Privacy
St. Philopater Mercurius & St. Mina
Privacy
How this website handles what you tell it. Last changed 2 September 2026.
This website is run by St. Philopater Mercurius & St. Mina Coptic Orthodox Church in Wayland, Massachusetts. It collects nothing about you until you fill something in, and what it collects then is read by the church office and by the servants who look after that part of the church — nobody else.
There is no advertising on this site, and nothing on it is sold, rented, or shared for anybody’s marketing. This page says plainly what each part of the site asks for, where it goes, and how to ask the office about it.
Simply reading the site
What the site collects on its own
Reading these pages does not identify you. The site carries no advertising trackers, no social media pixels, and no third-party analytics service — not Google Analytics, not any other.
Two things happen without you doing anything:
- Server logs. The site is served by Google Firebase Hosting, which keeps its own records of requests — the page asked for, the time, the browser, and the network address it came from. Those are Google’s operational and security logs, held under Google’s terms; the church does not read them page by page and does not use them to build a picture of anybody.
- Bookstore counts. The bookstore counts which books are looked at and what is typed into its search box, so the people who order stock know what the church is actually asking for. It does this with a random sixteen-character identifier kept in your browser — not a name, not an email address, and nothing that can be traced back to a person. The individual records are deleted after ninety days; only the totals are kept.
The site stores a few things in your own browser, which stay on your device. They are the shopping basket while you are filling it, that random bookstore identifier, a cached copy of the site’s colours so pages do not flash on loading, which stations on the festival tour you have collected, a saved panel width for administrators, and — if you have signed in before — a note that you have, so the sign-in button does not have to guess. Clearing your browser storage removes all of it.
When you write to us
Forms
The contact form asks for your name, an email address, a subject, your message, and a phone number if you would rather be called. It is stored so the office can answer it, and it is answered by the office.
Other forms on the site ask for whatever that form is for, and some let you attach a photograph. Whatever you type is stored as you typed it, together with the date, and — if you happened to be signed in — the account you were signed in as. Staff who have been given the forms area can read submissions and add a note about how one was handled. A submission is kept until the office is finished with it and for as long as the church needs the record of it.
Vehicle registration is different in one way worth naming: the plate, state, make, model and colour you enter, along with your name and a phone number or email address, are sent to Taksis — the church’s own app, running on a separate church system — because that is where the people who need to identify a car in the lot look it up. It is not sent anywhere outside the church.
A form that charges a fee hands the payment to Square. See below.
The bookstore and the offering
Buying and giving
The bookstore. Cards are taken by Square. The card fields on the checkout page belong to Square, and a card number goes from your browser to Square directly — it never reaches this site’s systems, and there is nowhere in them to keep one. What the church stores is the order itself: the name and email address you gave, what you bought, the total, and a postal address if you asked for the order to be posted rather than collected after the Liturgy. Your email address is what the receipt goes to, and giving the order number and that address back is how you look an order up later — the bookstore has no accounts and asks you to make none. Square keeps its own record of the payment under its own privacy policy, and a refund is made through Square by a member of staff.
Giving. The giving page shows Tithe.ly’s form inside our page, but you are dealing with Tithe.ly: what you enter there goes to them, under their privacy policy, and the church receives your contribution record through Tithe.ly rather than through this website. This site does not see or store your card, your bank details, or the amount.
Children
Summer camp registration
When camp registration is open it asks for the most personal information on this site, and it asks for it because the camp cannot be run safely without it. For each child: their name, date of birth, the grade they are entering, shirt size, which days they are coming, any allergies, and any medical note the camp needs — an inhaler, a condition, a medication. For the family: a parent or guardian’s name, email and phone number, somebody else to ring in an emergency and how they are related to the child, and the waiver.
This is read by the administrators who run the camp — the people building groups, taking the register, and standing in the kitchen at lunchtime — and by nobody else on the site. It is not shared outside the church. It is kept for the season and afterwards as the church’s own record of who attended.
Permission to photograph a child for the church’s galleries is asked separately, for each child, and it is recorded with that child’s registration. It is not assumed from anything else on the form.
Nothing on this site asks a child to fill anything in. Camp information comes from a parent or guardian, who can correct it or withdraw it by writing to the office. If you believe a child has sent us something, write and it will be deleted.
