Privacy Policy
A practical privacy baseline for the current site and future form integrations.
Information the site can process
The informational site may process standard server logs, device/browser information and analytics or storage data used to operate and measure the service. If a request form is enabled, the form can process the personal information shown in that flow and route it to the configured recipient(s).
How information is used
Data can be used to operate the site, provide the requested functionality, route a configured request, prevent abuse, troubleshoot errors, measure performance and meet applicable operational or legal obligations. PhilaLoan should not describe a use or recipient that is not actually configured.
Sharing and recipients
Third-party forms, networks, providers, analytics or infrastructure services can receive information only as described by the deployed flow and relevant notice/consent. The data-recipient page should identify the categories and purpose when a commercial request flow is active.
Security and retention
Collect only what is needed, restrict access to private runtime data, use HTTPS and appropriate security controls, and retain information according to the actual production purpose and policy. Users should not send banking passwords or full payment-card credentials through a generic contact form.
Choices and updates
Available privacy choices depend on the deployed technologies and data flows. Material changes to collection, recipients or use should be reflected in the policy and effective-date/version record before the new behavior is relied on.
External references
The policy context for this page is checked against Federal Trade Commission — Privacy and Security. Production-specific data flows, recipients, consent text, retention and security controls must still match the deployed site.
Production-specific scope
This policy applies only to the data, consent, communication or legal behavior actually deployed on PhilaLoan. Fields that depend on the legal entity, recipient, retention period, consent mechanism or provider relationship must be populated from the approved production configuration.
Effective-version control
A material change to forms, recipients, cookies, communications, disclosures or legal obligations requires a reviewed policy version. The published text should not silently inherit assumptions from an older configuration.
Security
Production deployments should use HTTPS, current server software, restricted access to private runtime data, strong administrator credentials and the minimum data collection necessary for the requested form integration.
Who wrote and reviewed this page
The primary author is shown separately from the editor, fact-checker and financial reviewer so each responsibility is explicit.
Ashley HarrisonSenior Editor — Loans & CreditIntent, clarity, disclosures and editorial consistencyFact-checked by
Timothy Moore, CFEI®Fact-Checker & Financial Education ReviewFacts, dates, source fit and factual consistencyAffordability reviewed by
Laura Gariepy, MBAConsumer Finance ReviewerRates, costs, repayment examples and affordability contextDecision details that can change the answer
Open only the topics that apply to your situation. Each module focuses on a different cost, timing, income, repayment, eligibility or provider question.
Related decisionPrivacy PolicyExplore
Explain the personal-information categories, sources, purposes, recipients, retention, security practices, choices, and contacts that actually apply to PhilaLoan.
Third-party forms, networks, providers, analytics or infrastructure services can receive information only as described by the deployed flow and relevant notice/consent. The data-recipient page should identify the categories and purpose when a commercial request flow is active.
Collect only what is needed, restrict access to private runtime data, use HTTPS and appropriate security controls, and retain information according to the actual production purpose and policy. Users should not send banking passwords or full payment-card credentials through a generic contact form.
Related decisionPrivacy NoticeExplore
Provide a concise, layered summary of PhilaLoan’s actual Privacy Policy before sensitive collection and path users to available privacy choices.
This notice summarizes the categories of information used by the site, why information may be processed, who can receive it in a configured request flow and where to find the full privacy policy and choices.
A recipient should be identified by role and purpose where the production flow sends data outside PhilaLoan. A broad “partners” label should not replace the configured data-recipient record.
Related decisionElectronic Consent (E-Consent)Explore
Explain the actual electronic-record and communication consent workflow, technical requirements, paper-copy process, and withdrawal process.
When a configured financial request requires electronic consent, the user should receive a clear description of the records covered and agree to receive them electronically before the dependent step occurs.
The user should have access to a device, browser and software capable of displaying, saving or printing the relevant electronic records. A method to request paper copies or withdraw consent should be described when required by the deployed flow.
Related decisionCommunications ConsentExplore
Distinguish service or transactional communications from marketing consent and explain the actual channels, opt-out process, and consent records.
A communications consent should identify the channels that may be used—such as email, telephone or text—the purpose of the communication, the parties covered and how the user can change preferences or revoke consent where applicable.
Messages needed to complete or service a requested transaction should not be described as identical to optional marketing outreach. The production flow should record the consent version and the recipients that rely on it.
Related decisionCookie and Storage PolicyExplore
Explain the cookies, local storage, analytics or similar technologies actually deployed by PhilaLoan, including provider, purpose, category, duration, and available controls.
Browser cookies or similar storage can support essential site functions, preferences, security, analytics and other configured purposes. The policy should distinguish necessary functions from optional measurement or marketing uses when the deployment uses them.
Embedded maps, analytics, forms or other services can set or read their own technologies subject to their configuration and policies. The site should not list a vendor or purpose that is not actually deployed.
