ChurchHub uses a small number of cookies, and no advertising or cross-site tracking cookies at all. This lists every one and what it does.
Last updated 25 July 2026
We do not run advertising networks, tracking pixels or third-party analytics that profile you across sites. The cookies below are either strictly necessary to sign you in and keep the platform secure, or they remember a preference you chose yourself.
Because we set no non-essential cookies, you will not see a consent banner asking to track you. If that ever changes, we will ask for consent before setting anything new.
| Name | What it does | Type | Lasts |
|---|---|---|---|
| authjs.session-token | Keeps you signed in. Scoped to the root domain so one login works across your church's subdomain and the main site. | Strictly necessary | 30 days, or until you sign out |
| authjs.csrf-token | Protects sign-in and form submissions against cross-site request forgery. | Strictly necessary | Session |
| authjs.callback-url | Returns you to the page you were trying to reach after signing in. | Strictly necessary | Session |
| theme | Remembers whether you chose light, dark or system appearance. Stored in local storage rather than sent to our servers. | Preference | Until cleared |
| sidebar | Remembers whether you collapsed the navigation sidebar. Also local storage. | Preference | Until cleared |
| __stripe_mid / __stripe_sid | Set by Stripe on payment pages to detect fraud. Only present when you are giving or paying for a subscription. | Strictly necessary (third party) | 1 year / 30 minutes |
Every browser lets you view, block and delete cookies — usually under Settings → Privacy. You can also clear the preference values from local storage there.
Be aware that blocking the strictly necessary cookies will stop you signing in: without a session cookie there is no way for the platform to know who you are between one page and the next.
Public pages served on your church’s subdomain — giving forms and calendar feeds — use the same cookies listed above. If your church embeds a ChurchHub calendar or giving form in its own website, those cookies apply on that page too, and your church should reference them in its own cookie notice.
For how we handle personal data more broadly, see the privacy policy. For the technical controls behind it, see GDPR & security.