Effective date: July 26, 2026 · Last updated: July 26, 2026
1. Who we are
OnChurch, referred to in this Privacy Policy as the "Service," is a church-management platform that helps churches and faith-based organizations manage their members, families, giving, donations, events, attendance, ministries, communications, church websites, volunteers, and administrative operations.
The Service includes the OnChurch public website, web-based administration platform, member portal, and mobile applications for iOS and Android.
OnChurch is owned and operated by Orloptechnology ("Orloptechnology," "OnChurch," "we," "us," or "our").
The OnChurch platform was designed and developed by Edilab Studio LLC. Edilab Studio LLC also provides ongoing software development, technical maintenance, troubleshooting, security updates, and technical support services for the platform.
Edilab Studio LLC acts as a contracted technology service provider to Orloptechnology. Edilab Studio LLC does not independently own the personal information stored through OnChurch and may only access platform information when reasonably necessary to maintain, secure, troubleshoot, improve, or support the Service.
For privacy questions, requests, or concerns, contact:
Service owner and operator: Orloptechnology
Platform developer and maintenance provider: Edilab Studio LLC
Business address: 1R Newbury St Ste 104, Peabody, MA 01960
2. Churches, members, and our roles
OnChurch supports different relationships, and the privacy responsibilities of each party depend on how information is collected and used.
Information controlled by Orloptechnology
When a user creates an OnChurch account, contacts OnChurch support, manages an OnChurch subscription, or interacts directly with the platform, Orloptechnology generally acts as the controller or business responsible for that account and service information. This may include:
- Name.
- Email address.
- Phone number.
- Authentication information.
- Profile information.
- Subscription information.
- Support communications.
- Device and technical information.
- Application preferences.
Information controlled by churches
When a church uses OnChurch to manage its congregation, members, families, students, donors, volunteers, events, ministries, attendance, communications, or other church operations, the church determines which information is collected and how it is used. For this church-directed information:
- The church generally acts as the controller or business responsible for the information.
- Orloptechnology provides the OnChurch platform and generally acts as a processor or service provider on behalf of the church.
- Edilab Studio LLC acts as a contracted technology provider or subprocessor supporting the operation and maintenance of the platform.
Church-controlled information may include: member directory records; family and household relationships; attendance; giving and donation history; volunteer assignments; ministry participation; event registrations; student or children's ministry records; prayer requests; pastoral notes; communications; and uploaded documents and images.
If you are a church member and want to access, correct, or delete information that a church maintains about you, you may need to contact the church directly. OnChurch and Edilab Studio LLC will reasonably assist the church in responding to valid privacy requests when technically required. Each church may also provide its own privacy notice explaining how that church collects and uses personal information.
3. Information we collect
We collect the following categories of information through the Service. We collect only what is needed to provide the features described below; we do not use the information for advertising.
| Category | Examples | Notes |
|---|---|---|
| Account & identity | Name, email address, password (stored hashed by our authentication provider), profile photo (optional), phone (optional), job title/role in a church | Provided by you or by a church admin who invites you. |
| Church membership | Which church workspace(s) you belong to, your role (e.g., owner, admin, staff, volunteer, member), teams/ministries | Controls what you can see and do. |
| People & family records | Directory contact details, household/family groupings, notes, tags, event registrations, attendance | Entered by church admins about congregants. |
| School records (if a church uses the school module) | Student name and grade, guardian name/email/phone, family address, tuition invoices, applications | May relate to minors. We do not collect dates of birth. |
| Giving & donations | Donor name/email, amounts, fund, date, method, and payment-processor reference IDs | Card details are handled by Stripe, not stored by OnChurch. See §8. |
| Subscriptions & billing | Church subscription plan and status, Stripe customer/subscription IDs, bank last-4 for payouts | For churches that pay for OnChurch or receive donation payouts. |
| Prayer & communications | Prayer request text, announcements, messages, comments you submit | Prayer requests may reveal sensitive personal circumstances. See §17 and §18. |
| Uploaded content | Profile photos, church logos, event/website images, documents you upload | Stored in secured storage buckets. |
| Device & technical | Push-notification device token, app version, platform (iOS/Android), general log data (e.g., IP address seen by our infrastructure providers), language preference | Push token is used only to deliver notifications you enable. |
| Partner/referral (if you join the partner program) | Payout details you provide, referral attribution data (including a hashed IP address and browser user-agent for click tracking) | Only for users who enroll as referral partners. |
Sensitive information. Because OnChurch supports faith communities, some information may reveal religious affiliation, and prayer requests or pastoral notes may reveal health, family, or other sensitive circumstances. We process this information solely to provide the Service to you and your church, and we restrict access by role. We do not use it for advertising or profiling.
