Privacy at a glance
- Churches control the ministry records they place in TheFaithApp; we generally process those records on their instructions.
- We separately control the data needed to run accounts, billing, security, support, and this website.
- Optional website analytics and advertising measurement stay off until a visitor accepts them.
- We do not sell personal data.
This Privacy Policy applies to TheFaithApp’s marketing website, church administration platform, public church pages and forms, companion mobile apps, support services, and related integrations (together, the Service). It should be read together with any privacy notice supplied by the church or other organisation through which you use the Service.
1. Who we are and the scope of this policy
TheFaithApp is operated by THEFAITH LTD, a company registered in England and Wales under company number 15841609. Our registered office and contact details appear at the end of this policy.
This policy explains our processing of personal data. “Personal data”, “controller”, “processor”, and “processing” have the meanings given by applicable data protection law, including the UK GDPR and Data Protection Act 2018 where they apply.
2. Our data protection roles
Data controlled by a church or organisation
A church, ministry, network, or other subscribing organisation normally decides why and how its member, donor, visitor, family, pastoral-care, safeguarding, giving, communication, and ministry records are used. For that customer data, the organisation is the controller and THEFAITH LTD acts as its processor. The organisation’s own privacy notice and instructions govern that processing.
If you want to exercise a right over customer data, contact the relevant organisation first. We support it in responding and will redirect a request when only that organisation can decide it.
Data we control
We act as controller for information needed for website operation, account administration, subscription billing, service security, product telemetry, support, legal compliance, and our own business communications. In some situations, a connected provider—such as a payment provider—also acts as an independent controller under its own privacy notice.
3. Personal data we collect
The data involved depends on the features used and the choices made by the customer or individual. It may include:
- Identity and contact data: name, email address, telephone number, postal address, profile image, date of birth, household relationships, and church affiliation.
- Organisation and account data: church details, branch, role, permissions, login and verification records, security settings, and audit history.
- Ministry and participation data: groups, attendance, events, volunteering, forms, communications, content, discipleship activity, prayer requests, and care workflows.
- Children and family-safety data: guardian relationships, consent records, check-in and pickup records, emergency contacts, authorised collectors, and safety information entered by the church or guardian.
- Sensitive and special category data: religious affiliation or beliefs inherent in church participation and, when a feature is deliberately used, health, pastoral-care, safeguarding, wellbeing, or other highly private information.
- Giving and transaction data: donor details, fund and allocation choices, amount, currency, transaction status, receipts, refunds, and limited processor references. Full card or bank credentials are collected by the connected payment provider rather than intended to be stored by TheFaithApp.
- Content and communications: files, images, audio, video, sermons, messages, support conversations, feedback, and other material submitted to the Service.
- Device, usage, and security data: IP address, browser or device type, timestamps, pages or features used, crash and diagnostic data, identifiers, and activity required to detect abuse and protect accounts.
- Integration data: identifiers, configuration, and content exchanged with services a customer chooses to connect.
4. Where the data comes from
We receive data directly from you; from the church or organisation that creates, imports, or manages your record; from another authorised user such as a guardian; from a connected provider; and automatically from the device or browser used to access the Service. Public forms and giving pages may collect data from people who do not have an account.
5. How we use data and our lawful bases
| Purpose | Lawful basis when we are controller |
|---|---|
| Provide accounts, subscriptions, support, requested features, and connected services | Performance of a contract or steps requested before entering one |
| Secure the Service, prevent fraud and abuse, troubleshoot, and maintain reliable operations | Our legitimate interests in operating a safe and dependable service; legal obligations where applicable |
| Administer billing, accounting, tax, disputes, and business records | Contract, legitimate interests, and legal obligations |
| Understand and improve website and product use | Legitimate interests for necessary service telemetry; consent for optional analytics or similar storage |
| Send service notices and respond to enquiries | Contract and legitimate interests |
| Send optional marketing | Consent, or legitimate interests where electronic-marketing law permits; every message includes an opt-out |
| Establish, exercise, or defend legal claims and comply with authorities | Legal obligations and legitimate interests |
Where consent is the basis, it can be withdrawn at any time without affecting earlier lawful processing. When we process special category data as controller, we also identify an applicable special category condition—such as explicit consent—at or before collection. When we are processor, the customer is responsible for selecting and documenting the relevant lawful bases and conditions.
6. AI-assisted features
When an authorised user deliberately invokes an AI, transcription, translation, or media-processing feature, the submitted prompt, selected source material, and generated output may be sent to the configured AI or media provider to complete that request. Customers should not submit data they are not authorised to use and should follow the privacy guidance shown in the product.
AI output is assistive and must be reviewed by a person. We do not use it, in our role as controller, to make solely automated decisions that produce legal or similarly significant effects about individuals.
8. International transfers
Some providers and customer users may process data outside the United Kingdom or the country where it was collected. Where transfer rules apply, we use an available lawful mechanism such as adequacy regulations, the UK International Data Transfer Agreement or Addendum, standard contractual clauses, and appropriate supplementary measures. A customer may also direct transfers through the integrations and users it configures.
9. Retention and deletion
We keep personal data only for as long as necessary for the purpose collected, the customer’s documented instructions, and legal, accounting, security, or dispute requirements. Retention therefore varies by record:
- customer-controlled ministry content remains subject to the customer’s retention choices, feature-specific controls, and the account lifecycle;
- account, contract, invoice, transaction, and audit records may be retained after account closure where needed for legal or financial obligations;
- support and security records are retained for a proportionate period to resolve issues and protect the Service;
- some sensitive workflows display their own shorter retention or deletion rules;
- backup copies are isolated and expire through our backup cycle unless preservation is legally required.
Plan downgrades preserve customer records as described on our pricing page, but may restrict creating new records or using features above the new allowance. Preservation is not a promise to keep data indefinitely after account termination.
10. Security
We use organisational and technical measures designed to protect personal data, including access controls, tenant separation, logging, encryption in transit, protected storage where appropriate, backups, and incident-response practices. Customers remain responsible for configuring permissions carefully, protecting credentials, reviewing integrations, and using the Service in line with their safeguarding and records policies. No internet service can guarantee absolute security.
11. Children and young people
The Service includes church-managed family, youth, check-in, safeguarding, and guardian workflows. A church or guardian—not a child acting alone—should provide and manage a minor’s data where required by law. Customers must have an appropriate lawful basis, give age-appropriate information, record guardian authority or consent when required, limit access, and follow local safeguarding rules. Some features are unavailable to minors or use additional safety restrictions.
13. Your data protection rights
Depending on the law and circumstances, you may have rights to:
- be informed and obtain access to your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- object to processing based on legitimate interests or to direct marketing;
- receive certain data in a portable format;
- withdraw consent; and
- complain to a data protection regulator.
These rights are not absolute. We may need to verify identity and may retain information where the law permits or requires it. For church-controlled records, contact the relevant church first; you may also contact us and we will help route the request.
14. Changes to this policy
We may update this policy when our services, providers, or legal obligations change. We will change the date above and, for a material change, provide a reasonable additional notice through the Service or by email where appropriate.
15. Contact and complaints
Contact us with a privacy question or request:
THEFAITH LTDCompany number 15841609
24–26 Arcadia Avenue
FIN009
London N3 2JU
United Kingdom
Email: support@thefaithapp.com
If you are in the United Kingdom, you may also complain to the Information Commissioner’s Office. If you live elsewhere, you may contact your local data protection authority. We would appreciate the opportunity to address the concern first.