Privacy Policy

We exist to help equip, organize, & grow churches through technology.

Privacy Policy

This Privacy Policy describes how One Church Software, Inc. (“One Church Software,” “One Church,” “we,” “us,” or “our”) collects, uses, and shares information. One Church Software, Inc. is the company that develops, owns, and operates the One Church Software platform, and is the developer identified on the Apple App Store and Google Play store listings for our mobile applications. This Privacy Policy applies to information collected through: (1) our websites, including onechurchsoftware.com, and other websites we own and operate (the “Websites”); (2) our cloud-based, subscription church management software (the “Platform”); and (3) our mobile applications, including “My One Church App” and “One Church Check-In,” which are available through the Apple App Store and Google Play (the “Apps”). The Websites, the Platform, and the Apps are referred to together in this Privacy Policy as the “Service.” It will notify you of the following:

  • What personally identifiable information is collected from you through the website, how it is used and with whom it may be shared.
  • What choices are available to you regarding the use of your data.
  • The security procedures in place to protect the misuse of your information.
  • How you can correct any inaccuracies in the information.

 

Definitions 

Capitalized terms not defined under this section shall have the meaning given in our Terms of Service.

“Children” means individuals under the age of 13.

“Chat Feature” means the interactive, real-time messaging functionality within the Service.

“User” means any individual who access, engages, registers for, or otherwise uses the Service, regardless of whether or not they have created an account. This definition shall include anyone who interacts on behalf of an organization or entity. 

“User Content” means any messages, files, images, links, or other content submitted or transmitted through the Service.

“We” means One Church Software employees, operators, and any other persons designated by One Church Software to perform responsibilities in relation to the Services

 

Information Collection, Use, and Sharing 

We are the sole owners of the information collected on this site. We collect information you voluntarily provide — such as your name, email address, and account details — as well as information generated through your use of the Service, including content you create or transmit, usage data, and device and connection information. We will not sell or rent this information to anyone.

We use the information we collect to deliver, operate, and improve the Service; enforce our Terms of Service and acceptable use policies; comply with our legal obligations (including mandatory reporting obligations under applicable law); respond to support requests; and communicate with you about the Service. We will not share User information with third parties outside of our organization, except to the extent necessary to fulfill User requests, support User accounts, or to maintain compliance with applicable laws or governmental investigations.

The content of private User messages will not be used for purposes of generating advertisements or to build a User advertising profile.  Users will have the option to opt out of communications We send either by email or text message regarding specials, new products or services, or changes to this Privacy Policy.

 

How to Opt Out or Request Deletion of Your Data

There are two audiences for our platform: (1) our customers and (2) the customers of our customers (typically church members and guests). This section details how to request personal data deletion for each audience.

Our Customers

You may opt out of any future contacts from us at any time by clicking on the unsubscribe link found in communication we send you. You can also do the following at any time by contacting us via the email address or phone number given on our website:

  • See what data we have about you, if any.
  • Change/correct any data we have about you.
  • Have us delete any data we have about you.
  • Express any concern you have about our use of your data.

Customers of our Customers (i.e., Church Members, Guests)

You can opt out of any emails your church sends you by clicking on the unsubscribe link in the footer. You can also opt out of text messaging at any time by replying STOP to your church’s specific text messaging number.

You may also request deletion of your data by logging into your church’s One Church portal. From there, click on “Visit My Profile” at the top of the side menu and then “Actions > Request profile deletion” from the upper right. Follow the on-screen prompts to complete the request. Your data (except giving history needed for tax purposes) will be automatically and fully deleted within 14 days from submission.

Please note that certain data may be retained beyond a deletion request where required by applicable law or legal process, in connection with an open law enforcement investigation, or as otherwise permitted under this Privacy Policy.

You can reach out to your church or One Church support if you need help with anything in this section.

 

Security 

We take reasonable precautions to protect your information. When Users  submit information via the website, the information is secured both on and offline using standard industry practices.

Sensitive information, such as payment data, is encrypted and transmitted in a secure manner. Before submitting sensitive data, Users should verify that they are using a secure web browser by checking for a closed lock icon on the bottom of the browser or by ensuring the web address of the page begins with “https”. Information accessed by One Church Software employees is limited to that which is necessary to carry out the job function for which such information was provided.

