Privacy Policy
How Oikos Church handles your data.
Preliminary draft. These terms are being finalized with legal counsel and may change before launch. Highlighted items still need completion.
Plain-language summary
- Oikos Church is software that churches use to run their ministry — people, groups, giving, children's ministry, calendars, and communication.
- Your church controls your data. We process it for your church, on your church's instructions. We don't sell it, don't advertise with it, and don't use it to train AI models.
- Children's information gets extra protection — see our Children's Privacy & Safety Addendum.
- We use a small set of trusted providers (hosting, payments, texting, AI). They're listed below.
1. Who we are and how to read this policy
This policy explains how Oikos United LLC ("Oikos," "we") handles information in the Oikos Church platform (the "Service"). Oikos Church is a multi-tenant SaaS sold to churches.
Roles matter here:
- For the information a church puts into the Service about its congregation ("Church Data"), the church is the controller — it decides what to collect and why — and Oikos is the processor, acting on the church's instructions.
- For a limited set of data we need to run our business (church-admin account info, billing, security logs), Oikos is the controller. This policy covers both, and says which is which.
If you are a congregant and have questions about your data, your first contact is usually your church; we assist your church as described here and in our Data Processing Addendum.
2. Information in the Service
Depending on the modules a church turns on:
- People: names, contact info, households/families, roles, membership status, attendance, notes, and prayer requests a church records.
- Groups & scheduling: group membership, volunteer schedules, serving history.
- Children's Ministry: children's names/ages, guardians and authorized pickups, allergy/health/special-needs notes, and check-in/out records. See the Children's Privacy & Safety Addendum — it governs children's data and controls over this policy where they differ.
- Giving & finance: donations, recurring-giving schedules, funds/designations, and year-end giving statements. Card/bank details are handled by Stripe, not stored by us. See the Giving & Donations Terms.
- Communication: messages and group texts a church sends (via our texting provider), and consent/opt-out status.
- Account & technical: church-admin login credentials (passwords stored only as secure hashes), and technical/security logs (timestamps, IP, error logs).
2a. Special-category and sensitive data — read this section carefully
A church membership system is, by its nature, a record of religious beliefs and affiliation: the fact that a person appears in a church's records at all can reveal their religion. Under the law this has specific consequences:
- EU/UK (GDPR Art. 9): data revealing religious or philosophical beliefs is "special-category" data, as are the health/allergy notes in Children's Ministry. Processing special-category data requires an Art. 9(2) condition. The church, as controller, is responsible for holding that condition — for a church this is typically Art. 9(2)(d) (processing by a not-for-profit religious body relating to its members and regular contacts, without disclosure outside the body without consent) or explicit consent (Art. 9(2)(a)). Oikos processes this data only as the church's processor, on its instructions, under the DPA.
- Virginia (VCDPA) and similar US state laws: "sensitive data" includes religious beliefs, mental or physical health information, and personal data collected from a known child — a church's congregant, health-note, and children's records fall squarely in this definition. The VCDPA requires the controller (the church) to obtain consent before processing sensitive data (and, for a known child, to comply with COPPA-style consent). Oikos supports this as processor; the church is responsible for the consent.
- Giving/donation data is treated by this policy as highly sensitive and restricted (see §6) — but note it is financial sensitivity under US state law, not GDPR Art. 9 special-category data. We track the two categories separately and protect both.
3. How information is used
Only to provide and operate the Service for your church:
- to run the modules the church enabled (people, groups, children's ministry, giving, calendar, communication);
- to authenticate users and enforce tenant isolation (one church cannot see another's data);
- to process giving through Stripe and produce giving records;
- to send communications the church initiates;
- to power optional Oikos AI features the church turns on (see §7);
- to provide support, secure the Service, prevent abuse, and comply with law.
We do not sell personal information, do not use it for cross-context behavioral advertising, and do not use Church Data — including children's or giving data — to train AI models.
Legal bases (EU/UK, where applicable): for Church Data we act on the church's instructions (the church establishes the legal basis with its congregants — and, because congregant data is special-category under Art. 9 (§2a), the church must also hold an Art. 9(2) condition, typically Art. 9(2)(d) or explicit consent); for our own controller uses, we rely on contract, legitimate interests (security, billing), and legal obligations.
4. Service providers (sub-processors)
We share information only with providers that help us run the Service:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and tenant isolation (RLS) | Church Data + account/auth data |
| [Hosting — Cloudflare Pages / CONFIRM] | App hosting, CDN, DNS, network security | Technical/connection data |
| Stripe | Online & recurring giving (payments) | Donation/payment data; card/bank data held by Stripe |
| Oikos Books (Oikos United LLC) | Backs church finance/giving ledger ("Powered by Oikos Books") | Church finance/giving data |
| Clearstream | Group/mass texting | Recipient phone numbers, message content, consent status |
| Anthropic (Claude API) | Powers optional Oikos AI features | Inputs to AI features (see §7) |
| [Background-check provider — if integrated / CONFIRM] | Volunteer screening status | Volunteer eligibility data |
Each provider is bound to protect the data and use it only to perform services for us. A current sub-processor list is maintained and made available to churches under the DPA. We may also disclose information to comply with law, protect rights and safety, or in a merger/acquisition (with notice and successor bound by this policy).
