ChurchHub holds personal data on behalf of churches. This explains what we collect, why we hold it, who can see it, and what rights people have over it.
Last updated 25 July 2026
There are two distinct relationships, and the difference matters for your rights.
Your church is the data controller for the records it keeps in ChurchHub — its members, children, donors and volunteers. The church decides what to record and why. If you are a church member asking about your own record, your church is the right first point of contact.
ChurchHub Ltd is the data processor for that information. We store and process it strictly on the church’s instructions and do not use it for our own purposes. We are a data controller only for the account data of the people who administer a subscription with us — names, work email addresses and billing details.
On behalf of a church, as its processor:
As a controller, for our own account and billing purposes:
Churches routinely record information that UK GDPR treats as special category data — religious belief is inherent in church membership, and children’s records often include medical and dietary needs.
We treat this data with extra restriction: pastoral notes and giving records are visible only to the roles a church explicitly grants, children’s records are limited to the Children team, and every access to a child’s record is written to an audit log the church can review. See GDPR & security for the technical detail.
Under UK GDPR you have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable format.
Because your church controls its own records, requests about a church record should go to that church, which can produce a complete export of any individual’s data from within ChurchHub. If you cannot reach them, contact us and we will help. You may also complain to the Information Commissioner’s Office at ico.org.uk.
Church data is stored in the United Kingdom or European Economic Area. Where a subprocessor requires a transfer outside the UK, it is covered by an adequacy decision or by International Data Transfer Agreement clauses.
We will post any change here and update the date at the top. Where a change materially affects how we handle personal data, we will email account administrators at least 30 days before it takes effect.