Coming soon · Public accounts are not open yet

Draft for owner review. This text was generated as a starting point and has not been reviewed by a lawyer. Replace it with approved policy before launch.

Privacy Policy

Draft · not yet effective

What we collect

Account details (name, email), church details you provide, and the forms and submissions your church creates and receives, including any files respondents upload. Submissions may contain personal or sensitive information entered by respondents; your church controls that data. The app also uses a keyed hash of a visitor's network address for short-lived abuse limits and stores limited browser metadata with submissions. A shortened hashed network identifier remains with a submission until that submission is deleted.

Signing in sets session cookies from our authentication provider. The app also sets a cookie that remembers which church you last selected and, during setup, a short-lived cookie that lets you resume creating your first form. These cookies are required for the app to work and are not used for advertising.

If your church subscribes to a paid plan, we store the customer and subscription identifiers issued by our payment provider together with the plan, status, and billing period. Card numbers are entered on the payment provider's pages and are not stored by the app.

How we use it

To run the service: rendering forms, storing submissions, sending the notification and confirmation emails your church configures, delivering submissions to the webhooks your church connects, and processing payments through our payment provider. Whether and how personal data may be shared beyond operating the service must be defined by the operator before this policy takes effect.

If you create an account from a tagged campaign link, we keep up to four short campaign labels (source, medium, campaign, and content) with your account to understand which outreach led to signups. We do not keep the full referring URL, use an advertising pixel for this measurement, or include form answers in it. How these labels are removed when an account closes, and how long they persist in backups, still needs to be defined by the operator; the app does not currently offer an account-deletion flow.

Who can see submissions

Inside the app, submissions are visible to members of the church that owns a form, according to the permissions that church sets. Submissions can also leave the app when a church configures it:

  • Notification emails go to every address a church adds as a recipient, whether or not that address belongs to a church member. By default these emails contain only the form name, the submission time, and a secure link. If a church switches a form to summary mode, the answers from the fields its administrators select are included in the email.
  • Churches on a plan with webhooks can send each submission, including all of its answers and the respondent's name and email, to endpoints they connect.
  • Churches can configure confirmation emails to respondents that contain text the church writes.

Operator access practices, including when staff may access customer data for support, must be defined before this policy takes effect.

Planning Center (not yet available)

The Planning Center connection is not currently offered to churches. No response is sent there while it is disabled, and no Planning Center directory is imported or synced into Forms for Church. Before this connection is offered, this policy must be updated to explain the limited account and duplicate-safety checks, the data a church chooses to send, and the retention of provider identifiers.

Processors

The service is planned to run on Vercel (hosting), Supabase (database, authentication, and file storage), Resend (email delivery), Stripe (payments), and Google Workspace (the operator's support mailbox). Each processes data under its own agreement. Which of these are active depends on the operator's configuration at launch; application email in particular is not active until an email sending key is configured. This list must be confirmed before this policy takes effect.

Retention and deletion

Church owners and admins can delete submissions and forms from within the app; only a church owner can delete the church. When a submission deletion succeeds, its response and file records are removed from the active database. Attached files are queued for later removal after issued upload links expire; this can take about three hours or longer if cleanup must retry. Previously issued download links may work for up to ten minutes while a file still exists.

Deletion in the app cannot retract copies that already left it: notification emails already delivered to recipients, submissions already sent to a connected webhook, and confirmation emails already sent to respondents remain with those recipients and systems.

Account deletion, backup retention, and final deletion timing must be defined by the operator before this policy takes effect.

Contact

Privacy questions can be sent to the address on our contact page.