Last updated 23 August 2026
A church is trusting us with its congregation's names, addresses and giving. This page says exactly what we do with that, in the order you would ask.
The short version. We never sell church or congregant data. We never share it with advertisers. Card numbers never touch our servers. A church’s data is visible only to the people that church invites, and to us only when we are fixing something.
For the church staff who hold an account, we are the controller — we decide what to collect to run the service.
For a congregation’s own records — members, giving, prayer requests — we are a processor acting on the church’s instructions. The church decides what to keep and for how long. If a member asks to be removed, ask their church; we will help the church do it.
We set one cookie: your sign-in session. It is httpOnly and SameSite=Lax, and it is not used for tracking.
On our marketing site we use Google Analytics with IP anonymisation on and both advertising signals turned off — we do not build advertising audiences from people who read about us. A church may connect its own analytics to its own site; that is between the church and that provider.
That is the whole list. We do not sell to or share with anyone else.
Churches record children for check-in and safety. That data is entered by the church, is visible only to the people the church authorises, and is never used for anything other than the feature it was entered for. We do not knowingly let children create accounts.
Ask us for a copy of your data, a correction, or deletion. Church administrators can export everything themselves from the admin at any time, without asking.
info@holdfast.church — 4724 Woodland Dr, Lawrence, KS.