Church OS

Privacy Policy

Effective date: [Aug 2026] · Last updated: [Aug 2026]

Church Engagement OS ("we," "our," or "us") is operated by The Barrett Group LLC. This policy explains what personal information is collected through Church Engagement OS, how it is used and protected, who it is shared with, and the rights available over that data. Church Engagement OS is a ministry engagement platform — not an accounting system, not a bank, and not a provider of legal or tax advice.

1. Who controls this data — a note before anything else

This section applies to every other section below it, so it comes first.

Your church is the data controller. We are the data processor. When a church signs up for Church Engagement OS, church staff enter and manage information about members, visitors, and guests — names, contact details, household relationships, giving records, event registrations. We do not collect this information directly from those individuals, and we do not decide what is collected or why — the church does. Our role is to store it securely, make it usable for the church, and follow the church's instructions about it (including instructions to export or delete it).

Practical effect: if you are a member of a church using Church Engagement OS and have a question about what information your church has recorded about you, or want to request a correction or deletion, your church is the right first point of contact, since they control that data and can act on it directly. We support export and deletion requests a church makes to us on your behalf (see Section 8), and we are glad to help if a church is unclear on how, but we cannot act on an individual member's request without the church's involvement, in the same way a payroll processor cannot act on an employee's request without their employer.

If you are church staff with your own login (an Admin or Staff account), different rules apply to your own account information (Section 2, Account and identity information) — there, we are the controller, the same as any ordinary SaaS login.

2. Information We Collect

Account and identity information (staff/admin logins)

  • Email address (used for authentication)
  • Display name
  • Authentication method: magic link or Google OAuth. We never store passwords.
  • Role and module permissions within your church's account

Member self-serve login information

  • Email address used for magic-link sign-in
  • Which person record(s) that email is linked to within a household

Records entered by church staff (controlled by the church — see Section 1)

  • People and households — name, contact info, birthdate, address, household relationships, status (active/inactive/visitor/deceased), and any custom fields a church chooses to record
  • Giving — donation amount, date, fund, tax treatment, and notes. Payment card data for online giving is handled directly by Stripe — we do not store card numbers (see Section 5).
  • Events — registrations, including guest registrations from people not otherwise in the system
  • Groups — ministry, small-group, and committee membership

Usage and technical data

  • Application logs, used for error diagnosis
  • Session data (managed by Supabase Auth)
  • Audit records of platform support access (see Section 6)

3. How Information Is Used

  • Provide the service — store and organize records the church enters, generate giving statements, process event registrations and payments
  • Access control — enforce the permissions each church configures, so a staff member sees only the modules they've been granted
  • Authentication — verify identity via magic link or Google OAuth
  • Improve reliability — diagnose errors and data issues using application logs
  • Legal compliance — respond to lawful requests and enforce our Terms of Service

We do not sell data. We do not use church or member data for advertising, and we do not share it with data brokers.

4. Data Sharing — Subprocessors

We share data only with the vendors necessary to operate Church Engagement OS, each contractually bound to use it only to provide services to us:

  • Supabase — database hosting and authentication. Row-level security policies enforce tenant isolation at the database layer, so one church's data is not reachable from another's.
  • Vercel — application hosting.
  • Stripe — payment processing, in two distinct roles (see Section 5).
  • Resend — transactional email (magic links, notifications) and, separately, broadcast email to a church's membership.
  • PostHog — product analytics. Receives usage data (features used, screens visited) to help us improve the product. Does not receive giving amounts, financial records, or the content of member records.

Legal requirements

We may disclose information if required by law, court order, or to protect the rights and safety of our users or the public, and will notify the affected church when legally permitted to do so.

Business transfers

If Church Engagement OS is acquired or merged, data may transfer to the successor entity. Affected churches will be notified before data becomes subject to a materially different privacy policy.

5. Payment Processing — Two Distinct Flows

Platform subscription. If a church subscribes to a paid tier of Church Engagement OS, Stripe processes that subscription payment directly. Stripe receives the church's billing contact and payment card data. Governed by Stripe's Privacy Policy.

