(555) 555-0100[email protected]EmergencySign in

Last updated: July 20, 2026

Demonstration notice. City of Riverbend is a demonstration municipal website operated by Innovation Nexus LLC to showcase the Civic Suite platform. It is not a real city. Please do not submit real sensitive personal information — including Social Security numbers, payment card numbers, or medical information. This policy describes how the demonstration actually handles the limited data it does collect.

1. Who we are

This site is operated by Innovation Nexus LLC ("we", "us"). We are the data controller for information collected through this site. You can reach us at [email protected].

2. Information we collect

Information you give us

  • Account details — name, email address, and a password (stored only as a salted hash, never in readable form).
  • Service requests and applications — the content you enter when you submit a service request, permit application, business licence application, or recreation registration.
  • Contact messages — anything you send us through the contact form.

Information collected automatically

  • A session cookie (or equivalent browser storage) to keep you signed in. It is strictly necessary for the site to function.
  • Standard server logs — IP address, browser user agent, requested page, and timestamp — used for security and troubleshooting.

We do not use advertising cookies, and we do not sell or share personal information for advertising or cross-context behavioural advertising.

3. Signing in with Google, Facebook, or Microsoft

You may create an account or sign in using a Google, Facebook, or Microsoft account. This is optional — you can always register with an email address and password instead.

When you choose social sign-in, you are redirected to that provider to authenticate. We never see your password. After you approve the request, the provider returns a limited profile to us.

Exactly what we receive and keep

  • Your email address — used as your account identifier, and to contact you about your requests.
  • Your display name — shown in your profile.
  • A provider account identifier — an opaque ID that lets us recognise you on your next sign-in.
  • Your profile picture URL, where the provider supplies one (Google and Facebook).
  • Whether the provider has verified your email address — we use this to decide whether the social login may be linked to an existing account.

What we do not receive or keep

  • Your password at that provider, ever.
  • Your contacts, friends list, posts, photos, calendar, files, or any other content. We request only the minimum scopes needed to identify you: openid email profile for Google and Microsoft, and email public_profile for Facebook.
  • Access tokens are not stored. The token issued during sign-in is used once, in memory, to read the profile described above, and is then discarded. We cannot act on your account at the provider, and we cannot access it again later.

Linking to an existing account

If the email returned by the provider already matches an account here, we link the two so you keep your history — but only when the provider asserts that the email address is verified. If it is not verified, we refuse the link rather than risk handing your account to someone else.

Disconnecting

You can revoke our access at any time from your provider's own settings — Google Account › Security › Third-party access, Facebook Settings › Apps and Websites, or Microsoft Account › Privacy › Apps and services. Revoking access stops future sign-ins; to also delete the account and data held here, contact us using the details below.

4. How we use information

We use the information above only to:

  • create and secure your account, and sign you in;
  • process and respond to the requests, applications, and registrations you submit;
  • send you transactional messages about those requests (we do not send marketing email from this site);
  • keep the service secure — detecting abuse, rate-limiting failed logins, and maintaining an audit record of administrative actions;
  • meet legal and public-records obligations where they apply.

5. Sharing

We do not sell your personal information. We share it only with: our hosting and infrastructure providers, acting on our instructions; the identity provider you chose, as part of the sign-in you initiated; and anyone we are legally required to disclose to. In a real municipal deployment, some submissions — such as permit applications and correspondence with the city — may be public records under state law.

6. Retention

We keep account information for as long as your account is active. Server logs are kept for a short operational period. When you ask us to delete your account, we delete or anonymise your personal information except where we must retain it for legal reasons.

7. Security

Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. Access to administrative functions is role-restricted and audited, and repeated failed logins are throttled. No system is perfectly secure, which is one more reason not to put real sensitive data into a demonstration site.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to withdraw consent, and to object to certain processing. To exercise any of these, email [email protected]. We will not discriminate against you for exercising them.

9. Children

This site is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided information, contact us and we will delete it.

10. Changes

If we change this policy we will update the date at the top of this page. Material changes affecting how we handle your information will be highlighted here.

11. Contact

Innovation Nexus LLC — [email protected]

See also our Terms of Service and Accessibility statement.