Privacy Policy
Last updated
The short version: this site does not track you. There is no analytics, no advertising, no advertising network, no social media pixel and no tracking cookie. We do not build a profile of you, and we do not sell or share information about you with anyone.
What follows describes what the site actually does today, checked against the running application rather than written from a template. The date this page was last updated is shown at the top.
You do not need an account
Reading prayer times on this site requires no account, no sign-in, no email address and no personal details of any kind. There is no registration form, no contact form and no newsletter anywhere on the public site.
Cookies
The site sets two cookies, both of them its own, and both needed for the site to work at all. Neither is used to identify you, to follow you between sites, or to advertise to you.
| Cookie | What it is for |
|---|---|
| laravel-session | Holds the reference to your browsing session on this site. It is marked HttpOnly (so page scripts cannot read it), Secure (so it is only sent over HTTPS) and SameSite set to Lax (so it is not sent from other websites). It expires after 2 hours. |
| XSRF-TOKEN | A security token that lets the site verify a submitted form came from this site and not from another one. Marked Secure and SameSite set to Lax, and it expires after 2 hours. |
Because these are the only cookies, and both are strictly necessary to serve the site, there is no cookie consent banner. If we ever add a cookie that is not strictly necessary, that will change, and this page will say so before it does.
What the server records
Serving a web page leaves some technical traces. These are the ones this application creates:
- A session record. Alongside the session cookie above, the server keeps a matching record that includes your IP address, your browser's user-agent string and the time of your last request. This is standard framework behaviour and is what makes a session work; it is not used to identify or profile you.
- An error log. When something goes wrong, the application writes a technical record to a log file on the server. That record can include the address that was requested and the internal details of the fault. It exists so that faults can be found and fixed. It is not currently deleted automatically, so we would rather tell you that than quote a retention period the site does not actually enforce.
- Web server logs. The site runs on hosting we do not operate ourselves. Hosting providers normally keep their own access logs, which typically include IP addresses. Those logs sit outside this application and we do not control how long they are kept.
Other companies your browser contacts
We keep this list as short as we can. On a public page of this site, your browser contacts one outside service:
- fonts.bunny.net — the web font the site is typeset in is downloaded from here. Like any request your browser makes, it necessarily tells that provider your IP address and which font was requested. No cookie is set by it, and we send nothing else to them.
Everything else a page loads — its styles, its one small script and the prayer-time data itself — comes from this site's own domain.
What we do not run
Stated plainly, because a privacy policy is most useful when it rules things out:
- No web analytics. No Google Analytics, and no alternative to it. We do not measure your visit.
- No advertising. No ad network, no AdSense, no ad slots, no advertising or measurement cookies, and no personalised advertising.
- No social media buttons, embeds, pixels or share trackers.
- No fingerprinting, and no attempt to recognise you across visits or devices.
- Nothing sold or shared. We do not sell, rent or trade information about visitors, and we do not pass it to advertisers or data brokers.
An honest note about the code. The application does contain optional connections to Google Search Console, Google Analytics and Google AdSense, built for later use. None of them is configured, and none of them is running. No credentials are installed and nothing is sent to Google from this site. They are inert code, not active services, and we mention them so that a reader who looks at the project can see we have not hidden them. If any is ever switched on, this page will be updated to describe it before the change goes live.
Information you choose to send us
If you email us — at info@allprayertime.uk, for a question or to report a prayer time that looks wrong — then we have your email address and whatever you chose to write. We use it to reply to you and to look into what you reported, and for nothing else. We do not add you to a mailing list.
Email reaches us through an ordinary mailbox provided by our hosting provider. Please do not send us anything sensitive: an email is not a secure channel, and a prayer-time report never needs to contain personal information.
If a report you send leads to a correction being published, what appears on the site is the corrected time and the reason for it. Your name and email address are not published.
Administrator accounts
This section applies only to the small number of people who are given an account to run the site. Visitors never have an account, and nothing here applies to ordinary readers.
- An account record holds a name, an email address used to sign in, a securely hashed password and a role. The password itself is never stored in a readable form.
- Changes made through the admin — editing a page, approving a correction, changing a setting — are written to an internal audit record that includes who made the change, what changed and the IP address it was made from. That record is how the site can show that a published time was not altered quietly.
- Anything resembling a password, token, key or credential is filtered out before an audit record is written.
Requests the site makes to other services
To check its own prayer-time calculations, the site sometimes makes requests from the server to independent reference sources — the US Naval Observatory among them. Those requests are started by us, not by your visit, and they contain only a place and a date. No information about you is included in them.
Your rights
Under UK data protection law you have rights over personal information held about you, including the right to ask what is held, to ask for it to be corrected or deleted, and to complain to the Information Commissioner's Office.
In practice there is usually very little to ask for: unless you have emailed us or been given an administrator account, what exists is a short-lived session record and whatever appears in the server logs.
To ask about anything on this page, or to ask us to delete something you sent us, email info@allprayertime.uk.
Changes to this page
This page describes the site as it works on the date shown at the top. If what the site does with data changes — if analytics or advertising is ever introduced, or a form is added — this page will be updated to describe it.
This is a plain description of how the site behaves, written so that a reader can check it against what the site actually does. It is not legal advice.