Cookie policy

ChurchHub uses a small number of cookies, and no advertising or cross-site tracking cookies at all. This lists every one and what it does.

Last updated 25 July 2026

1. Our approach

We do not run advertising networks, tracking pixels or third-party analytics that profile you across sites. The cookies below are either strictly necessary to sign you in and keep the platform secure, or they remember a preference you chose yourself.

Because we set no non-essential cookies, you will not see a consent banner asking to track you. If that ever changes, we will ask for consent before setting anything new.

2. Cookies we set

NameWhat it doesTypeLasts
authjs.session-tokenKeeps you signed in. Scoped to the root domain so one login works across your church's subdomain and the main site.Strictly necessary30 days, or until you sign out
authjs.csrf-tokenProtects sign-in and form submissions against cross-site request forgery.Strictly necessarySession
authjs.callback-urlReturns you to the page you were trying to reach after signing in.Strictly necessarySession
themeRemembers whether you chose light, dark or system appearance. Stored in local storage rather than sent to our servers.PreferenceUntil cleared
sidebarRemembers whether you collapsed the navigation sidebar. Also local storage.PreferenceUntil cleared
__stripe_mid / __stripe_sidSet by Stripe on payment pages to detect fraud. Only present when you are giving or paying for a subscription.Strictly necessary (third party)1 year / 30 minutes

3. Controlling cookies

Every browser lets you view, block and delete cookies — usually under Settings → Privacy. You can also clear the preference values from local storage there.

Be aware that blocking the strictly necessary cookies will stop you signing in: without a session cookie there is no way for the platform to know who you are between one page and the next.

4. Cookies on your church's own pages

Public pages served on your church’s subdomain — giving forms and calendar feeds — use the same cookies listed above. If your church embeds a ChurchHub calendar or giving form in its own website, those cookies apply on that page too, and your church should reference them in its own cookie notice.

5. Related documents

For how we handle personal data more broadly, see the privacy policy. For the technical controls behind it, see GDPR & security.

Questions about this document? Email privacy@chhub.app or write to us at the address in Support.