Messages transmitted through messaging features are encrypted in transit using industry-standard TLS (Transport Layer Security) encryption. Message content is stored on our servers and is subject to standard data security practices.

 

Registration

To use this website, users must complete an online registration which requires certain personal information to be provided, including but not limited to name and email address. Additional information regarding User demographics may be requested, however such information is not required for purposes of registration. By providing the registration information, the User consents to being contacted regarding the Services on the site. Communications may include additional products and services provided by the company.

Users may opt to personalize their profiles by uploading a profile picture. This picture will be visible to other site Users and may be accessed by church guests during services. A User has the option to remove their profile picture at any time by reviewing their profile and selecting “Remove Image” under the existing profile picture. We reserve the right to remove any User profile picture for any reason without providing prior notice or obtaining User consent. We will not take additional steps to share this image with third parties outside of ordinary site Users.

 

Orders

We request information from you on our order form. To buy from us, Users must provide contact information such as name and billing address and financial information including credit card information). This information is used for billing and order fulfillment. If We have trouble processing an order, this information will be used to contact the User.

 

Third-Party Services 

In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.

We may share data with third parties as necessary to operate the Service, support the safety and integrity of the platform, or comply with applicable law. This may include service providers who assist us in delivering, securing, or improving the Service, including technology used to support child safety on the platform (e.g., Microsoft Corporation’s image scanning technology). We disclose data to the National Center for Missing and Exploited Children (NCMEC) as required by federal law, and to law enforcement agencies in response to lawful legal process or exigent safety circumstances. We may also disclose data to federal, state, or other regulatory agencies where such disclosure is compelled by law or legal process. Within organizational accounts, administrators may have access to data associated with their organization in accordance with their assigned role and permissions. We do not sell your data to third parties for commercial purposes.

Purchase related transactions initiated by Users require the use of third party service providers such as payment gateway and other transaction processors. Such third party service providers may have their own privacy policies and procedures for handling the data entered into their respective platforms. We do not control such third party platforms and recommend that Users review the respective privacy policies in effect to best understand the collection of data by such sites. Third party providers may be subject to the laws of a different jurisdiction. Users are advised to review the jurisdictional requirements listed for third party providers. Once Users leave our store’s website or are redirected to a third-party website or application, they are no longer governed by this Privacy Policy or our website’s Terms of Service

 

Cookies

We use “cookies” on this site. A cookie is a piece of data stored on a site visitor’s hard drive to help us improve your access to our site and identify repeat visitors to our site. For instance, when we use a cookie to identify you, you would not have to log in a password more than once, thereby saving time while on our site. Cookies can also enable us to track and target the interests of our users to enhance the experience on our site. Usage of a cookie is in no way linked to any personally identifiable information on our site.

Some web browsers offer a “Do Not Track” feature that lets you signal your preference not to have your online activity tracked. Because the cookies described above are not linked to any personally identifiable information, our Service does not currently respond to Do Not Track signals, and our use of cookies remains the same regardless of whether such a signal is detected. You may still control or disable cookies through your browser settings, though doing so may affect certain features of the site, such as staying logged in between visits. See “Your State Privacy Rights” below regarding opt-out rights and Global Privacy Control for residents of states with applicable privacy laws.

 

Mobile Applications (My One Church App and One Church Check-In)

We make our Service available through mobile applications, including My One Church App and One Church Check-In, which are distributed through the Apple App Store and Google Play. This Privacy Policy applies to these Apps in the same way it applies to our Websites and Platform. This section describes information practices that are specific to the Apps.

Information collected through the Apps. In addition to the information described elsewhere in this Privacy Policy, the Apps may collect: (a) device and connection information, such as device model, operating system version, unique device or installation identifiers, app version, and mobile network information; (b) usage and diagnostic information about how the Apps perform and are used; and (c) information you choose to provide through App features, such as content you submit, profile pictures, and check-in or registration information.

Device permissions. Depending on the features you use and the permissions you grant, the Apps may request access to certain device capabilities, such as the camera and photo library (for example, to add a profile picture or to capture check-in information), push notifications, and, where applicable, approximate location. You can grant or revoke these permissions at any time through your device settings. Disabling a permission may limit the functionality of the Apps.

