‹ Back to LodgeWise

LODGEWISE

Privacy Policy

Last updated: 2026-09-07


In short

Your lodge decides what is held about you. We host it. We do not sell it, we do not advertise against it, and we do not train machine-learning models on it. You can export everything we hold about you, and delete your account, from inside the app — and §8 says plainly what deletion does not remove, because some of it stays as your lodge's own record.

1. Who we are, and who is responsible for what

LodgeWise is lodge-management software. This policy covers the LodgeWise app (iOS, Android and web) and the website at lodgewise.app.

Your lodge is the controller of your personal data. We are its processor. In plain terms: the lodge decides what to record about its members and why; we store and process it on the lodge's instructions. If you want something changed or removed, your Secretary is usually the right first stop — though you can always write to us and we will help.

For our own business records — billing a lodge, our support correspondence, security logs — we are the controller.

"We" is Mishan Warnakulasuriya, who operates LodgeWise as a sole proprietor. Data-protection law requires a controller to identify itself, and a policy that says "we" without ever saying who is not much use to someone trying to exercise a right against it. Write to [email protected].

LodgeWise is not affiliated with, endorsed by, or sponsored by any Grand Lodge or Masonic governing body.

2. What we hold

About you as a member

Your lodge's roster record can hold: your name and preferred name, email address, telephone number, postal address, date of birth, Grand Lodge member number, your degree and standing, the date you became a member and the date you were raised, your spouse's name, an emergency contact's name and telephone number, a photograph, and free-text notes written by lodge officers.

Not all of it is required. Which of it your lodge records is your lodge's decision.

What the lodge does with the app

Attendance, event responses, dues records and payment status, expense claims and receipts, minutes, documents, library and education material, committee membership, candidate progress, officer assignments, and messages you send in the app.

Non-members

The app also records people who are not members: petitioners and their sponsors, visiting brethren signed into an attendance register (name, lodge, jurisdiction, degree), and external examiners (name, email). If you are one of these people, the lodge that recorded you is the controller of that record.

Technical

Your IP address and browser/device identifier are recorded with your sign-in sessions and in the lodge's audit log, so an officer can see who changed what. Push notification tokens for your devices, if you turn notifications on.

What we do NOT hold

  • No health or medical field exists in the product. (A lodge may run a "Sickness & Distress" committee — that is a committee category, not a health record. But note that an officer could type anything into a free-text note, and §12 asks officers not to.)
  • No advertising identifiers, no ad tracking, no third-party ad SDKs.
  • No card numbers. See §5.
  • 3. Why we hold it, and on what basis

    To operate your lodge's instance of the app: render the roster, run the calendar, take attendance, track dues, keep minutes, send the notices an officer chooses to send, and let members message one another.

    Where UK/EU data-protection law applies, the lawful basis is the lodge's legitimate interests in administering its own membership, or the performance of the lodge's arrangements with its members — as determined by the lodge, not by us. We process on the lodge's documented instructions.

    We never use lodge or member data for advertising, and never sell, rent or trade it. We do not use it to train machine-learning models.

    4. Who can see it

  • Fellow members of your lodge can see your directory entry.
  • Officers and administrators can see restricted fields — telephone, address, date of birth, Grand Lodge number, spouse and emergency contact, and officers' notes.
  • You control some of it yourself. The app lets you hide your phone, email, address, date of birth and spouse's name from the directory, and no officer can override that choice on your behalf — the setting is deliberately not editable from the roster screen.
  • Never other lodges. Cross-lodge visibility does not exist.
  • Us, only as needed to run and support the service, and to investigate abuse or a security incident. Administrative access is logged.
  • 5. Companies we rely on

    WhoWhat reaches themWhere it goes
    CloudflareEverything — they host the application, database and file storageOur infrastructure provider
    ResendRecipient addresses and the content of emails we send on your lodge's behalfEmail delivery
    AppleDevice push tokens and notification content; and, if you use Sign in with Apple, a token verified against ApplePush notifications, sign-in
    GoogleAndroid device push tokens and notification contentPush notifications on Android
    StripePayment and billing details, where a lodge has enabled online duesPayments
    SentryCrash and error diagnostics, with personal data scrubbed before sendingFault diagnosis

    On payments: if your lodge takes dues through the app, your card details never reach LodgeWise. They go directly from your device to Stripe, and the payment is made onto your lodge's own Stripe account. We never see, store or transmit a card number.

    On the marketing website (lodgewise.app): Cloudflare's own Web Analytics collects aggregate page-view statistics. It sets no cookie and does not track you across sites. It runs on the marketing site only — not in the app.

    We do not add any other analytics or tracking. There are no advertising SDKs in the app at all.

    6. Where your data is held

    LodgeWise runs on Cloudflare's global network. We do not currently commit to storing your lodge's data in a particular country or region, and Cloudflare may store and process it in any of its locations, including outside the UK and EEA. Where such a transfer is subject to UK/EU law, it relies on the safeguards in Cloudflare's own data-processing terms, including Standard Contractual Clauses.

    If your lodge or its Grand Lodge requires data residency in a specific country, tell us before you sign up — we would rather say no than say yes and be wrong.

