Privacy Policy

How TODO — your registered company name handles personal information in FaithCMS — both for the staff who run a church account and for the members whose records are stored in one.

1.Two kinds of people in this policy

It matters which one you are, because our role is different for each.

  • Subscribers — the church or organization that holds an account, and the staff who sign in. We are the controller of that data: we decide what we collect to run the service and bill for it.
  • Members— the people in a church’s directory, giving records, event registrations, and mailing lists. That data belongs to the church. We only process it on their instructions, as their service provider. If you are a member and want your record changed or removed, ask your church first — they control it, and they can act immediately.

2.What we collect

  • Account data: your name, email, hashed password, role, and the organization you belong to. Passwords are stored only as a one-way hash — we cannot read them.
  • Billing data: your organization name, subscription status, plan, and Stripe customer and subscription identifiers. Card numbers go directly to Stripe; we never receive or store them.
  • Content you upload: member and household records, giving history, attendance, events and registrations, pages, sermons, songs, documents, and media files.
  • Operational logs: IP address, browser user-agent, and timestamps for requests, sign-ins, and errors — used for security, abuse prevention, and debugging.
  • Email delivery events: whether a message we sent for you was delivered, bounced, or unsubscribed, so lists stay clean and we honor opt-outs.

We do not sell personal information, we do not share it with advertisers, and we do not use your content or your members’ data to train machine-learning models.

3.Why we use it

  • To provide the service you signed up for and keep your data available to you.
  • To authenticate sign-ins and enforce who may see what.
  • To take payment for your subscription and to send billing notices, including trial-expiry and failed-payment warnings.
  • To send messages you ask us to send on your behalf (broadcasts, event reminders, serving requests, certificates).
  • To detect and prevent abuse — rate limiting, card-testing protection, and security investigation.
  • To meet legal and accounting obligations.

4.Tenant isolation

Every table and every query in FaithCMS is scoped to one organization, and the organization is resolved from the domain the request arrives on. One church cannot read another church’s records, and there is no shared or cross-tenant directory.

Ballots in the elections module are stored with no link back to the voter, so results are anonymous even to us.

5.Who we share it with

We use a small set of processors, each only for what it does:

  • Stripe — subscription billing, and the donation payments that settle to each church’s own connected account.
  • Our hosting and database providers — running the application and storing your data.
  • Object storage — the media and files you upload.
  • Our email provider — delivering transactional mail and the broadcasts you send.
  • Google — only if a staff member chooses “Continue with Google”, and only to confirm the email address on that account.

We may also disclose information where the law requires it, or where it is necessary to protect someone’s safety or defend our legal rights.

6.How long we keep it

  • Your content is kept for as long as your account is open.
  • When an account is closed, we retain its data for 30 days so it can be recovered, then delete it.
  • Operational logs are kept for a short, rolling period for security and debugging.
  • Some billing and tax records are kept longer where law requires it.

7.Security

  • Traffic is encrypted in transit with TLS.
  • Passwords are stored only as a one-way hash, never in a recoverable form.
  • Access inside an account is controlled by roles and per-module permissions.
  • Sensitive endpoints are rate-limited, and payment webhooks are signature-verified.

No system is perfectly secure. If a breach affects your data, we will notify you without undue delay and tell you what we know and what we are doing about it.

8.Your choices and rights

Depending on where you live you may have the right to access, correct, export, or delete your personal information, and to object to some processing.

  • If you are a church member: contact your church. They control your record and can edit or delete it themselves. Every broadcast we send on their behalf also carries a working unsubscribe link.
  • If you are a subscriber: you can export your data from the admin area at any time, or email TODO — privacy@yourdomain.com and we will respond within 30 days.

9.Cookies

We use cookies for the things the product cannot work without: keeping you signed in, remembering your admin light/dark preference, and security protections such as CSRF tokens. We do not run advertising or cross-site tracking cookies.

10.Children

FaithCMS is sold to organizations, not to children, and is not directed at children. Churches do store records for minors — for example church-school attendance. That data belongs to the church, which is responsible for having the appropriate parental consent for it.

11.Changes and contact

If we make a material change to this policy we will email the account owner and update the date below. For any privacy question or request, contact TODO — privacy@yourdomain.com, or write to TODO — your registered company name, TODO — your business postal address.


Questions about this page? Email TODO — support@yourdomain.com. Last updated July 22, 2026.