We do not knowingly collect: government ID numbers (other than an optional church tax ID a church may enter for receipts), precise device geolocation, biometric identifiers, or advertising identifiers.
4. Where information comes from
- From you — when you register, sign in, complete your profile, give, RSVP, submit a prayer request, or contact us.
- From your church — administrators and staff enter information about members, families, students, donors, and volunteers.
- Automatically — a push-notification token when you enable notifications; standard technical/log data generated by our infrastructure providers; your in-app language and workspace preferences.
- From service providers — for example, our payment processor confirms the status of a donation or subscription (never the full card number).
5. How we use information
- Provide the Service — create and secure accounts, run church workspaces, process and record giving, manage events and attendance, deliver announcements and notifications, and host church websites.
- Communicate with you — send transactional messages such as sign-in links, receipts, and service notices.
- Security & fraud prevention — authenticate users, enforce church-by-church data isolation, keep audit logs, and detect misuse.
- Support — respond to your requests and troubleshoot.
- Legal & accounting — keep records required for tax, donation receipts, and legal compliance.
- Improve the Service — understand which features are used, using our own internal, church-scoped reporting. We do not use third-party advertising or cross-app tracking analytics.
We do not sell personal information, and we do not use it for targeted advertising or to track you across other companies' apps or websites.
6. Legal bases (EEA/UK)
Where the EU/UK GDPR applies, we rely on: performance of a contract (to provide the Service you or your church requested); legitimate interests (to secure, maintain, and improve the Service in ways you would reasonably expect); consent (for example, push notifications and any optional marketing); and legal obligation (for example, retaining financial records). For information a church controls, the church is responsible for establishing the appropriate legal basis and any required consents (including for minors).
8. Service providers
We use contracted technology providers to operate, maintain, secure, and support the Service. Each provider should receive only the information reasonably necessary to perform its assigned function.
Supabase
Function: backend infrastructure; PostgreSQL database; user authentication; secure session management; file and image storage; real-time database updates; and server-side functions and APIs, where configured.
Information handled: Supabase may process or store account information, church workspace information, member records, family records, event information, attendance, donation records, application settings, uploaded content, authentication information, and other information entered into the Service. Passwords are managed through Supabase authentication and are not stored by OnChurch as readable plain-text passwords. The specific Supabase hosting region and data-transfer configuration match the production Supabase project settings. [Confirm hosting region.]
Vercel
Function: hosting the OnChurch website; hosting the web application and administration portal; application deployment; content delivery; serverless functions, when used; and performance, security, and operational logging.
Information handled: Vercel may process standard request and technical information necessary to deliver the Service, such as IP address, browser type, device type, user-agent information, requested pages, request timestamps, application and server logs, and general diagnostic information. Vercel does not own OnChurch user information and processes technical information as a hosting and infrastructure provider.
Edilab Studio LLC
Function: platform design and development; ongoing application maintenance; technical support; troubleshooting; bug fixes; security updates; performance improvements; feature development; and infrastructure and deployment assistance.
Information handled: Authorized Edilab Studio LLC personnel may have limited access to application systems, technical logs, Supabase infrastructure, Vercel deployments, and user information when reasonably necessary to investigate a technical problem, correct a software error, respond to a support request, maintain application security, deploy an approved update, restore platform functionality, or protect against unauthorized access or misuse.
Edilab Studio LLC may not sell OnChurch information, use it for independent advertising, create independent profiles about users, or use the information for purposes unrelated to providing development and maintenance services to Orloptechnology. Access should be limited to authorized personnel and protected through appropriate administrative, contractual, and technical safeguards.
Payment processing (Stripe)
Payments are processed by Stripe. Stripe handles payment-card information directly; OnChurch does not store complete payment-card numbers or card security codes. Stripe may receive donor or customer name, email address, payment amount, donation fund, subscription information, transaction reference, payment-method information, and fraud-prevention information. Churches receive donations through their own Stripe connected accounts.
Transactional email (Resend)
Transactional email is delivered by Resend, which may process recipient email addresses, sender information, email subject lines, transactional email content, delivery status, and basic delivery logs. These messages are used for account verification, password resets, invitations, receipts, security notices, and other operational communications.
Push notifications (Apple / Google via Expo)
Push notifications are delivered through the Apple Push Notification service, Google notification services, and Expo, which may process device push tokens, application identifiers, notification delivery information, and notification content. Push notifications are used only for features such as church announcements, reminders, event updates, account notices, and other communications enabled by the user or the user's church.
