Policies

Privacy policy

What this church collects, why, how long it is kept, and who else is involved — including the particular care that prayer requests and pastoral messages are given. Draft wording for qualified review, not legal advice.

Template preview: replace and approve church-specific content before launch.
Before this page is published. This is template wording, not legal advice, and it has not been reviewed for any particular church. Have qualified counsel read and adapt it, replace every placeholder written in [CAPITALS AND BRACKETS], confirm that it describes what your church actually does, and delete this paragraph.

Who this policy is about

[CHURCH NAME] ("we", "us") is responsible for the personal information described here. You can reach us at [POSTAL ADDRESS], by email at [PRIVACY CONTACT EMAIL], or by telephone on [TELEPHONE NUMBER]. Questions about this policy should go to [NAME OR ROLE RESPONSIBLE FOR DATA PROTECTION].

This policy covers this website. It does not cover our online store, which is a separate application with its own privacy policy, or any third-party service we link to.

What we collect, and why

Simply reading the site. Nothing is asked of you and nothing is stored about you. This website sets no cookies for visitors, runs no analytics, carries no advertising, and loads no fonts, scripts or images from other companies. Our hosting provider keeps ordinary server logs, which include IP addresses, for [SERVER LOG RETENTION PERIOD].

Contacting us. The contact form asks for your name, email address, the department you want to reach, a subject and your message. A telephone number is optional. We use this to answer you and to pass your message to the right person.

Prayer requests. The prayer form asks for a title, your request, a category and an email address. Your name and telephone number are optional, and you may submit anonymously. Two separate choices are yours alone: whether your request may be shown publicly, and whether someone may follow up with you. Both default to no.

The newsletter. We store your email address, the date you consented and where you signed up. We confirm every address before sending anything to it, so an address cannot be added by someone else.

Saying you have prayed. The counter on a public prayer request records that someone prayed, not who. Your address and browser are combined and put through a one-way cryptographic hash so that the same person is only counted once; the result cannot be turned back into an address or used to recognise you elsewhere.

Photographs. Location data, camera details and other hidden information are stripped from every image when it is uploaded. If you appear in a photograph and would rather not, please ask us to remove it.

Staff accounts. People who work on the site have accounts holding a name, an email address, a password that is stored only as an irreversible hash, and a record of sign-ins and changes made in the system.

Prayer requests and pastoral care

Prayer and pastoral correspondence are the most sensitive things this church handles, and they are treated differently from everything else.

  • Every request arrives private and unpublished, and stays that way until a member of the prayer team reviews it. That is true however the request reaches us.
  • A request is never shown publicly unless you have given consent, and even then only after review. Consent can be withdrawn at any time.
  • If you ask to remain anonymous, your name is removed before the request ever leaves our database. It is not sent to your browser and hidden by the page; it is never sent at all.
  • Only the people who need to see prayer requests can see them. Records of staff activity are deliberately kept free of the content of any request, so that reviewing who did what does not expose what was asked.
  • Depending on where you live, information about your health, beliefs or circumstances may carry additional legal protection. Where it does, we handle it on the basis of your explicit consent, and you may withdraw that consent.

Please do not use this website in an emergency. It is not monitored continuously and no one may see your message for some time. In an emergency, contact [EMERGENCY NUMBER FOR YOUR COUNTRY] or [LOCAL CRISIS LINE AND NUMBER].

Cookies

This website uses one cookie, named church_session. It is set only when a member of staff signs in to the private workspace, it identifies that session and nothing else, and it is removed when they sign out or after [SESSION LENGTH] hours. It cannot be read by scripts, it is only ever sent over an encrypted connection, and it is not sent when another website links to ours.

There are no advertising, analytics, profiling or social-media cookies, and there is no cookie banner because there is nothing to ask you about.

How long we keep things

  • Contact messages: two years from the day they are sent, then deleted.
  • Prayer requests: [PRAYER REQUEST RETENTION PERIOD]. Tell us at any time and we will remove yours sooner.
  • Newsletter subscriptions: until you unsubscribe, plus a record that you did so, which stops you being added again by mistake.
  • Staff sign-in sessions: [SESSION LENGTH] hours, and immediately when the person signs out or their password changes.
  • Records of staff activity: [AUDIT LOG RETENTION PERIOD].

Who else is involved

We use a small number of companies to run the site. They act on our instructions and may not use anything of yours for their own purposes.

  • An email provider, to deliver replies, newsletter confirmations and account messages.
  • [NEWSLETTER PROVIDER, OR DELETE THIS LINE], which holds subscriber addresses if the church uses one.
  • Cloudflare Turnstile, which checks that form submissions come from a person rather than a machine. It receives the information needed to make that check and does not identify you to us.
  • YouTube, if you choose to play a video. Videos are shown as still images until you press play, so nothing reaches YouTube before you ask for it, and the privacy-enhanced player is used.
  • Our hosting provider, [HOSTING PROVIDER AND COUNTRY].

We do not sell personal information, we do not share it for advertising, and we do not use it to build profiles or make automated decisions about anyone.

Giving and the online store

Giving is handled entirely by [GIVING PROVIDER], on their own website and under their own privacy policy. No card, bank or payment details are entered on this website or stored by us.

The online store is a separate application with its own accounts, its own records and its own privacy policy. Signing in here does not sign you in there, and the two do not exchange information about you.

Children and young people

We do not knowingly collect information from children through this website. Where a ministry needs details about a child, we collect them from a parent or guardian, on paper or in person, under [NAME OF THE CHURCH SAFEGUARDING OR CHILD PROTECTION POLICY]. If you believe a child has sent us information through this site, tell us and we will delete it.

How we protect information

  • Everything travels over an encrypted connection, and browsers are instructed to refuse an unencrypted one.
  • Passwords are stored using a modern, deliberately slow hashing algorithm and can never be read back or recovered — only replaced.
  • Staff may add an authenticator app as a second step at sign-in. Removing or replacing it requires the account password and the current code.
  • Sign-in attempts are limited, and repeated failures lock an account temporarily.
  • Staff see only what their role requires. Significant actions are recorded.
  • Uploaded images are re-encoded, stripped of hidden data and stored outside the public web root.

No system is perfectly secure, but we take these measures seriously and review them.

Your rights

Depending on where you live, you may have the right to ask us for a copy of what we hold about you, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent you have given. Exercising these rights costs nothing and will not affect how you are treated.

Write to [PRIVACY CONTACT EMAIL] and we will respond within [RESPONSE PERIOD]. We may need to confirm who you are first, so that we do not disclose someone else's information to the wrong person.

If you are not satisfied with our response you may complain to [NAME OF THE SUPERVISORY AUTHORITY OR REGULATOR AND HOW TO CONTACT IT].

Where information is held

Information is stored in [COUNTRY OR REGION]. Where a provider we use transfers it elsewhere, we rely on [DESCRIBE THE SAFEGUARD RELIED UPON].

Changes

If this policy changes we will post the new version here and update the date below. If a change materially affects how we use information you have already given us, we will tell you directly where we can.


Effective [DATE THIS POLICY TAKES EFFECT]. Last reviewed [DATE OF LAST REVIEW].

Back home