07
Deletion and your choices
Use Delete Account in the App, or use the account deletion form linked from the Site. Requests are verified with a one-time code and your account password. Access is disabled immediately; sessions, device tokens, notification settings, favorites, chant progress, social sign-in links, and connections are revoked or removed. Messages you sent are marked deleted so the conversation can be cleaned up without exposing an active account.
For 30 days, authorized support can restore a deleted account. After that recovery window, identifying profile fields are irreversibly anonymized and the recovery copy of social-provider identities is removed. Billing, fraud, dispute, security, and legally required records may remain in an anonymized or restricted form. Local App data is removed when you delete the App or clear its data; SanghaPath cannot erase data that never left your device.
You may also ask us to correct profile information or provide a copy of account data by writing to privacy@sanghapath.com. We may verify your identity and respond within the period required by applicable law.
§08
Children
The App is not directed to children under 13. We do not knowingly collect an account from a child under 13. If you believe one exists, contact privacy@sanghapath.com and we will investigate and delete it where required.
§09
Changes and contact
We will update the date above when this policy changes. If a change materially affects how we use information, we will provide notice in the App or on the Site where practical. Questions, requests, and complaints can be sent to privacy@sanghapath.com.
§10
Reports and moderation records
When you submit a report, we collect the selected reason, optional details, and the account or content identifiers needed to review it. Reports and moderation audit records are retained for up to 24 months for safety, appeals, and legal compliance, then deleted or anonymized. Access is limited to authorized reviewers.