External assets and content-delivery services
The Service loads fonts, icons, QR-code images, and code libraries from external content-delivery providers (currently Google Fonts, unpkg, and api.qrserver.com). These providers may receive standard technical request information such as an IP address, browser type, requested asset, and request time. No user profiles are built. The production code should be re-audited before publication to confirm every active external provider; any provider no longer used should be removed from this policy and, where possible, from the application.
[Confirm each provider's current data-processing terms/DPA are in place.] We do not use any advertising, marketing-analytics, attribution, or crash-reporting SDKs.
9. Cookies and tracking technologies
The mobile app does not use advertising cookies or third-party tracking. Our websites use only strictly necessary browser storage — for example, keeping you signed in, remembering your selected church workspace, and remembering your language choice. We do not use nonessential analytics, advertising, or marketing cookies, so we do not display a consent banner for them. See our separate Cookie & Tracking Technologies Policy for details.
10. Hosting and storage
The OnChurch web platform is hosted using Vercel. Application information, authentication, database records, uploaded files, and real-time platform information are managed using Supabase. The mobile application communicates with the OnChurch backend and Supabase infrastructure through encrypted HTTPS connections.
Information may be processed in the United States or another region configured in the applicable Vercel and Supabase production projects. Before publishing this Privacy Policy, the exact production regions should be verified from the Supabase project settings, the Vercel project settings, the payment-provider configuration, the email-provider configuration, and any backup or external-storage configuration. [Confirm production regions.]
11. Device permissions (mobile app)
The OnChurch mobile app requests device permissions only when you use a related feature:
- Notifications — to send church announcements, reminders, and updates you choose to receive. You can disable these in device Settings at any time.
- Camera / Photos — only if you choose to add or change a photo (for example, a profile picture, church logo, or event image). If you decline, you can still use the app and add images from your library instead, or skip the photo.
The app does not request tracking permission, does not access your precise location, contacts, microphone, or health data, and does not show an App Tracking Transparency prompt because it does not track you.
12. International data transfers
Our providers may process information in the United States and other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for transfers of personal information out of the EEA/UK. [Confirm hosting regions and transfer mechanisms.]
13. Data retention
We keep personal information only as long as needed to provide the Service and to meet the purposes below. The following are OnChurch's retention rules.
| Data | Retention rule |
|---|---|
| Active account | Retained while the account is active and reasonably necessary to provide the Service. |
| Account deletion | On request we immediately disable access, revoke active sessions, and remove push tokens, and begin deleting or anonymizing personal profile information immediately. Deletion from active production systems is completed within 30 days, unless information must be retained for legal, security, fraud-prevention, financial, or contractual reasons. We confirm when the request is received and when it is completed. Deactivation alone is not sufficient. |
| Church-controlled records (member, family, attendance, ministry, event, school, volunteer) | Retained while the church has an active account, until the church deletes the data or instructs us to, or until the church's contract ends and the post-termination period expires. On church termination, an authorized administrator has up to 30 days to export applicable data; remaining church-controlled production data is deleted or anonymized within 60 days after termination, unless retention is legally required. |
| Donation, payment, subscription, tuition & financial records | Retained for 7 years from the transaction date, or longer where required by tax, accounting, fraud-prevention, or financial laws. We do not retain full card numbers or security codes. Retained financial records are disconnected from deleted user profiles where possible while preserving legally required transaction records. |
| Security & audit logs | Retained for 12 months, unless a security investigation, legal hold, or fraud/unauthorized-access inquiry requires longer. Logs are designed not to contain prayer requests, pastoral notes, complete payment information, or other sensitive content. |
| Support requests | Retained for 3 years after the request is closed, unless a dispute, legal obligation, or security investigation requires longer. |
| Email & invitation records | Transactional-email delivery records up to 12 months; unused church invitations expire after 90 days; unaccepted invitation records are deleted after at most 12 months. |
| Push-notification tokens | Removed when you delete your account, sign out permanently (where technically appropriate), when a token is invalidated, or when notifications are disabled and the token is no longer required. |
| Uploaded files | Retained while the related account, church record, event, or feature is active; deleted when you delete them, when the underlying record is deleted, during account deletion, or after the church's retention period on termination. |
| Backups | Deleted information may remain in encrypted backups for up to 90 days before automatic rotation permanently removes it. Backups are not restored to production except in a legitimate disaster-recovery event; when restored, previously approved deletion requests are reapplied where technically feasible. [Verify the provider backup window matches; correct if it differs.] |
Information may be retained longer where reasonably required for tax/accounting, fraud prevention, security investigations, legal claims, court orders, regulatory obligations, or enforcing agreements. Once that reason expires, the information returns to the normal deletion schedule.
