Privacy & Trust

Your data, closed by design.

How ChurchPlan actually protects your congregation day to day: two kinds of information kept apart on purpose, visibility your church dials item by item, member data owned by the church and safeguarded by us — and the things we will never do with any of it.

Private by default · your admins decide what is ever public · we never sell or pool your data.

The architecture

Two kinds of information, kept apart on purpose

Most worries about church software come down to one fear: who can reach our members' data? ChurchPlan answers it structurally. Private records and public events live on two separate planes — and only one of them can ever leave your church.

Sealed — never leaves

Your private records

Member profiles, contact details, giving history, attendance, and your directory stay inside your church alone. This is the architecture, not a setting you have to find and switch on.

  • Never pooled with other churches
  • Never sold or rented to anyone
  • Never shown on a community calendar
Shared only if you choose

The events you publish

An event you choose to announce carries its details outward — name, time, place, and a booking link — just like a flyer on the noticeboard or a listing on your own website. No member data travels with it.

  • + Published one event at a time
  • + Scoped by you, from global to a single group
  • + Changeable, or switched off, any time
At a glance

Privacy, on one page.

Privacy law compliance at a glance — PIPEDA (Canada), GDPR (EU), UK GDPR, CCPA/CPRA (California), the Australian Privacy Principles and the NZ Privacy Act 2020, built on consent, secure data handling, role-based access and audit trails

Every event carries an audience dial — open it to the wider community, share it across your diocese, or keep it to a single group. See it in action on The ChurchPlan App page.

What this means for you

Trust you can verify, not just claims

Closed

A community, not a directory

Your records aren't part of a shared pool that other organizations can browse. Each church's data is its own — separate by default, with no back door for anyone else to look in.

Controlled

The audience is always yours

From a global announcement down to a single service team, you decide who can see and book each event — and you can narrow it, widen it, or make it private whenever you like.

Owned

Your data stays yours

Your church owns its information. ChurchPlan is the custodian that runs the platform on your behalf — we hold nothing we couldn't hand straight back to you.

In writing, not just on this page

Commitments your church can hold us to.

These aren’t marketing lines — they’re obligations in the Master Service Agreement and Data Processing Agreement every church signs.

99.5%
Uptime SLA

Monthly commitment with service credits if we miss it.

72h
Breach notification

You are notified of any personal-data breach within 72 hours, in writing.

90 days
Your data, on exit

Full export window after termination — your records leave with you.

Logged
Immutable export logs

Every data export is recorded — who, when, what — and the log can’t be edited.

Data ownership

Your church owns it. We safeguard it.

There's a clear, deliberate split in who plays which role — the same split that runs through our Data Processing Agreement.

Your church

The owner Data Controller

Your church decides what information is collected, how it's used, and who in your team can reach it. The relationship with your congregation is yours, and so is the data behind it. In the language of the privacy laws — and of our Data Processing Agreement — your church is the data controller.

ChurchPlan

The custodian Data Processor

We operate the platform on your instructions — storing, protecting, and processing your data so your team can do its work. We don't repurpose it, and we don't claim it as ours. In legal terms, ChurchPlan is the data processor — what the CCPA calls a “service provider.”

Built for churches in many countries

ChurchPlan is designed around the privacy obligations churches face across the regions we serve. Where the rules differ, the platform is built to respect them.

CanadaBuilt around PIPEDA principles
United StatesState-level privacy expectations
UK & EUBuilt around GDPR principles
AustraliaBuilt around the Australian Privacy Principles
New ZealandBuilt around the Privacy Act 2020
Our commitments

Things we never do with your data

  • × Sell, rent, or trade your members' information
  • × Pool member records across different churches
  • × Share giving or contact data with other churches
  • × Put member identities on a community calendar
  • × Expose who follows or attends across church lines
  • × Use your congregation's data to advertise to them
For parish councils

Questions worth asking

Can other churches see our members?

No. Member profiles, contact details, giving, and attendance stay inside your church alone. They are never pooled with, visible to, or shared with any other church on the platform.

If a member gives to another church’s cause, who issues the receipt?

The recipient church — under its own registered charity number. Every receipt on ChurchPlan is issued by the charity that actually receives the gift, in full compliance with CRA, IRS, ATO, and New Zealand IRD rules. And it works in your favour too: gifts made to your church through the platform are receipted by you, in your name.

What actually shows up on the community calendar?

Only the events you choose to publish, and only the details you'd already put on a public flyer — name, date, place, and a booking link. You scope each event yourself, and nothing about your members travels with it.

Who owns our data?

Your church does. ChurchPlan operates the platform on your behalf as the custodian of that data — we store and protect it, but we don't own it or repurpose it. If you leave, your data goes with you. In the language of the privacy laws and our Data Processing Agreement, your church is the data controller and ChurchPlan is the data processor — what the CCPA calls a “service provider.”

Can we keep everything private?

Yes. Set events to Church only or Private, or simply don't publish them, and nothing is discoverable outside your congregation. Discovery is something you opt into, event by event — never the default we impose.

How is this different from putting events on our own website?

The data shared is the same — public event details, never member data. The difference is reach: a published event can be surfaced to people nearby and followed for updates. That's broader distribution you opt into and can scope or switch off, not broader exposure.

Built for churches, with your data closed by design

Start on the free plan, or book a walkthrough and we'll show you the audience controls live.