Catholic Intelligence A work of service to the Church

Legal

Privacy Policy

What this record asks of you, what it does with it, and what it will never do with it.

Effective: 6 August 2026 · Last updated: 6 August 2026 · Version: 1.0

In short

We ask for a name and an email address so that a person can decide whether to open a door, and so that we can write back. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we run no advertising network. Analytics are aggregate and cookieless. The record of the Church that this site publishes is a record of institutions and offices, not a dossier on private individuals.

1. Who is responsible

Ocean Edgewater, LLC, a California limited liability company, operates Catholic Intelligence and is the business and controller responsible for the personal information described here. Write to [email protected] about anything in this policy. The full registered address is provided on request and on every invoice.

2. What we collect, and why

When you ask to enter. Name, email address, and optionally your office or role and a line about what brings you here. We use these to decide on and administer access, and to write back. A person reads every request.

When you register interest in the archive. Email address, organization where you give it, and what you are looking for. We use these to respond, to quote, and to decide which cut of the record to prepare next.

When you buy. Billing details and payment confirmation. Card numbers are collected and held by Stripe, Inc. and never reach our servers.

When you correct the record. What you tell us about a parish, diocese, or institution, and how to reach you if we need to check it.

When you sign in. Your email address and a session cookie that identifies your session. It is strictly necessary for the site to know you are signed in, and it is not used for tracking.

Automatically. Server logs recording the request path, timestamp, user agent, and a salted one-way hash of the IP address rather than the address itself, so that abuse can be rate-limited without our building a re-identification surface. Aggregate, cookieless page analytics.

We do not ask for, and ask that you do not send us, information about health, finances, government identifiers, or the religious beliefs of private individuals. Note that the fact of your interest in this site may itself imply a religious affiliation; we treat contact details given to us as ordinary contact information and do not infer, record, or share any belief from them.

3. Why we are allowed to (legal bases)

For visitors in the United Kingdom, the European Economic Area, and Switzerland, we rely on: contract, to provide access or a Dataset you asked for; legitimate interests, to keep the site secure, to prevent abuse, to understand aggregate use, and to correspond with people who wrote to us, balanced against your rights; consent, where you opt in to anything optional, which you may withdraw at any time; and legal obligation, for tax and accounting records.

4. Who processes it for us

We keep the list of processors short and name them:

  1. Cloudflare, Inc. hosting, delivery, and the database behind the site;
  2. Resend transactional email, including the message that tells us you asked;
  3. Stripe, Inc. payment processing, as an independent controller for its own compliance purposes;
  4. Supabase database services for parts of the record;
  5. PostHog aggregate product analytics.

Each acts on our documented instructions under a written data-processing agreement, except Stripe as noted. We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. We have not done so in the preceding twelve months, including for anyone we know to be under sixteen.

We may disclose information if compelled by valid legal process, to establish or defend legal claims, or to protect the rights and safety of any person; and to a successor in the event of a merger or acquisition, under obligations no less protective than these.

5. How long we keep it

Access requests and the correspondence about them: for as long as the account or invitation stands, and twenty-four (24) months after it lapses. Interest and dataset enquiries: twenty-four (24) months from last contact. Purchase and invoice records: seven (7) years, as tax law requires. Hashed server logs: ninety (90) days. Corrections you send about the record: kept with the record, because the receipt is the point of the correction.

Ask us to erase your information earlier and we will, except where we must keep it for the tax records above.

6. Your rights

If you are a California resident, you have the right to know what personal information we have collected, the sources, the purposes, and the categories of recipients; to request deletion; to request correction; to opt out of sale or sharing, which is moot here because we do neither; and not to be discriminated against for exercising any of these. Categories collected in the last twelve months are identifiers (name, email, hashed IP) and commercial information (what you ordered), collected from you directly.

If you are in the United Kingdom, the EEA, or Switzerland, you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent. You may lodge a complaint with your supervisory authority; we would rather you wrote to us first.

Exercise any right by writing to [email protected]. We answer within forty-five (45) days, and within thirty (30) days where the UK or EU rules apply. We will verify your identity by asking you to reply from the address on file, and we do not charge for a reasonable request. An authorized agent may act for you with written proof.

7. Where it goes

We operate from the United States, and our processors may handle information in the United States and other countries. Where personal information moves out of the United Kingdom or the EEA, it is transferred under the European Commission’s Standard Contractual Clauses and the UK Addendum, with the supplementary measures our processors publish.

8. Cookies

We set a session cookie when you sign in, and an invitation cookie when you follow an invitation link. Both are strictly necessary to keep you signed in and are not used to track you across sites. We set no advertising cookies. Analytics are collected without cookies and in aggregate.

We honour the Global Privacy Control signal where a browser sends one. Because we neither sell nor share personal information, honouring it changes nothing about what we do, and we say so rather than implying a concession we did not make.

9. The record itself, and clergy

The record this site publishes is a record of institutions and public offices: dioceses, parishes, cathedrals, universities, religious institutes, the times at which they offer Mass and confession, and the names and official contact details of those who hold office in them. That information is compiled from what those institutions publish about themselves and from the published references of the Holy See, as described in the Data Provenance and Sourcing Statement.

A bishop’s name, see, and diocesan office are facts about a public office, not private personal data, and we publish nothing about the private life of any cleric or lay employee. If you hold an office named in the record and want a personal detail corrected or removed, write to us and we will act: a correction from an institution about itself outranks every other source we have. Where a name is removed, the office is left standing and blank rather than filled with a guess.

10. Security, children, and changes

Security. Traffic is encrypted in transit. Access to systems holding personal information is limited to those who need it. IP addresses are salted and hashed at ingestion. No system is perfectly secure, and we do not claim ours is.

Children. This site is not directed to children under thirteen (13) and we do not knowingly collect their personal information. Write to us if you believe we have, and we will delete it.

Changes. We publish revisions here with a new version number and effective date. Where a change is material, we will say so at the top of this page for at least thirty (30) days, and notify account holders by email.