Push notifications. If you enable push notifications, we may send you messages related to the Service. You can disable push notifications at any time through your device settings.

Data Safety and App Privacy disclosures. The disclosures we provide on the Apps’ store listings — including the Google Play “Data safety” section and the Apple App Store “App Privacy” labels — are intended to be consistent with this Privacy Policy. If you believe there is a discrepancy, this Privacy Policy governs, and we ask that you contact us so we can address it.

Deleting your data and the Apps. You may request deletion of your data as described in “How to Opt Out or Request Deletion of Your Data” above. You may also uninstall the Apps at any time through your device. Uninstalling an App does not by itself delete information previously submitted through the Service; to request deletion, please use the mechanisms described in this Privacy Policy.

App store terms. Your download and use of the Apps is also subject to the terms and policies of the applicable app store (such as the Apple Media Services Terms and Conditions and the Google Play Terms of Service). The applicable app store is not responsible for the Service or for this Privacy Policy.

 

Links

This website contains links to other sites. Please be aware that We are not responsible for the content or privacy practices of such other sites. We encourage Users to be aware when they leave our site and to read the privacy statements of any other site that collects personally identifiable information.

Your State Privacy Rights

Depending on where you live, you may have additional rights regarding your personal information under state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), the Colorado Privacy Act (“CPA”), the Virginia Consumer Data Protection Act (“VCDPA”), the Connecticut Data Privacy Act (“CTDPA”), the Utah Consumer Privacy Act (“UCPA”), and similar laws in other states (collectively, “State Privacy Laws”). This section describes those rights and how to exercise them. It supplements, and does not replace, the other sections of this Privacy Policy.

Depending on where you live, your rights under State Privacy Laws may include the right to:

  • Know and access the categories and, where required, the specific pieces of personal information We have collected, used, disclosed, or (where applicable) sold or shared about you, and the categories of sources and third-party recipients;
  • Correct inaccurate personal information;
  • Delete personal information, subject to certain exceptions (for example, completing a transaction, legal compliance, or security);
  • Opt out of the sale of personal information and the sharing of personal information for cross-context behavioral advertising, and, where applicable, opt out of certain profiling in furtherance of decisions that produce legal or similarly significant effects;
  • Limit the use and disclosure of sensitive personal information, or, in states that require opt-in consent, have Us obtain your consent before processing sensitive personal information;
  • Obtain a portable copy of your personal information;
  • Not be discriminated against for exercising any of these rights; and
  • Appeal a denial of a request, as described below.

Categories of Personal Information

Depending on your use of the Service, We collect the following categories of personal information, as those categories are defined under applicable State Privacy Laws: identifiers (such as name, email address, phone number, and account credentials); commercial information; internet or network activity information (such as cookies and usage data); approximate geolocation data (such as IP-based location); audio, visual, or similar information (such as profile pictures and Chat Feature content); and, because the Service is used to manage religious organizations and their members, information reflecting religious beliefs or affiliation.

Sensitive Personal Information and Religious Data

Because the Service is used to manage religious organizations and their members, personal information processed through the Service – including a User’s association with a religious organization – may constitute “sensitive personal information” under the CCPA/CPRA, CPA, VCDPA, CTDPA, and similar laws. We do not use sensitive personal information to infer characteristics about you for purposes unrelated to operating the Service, and We do not sell sensitive personal information. Where applicable law requires opt-in consent before processing sensitive personal information, We rely on the Organization’s collection of that consent from its members and Users, or on an applicable exemption, such as processing that is necessary to provide a service the User has requested.

Opt-Out of Sale, Sharing, and Targeted Advertising

As described in the Cookies section above, We use cookies that may enable targeted advertising. To the extent this constitutes a “sale” or “sharing” of personal information under applicable State Privacy Laws, you may opt out by contacting Us at legal@onechurchsoftware.com. Where required by law, We will also honor a recognized universal opt-out mechanism, such as Global Privacy Control, transmitted through your browser.

How to Exercise Your Rights

You may submit a request to exercise these rights by contacting Us at legal@onechurchsoftware.com, or through the deletion and access mechanisms described above in “How to Opt Out or Request Deletion of Your Data.” We will take reasonable steps to verify your identity before completing your request. We will respond within the time period required by the applicable State Privacy Law, generally 45 days from receipt of a verifiable request, which We may extend once by an additional 45 days when reasonably necessary, with notice to you. You may designate an authorized agent to submit a request on your behalf; We may require proof of the agent’s authorization and independent verification of your identity.

