01Who we are
ChurchOrb is a platform that helps churches run their day-to-day life in one place: services, giving, events, chat, groups, media, and member care. When we say “we”, “us” or “ChurchOrb” in this policy, we mean the team behind the ChurchOrb platform, reachable at privacy@churchorb.com.
ChurchOrb is multi-tenant. That means each church runs its own workspace with its own members, roles and data. When your church brings you into their workspace, both you and your church have a hand in what data flows through the platform. This policy explains our side of that. Your church may also have its own privacy notice that governs how they use the information you share with them.
02What we collect
We only collect what we need to make ChurchOrb work well for you and your church. Here is the full picture, grouped by why it exists.
Information you give us
- Account basics
- Your name, email address, password (stored as a salted hash, never in plain text), and optionally a phone number. If you sign in with Google or Apple instead, we receive your name and email from them.
- Profile details
- Anything you choose to add to your profile: photo, bio, birthday, address, family relationships, and similar details you share so your church community can recognise and reach you.
- Church roles and permissions
- The role your church assigns you (member, admin, ministry lead, and so on), the ministries or groups you belong to, and any custom fields your church has configured.
- Content you create
- Chat messages, voice notes, photos and videos you send, prayer requests, event RSVPs, form submissions, giving records, notes on sermons, and anything else you post inside your workspace.
- Giving information
- ChurchOrb does not process payments. When your church publishes bank account details for donations, we display them inside the app so you can tap to copy them into your own bank app. We do not collect card details, we do not move money on your behalf, and we do not keep any record of the transfers you make from your bank.
Information we collect automatically
- Device and app data
- Your device model, operating system version, app version, language, and time zone. We use this to keep the app compatible and diagnose crashes.
- Push notification tokens
- If you enable notifications, we store the anonymous push token issued by Apple or Google so we can deliver alerts about chats, events and giving reminders. The token identifies the device, not your identity, and can be revoked from your OS settings.
- Authentication and session data
- Login timestamps, IP addresses at sign-in, and a secure session token so you stay signed in between visits. We keep short-lived security logs to detect suspicious activity.
- Product usage
- Basic technical logs of the actions you take (for example, which screens loaded, which uploads succeeded) so we can debug problems and understand which features to invest in. We do not use advertising identifiers and we do not sell any of this data.
Sensitive information
By nature, ChurchOrb touches on your religious affiliation and activity in a faith community. Under some privacy laws that is a special category of data. We treat it with the same care as your identity: we do not share it with third parties for marketing, we do not profile you for advertising, and we only process it to run the service you and your church signed up for.
03How we use it
We use your information to:
- Provide the ChurchOrb service: authenticate you, deliver chats, store your media, process your giving, and keep everything in sync across your devices.
- Personalise your experience: show you the right church workspace, surface events you care about, and remember your preferences.
- Keep the platform safe: detect abuse, prevent unauthorised access, respond to security incidents, and enforce our Terms of Service.
- Communicate with you: send transactional messages about your account (password resets, giving receipts, security alerts), and, with your consent, occasional product updates.
- Improve the product: understand which features help churches, fix bugs, and design new capabilities. This analysis is done in aggregate wherever possible.
- Meet legal obligations: retain the records the law requires us to keep, and respond to lawful requests from authorities.
We do not sell your personal information, and we do not use it to train third-party advertising models.
05Your rights and choices
You have real, actionable control over your information. Depending on where you live, some of these rights may be granted by law (GDPR in Europe, CCPA in California, NDPR in Nigeria, and others). Even where they are not required by law, we offer them anyway.
- See your data. You can view most of your information directly inside the app. If you want a machine readable export, contact us at privacy@churchorb.com and we will send it within thirty days.
- Correct your data. You can edit your profile, contact details and preferences from the app. For anything you cannot self-service, write to us and we will fix it.
- Delete your account. You can permanently delete your ChurchOrb account from within the app. Doing so removes your personal profile, your DMs, and your session data. Some records may remain, for example giving receipts your church needs for accounting or content you posted in shared workspaces that is now part of another member's conversation history. Where the law lets us, we will delete those too on request.
- Delete an entire church workspace. If you are the owner of a church on ChurchOrb, you can request deletion of the whole workspace. This is a two-step, email-confirmed action because it wipes chat history, media, giving records and every member's data inside that workspace. We keep a short audit log of the deletion itself for legal traceability.
- Opt out of non-essential emails. Every product update or newsletter we send has an unsubscribe link. Account and security emails cannot be turned off because you need them to use the service safely.
- Restrict, object, or complain. If we are processing your data in a way you disagree with, you can ask us to restrict or stop. You also have the right to lodge a complaint with your local data protection authority.
06How long we keep it
We keep your data for as long as your account is active, plus a short buffer to recover from mistakes or resolve disputes. After that:
- Deleted messages and media are removed from our live systems within seven days.
- Backups roll over on a rolling ninety day window, so a full purge from every backup takes up to that long.
- Security logs (sign-in attempts, suspicious activity) are kept for one year and then discarded.
07How we protect it
We take security seriously. In practice this means:
- All traffic between your device and ChurchOrb is encrypted with TLS. Nothing sensitive travels in the clear.
- Passwords are stored as salted hashes using modern algorithms. Even we cannot see your password.
- Access to production data is limited to a small group of engineers, gated by strong multi-factor authentication and audited.
- We follow the principle of least privilege inside our services: each system only reads or writes the data it strictly needs.
- We patch and update our infrastructure regularly, and we run automated checks for known vulnerabilities in our code and dependencies.
No system is unbreakable. If we ever suffer a breach that affects your data, we will tell you what happened, what we did about it, and what you should do, within the timelines the law requires (usually seventy-two hours for GDPR).
08Children and family accounts
ChurchOrb is designed for anyone aged thirteen and up. If you are younger than thirteen, please do not create an account for yourself.
Churches often want to add children and youth to their family or group directories. We support this through the workspace admin, not through direct sign-ups from children. Parents or guardians can request that any information about their child be corrected or deleted by contacting the workspace admin, or by writing to us if the workspace no longer exists.
09Where your data lives
ChurchOrb is a global service. To make the platform fast and resilient we may store and process your information in data centres outside your home country. When we do, we make sure the transfer uses safeguards accepted under privacy laws such as GDPR (for example, Standard Contractual Clauses).
10Changes to this policy
We will update this policy when the service changes in a way that affects your privacy. When we make material changes, we will notify you inside the app or by email before the changes take effect, and we will always show the effective date at the top of this page. Older versions are archived and available on request.
11Contact us
Questions, requests or concerns about privacy can go to:
- privacy@churchorb.com
- Postal address
- ChurchOrb, Attn: Privacy
Address details available on request at privacy@churchorb.com.
We aim to respond to every privacy request within seven business days, and always within thirty.