5. Tenant isolation and access
The Service is multi-tenant and is designed so that each church's data is logically isolated (using row-level security) and one church's users cannot access another church's data. Within a church, access is designed to be role-based — staff and volunteers see what their role needs, and congregants/guardians see their own (and their children's) information. Churches administer their own roles. These isolation and access controls are subject to ongoing security review and verification (see our internal security review) and are described as our intended design, not a guarantee that a control is perfectly effective at every moment.
6. Giving and donor privacy
Donation amounts and donor identity are sensitive and are designed to be restricted to authorized finance/pastoral roles within the church (subject to the security review noted in §5 and §11). Card/bank data is processed by Stripe (PCI Level 1); the Service is designed so Oikos does not receive or store full card numbers (SAQ-A posture). See the Giving & Donations Terms and §4. Giving data is never sold, never advertised with, and never used to train AI.
6a. Public giving pages (outside donors)
A church may share a public campaign giving page (link or QR code) that anyone — including people who are not part of the church — can use to give by card. If you give through such a page:
- We collect the name and email you choose to provide (used for your receipt and the church's giving records) and the gift details (amount, campaign, one-time or recurring). Stripe collects your card and billing details; Oikos does not receive or store full card numbers.
- The church is the recipient of your gift and the controller of your donor record. Oikos processes it as the church's service provider. For questions about your data or your gift, contact the church; this policy's §6 (donor privacy) and §10 (your rights) apply.
- Your information is used only for processing the gift, your receipt, and the church's donation records — never sold, never used for advertising, never used to train AI.
- If you set up a recurring gift, see the Giving & Donations Terms for your authorization and how to cancel.
7. Oikos AI
Optional Oikos AI features (e.g., ask-your-data, AI-assisted setup, marketing content) are powered by Anthropic's Claude API. Where an AI feature answers questions about church data, it is designed to minimize what leaves the church's environment (for data questions, sending the question and data structure/schema rather than bulk records, consistent with the Oikos Books design). If we change an AI feature so that additional church data is sent to the provider, we will update this policy first. We do not use church data to train AI models; per Anthropic's commercial API terms as of this policy's effective date, Anthropic does not use API inputs/outputs to train its models (Anthropic's stated practice, not an Oikos warranty). AI outputs may be inaccurate and are not professional advice. Oikos AI is off unless the church enables it. See the Terms of Service (AI section) and the Financial-Advice & Accuracy Disclaimer. [CONFIRM exact AI data-flow per feature with Dev before finalizing.]
8. Communication and texting
If a church uses texting, message recipients can opt out (reply STOP) at any time, and the church is responsible for having the required consent to message its congregants. See the SMS/Messaging Consent & A2P/TCPA Policy.
9. Data retention
Retention differs by data type, because some church records carry their own legal retention obligations:
- General congregant/account data: retained while the account is active; on termination, deleted or returned per the DPA (default within [30] days), minus limited records we must keep for law/billing.
- Giving/financial records: because donation and financial records often must be kept for multiple years (IRS/church record-keeping), these are retained for [the applicable legal/record-keeping period] and then deleted or de-identified — even where a general deletion is requested. The church should export its records before terminating. This reconciles congregant deletion rights with financial-record retention; deletion applies except where retention is legally required.
- Children's data: follows the Children's Privacy & Safety Addendum.
- Congregant deletion requests are generally fulfilled by the church in-app; we assist per the DPA. [CONFIRM windows with Paul/attorney.]
10. Your rights
- Congregants: contact your church to access, correct, or delete your information; the church can do this in-app. Where required by law, we assist the church in responding.
- EU/UK (GDPR): rights to access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with a supervisory authority — exercised through the church (controller).
- California (CCPA/CPRA): rights to know, access, delete, correct, and to opt out of sale/sharing — we do not sell or share personal information. For Church Data, Oikos acts as a service provider and does not use it beyond providing the Service.
11. Security
We use measures designed to protect Church Data: TLS in transit; tenant isolation (row-level security); role-based access; hashed passwords; access logging; and least-privilege production access. These describe our intended design and are subject to an ongoing security review; they are not a guarantee that any control is perfectly effective at every moment, and no system is perfectly secure. [CONFIRM with Dev/Security before publishing: encryption-at-rest (especially children's and giving data) and verified cross-tenant isolation — do not publish a specific security claim we have not verified, particularly given the pending review.] We notify churches of personal-data breaches without undue delay per the DPA and applicable law.
12. Children and teens
Information about children (under 13) and teens (13–17) is governed by the Children's Privacy & Safety Addendum. In short: the church obtains any required parental/guardian consent, minors do not create public accounts, minors' data (including teens') is never used for advertising, profiling, sale, or AI training, and heightened protections apply. Teen data is also subject to applicable state minor-privacy laws.
13. International transfers
The Service is operated from the United States. If a church or congregant accesses it from outside the US, information is processed in the US. For EU/UK data, transfers rely on appropriate safeguards (e.g., SCCs) per the DPA where required. [CONFIRM data-residency posture; current infra is US-hosted.]
14. Changes; contact
We may update this policy and will notify churches of material changes. Contact: Oikos United LLC, [INSERT address], [[email protected] — CONFIRM].