Privacy Policy

Last updated: July 9, 2026

This Privacy Policy explains how [Provider Legal Name](“ChurchBase”, “we”, “us”, or “our”) collects, uses, and protects information in connection with the ChurchBase platform — our church websiteand management service (the “Service”). It is incorporated into our Terms of Service.

The short version: churchesown their data; we host and process it to run their sites and tools. We collect what we need to operate the Service, we don’t sell personal information, and churches control the member data they bring onto the platform.

1. Two Roles We Play

We handle information in two different capacities:

  • As a business (controller) for the information churches give us directly — account details, billing information, support conversations, and usage of the platform.
  • As a service provider (processor) for the information churches and their members put into the platform — member profiles, event data, media, giving-related records, and anything synced from integrations like Planning Center or Google Calendar. For that data, the church is responsible for it and controls it; we process it only to provide the Service.

If you are a member or visitor of a church that uses ChurchBase and have questions about how that church handles your information, contact the church directly — their own privacy practices govern the data they collect.

2. Information We Collect

  • Account information. Name, email address, and role of the people who create or are invited to a ChurchBase account, plus the church's name and contact details.
  • Billing information.Payments are processed by Stripe. We don’t store full card numbers; we receive limited billing details (such as plan, payment status, and the last digits of a card) needed to manage your subscription.
  • Church content and member data (processed on the church's behalf). Website content and media, member and contact records, calendars and events, and data synced from connected services (such as Planning Center or Google Calendar) that the church authorizes.
  • Usage and technical data. Log data, device/browser information, IP addresses, and diagnostic data (such as error reports) that help us keep the Service secure and working well.
  • Anonymous website analytics. Public tenant sites assign a first-party random visitor identifier for up to one year and a session identifier for approximately 30 minutes. We use them with page path, referring host, device/browser, country, and campaign parameters to count visits and understand which site and Link Page destinations are useful. We do not include a Link Page label, full outbound URL, URL query string, email address, phone number, or signed-in identity in Link Page click events.
  • Support communications. Messages you send us and the context needed to help you.

3. How We Use Information

We use information to:

  • provide, operate, and secure the Service (hosting sites, syncing integrations, backups);
  • process subscriptions and payments;
  • provide support and communicate about the Service (including notices required by our Terms);
  • monitor performance, fix errors, and improve the platform; and
  • provide churches with aggregate website and Link Page analytics without advertising profiles;
  • comply with legal obligations.

We do not sell personal information, and we do not use church member data for advertising.

4. How Information Is Shared

We share information only with:

  • Service providers (subprocessors) who help us run the platform — such as hosting and infrastructure providers, payment processing (Stripe), and error/performance and product analytics (including PostHog Cloud in the United States) — under agreements that limit their use of the data to providing services to us. A current list of subprocessors is available on request at [support email].
  • Integrations the church connects — e.g., Planning Center or Google — data flows to/from those services only as the churchconfigures, under those services’ own terms.
  • Legal requirements — if required by law, subpoena, or to protect the rights, safety, or security of ChurchBase, our customers, or others.
  • Business transfers— if we’re involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this policy.

5. Data Retention

  • Active accounts: we retain data for as long as the church's account is active.
  • After cancellation: churches can export their content and data for 30 days after cancellation, after which we delete it from active systems. Residual copies may persist in routine backups for a limited period before being purged.
  • Billing records are kept as required for tax, accounting, and legal purposes.
  • Website analytics: the temporary raw Supabase page-view bridge is retained for up to 90 days. Aggregated trends and PostHog event data follow our configured service retention and are deleted or anonymized when no longer needed for the purposes above.

6. Security

We use reasonable administrative, technical, and physical safeguards to protect information — including encryption in transit, access controls that separate each church'sdata (multi-tenant isolation), and backups. No system is perfectly secure; if we learn of a breach affecting your data, we’ll notify affected churches without undue delay.

7. Children's Information

The Service is intended for use by churches and their staff/volunteers — not for direct use by children. Churches may store information about minors (for example, in member or check-in records); the church is responsible for obtaining any consents required for that data, and we process it solely on the church's behalf. Public websites built on ChurchBase are directed at general audiences.

8. Your Rights & Choices

  • Churches (account holders) can access, correct, export, or delete their data through the platform or by contacting us, and can cancel at any time as described in the Terms.
  • Individuals whose data a church has stored on the platform should direct requests (access, correction, deletion) to that church; we’ll assist the church in fulfilling them.
  • Depending on where you live, you may have additional rights under applicable privacy laws. To exercise them, contact us at [support email]and we’ll respond as required by law.
  • You can clear or block the anonymous first-party analytics cookies in your browser. Public pages and outbound links continue to work, but aggregate visitor counts may be less accurate.

9. Where Data Is Processed

Our Service is operated from the United States, and data is processed and stored in the United States (and any other locations used by our infrastructure providers). By using the Service, churches direct us to process data in these locations.

10. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we’ll give churchesat least 30 days’ notice by email or in-app notice before the changes take effect. The “Last updated” date at the top shows the current version.

11. Contact Us

Questions or requests about privacy: [Provider Legal Name], [support email].