Privacy Policy
What Broadview Heights Today records about you, what other people can see, and how to stop it.
This page describes Broadview Heights Today, run by [REVIEW: operating entity legal name]. In force from [REVIEW: effective date].
We have written it by going through the site's own code rather than filling in a template, so it says what actually happens. Where something has not been decided yet, it says that too.
If you only read the site
You do not need an account to read the directory, a business page or a review. We do not ask you to identify yourself and we do not build a profile of you. The pages described here do not load advertising or analytics scripts belonging to other companies.
Like any web server, ours records the ordinary details of requests it serves. Some parts of the site also count requests to hold off bots — see stopping abuse below for exactly what those counters contain.
What you give us when you join
- Your email address. We need it to confirm the account and to sign you in.
- A username. This is public — it is what appears on your reviews if you do not set a display name.
- A password, which we store scrambled (hashed). We cannot read it and neither can anyone who steals the database file.
- The date you joined, and the date you were last active.
- A record that you agreed to these terms — which document, which version, when, and the network address you agreed from, kept in full. This is the one place we deliberately keep an unscrambled address alongside your account, because a record of agreement that cannot say where and when it happened is not worth keeping. It is written when you join and again any time we change these pages and ask you to agree. We never edit or delete these rows, including when an account is closed.
What you can add to your profile
All of these are optional, and all of them are public if your profile is public:
- A display name, to be shown instead of your username.
- A short bio.
- A location, in your own words.
- A link to your own website.
- A profile picture.
There are two switches next to them. “Show my profile” takes your profile page off the public site when you turn it off. “Show my email address” is off unless you turn it on — and even when it is on, your address is only shown to visitors who are signed in, so it is not sitting there to be scraped.
Member profile pages are marked do not index for search engines unless this hub deliberately turns that on. Writing a review about a restaurant is not the same as asking to be a search result for your own name.
What you write
- Reviews — the star rating, the text, and when you wrote it. Public, with your display name next to them.
- Earlier versions of a review you edited. We keep them. They are not shown on the site; they exist so that a review which was quietly rewritten after an owner replied to it can still be understood.
- Comments on business posts and on reviews. Public.
- Business listings you create — everything in them is meant to be published, including the address, phone number, email and website you type in.
- An ownership claim — your contact name, a contact phone number, and whatever you write to show the business is yours. This is not published. A moderator reads it.
- Business posts — offers, events and updates. Public while they are live.
- Reports you send about somebody else's content — which item, the reason you picked, and your notes. Not published. Moderators see it.
Photographs
When you upload a picture — a profile photo, a logo, a gallery shot — we do not store the file you sent. We decode it and write out a fresh one. That is a safety measure, and it has a useful side effect: the camera data attached to the original, including any GPS location, does not survive. Only the pixels do.
The picture we write out is a file in the site's public media folder with a random name. Anyone who has the link can fetch it, whether or not they are signed in and whether or not they came from the page it is on. That is how pictures on the web work, but it is worth saying plainly: do not upload a photograph you would not want handed around.
When a picture is deleted we remove the file from the server as well as the record of it, so the link stops working. If the file itself cannot be removed for some reason, the record of the deletion says so plainly rather than claiming success, and a moderator is told to finish the job by hand. We would rather tell you that than pretend a file is gone when it is not.
Signing in
Every sign-in attempt is recorded — the ones that work and the ones that do not. Each record holds the date, the address your connection came from, the browser identification string your browser sent, what was typed in the email or username box, and whether it succeeded.
This is the record that lets us tell “you forgot your password” from “somebody is working through a list of passwords on your account”. It is deliberately not deleted when an account is deleted, because a security record that disappears the moment the attacker closes their account is not a security record.
- “Remember me.” If you tick it, we store a token in your browser and a matching one here, and it lasts 30 days. Signing out clears it.
- One-time sign-in links. If you ask for one, we email a link that works once and expires after an hour.
- If somebody tries to register using your address, we email you to say so — with the date and the address the attempt came from — and we do not create a second account. We do not tell them whether you have an account here.
Stopping spam, bots and mail-bombing
A site where anyone can type an email address into a form is a site that can be pointed at a stranger's inbox. Several small counters exist to stop that, and they are worth describing exactly. Sign-in records and the agreement record described below are the two places we keep a network address in full; everywhere else it is scrambled or not kept at all.
- We do not store your IP address against anything you post. When you post a review or a comment we store a one-way fingerprint of it instead, scrambled with this site's own secret key. It cannot be turned back into an address, and it is useless on any other site. It lets us notice several accounts posting from one connection; it does not let us — or anyone who took the database — work out where you were.
- A fingerprint of the review text, for reviews longer than about a sentence. It is there to catch the same paragraph posted under several accounts. Short reviews are not fingerprinted at all, because “Great service, thank you!” is written honestly a hundred times a year.
- Short-lived counters on the sign-in, registration and sign-in-link forms. They count against a scrambled key made from your address, from the wider network block your connection sits in, and from the address a message would be sent to. They are held in a cache and expire on their own after a minute, an hour or a day.
- A hidden field and a one-use form token, kept in your session for up to 30 minutes. People never see the hidden field; automated scripts fill it in and give themselves away.
- When one of these refuses a request, we write a line to our log with a short scrambled stand-in for the address — never the address itself.