    7. How it is protected

  • In transit: HTTPS everywhere.
  • Chat messages are encrypted in our database with a key held separately from the data. Files attached to messages, uploaded documents, receipts, avatars and event photographs are not separately encrypted by us — they rely on our storage provider's own encryption at rest, like any file we hold.
  • Database backups are encrypted with AES-256-GCM before they leave the application, under a key that is not stored with them. If that key is missing the backup refuses to run rather than write anything readable. They are replaced nightly and deleted after 90 days.
  • Backup copies of files — documents, receipts, photographs, avatars — are not separately encrypted, exactly as the originals are not. They rely on our storage provider's encryption at rest. They are kept for as long as the file itself is, and deleted when you delete your account or when your lodge closes — see §8.
  • Passwords are never stored. We keep a PBKDF2-SHA256 derivation (100,000 iterations, per-user salt) from which the password cannot be recovered.
  • Sessions last up to 90 days on a phone and 30 days on the web while you keep using the app, and expire absolutely after 180 days regardless.
  • Every administrative action is written to your lodge's audit log, with the actor, the time, and the IP address.
  • No system is perfectly secure and we do not claim otherwise. If we become aware of a breach affecting your lodge's data we will notify the lodge's administrators without undue delay.

    Found a weakness? [email protected]. Please give us a reasonable chance to fix it before telling anyone else.

    8. Deleting your account — what actually happens

    You can delete your account from More → Delete account. Precisely:

    Removed

  • Your login: email address, display name, password, Sign in with Apple link.
  • Every session, so you cannot sign back in.
  • Your device push tokens and calendar subscription links.
  • The link between your roster record and your payment identity at Stripe, where your lodge collects dues in the app. Stripe keeps its own record of payments for its legal obligations; that is between you and your lodge's payment account, and we cannot delete it for you.
  • From your lodge's roster record: your email, telephone, postal address, date of birth, spouse's name, emergency contact, preferred name, your photograph, any officers' notes about you, and any note explaining a reduction in your dues.
  • Kept, and why

  • Your name, degree, standing, and the dates you joined and were raised. These are the lodge's record — it files an annual return to its Grand Lodge from them — and they are not ours to delete. This is the part people are surprised by, which is why it is here and not in a footnote.
  • Messages you sent stay in the lodge's message history, still attributed to you. Deleting your account does not rewrite the lodge's record of its own conversations.
  • Attendance, dues records and event responses remain as lodge records.
  • Your lodge's audit log keeps a record that fields were erased, naming the fields — never their values.
  • Backups. Two kinds, and they behave differently.

  • Database snapshots taken before you deleted your account still contain your data. They are encrypted, and deleted automatically 90 days after they are made.
  • Copies of your files — your photograph, anything you uploaded — are deleted from the backup at the same time as the live copy, not 90 days later. We do not wait, because a file backup is not rewritten nightly the way a database snapshot is, so waiting would mean keeping it far longer than 90 days rather than less.
  • So "erased" means: your files are gone from everywhere immediately, and your database records are gone from the live system immediately and from backups within 90 days.

    If your lodge removes you instead of you deleting your account, your roster record stays with the lodge under the lodge's own rules.

    9. How long we keep things

    Your lodge's dataWhile the lodge subscribes, then 30 days for export, then deleted
    Your login, if your lodge closes its accountDeleted with the lodge, if it was your only lodge. See below.
    Encrypted database backups90 days, then deleted automatically
    Backup copies of your filesAs long as the file itself — removed when you delete your account or your lodge closes
    Sign-in and password-reset tokens7 days after use
    Email delivery records90 days
    Notification history180 days
    Lodge audit logRetained as the lodge's record
    Our platform audit log400 days
    Billing recordsRetained as long as the law requires

    If your lodge closes its LodgeWise account and it was your only lodge, your login is deleted along with it — email address, display name and password all go, the same as if you had deleted the account yourself. Nothing is left behind for an account you can no longer use.

    (Changed 2026-09-06. Until then the login survived a lodge closure, on the reasoning that keeping it let another lodge invite you without starting again. That reasoning did not survive the question it invites: it meant holding an email address and a password hash indefinitely, for someone with no membership and nothing to sign in to, who had not asked us to keep anything.)

    If you belong to another lodge as well, nothing happens to your login: you lose access to the lodge that closed and keep everything else.

    10. Your rights

    Depending on where you live you may have the right to ask for a copy of your data, to correct it, to delete it, to restrict or object to its processing, and to receive it in a portable format.

    Two of these you can exercise right now without asking anyone:

  • More → Export my data gives you a machine-readable file of everything we hold about you as a person.
  • More → Delete account does what §8 describes.
  • For anything else, ask your lodge's Secretary — the lodge is the controller. If you would rather come to us, or the lodge does not respond, write to [email protected] and we will help, and will tell the lodge unless there is a reason not to.

    You can also complain to your data-protection regulator. In the UK that is the Information Commissioner's Office (ico.org.uk).

    California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit. You will not be discriminated against for exercising a right.

    11. Children

    LodgeWise is for adults. You must be 18 or older to hold an account — Masonic membership requires majority in every jurisdiction we know of.

    We do not knowingly collect personal information from children. If you believe a child has an account, write to [email protected] and we will remove it.

    12. A note for officers

    You can write free text about a brother in several places — roster notes, candidate notes, follow-up notes, minutes.

    Those are records about a real person, and in many jurisdictions that person can demand a copy of every one of them. Write what the lodge needs and no more, and think before recording anything about someone's health, finances or family circumstances. There is no medical field in this product on purpose; please do not create one out of a notes box.

    13. Changes

    If we change this policy in a way that matters, we will tell you in the app or by email before it takes effect. The date at the top always reflects the current version.

    14. Contact

  • Privacy: [email protected]
  • Security: [email protected]
  • Anything else: [email protected]