Children's Privacy & Safety
How we protect children’s data and secure check-in.
Preliminary draft. These terms are being finalized with legal counsel and may change before launch. Highlighted items still need completion.
Why this document exists (plain language)
Oikos Church includes a Children's Ministry suite (Sunday School, Youth, VBS) that handles information about minors — who they are, who may pick them up, their allergies and health notes, and their attendance. It also gates volunteers behind background checks. Children's data is the most sensitive data the platform touches and carries the most legal risk (COPPA, state child-privacy laws, and real-world child-safety duties). This addendum defines how that data is handled and who is responsible for what.
The core allocation of responsibility:
- The Church is the party with the direct relationship to families. The Church decides what to collect, obtains any required parental/guardian consent, sets who may access a child's record, and runs its own child-safety policy. Under privacy law, the Church is the controller of children's data.
- Oikos United LLC is the technology provider (processor). We build the controls (secure check-in/out, guardian matching, room ratios, role-based access, background-check gating) and process children's data only to provide the Service to the Church, on the Church's instructions. We do not use children's data for any other purpose, ever.
1. Scope
This addendum supplements the Oikos Church Privacy Policy, Terms of Service, and Data Processing Addendum. It governs personal information about children (individuals under 18, with heightened rules for under-13 under COPPA) processed through the Children's Ministry features. Where this addendum conflicts with the general Privacy Policy on children's data, this addendum controls.
2. Children's information the platform can process
Configured by the Church; typically:
- Child identity: name, age/grade, birthdate, photo (if the Church enables it), and a check-in identifier/code.
- Guardian/authorized-pickup: names and contacts of parents/guardians and approved pickup persons; the guardian↔child relationship.
- Health & safety notes: allergies, medical/dietary notes, and special-needs notes the Church chooses to collect. These are sensitive and are treated with the highest protection.
- Attendance & check-in/out records: time, room, and who checked the child in/out.
- Volunteer eligibility: background-check status of adults working with children (see §7).
Data minimization: the platform is configured to collect only what the Church needs for safe operation. We recommend Churches collect the minimum necessary and avoid free-text health detail beyond what safety requires.
3. COPPA and parental consent (posture: UNRESOLVED — treated conservatively)
- COPPA (the US Children's Online Privacy Protection Act) restricts collecting personal information online from children under 13. Our working assumption is conservative: we do not assume Oikos is exempt, and we do not rely on the "school/church acts as the parent's agent" theory (that FTC position is narrow, developed for schools, and its extension to churches is uncertain).
- The open question — which the attorney must resolve — is whether any Oikos-provided or Oikos-hosted flow (for example, a family/guardian self-registration form, youth self-check-in, or a minor using a feature) causes Oikos (not just the Church) to be an "operator" that collects children's information online. If it does, a verifiable-parental-consent (VPC) mechanism will be required and must be built before that flow handles real under-13 data.
- Until that question is resolved conservatively in our favor, we design as if VPC may be required: children's records are created and managed by Church staff/volunteers and guardians (not by children themselves), minors do not create public accounts, and any family-facing registration flow is gated pending the COPPA determination.
- Parental/guardian consent is obtained by the Church. The Church represents it has the right to enter each child's information and has obtained any consent required by law or its own policy. The platform provides guardian-linked records and check-in to support this but does not substitute for the Church's consent process.
3a. Teens (ages 13–17)
COPPA covers under-13, but a growing set of state laws protect minors 13–17 (e.g., Virginia's VCDPA known-minor provisions, and minor-specific rules in other states). Note: under the VCDPA, personal data collected from a known child is per-se "sensitive data" requiring consent — and a church's records are additionally sensitive because they reveal religious affiliation (see Privacy Policy §2a). The Church, as controller, holds both consent obligations. For teen data (e.g., Youth Group), the platform applies the same heightened protections as for younger children (need-to-know access, no advertising/profiling/sale, no AI training) and the Church is responsible for any consent those laws require.
- Right to review and delete. A parent/guardian may ask the Church to review, correct, or delete their child's information. The Church can fulfill this in-app; where the Church needs our help, we assist per the DPA. We do not knowingly retain a child's data after the Church deletes it, subject to the retention rules in §6.
- No behavioral advertising, ever. Children's data is never used for advertising, profiling, sale, or AI-model training. This is absolute.
4. Secure check-in / check-out
- Check-in generates a matched code/label so a child is released only to an authorized guardian/pickup person.
- Check-out requires the matching code or an authorized person on the child's record.
- Check-in/out events are logged for safety and dispute resolution.
- The platform supports safe release; it does not guarantee it. Physical supervision and release decisions are the Church's responsibility and its staff/volunteers'. Oikos is not responsible for a Church's operational failure to follow its own check-in/out procedures (see Limitation of Liability in the ToS).
5. Access controls (who can see a child's record)
- Access is role-based and tenant-isolated (multi-tenant RLS): only authorized Church roles (e.g., children's-ministry leaders, check-in volunteers within scope) can see the child data they need, and only within their own Church tenant.
- Guardians see only their own children.
- Health/allergy notes are surfaced to volunteers on a need-to-know basis (e.g., a child's room/leader), not broadly.
- The Church administers roles and is responsible for granting access appropriately. Security review of these controls is tracked separately; this addendum states the policy those controls must meet.
6. Retention and deletion of children's data
- Children's data is retained only as long as needed for the Church's ministry operations and its record-keeping, then deleted or de-identified.
- On a guardian/Church deletion request, the child's record is deleted within [30] days, except limited attendance/safety logs the Church must retain for its own liability records (retained no longer than [INSERT] and then purged). [CONFIRM windows with Paul + attorney.]
- On Church account termination, children's data is deleted or returned per the DPA.
- Data minimization at rest: we recommend Churches periodically purge inactive child records.
7. Volunteer background-check gating (adults, not children)
- The platform can gate volunteers from serving with children until a background-check status is recorded/verified.
- The Church runs the background-check process (through its chosen provider) and makes the eligibility decision. If a third-party screening provider is integrated, that provider's terms and FCRA obligations (adverse-action notices, permissible purpose, applicant disclosures/consent) are the Church's responsibility as the entity requesting the check.
- Oikos does not make hiring/volunteer eligibility decisions and is not a consumer-reporting agency.
8. Health/allergy information
Allergy, medical, dietary, and special-needs notes are sensitive personal information about minors. The platform: limits their display to need-to-know roles; does not use them for any purpose other than child safety within the Church; and applies the same security as other children's data. The Church is responsible for the accuracy of these notes and for acting on them operationally. The platform is an information tool and is not a substitute for the Church's supervision, medical judgment, or emergency response.
9. Security
Children's data is designed to receive the platform's protections (encryption in transit, tenant isolation via row-level security, role-based need-to-know access, access logging). These describe our intended design and are subject to the pending security review; they are not a guarantee. Real children's data must not be processed in production until Dev confirms encryption-at-rest for child records and Security verifies that cross-tenant isolation fully protects child data — this is the single question an attorney and a parent will ask first. A children's-data breach is treated as high-severity and notified per the DPA and applicable law.
10. Church representations (what the Church agrees to)
By using Children's Ministry features, the Church represents and agrees that it:
- has the right and any required parental/guardian consent to enter each child's information;
- will use children's data only for its legitimate ministry purposes;
- will grant access only to appropriately screened, authorized persons and follow its own child-safety policy;
- runs and stands behind its volunteer background-check and supervision practices;
- will honor guardian requests to review/correct/delete a child's data;
- will not use the platform to collect more children's data than it needs.