What other people can see about you
- Your display name or username, and your picture, next to anything you post.
- Your profile page: your bio, location and link, and your published reviews.
- The month you joined — “Member since March 2026”. Not the day, and not the time. The exact moment you signed up is nobody's business.
- Your email address only if you switched it on, and only to signed-in visitors.
- How many people follow a listing, and how many liked a post or a review. We do not publish a list of who they are.
Other people never see:
- Your password, in any form.
- Your email address, unless you deliberately switched that on.
- Your sign-in history, or the address you connect from.
- Who you have blocked. Blocking is silent — the other person is simply not shown to you, and you are not shown to them. They are not told.
- Reports you have sent, or ownership-claim evidence you have submitted.
- Your email notification settings.
Cookies and staying signed in
Signing in sets a session cookie so the site knows it is still you from one page to the next. Ticking “remember me” sets a second one that lasts 30 days. Forms carry a security token that stops another website posting them on your behalf.
That is all of it for the pages described here. There is no advertising cookie and no third-party analytics tag. If you clear your cookies you will simply be signed out.
Email we send you, and how to stop it
Account email. These come with having an account and cannot be switched off while you have one:
- The code that confirms your address when you register.
- A one-time sign-in link, when you ask for one.
- A notice if somebody tries to register using your address.
Everything else is a choice. In your profile settings there are four switches:
- Replies to my reviews — on unless you turn it off. It follows directly from something you did.
- Decisions about my content — on unless you turn it off, for the same reason.
- Updates from businesses I follow — off until you turn it on.
- Weekly community digest — off until you turn it on.
Anything that looks like marketing starts switched off. You can change all four at any time, and every message we send that is not an account message carries an unsubscribe link.
The email newsletter is a separate list with its own sign-up and its own unsubscribe link. Leaving it does not affect your account, and closing your account does not automatically take you off it.
The site also keeps an on-site notification inbox — replies, follows, moderator decisions. That is not email and turning the email switches off does not empty it, because an inbox that silently dropped things would be lying to you about what happened to your words.
Moderation records
When a moderator publishes, hides, removes, suspends or restores something, we write a record of it: which moderator, what they did, what it was done to, the reason, and when.
That record is kept after the content itself is gone, and it cannot be edited or deleted from within the site. An audit trail you can quietly rewrite is not an audit trail. It is what lets us answer “why was my review taken down?” months later, and it is what protects a business owner from a moderator acting on a grudge.
It holds our decision — not a copy of what you wrote.
How long we keep things
- Your account and what you posted — while your account is open.
- A review you delete — taken off the site immediately. We keep the record of it, because reviews get replied to and reported, and a row that vanishes takes the other person's reply and the report with it.
- Earlier versions of edited reviews — kept.
- Moderation records — kept, as above.
- Sign-in records — kept, including after an account is closed.
- Agreement records — kept, including after an account is closed, and including the address they were made from. They are the evidence of what you were shown and when.
- The anti-abuse counters — they delete themselves within a day at most.
- Deleted pictures — the file is removed from the server, not just hidden.
We have not set a fixed period after which sign-in and moderation records are deleted, and we would rather say so than print a number nobody has agreed. [REVIEW: retention period for sign-in records and moderation records]
Who else sees any of this
We do not sell your information and we do not hand it to advertisers or data brokers.
The people who can see it are: our moderators, in order to moderate; and the companies that host the site and deliver our email, who hold it because that is where it physically lives. [REVIEW: hosting and email delivery providers to name]
We would also hand something over if we were legally required to, or if we believed it was needed to stop somebody being hurt.
What you can do
- See and change what you gave us — your profile settings.
- Take your profile off the public site — the “show my profile” switch.
- Unpublish your email address — the “show my email address” switch.
- Take down a review — delete it from your account.
- Take a listing off the directory — from your account. Its reviews are hidden with it rather than deleted, and they return if you put it back.
- Ask for a copy of what we hold about you — write to the address at the bottom of this page from the address on your account.
- Ask us to correct something that is wrong.
Closing your account
You can ask us to close your account from your profile settings.
Be clear about what that does. It is a request that a person deals with, not an instant automated wipe. The moment you send it, your public profile is hidden. Nothing is destroyed at that point. It goes into the moderators' queue, a person works through it, and you can cancel it at any time until they do.
We do it this way because a one-click irreversible wipe is the wrong shape for this site: your reviews are attached to real businesses, and a listing of yours may have been claimed and checked by hand. We would rather a person looked at it than have someone lose all of that to a misfired click.
Some things stay behind afterwards, and you should know which: sign-in records, moderation records, and reviews that other people have publicly replied to or reported. If that matters to you, say so when you write to us and we will tell you exactly what is left.
Children
This site is not intended for children under 13 and we do not knowingly hold accounts for them. We do not ask your age, so we rely on you.
If you are a parent or guardian and you think your child has an account here, write to us and we will remove it and what was posted from it.
Changes to this page
If we change what we collect or what we do with it, we will change this page and put a notice on the site. This page is kept in step with the code, not with a template.
Getting in touch
For anything on this page — a copy of your data, a correction, closing your account, or a question — write to weldon@weldonpc.com, or by post to Broadview Heights Today · c/o WeldonPC, PO Box 318364, Independence, OH 44131.
See also the Terms of Use, the Community Guidelines and the copyright takedown route.