Privacy Policy
Last updated: 2026-10-08 · Applies to https://lumbini.info
Lumbini.info ("the Registry", "we") operates a public provenance and consecration registry for sacred artifacts of the Lumbini region. This policy explains what data we collect, why, how it is protected, and the choices you have.
1. Data we collect
- Registry searches. When you verify a registry number, we store the time of the query and a masked IP address (the last octet is removed, e.g. 183.69.238.xxx) for abuse detection and risk flagging. Full IP addresses are never published.
- Contact and discrepancy forms. If you send us a message or report a record problem, we store the name, contact detail and message content you provide. These fields are encrypted at rest (AES-256-GCM).
- Download counts. When you download a certificate or report PDF, we record an anonymous counter (document type and reference number only — no account, no fingerprint).
- Browser local storage. Your language preference and cookie-consent choice are stored in your own browser's local storage. This data never leaves your device.
- Staff accounts. Registry staff authenticate with an account; passwords are stored as salted hashes only.
2. What we do not do
- No tracking or advertising cookies are set.
- No analytics beacons, fingerprinting, or third-party trackers are embedded.
- We do not sell or rent any personal data.
- Artisan personal names are masked (shown as ***) in all public interfaces.
3. Legal basis and purpose
Data is processed to operate the registry: verifying artifact records, preventing fraud and abuse, and responding to inquiries. Query logs with masked IPs are retained for security auditing; contact messages are retained until your request is resolved.
4. Data sharing
We do not share personal data with third parties except where required by law or to protect the integrity of the registry (for example, investigating fraud against the registry).
5. Your rights
You may request access, correction, or deletion of personal data you submitted through our forms by emailing support@lumbini.info. You can decline the consent banner at any time by clearing your browser's local storage, which stops the anonymous download counter for your visits.
6. Security
We use HTTPS encryption in transit, application-layer encryption for submitted contact data, access-gated administration, rate limiting, and security response headers. See our Standards & Oversight page for operational details.
7. Changes
We may update this policy from time to time. Material changes will be announced on this page with a new revision date.
8. Contact
Privacy questions: support@lumbini.info.
← Back to Lumbini.info
// 页脚链接为静态 HTML(可被搜索引擎直接抓取);横幅仅依赖 localStorage,不需要 Vue
// ============================================================================
$sf = isset($_SERVER['SCRIPT_FILENAME']) ? realpath($_SERVER['SCRIPT_FILENAME']) : false;
if ($sf === realpath(__FILE__)) { http_response_code(403); exit; }
?>