Skip to content
Legal

Privacy policy

What we collect, why, who we share it with, and the rights you have over it.

Last updated September 2026

Template. This document is a starting point written in plain English. Review it with counsel before relying on it, and replace the bracketed placeholders with your legal entity, governing law and contact details.

1. Who this covers

This policy explains how Steeple handles personal data. It covers two situations:

  • Visitors and account holders: people who browse this website, sign up, or are invited to a church workspace. For this data we are the controller.
  • People in a church's workspace: members, visitors, donors, volunteers and children whose records a church keeps in Steeple. For this data the church is the controller and we are its processor, under our data processing addendum. If you want to see, correct or delete a record a church holds about you, contact that church first; we will help them respond.

2. What we collect

From account holders

  • Name, email address and a hashed password, or an invitation token.
  • The church you belong to and your role in it.
  • Sign-in events and security-relevant actions, recorded in the audit log with time and IP address.

On behalf of churches

  • Directory records: names, contact details, household relationships, tags, custom fields and notes the church chooses to keep.
  • Attendance and check-in records, including for children (see below).
  • Giving records: amount, date, fund, method and donor. We store the last four digits and brand of a card as reported by Stripe, never the full card number.
  • Messages sent and received through the Service, including SMS conversations and email delivery events.
  • Form and prayer submissions, group sign-ups and event registrations submitted through a church's public pages.

Automatically

  • Server logs with IP address, browser type and the pages requested, kept for a limited period for security and troubleshooting.

3. How we use it

  • To provide the Service to the church and its users.
  • To send transactional messages such as password resets, invitations, giving receipts and volunteer scheduling requests.
  • To bill paid plans and detect fraud or abuse.
  • To support you and improve the Service, using aggregated usage information that does not identify individuals.

We do not sell personal data, and we do not use Customer Data to advertise to anyone.

4. Donor data

When you give online, you enter payment details on a page hosted by Stripe. Stripe processes the payment on the church's own Stripe account and tells us the result. We record the gift against your donor record so the church can issue receipts and annual statements. If you give by text, we store your phone number and the gift command you sent. Stripe's handling of your payment details is governed by Stripe's privacy policy.

5. Text messages, consent and STOP

  • Churches may only text people who have opted in. The Service records the opt-in status on each person and refuses to send to anyone who has not opted in.
  • Reply STOP, STOPALL, UNSUBSCRIBE, CANCEL, END or QUIT to any message to opt out immediately. Reply START, YES, UNSTOP or SUBSCRIBE to opt back in. These keywords are handled automatically and the change is logged.
  • Message and data rates may apply. Message frequency depends on the church.
  • Messages are delivered through Twilio, which processes phone numbers and message content to deliver them.

6. Children's data and check-in

Churches use Steeple to check children into classes. Those records are created by a parent, guardian or church volunteer, not by the child, and typically include the child's name, date of birth or grade, allergies or medical notes the family provides, the room, a security code and the time of check-in and check-out.

  • We process this data only on the church's instructions and never contact children directly.
  • The Service is not directed to children and we do not knowingly create accounts for anyone under 18.
  • Parents who want to see or remove a child's record should contact the church, which controls it.

7. Cookies

We use one strictly necessary cookie, church_session, to keep you signed in. It is HttpOnly and expires when the session does. Public church pages, giving pages and check-in kiosks may use additional strictly necessary cookies or local storage to remember a device authorization or a form in progress. We do not use advertising or cross-site tracking cookies on this site.

8. Who we share data with

Only the providers we need to run the Service, each for a stated purpose: Stripe (payments), Twilio (SMS), Resend (email), Anthropic (optional AI features, only when invoked), and our hosting provider (servers, database and backups). We may also disclose data when required by law or to protect the safety of people using the Service. The full list, with roles, is in the data processing addendum.

9. Security

Data is encrypted in transit, isolated per church, protected by role-based access, and backed up daily with off-site copies. Card data is handled entirely by Stripe. Read the security page for detail, including what we do not have yet.

10. Retention

We keep data for as long as the church's workspace exists or as long as needed for the purpose it was collected. Churches can delete individual records or the whole workspace at any time; deleted data is removed from backups within [30] days. Server logs are kept for [90] days. Billing records are kept as long as tax law requires.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete or export personal data about you, to object to or restrict certain processing, and to complain to a supervisory authority. For data about you as an account holder, email us. For data a church holds about you, contact the church; we will assist them within the time the law allows. We will not discriminate against you for exercising any right.

12. International transfers

Our servers are located in [region]. Our subprocessors may process data in other countries. Where a transfer of personal data out of its home jurisdiction requires safeguards, we rely on the mechanisms described in the DPA, such as standard contractual clauses.

13. Contact and changes

Questions or requests: [email protected]. Postal address: [Steeple legal entity name and address]. If we change this policy in a material way we will email account holders and post the new version here with an updated date.