Church Registry ← Back to homepage
Legal

Privacy Policy

Last updated June 22, 2026

Our promise: we will never sell, rent, or trade your church’s information, and we will never use the personal data in your account to market to your members. This policy explains what we collect, why, and the choices you have.

This Privacy Policy explains how Church Registry, Inc. (“Church Registry,” “we,” “us,” or “our”), a company organized in Nevada, collects, uses, and shares personal information in connection with our church management software and websites (the “Service”). By using the Service, you agree to the practices described here.


1 Scope & two kinds of data

The personal information involved in the Service falls into two distinct categories, and it is important to understand the difference:

  • Data we collect for our own purposes. Information about the churches and people who sign up for and administer a Church Registry account, such as account owners and staff. We are responsible for this data, and this policy describes how we handle it.
  • Data churches collect through us. Information that a church stores in its account about its members, guests, donors, and others, such as profiles, giving records, attendance, and check-ins. The church controls this data and decides how it is used. We process it on the church’s behalf to provide the Service. If you are a church member with questions about your information, please contact your church directly.

This policy focuses on the data we collect and control. For information a church stores about its people, the church’s own privacy practices apply.

2 Our role: controller vs. processor

Where data protection laws apply, our role depends on the category of data:

  • Under the General Data Protection Regulation (GDPR) and UK GDPR, for data a church stores about its people, the church is the data controller and we act as a data processor. For the account data we collect for our own purposes, we are the controller.
  • Under the California Consumer Privacy Act (CCPA), as amended by the CPRA, for data a church stores about its people, the church is the business and we act as a service provider.

As a service provider and processor, we use a church’s data only to provide the Service and follow the church’s instructions, not for our own independent purposes.

3 How we collect information

When you sign up

When you create an account, we ask for information such as your name, email address, username, organization name, and account credentials. This may include identifiers and similar categories of personal information. We use it to create and administer your account and to communicate with you.

Automatically, as you use the Service

We automatically collect certain information about how the Service is accessed and used, such as device and browser type, IP address, pages viewed, and usage activity. This helps us operate, secure, and improve the Service.

When you choose to provide it

You may provide additional information when you contact support, respond to a message, or otherwise interact with us.

When connecting third-party services

If your church chooses to connect a third-party service or integration to its account, you authenticate to Church Registry directly, and you control what that connection can access. Third-party services have their own privacy practices, which we do not control.

4 Cookies & analytics

Cookies and similar technologies. We use cookies and similar technologies to keep you signed in, remember your preferences, and improve your experience. You can control cookies through your browser settings, though some features may not work properly without them.

Analytics. We use analytics to understand how the Service is used, such as traffic and usage metrics, so we can improve it. Where we use third-party analytics providers, they are required to protect your data and are not permitted to use it to build advertising profiles about you across other sites. Where the law requires consent for certain analytics, we will seek it. Any analytics data is used for analytical purposes only.

5 How we use information

We use the information we collect to:

  • Provide, maintain, and improve the Service.
  • Create and administer your account and authenticate users.
  • Process payments and manage subscriptions.
  • Provide customer support and respond to your requests.
  • Send service, security, and billing notices, and (where permitted) occasional product updates you can opt out of.
  • Monitor and protect the security, integrity, and performance of the Service, and detect and prevent fraud and abuse.
  • Comply with our legal obligations and enforce our terms.

We do not sell your personal information, and we do not use the personal information in a church’s account to market to that church’s members.

6 Disclosure & sharing of data

Service providers

We share information with third parties who perform services on our behalf so we can operate the Service. They are authorized to use the information only to provide services to us. These include providers that help with:

  • Processing payments. We use Stripe and Authorize.net to process card payments. Authorize.net handles and stores cardholder information, including names and card details, to process payments. We do not store full card numbers ourselves.
  • Hosting and maintaining our cloud environment.
  • Sending emails and messages.
  • Providing customer support.
  • Analytics, fixing bugs, and detecting and preventing fraud and spam.