14. Your choices and rights
- Access & portability — you can request a copy of the personal information associated with your account.
- Correction — you can edit your profile in the app, or ask us to correct information.
- Deletion — you can delete your account directly in the app at Profile → Privacy & Legal → Delete my account. This removes or anonymizes your personal account information. Some records controlled by your church, or required for legal/financial reasons, may be retained as described in §13.
- Notifications — turn push notifications on or off in device Settings.
- Marketing — we send primarily transactional messages; any optional marketing is opt-in and you can withdraw consent at any time.
To exercise a right, use the in-app controls or contact support@myonchurch.com. If your request concerns information a church controls, we will refer it to, or handle it together with, your church. We will not discriminate against you for exercising your rights.
15. U.S. state privacy rights
Depending on your state (for example, California, Colorado, Virginia, and others), you may have the right to know, access, correct, delete, and obtain a portable copy of your personal information, and to appeal a denied request. We do not sell personal information and do not share it for cross-context behavioral advertising, so no opt-out of sale/sharing is required. To exercise your rights, contact support@myonchurch.com. [Confirm applicable states and any authorized-agent process.]
16. EEA/UK rights
If you are in the EEA or UK, you have the rights to access, rectify, erase, restrict, and object to processing, and to data portability, as well as the right to lodge a complaint with your local supervisory authority. For information a church controls, please also contact your church. [If offering the Service in the EEA/UK, confirm any EU/UK representative under GDPR Art. 27.]
17. Children and minors
The minimum age to create and maintain an individual OnChurch user account is 18 years old. OnChurch is a general-audience church-management platform intended for adult church administrators, staff, volunteers, parents, guardians, donors, and adult church members. It is not designed or directed primarily toward children, is not intended for use by children under 13, does not participate in Apple's Kids Category, and does not permit minors to create their own independent accounts. We do not knowingly allow anyone under 18 to create a direct OnChurch account.
Churches may use OnChurch to maintain administrative records concerning minors — for example student names, grade or ministry group, parent or guardian contact details, attendance, event registrations, family or household relationships, and school or youth-ministry information. This information is entered and controlled by authorized adult church administrators, staff, parents, or guardians; it is not collected directly from children through child-owned accounts. We do not collect children's dates of birth.
The church is responsible for obtaining any required parental or guardian authorization, determining which information about minors is necessary, responding to parental access/correction/deletion requests, and following applicable child-protection and privacy laws (such as COPPA in the U.S. or GDPR for children in the EEA/UK).
OnChurch and its technical service providers: minimize information collected about minors; restrict access through role-based permissions; do not use minors' information for advertising, behavioral tracking, or sale; do not allow public exposure of school, youth, or children's records; assist churches with valid deletion and correction requests; and remove information reported as entered without proper authorization where legally and contractually appropriate.
If youth accounts are introduced in a future version, they will not be activated until a separate parental-consent, guardian-management, age-assurance, privacy, and deletion workflow has been designed and legally reviewed. If you believe a child's information was collected without appropriate authorization, contact support@myonchurch.com.
18. Security
Orloptechnology, with technical support from Edilab Studio LLC, uses reasonable administrative, technical, and organizational measures designed to protect personal information. These measures may include:
- Encryption in transit using HTTPS and TLS.
- Supabase authentication.
- Hashed password storage.
- Secure session tokens.
- Role-based access controls.
- Church-by-church workspace isolation.
- Supabase Row Level Security policies.
- Restricted administrative access.
- Secure environment-variable management.
- Access logging.
- Controlled production deployments through Vercel.
- Secure payment processing through external payment providers.
- Regular platform maintenance and security updates by Edilab Studio LLC.
Edilab Studio LLC's access to production systems should be limited to authorized team members who require access for maintenance, support, security, or development purposes. No method of electronic storage or transmission is completely secure; therefore, Orloptechnology and Edilab Studio LLC cannot guarantee absolute security. Users are responsible for protecting their passwords, devices, email accounts, and login credentials.
19. Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date above and, for material changes, provide additional notice where appropriate. Your continued use of the Service after an update means you accept the revised policy.
20. Contact us
For questions about this Privacy Policy, privacy rights, personal information, account deletion, or the OnChurch Service, contact:
Service owner and operator:
Orloptechnology
1R Newbury St Ste 104, Peabody, MA 01960
Platform development and technical maintenance:
Edilab Studio LLC
Edilab Studio LLC provides technical services on behalf of Orloptechnology but is not the owner of the OnChurch platform. Requests concerning information controlled by an individual church may be referred to the applicable church. OnChurch and Edilab Studio LLC may assist the church in completing the request when appropriate.