Privacy policy

ChurchHub holds personal data on behalf of churches. This explains what we collect, why we hold it, who can see it, and what rights people have over it.

Last updated 25 July 2026

1. Who is responsible for your data

There are two distinct relationships, and the difference matters for your rights.

Your church is the data controller for the records it keeps in ChurchHub — its members, children, donors and volunteers. The church decides what to record and why. If you are a church member asking about your own record, your church is the right first point of contact.

ChurchHub Ltd is the data processor for that information. We store and process it strictly on the church’s instructions and do not use it for our own purposes. We are a data controller only for the account data of the people who administer a subscription with us — names, work email addresses and billing details.

2. What we collect

On behalf of a church, as its processor:

  • Contact and profile details a church records about people — names, addresses, phone numbers, email addresses, dates of birth, family relationships and photographs.
  • Children's records, including guardians, medical and allergy notes, and check-in and check-out events.
  • Giving records, including donation amounts, funds, pledges and Gift Aid declarations.
  • Attendance, group membership, rota assignments and service plans.
  • Pastoral notes, where a church chooses to record them.
  • Communications sent through the platform, and their delivery status.

As a controller, for our own account and billing purposes:

  • Account holder name, email address and password (stored only as a hash — we never see it).
  • Subscription and payment details, handled by Stripe. We store a Stripe customer reference, never full card numbers.
  • Security and audit logs — sign-in events, IP address, and changes to sensitive records.

3. Our lawful bases

  • Contract — to provide the service to a subscribing church and take payment for it.
  • Legitimate interests — to keep the platform secure, prevent abuse, and support customers. We balance this against the rights of the people whose data we hold.
  • Legal obligation — to keep financial records, and to meet Gift Aid requirements where a church claims it.
  • Consent — for marketing emails to church administrators, and for any special category data (such as a child’s medical notes) that a church collects. Consent can be withdrawn at any time.

4. Special category and children's data

Churches routinely record information that UK GDPR treats as special category data — religious belief is inherent in church membership, and children’s records often include medical and dietary needs.

We treat this data with extra restriction: pastoral notes and giving records are visible only to the roles a church explicitly grants, children’s records are limited to the Children team, and every access to a child’s record is written to an audit log the church can review. See GDPR & security for the technical detail.

5. Who we share data with

We do not sell data, and we never share one church’s data with another. We use a small number of subprocessors to run the service:

  • Hosting and database — UK/EU regions.
  • Stripe — payment processing, both for subscriptions and for a church's own online giving.
  • Resend — transactional email, where a church has connected it.
  • Twilio — SMS and WhatsApp messaging, where a church has connected it.

Each is bound by a data processing agreement. A current list of subprocessors is available on request, and we give notice before adding a new one.

6. How long we keep it

  • Church records — for as long as the church subscribes. When a subscription ends, data is retained for 90 days so an account can be reinstated, then deleted.
  • Giving and Gift Aid records — retained for seven years where a church has claimed Gift Aid, to meet HMRC requirements.
  • Audit and security logs — 24 months.
  • Deleted individual records — removed from the live database immediately and purged from backups within 35 days.

7. Your rights

Under UK GDPR you have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable format.

Because your church controls its own records, requests about a church record should go to that church, which can produce a complete export of any individual’s data from within ChurchHub. If you cannot reach them, contact us and we will help. You may also complain to the Information Commissioner’s Office at ico.org.uk.

8. Where your data is held

Church data is stored in the United Kingdom or European Economic Area. Where a subprocessor requires a transfer outside the UK, it is covered by an adequacy decision or by International Data Transfer Agreement clauses.

9. Changes to this policy

We will post any change here and update the date at the top. Where a change materially affects how we handle personal data, we will email account administrators at least 30 days before it takes effect.

Questions about this document? Email privacy@chhub.app or write to us at the address in Support.