Privacy
Privacy Policy
Last updated 5 October 2026
A church trusts us with the records of its people. This is what we collect, why, who else handles it, and what you can ask of us — in plain words.
1.Who we are, and whose data it is
ChurchDiary is church management software, built and run from Chennai, India. This policy covers two kinds of personal data, and our role differs between them.
- Data a church keeps in ChurchDiary — its members, families, workers, giving and records. The church decides what to record and why; it is in charge of that data. We store and process it only to run the service for the church, and only on its instructions.
- Data about you as our customer or visitor — when you visit this website, ask for a demo, contact us or create an account. For this data we decide how it is used, and this policy explains how.
If you are a church member with a question about your record, ask your church first: it can see, correct and remove what it holds about you. You can also write to us, and we will pass the request on.
2.What this website collects
As you browse, this website records your visit so we can see what churches look for and where the site falls short:
- the pages you open, how long each was in view, how far down you read, and the links and buttons you click;
- which forms you start and send — not what you type, until you send it;
- how you arrived: the site that sent you, the campaign tags on the link, and an advertiser’s click id if an ad brought you;
- your device type, browser, operating system, screen size, language, time zone, connection type and the currency you chose;
- your approximate location (country, region, city) where our hosting supplies it, and a scrambled (salted and hashed) form of your IP address — never the address itself.
All of it is tied to a random id this browser keeps for this site, so a second visit is recognised as the same visitor.
When you send a form — creating an account, requesting a demo or contacting us — we receive what you entered:
- Create an account — your organisation’s and church’s names, your name, email address, phone number (optional) and country.
- Request a demo — your name, church, email address, phone number, the size of your church, a preferred date and anything you write to us.
- Contact us — your name, church, email address, the reason you are writing and your message.
We then link those details to the visit history above, so we know what you had already looked at when we reply. We use them to set up your account, arrange the demo or answer you. We do not sell them, and we do not add you to a mailing list you did not ask for.
4.What the service holds
What a church records is up to the church. Depending on what it uses, the service can hold:
- People — names, contact details, addresses, dates of birth, gender, occupation, photographs, family relationships and member numbers.
- Church life — baptism, salvation, child dedication and marriage records, with their dates, places, photographs and certificates; groups; prayer requests.
- Workers — designations, education, ordination, family details and the documents a church chooses to keep, which can include proof of identity or address.
- Money — gifts, offerings and transactions, with the giver’s name and contact details.
- Sign-in — for each login, its name, email address and phone number, a hashed password, and a history of sign-ins with the time, the IP address and the browser used.
Some of this is sensitive — records of faith reveal religious belief, and identity documents carry government numbers. A church should record only what it needs, tell its people what it keeps, and have their consent where the law asks for it, including a parent’s or guardian’s for a child.
5.Church websites
Each church can publish its own website from ChurchDiary. To show the church how its site is used, those websites count visits: pages viewed, time on a page, clicks, the referring site and the visitor’s language and time zone, against a random identifier kept in the visitor’s browser.
- A visitor’s IP address is hashed before it is stored, and the address itself is not kept.
- Individual visit events are deleted after 90 days.
- A browser that sends Do Not Track is not counted.
A church may also switch on Google Analytics, Google Tag Manager or Microsoft Clarity for its own site, and its forms are protected by Google reCAPTCHA. Those services then receive visitor data under their own policies, and the church is responsible for telling its visitors.
7.How it is protected
- Every screen checks the signed-in person’s role, and each church’s data is kept apart from every other church’s.
- Passwords are never stored. We keep a salted hash (PBKDF2-SHA256, 600,000 rounds), which cannot be turned back into the password.
- Repeated failed sign-ins lock the account for a while.
- Data travels over encrypted connections (HTTPS).
No system is perfectly secure. If a breach affects your data, we will tell the church concerned, and the authorities where the law requires it, without undue delay.
8.How long it is kept
- A church’s data is kept for as long as the church has an account. The church can change or delete records at any time.
- Enquiries from this website are kept while we are in touch with you, and deleted when they are no longer needed.
- The record of each page view and click on this website is deleted after 180 days. The summary of each visit, and of each visitor, is kept to show how the site is used over time, and is deleted if you ask us.
- Database backups are taken around each release and kept for 14 days, so deleted data can remain in a backup for up to that long before it is gone.
When a church closes its account, we delete its data, apart from what the law requires us to keep.
9.Your rights
You can ask to see the personal data held about you, to correct it, or to have it deleted, and you can withdraw consent you have given. For data a church keeps, the church answers the request; we help it do so. For data about you as our customer, write to us and we will answer.
If you are not satisfied with our answer, you can complain to the data protection authority where you live — in India, the Data Protection Board of India.
10.Changes and contact
When this policy changes, the new version appears here with a new date. If the change is significant, we will tell account holders by email before it takes effect.
Questions, requests and complaints: support@churchdiary.in, or through our contact page.
See also our Terms of Service.