✦ Legal ✦
Privacy Policy
Last updated September 2026
Your church trusts you with sensitive information about its members - and you trust us with that same information when you use WorshipHQ. This policy explains, in plain language, what we collect, why, how it’s protected, and the choices you and your church have.
1. Who this covers & who controls what
Your church is the data controller for the information it enters about its members, visitors, and donors - it decides what to collect and why. WorshipHQ is the data processor: we hold and process that information only to provide the Service to your church, following your church’s instructions (given through how you use the app).
2. Information we collect
- Account details: your church’s name and address, and the names, emails, and phone numbers of the admins and team members you register.
- Church data you enter: member and visitor records, attendance, groups, giving and pledges, welfare and accounting entries, events, and similar ministry information.
- Communications content: the SMS and email messages your church sends through the platform, and delivery status (sent, delivered, failed) so you can see whether they went through.
- Payment information: handled entirely by Paystack - we never see or store full card or mobile-money numbers, only the outcome of a transaction.
- Biometric information (only if you enable it): see the dedicated section below.
- Usage & device data: basic technical logs (IP address, browser type, pages visited, timestamps) needed to keep the Service secure, diagnose problems, and improve performance.
3. Biometric information
Fingerprint check-in is optional and off by default - a church administrator must explicitly turn it on and enrol each member. If your church uses it:
- We store an encrypted mathematical template derived from a fingerprint scan - not a photograph or image of the fingerprint.
- The template is used only to recognise that person at check-in. It is never used for any other purpose, never sold, and never shared with advertisers or any third party outside the providers strictly needed to run the feature.
- It is your church’s responsibility to obtain each person’s informed consent (or a parent/guardian’s consent for a minor) before enrolment, in line with any biometric-privacy law that applies to you.
- An administrator can delete a member’s biometric data at any time from their profile, and it is deleted automatically when the member record itself is deleted.
4. Children’s & minors’ information
WorshipHQ is a tool for churches, not a service offered directly to children. Where a church keeps records for its children’s or teen ministry - including a parent or guardian’s name and phone number - that information is entered and managed by the church, which is responsible for having the appropriate parental consent. We do not knowingly collect information directly from a child, and our public sign-up flow is intended only for an adult acting on behalf of a church.
5. How we use information
To provide and maintain the Service, process payments, deliver the messages your church asks us to send (including receipts, reminders, and sign-in verification codes), provide customer support, keep the platform secure, and improve reliability and features. We do not sell your data, and we do not use your church’s member data for advertising - ours or anyone else’s.
6. How we share information
We share information only with the providers that make the Service work, and only as much as each needs to do its job:
- Paystack - to process subscription payments.
- Our SMS & email providers - to deliver the messages your church sends and our own security notices.
- Cloud hosting & database providers - reputable infrastructure providers that store and run the Service; your church’s data is logically isolated from every other church’s.
We may also disclose information if required by law, to protect the rights or safety of WorshipHQ or others, or in connection with a merger, acquisition, or sale of assets - in which case the new owner would remain bound by this policy for data already collected.
7. Data retention
We keep your church’s data for as long as your account is active. If you cancel, we retain it for a reasonable period in case you resubscribe, after which it is permanently deleted from our production systems. You can delete individual records (a member, a message, a biometric enrolment) within the app at any time, and export a full copy of your church’s data whenever you like.
8. Security
Data is encrypted in transit, and each church’s data is isolated from every other church’s at the database level. We apply access controls and audit trails to guard against unauthorised access, and a small number of authorised support staff may access account information only when necessary to provide support, troubleshoot an issue, or as required by law. No system is perfectly secure, but we take safeguarding your data seriously and continually invest in improving it.
9. International data storage
Your data may be stored and processed on servers located outside your church’s country, operated by our hosting and database providers. Wherever it’s stored, we require the same standards of protection described in this policy.
10. Your rights & choices
- Export your church’s data at any time from Settings → Download data.
- Correct or delete member records directly within the app.
- Delete a member’s biometric enrolment at any time, without deleting the rest of their record.
- Ask us to close your account; we’ll retain data only for a reasonable period before deleting it.
- Depending on where your church is based, you or the individuals in your records may also have rights to access, correct, or object to processing under local data-protection law - including the right to lodge a complaint with your national data-protection authority (for example, Ghana’s Data Protection Commission under the Data Protection Act, 2012, Act 843).
11. Cookies
We use only the essential cookies needed to keep you signed in and to remember basic preferences. We don’t use third-party advertising or tracking cookies on the WorshipHQ app.
12. Messaging consent
Churches are responsible for having permission to contact the people they message through the Service. SMS and email features should only be used to reach people who expect to hear from the church.
13. Changes to this policy
We may update this policy from time to time, most often to reflect new features or legal requirements. If we make a material change, we’ll notify account owners by email or in-app notice before it takes effect. The version shown here always reflects our current policy.
14. Contact
Privacy questions or requests - including data access, correction, or deletion requests? Email support@worshiphq.org and we’ll help.