Privacy Policy

MyChurch by Giftinz handles real congregation data. This policy explains, in full, how we collect, use, and protect it, including member records, attendance, giving history, and pastoral care.

Last Updated: 25/07/2026 | Effective Date: 25/07/2026

1. Introduction

MyChurch is a Giftinz product: a church website, giving, and member-management platform operated by Giftinz Limited (UK) and Giftinz Invent Limited (Nigeria), the same companies that operate Giftinz's core gifting platform at giftinz.com.

This Privacy Policy is dedicated to MyChurch and explains how we handle data that is specific to running a church on our platform, including member records, attendance, pastoral and welfare data, and congregational giving. For data handling that MyChurch shares with the rest of Giftinz, such as payment processing mechanics, general account security, and international transfers, this policy cross references, rather than repeats, Giftinz's Privacy Policy.

By using MyChurch, whether as a church, a Church Admin, or a member, you consent to this Privacy Policy, Giftinz's shared Terms of Service, and any applicable local laws.

2. Scope

This policy applies to:

  • Every church using MyChurch to run its website, giving, or member records
  • Every member, visitor, or first timer whose data a church holds on MyChurch
  • Every Church Admin, pastor, or team member with a role on a church's MyChurch account
  • Public MyChurch pages such as church directories, church websites, and the Bible reader

It does not replace Giftinz's Privacy Policy — it sits alongside it for the parts of MyChurch that are genuinely different from Giftinz's core gifting and events product.

3. Data We Collect

3.1 Church Account Data

Church name, denomination, faith type, location, contact details, registration and legal entity information, branch structure, department and giving category setup, and the church's chosen website content and theme.

3.2 Member Records

Full name, phone number, email, gender, marital status, address, emergency contact, department and group membership, membership status, join date, preferred contact channel, attendance, and any custom fields a church has configured for its own register. Joining a church on MyChurch never requires the member to create an account.

3.3 Giving & Financial Data

Tithe, offering, campaign, and pledge amounts, giving category, currency, and giving history by member, recorded against the church's own account. Card, bank, and mobile money details are collected and processed by our payment providers, not stored by MyChurch directly. See Section 5 below.

3.4 Pastoral & Care Data

Prayer requests, welfare/pastoral care notes, and care case records that a church chooses to record about its own members. This category has additional protections described in Section 4.

3.5 Information We Collect Automatically

Device and browser information, IP address, and usage data (page views, feature usage) when you visit a church website or MyChurch's own pages, on the same terms described in Giftinz's Privacy Policy.

4. Pastoral & Care Data

Prayer requests default to private, visible only within a church's own moderation and pastoral care tooling, never on any public wall or page unless a member has explicitly chosen to share it publicly.

Welfare and pastoral care cases are protected by a permission model separate from general member record access: a care case is only visible to the specific people assigned to it (for example, a pastor or care team member granted a "manage care" or "full access" scope for that church), and every access, whether allowed or denied, is written to an audit trail.

Prayer requests and pastoral/welfare care data are never included in member data exports (such as a church's member CSV export) and never appear on any public surface. This is a firm product rule, not a configurable setting.

5. Giving & Payment Data

Tithes, offerings, campaigns, and pledges given on MyChurch are processed through the same Giftinz payment infrastructure and payment providers used across Giftinz, including card payments, bank transfers, and mobile money, disbursed to the church's own verified beneficiary account. We do not hold funds on a church's behalf.

For how payment data is collected, verified, secured, and shared with payment processors and identity verification partners (including KYC/AML checks, PCI-DSS compliant processing, and fraud detection), see Sections 3, 6, and 10 of Giftinz's Privacy Policy, which apply to MyChurch giving in full, and we do not repeat that detail here.

What MyChurch adds on top: giving is recorded against the specific member and giving category it belongs to, so a church can see its own giving history and issue records (such as Gift Aid declarations, where applicable) without a separate spreadsheet.

6. Who Can See What

Access to a church's data on MyChurch is role based. A Church Admin only sees what their assigned scope grants, for example, a finance focused role sees giving and financial reporting but not necessarily pastoral care cases, while a role with full access sees everything the church itself can see.

  • Owner / full access – sees and can manage everything for that church
  • Finance admin – giving, pledges, and financial reporting
  • Care / pastoral roles – only the specific care cases they are assigned to, per Section 4
  • Members – their own record and giving history, and any public information the church has chosen to publish

Roles and scopes are set by the church itself. Giftinz staff do not access a church's member or pastoral data except as needed to provide support, investigate misuse, or comply with the law, consistent with Giftinz's Privacy Policy.

7. Data Sharing

We may share MyChurch data with:

  • The church itself and the Church Admins it has assigned roles to
  • Payment processors and identity verification partners, for giving and church verification (see Giftinz's Privacy Policy for the full list)
  • Cloud hosting, messaging (SMS/WhatsApp/email), and analytics vendors that support the Service
  • Regulatory authorities and law enforcement, when required by law

We do not sell member or church data to third parties, and pastoral/care data is never shared outside the church's own assigned care team except where the law requires it.

8. Data Controller

Each church using MyChurch is its own data controller for the member and pastoral data it chooses to record. A church decides what data to collect from its members, who on its team can see it, and how long to keep it, within the limits this policy and MyChurch's Terms allow.

Giftinz Limited (UK) and Giftinz Invent Limited (Nigeria) act as the data processor providing the MyChurch platform and infrastructure the church runs on, and are the controller for account, payment, and platform level data described in Giftinz's Privacy Policy (such as fraud prevention and platform security).

If you are a member with a question about your own data, your church is usually the right first point of contact, since it controls its own member records. If you are unsure who to contact, email us at the address in Section 15 and we will direct you.

9. Retention, Export & Deletion
  • A church can export its own member register (excluding pastoral/care data, per Section 4) as a CSV at any time
  • Member and giving data is kept for as long as the church's MyChurch account is active
  • A church may request deletion of its member data, subject to the same regulatory retention periods described in Giftinz's Privacy Policy for financial record keeping (for example, giving records tied to payment compliance)
  • An individual member can ask their church, or MyChurch directly, to correct or remove their own record, subject to the church's own retention obligations
10. Security

MyChurch runs on the same security foundation as Giftinz: encryption in transit and at rest, PCI-DSS compliant payment processing, and access controls scoped by role. Pastoral and care data carries the additional, permission scoped access model described in Section 4, with every access attempt logged.

11. Children & Young Members

Churches commonly record younger members (for example, in children's or youth ministry) as part of their congregation. A church is responsible for having appropriate consent from a parent or guardian before recording a minor's data, and for applying the same care to that data as any other member record. MyChurch itself, as a platform for account holders and Church Admins, is not intended for use by anyone under 18.

12. Your Rights

Under GDPR and NDPR, you have the right to access, correct, restrict, or request erasure of your data, and to receive it in a portable format, in the same way described in Giftinz's Privacy Policy. For a member record held by a specific church, we may direct your request to that church first, since it controls its own member data.

To exercise your rights, email privacy@giftinz.com.

13. Cookies

MyChurch uses cookies on the same basis described in Giftinz's Cookie Policy, which covers MyChurch by name. We do not use separate or additional cookie categories for church websites.

14. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated to churches via email or in-app notification.

15. Contact Us

For privacy questions specific to MyChurch:

mychurch.giftinz.com

Data Controllers:

  • • Your church – for its own member and pastoral care data
  • • Giftinz Limited (UK) – for UK/EU platform and payment data
  • • Giftinz Invent Limited (Nigeria) – for Nigerian platform and payment data

For anything not specific to MyChurch, see Giftinz's Privacy Policy.