Skip to main content

ChurchHearth

Effective September 6, 2026

Privacy

How ChurchHearth handles information for churches, staff, members, and invitees in the current product.

This page describes ChurchHearth's current practices during the pilot program.

Who this policy covers

  • Church administrators and staff who sign in to the admin console for their church.
  • Members who use the mobile app within their church's protected space.
  • Invitees who receive a church invitation before creating an account.

Each church has its own protected space. Data for one church is not exposed to users of another church except to authorized ChurchHearth personnel responsible for operating the service.

Information we process

The product currently stores and processes categories such as:

  • Account and membership data — account and sign-in identifier, church membership, roles, household relationships, and profile fields maintained by the church or member.
  • Event and RSVP data — church and optional group events, RSVP responses, and related scheduling metadata.
  • Group, serve, and connection data — group membership, serve sign-ups, and member-initiated connection requests visible according to authorization rules.
  • Care and prayer requests — sensitive pastoral information with stricter access controls than ordinary community content.
  • Communications and content — announcements, curated content, and knowledge documents published by church staff to authorized audiences.
  • Device and session data — information required to authenticate users, deliver push notifications where enabled, and maintain secure sessions.
  • Invitation and email delivery metadata — invitation codes, delivery status, and message identifiers for operational email when enabled.

How information is used

We use this information to operate the service for the church that collected it:

  • Authenticate users and enforce church-scoped authorization.
  • Display events, groups, serve opportunities, care workflows, and church communications to authorized users.
  • Send transactional email when explicitly enabled and initiated by church staff workflows.
  • Maintain operational logs needed to run the service securely without storing unnecessary message content.

We do not sell personal information. We do not use the product to send unrelated marketing email.

Retention and deletion

Church-owned records can be removed from active use while preserving audit needs where required. Retention, export, and member deletion practices may differ by jurisdiction and church needs during the pilot program. Contact us for questions about a specific church.

Security

Authorization is enforced on the server for every church-owned record. Pastoral care information requires explicit permissions beyond ordinary community access. Member apps access church information through secured application services rather than direct database connections from personal devices.

Contact

For privacy questions, contact support@churchhearth.com.

Legal entity: Church Hearth Digital, Inc.