Galleries and the livestream
Photographs
Anybody may send a photograph to a ministry’s gallery, without signing in. A photograph you send stays private until an administrator has looked at it and approved it. Once approved it is published on a public page, which means it can be seen by anyone and does not require a sign-in to view.
The published copy is re-encoded rather than passed on as you sent it, and that re-encoding removes everything the file carried besides the picture — the camera and phone details, and any location the photograph was tagged with.
Sending photographs does create an anonymous session in your browser, even though you are never asked to sign in and no account of yours is involved. It holds no name, no email address and nothing else about you; it exists so the church can count how many photographs have come from one browser in a day and stop a flood. Alongside it the church stores a scrambled form of the network address they were sent from — scrambled one way, so that it counts uploads without recording where anybody was. Both are kept for a day.
Large photographs are made smaller in your browser before they are sent. That happens on your own device, and the church only ever receives the smaller copy.
If a photograph of you or of your child is on this site and you would rather it were not, write to the office and it will be taken down. You do not need to explain why.
The Liturgy is streamed on YouTube. The camera is on the sanctuary, but a congregation is sometimes in frame, and a stream that has been recorded stays on the church’s YouTube channel afterwards.
Servants and staff
Accounts
Accounts on this site exist only for the servants and staff who edit it. There is no account for visitors, and nothing on the site asks a parishioner to make one.
Signing in uses the church’s Microsoft account. The password is typed to Microsoft, never to this site, and this site never receives it. What is stored is the account’s identifier, the name and email address Microsoft provides, and which areas of the site that person has been given.
A servant can delete their own account from the account menu. That deletes the sign-in and the record of what they were allowed to administer. It deliberately does not erase who edited what: the note that a page was changed, or a photograph approved, by a particular person stays, because it is the church’s record of what was published rather than a description of anybody. Deleting the account here does not touch the Microsoft account itself, which belongs to the church’s Microsoft tenant.
Named, not summarised
Services this site relies on
Each of these does one job, and each holds what it needs for that job under its own privacy policy:
- Google Firebase — hosting, the database, file storage, and sign-in. Everything the site stores is stored here.
- Google reCAPTCHA Enterprise — how the site tells a real browser from a script before it will read or write anything. It runs on the pages you visit and sends Google signals about the browser and device; Google may set cookies on its own domain in the course of it. It is a check, not a puzzle: there is nothing to click.
- Square — bookstore payments and any form that charges a fee.
- Tithe.ly — the offering, on the giving page.
- Microsoft — sign-in for servants and staff.
- YouTube — the livestream player. Playing a video lets YouTube set its own cookies.
- Google Maps — the map on the contact page.
- Breeze — the church’s own records system, which the calendar reads from. The reading happens on our side; nothing about you is sent to it by your visit.
- Taksis — the church’s app, which receives vehicle registrations.
How it is held
Keeping it, and keeping it safe
The site is served only over an encrypted connection, and a browser that has visited once is told to refuse an unencrypted one. What the pages themselves are allowed to load and reach is restricted to the services named above, so a script injected from anywhere else does not run.
Access is granted one area at a time rather than by a single shared password: somebody given the forms area cannot read camp registrations, and somebody given the camp cannot read the church’s finances. Card numbers are never in the church’s systems at all.
How long something is kept depends on what it is. Bookstore browsing counts are deleted after ninety days. A form submission is kept while the office is dealing with it and for as long as the record is needed afterwards. Orders and camp registrations are kept as the church’s own records. Nothing is kept because it might be useful to somebody one day.
Write to the office
Asking what we hold
You may ask what this site holds about you, ask for it to be corrected, or ask for it to be deleted, and the church will do it. Write to the office — the address and a form are on the contact page, or email info@spsmwayland.org.
Two honest limits. Some records the church keeps as its own history — who published a page, who attended a camp, what an order was for — and those are kept even when an account is deleted. And Square and Tithe.ly hold their own copies of a payment; a request about a payment record has to go to them, and the office will tell you how.
This notice is part of the website itself, so it changes when the site does, and the date under the title above is the date it last changed. There is no mailing list to notify, and the church will not quietly weaken it: if what the site does with your information changes, this page changes in the same breath.