Member giving and event payments (Stripe Connect). When a church enables online giving or paid event registration, funds from members and guests are processed through Stripe Connect and settle directly into the church's own connected Stripe account — not ours. We facilitate this technically but do not take custody of these funds at any point. Payment card data for these transactions goes directly to Stripe; we store only the resulting record (amount, date, fund, and a reference to the Stripe transaction).

6. Data Security

  • Data is encrypted in transit (TLS) and at rest.
  • Row-level security (RLS) is enforced at the database layer, scoped by church, so no church's data is reachable by another's queries — this is a database-level guarantee, not only an application-level check.
  • Authentication is passwordless (magic link or Google OAuth) for staff and members alike. No passwords are stored.
  • The credentials used for backend administrative operations are never reachable from the browser application.
  • Platform support access is logged and time-limited. If our support team needs to view a church's account to help resolve an issue, that access is read-only, automatically expires (currently within 8 hours), and every session is written to an audit record — who accessed what church's data, when, and for how long.
  • We conduct periodic access reviews and maintain a tested backup/restore process.

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at the address in Section 12.

7. Data Retention

  • Active accounts — data is retained for as long as a church's account is active, per the church's own configuration and requests.
  • Backups — purged on a routine rotation schedule.
  • Giving records — churches may need to retain financial records for tax substantiation purposes even after a member is no longer active or has requested deletion of their personal information. See Section 8 for how we handle this tension between deletion requests and legitimate recordkeeping needs.

8. Export and Deletion

Both are church-controlled actions, consistent with the church being the data controller (Section 1):

  • Export. A church can export records for an individual person (for responding to that person's own request) or export its entire account's data (if it stops using Church Engagement OS).
  • Deletion / erasure. A church can request that a person's personal information be redacted. Where a church has a legitimate ongoing need to retain the underlying financial record (for example, tax substantiation for a prior year's giving), we support redacting personal details while preserving the financial record itself — the church decides which applies and we execute it; we do not unilaterally decide to keep or delete data over a church's instruction.

9. Children's Information

Church Engagement OS does not have child-facing accounts or logins. Any information about a child (for example, a birthdate or a youth-event registration) is entered by church staff or a parent/guardian — we do not collect information directly from children.

10. A Note on Religious Information

Church Engagement OS is, by its nature, built around religious congregations, and the information it stores (church membership, giving, ministry involvement) is inherently connected to religious affiliation — treated as a sensitive category of personal information under several privacy frameworks (including the EU GDPR). We take this seriously: this information is handled with the same tenant-isolation and access controls as everything else in this policy, and is never used for any purpose beyond what the church itself configures.

11. Changes to This Policy

We may update this policy as the product evolves. For material changes, we will notify affected churches by email in advance of the change taking effect. The "Last updated" date above reflects the most recent revision.

12. Contact

Questions or requests related to privacy:

  • Email: privacy@engagement.church
  • Website: engagement.church
  • The Barrett Group LLC

13. California Privacy Rights

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Because your church is generally the controller of your personal information (Section 1), requests to exercise these rights should generally go to your church first; we support and execute requests a church makes to us.

No sale or sharing of personal information

We do not sell personal information, and we do not share it for cross-context behavioral advertising as defined under the CPRA.

Your rights under the CPRA

  • Right to know what personal information is collected, used, disclosed, and shared.
  • Right to delete personal information, subject to legitimate recordkeeping needs (Section 8).
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing — we do not sell or share personal information, but the right exists regardless.
  • Right to non-discrimination for exercising any of these rights.

Email privacy@engagement.church with the subject line "California Privacy Rights Request," including your name, the church you're associated with, and the right you wish to exercise. We will take reasonable steps to verify identity and involve the relevant church before acting, and will respond within 45 days (extendable by an additional 45 days as permitted by law).

The Barrett Group LLCPrivacyTerms