Third-party services you connect

If a church enables a third-party service or integration, information may be shared with that service according to the permissions granted. Those services are controlled by others and governed by their own privacy practices.

Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a different privacy policy.

We do not sell or rent your personal information to third parties.

7 Disclosure for legal reasons

We may disclose personal information if required to do so by law or in response to valid requests by public authorities, such as a court or government agency. We may also disclose information when we believe in good faith that it is necessary to comply with a legal obligation, protect and defend our rights or property, prevent or investigate possible wrongdoing, protect the personal safety of users or the public, or protect against legal liability.

8 Security of data

The security of your data matters to us. We use commercially reasonable measures to protect personal information, including encryption in transit and access controls. However, no method of transmission over the Internet or electronic storage is completely secure, so we cannot guarantee absolute security. If you have questions about our security practices, contact us at public@churchregistry.com.

9 Breach notification

If a data breach affecting your personal information occurs, we will notify you without undue delay after discovering it, by a notice within the Service and by email to your last listed email address, as appropriate and as required by law. By using the Service, you agree that we may send these notifications electronically.

10 Retention of data

We retain personal information for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we take reasonable steps to delete or de-identify it. A church can also delete data within its account, subject to any legal retention requirements.

11 Your rights

Upon request, we will provide information about the personal information we have collected about you, such as the categories of information, the specific pieces, and the categories of sources. You may request to access, correct, delete, or object to our use of your personal information by contacting us at public@churchregistry.com. If you email us, please include “Personal Information Inquiry” in the subject line. We may ask you to verify your identity before responding, and we will respond within a reasonable timeframe as required by applicable law.

You may have additional rights depending on where you live. You can contact us at any time to exercise your data protection rights, and we will consider your request under applicable law. If a church controls the data in question, we may direct your request to that church.

12 EEA & UK residents

If you are in the European Economic Area or the United Kingdom, you have rights under the GDPR, including the rights to access, correct, delete, restrict, or object to the processing of your personal information, and the right to data portability.

Legal basis. We process personal information where we have a lawful basis to do so, such as performing our contract with you, complying with legal obligations, your consent (which you may withdraw), or our legitimate interests in operating and securing the Service.

International transfers. Your information may be processed in the United States or other countries that may have different data protection laws. Where required, we use appropriate safeguards for such transfers. You also have the right to lodge a complaint with your local data protection authority.

13 U.S. state privacy rights

Residents of certain U.S. states, including California, have specific rights regarding their personal information. Depending on your state, these may include:

  • Information or deletion. The right to request the categories and specific pieces of personal information we have collected, and to request deletion.
  • Correction. The right to request that we correct inaccurate personal information.
  • Portability. The right to receive a copy of certain information in a portable format.
  • Do not sell or share. The right to opt out of the sale or sharing of personal information. Church Registry does not sell or share personal information as those terms are defined under these laws.
  • Limit sensitive information. The right to limit the use and disclosure of sensitive personal information to what is necessary to provide the Service.
  • Non-discrimination. The right not to receive discriminatory treatment for exercising your privacy rights; we will not deny service or charge different prices because you exercised a right.

Exercising your rights. To make a request, contact us at public@churchregistry.com. We will verify your identity before fulfilling the request, and you may use an authorized agent where the law permits. We do not use sensitive personal information for purposes other than providing the Service, and we do not share personal information with third parties for their own marketing.

14 Children’s information

The Service is intended for use by churches and the adults who administer them, not for direct use by children. Churches may store information about minors (for example, for check-ins or family records), and that information is controlled by the church, which is responsible for obtaining any required parental consent. We do not knowingly collect personal information directly from children for our own purposes. If you believe a child has provided us information directly, please contact us so we can address it.

15 Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will post the updated policy here and revise the “last updated” date, and where appropriate we will provide additional notice. Your continued use of the Service after a change takes effect means you accept the updated policy.

16 Contact us

If you have questions about this Privacy Policy or how we handle your information, contact us at public@churchregistry.com. Church Registry, Inc. is organized under the laws of the State of Nevada.