1. Who we are
HolyCRM.app ("HolyCRM", "we", "us") provides a web-based CRM for church administration. This policy explains what personal data we handle and why.
2. Data we process
- Account data — name, email address and password for people who sign in to administer a church.
- Church records — information a church enters about its members, visitors, groups, ministries, events, serving rotas and finance. The church is the controller of this data; we process it on the church's behalf.
- Usage data — basic, aggregate analytics about how the app is used, to improve reliability and performance.
3. How we use it
- To provide and secure the service.
- To authenticate users and enforce church-level access.
- To send account and service emails (invitations, password resets, email verification).
- To diagnose problems and improve the product.
4. Sharing
We do not sell personal data. We share it only with infrastructure providers that host and deliver the service, under contract, and where required by law.
5. Church-to-church isolation
Data belonging to one church is not accessible to another. Access is scoped to the churches a user is a member of and enforced on our servers.
6. Retention
Church records are retained while a church's account is active and for a limited period afterwards, then deleted or anonymised. A church can request export or deletion of its data.
7. Your rights
Depending on where you live, you may have rights to access, correct, export or delete personal data about you. Members and visitors should contact their church first, as the church controls that data; you can also contact us.
8. Security
We use industry-standard measures including encrypted transport, hashed passwords, membership-based access rules and least-privilege roles. No system is perfectly secure; report concerns to security@holycrm.app.
9. Changes
We will post any changes to this policy on this page and update the date above.