Appeals

If We decline to act on your request, you may appeal by contacting Us at legal@onechurchsoftware.com. We will respond to your appeal within the time period required by applicable law (generally 45 to 60 days). If your appeal is denied, some states, including Colorado, Connecticut, and Virginia, permit you to contact your state Attorney General.

 

Children’s Privacy 

One Church Software is a church management platform primarily designed for use by adults. We have implemented technical safeguards designed to prevent Children from accessing the Chat Feature. Organizational Users that may include Children among its members are responsible for ensuring Children are not using the Site’s Chat Feature and are subsequently responsible for terminating any use of the feature by a Child.  If violations are reported to us, we will take appropriate action consistent with applicable law, including COPPA, and this Privacy Policy. If We are notified of any violations of this policy, We will take appropriate action to maintain compliance with COPPA, this Policy, and any other applicable laws or regulations.

Any adults holding and/ or maintaining an account on behalf of a Child are responsible for managing the profile and the information submitted on behalf of the Child.

We do not knowingly collect personal information directly from Children through the Chat Feature or other interactive features of the Service. If violations are reported to us — for example, if a Child has independently accessed the Service and submitted personal information without adult oversight — we will take appropriate action consistent with COPPA and this Privacy Policy. See “Children’s Ministry Data” below regarding information submitted on a Child’s behalf by a parent, guardian, or Organization staff member.

If you have concerns about a Child’s data or access, please contact us at legal@onechurchsoftware.com.

Children’s Ministry Data (Check-In, Registration, and Program Records)

Some Organizations use the Service to support children’s ministry programs, including check-in and check-out, classroom or group rosters, and health, safety, or allergy notes (“Ministry Data”). Ministry Data is submitted by a parent, legal guardian, or authorized Organization staff member on behalf of a Child – not directly by the Child. By submitting Ministry Data, the Organization represents that it has obtained any consent required from a parent or legal guardian under COPPA and other applicable law.

We apply the following additional safeguards to Ministry Data:

  • Access to Ministry Data is limited to the Organization’s administrators and to staff or volunteers assigned to the applicable ministry role;
  • Ministry Data is not used to generate advertising or to build an advertising profile of a Child, and is not sold or shared with third parties for marketing purposes;
  • Ministry Data is retained only as long as necessary for the Organization’s ministry, safety, and recordkeeping needs, or as required by law, and may be deleted by an Organization administrator through the Organization’s One Church portal; and
  • Where a check-in or check-out feature displays a Child’s name or photo (for example, on a classroom or pickup screen), the display is limited to the Organization’s staff, volunteers, and authorized guardians involved in pickup, and is not made available to the public.

The safeguards in this section are in addition to, and do not replace, the other safeguards described in this Children’s Privacy section. Organizations are responsible for determining whether their use of check-in, registration, or ministry program features triggers additional obligations under COPPA or other applicable law, and We are available to support that assessment on request.

 

Content Scanning and Child Safety Reporting

To ensure compliance with applicable laws, We engage a third party to scan images and Chats as may be necessary. These safeguards are only in place to ensure the safety of Users and this information is not stored beyond what is necessary to carry out the procedures.

To protect children and comply with applicable law, we use Microsoft PhotoDNA technology to automatically scan image content transmitted through the Chat Feature. PhotoDNA works by generating a digital hash (a one-way mathematical fingerprint) of each image and comparing it against a database of hashes derived from known child sexual abuse material (CSAM), maintained by NCMEC and other authorized child safety organizations. If a match is detected, the image is flagged and our response procedures are initiated.

PhotoDNA does not scan text messages. It does not store a copy of images beyond what is necessary for the hashing process, and the hash itself cannot be used to reconstruct the original image. This scanning is a condition of access to the Chat Feature and cannot be opted out of.

Mandatory Reporting to NCMEC

Federal law (18 U.S.C. § 2258A) requires electronic service providers to report apparent violations of federal child sexual exploitation laws to the NCMEC CyberTipline. If we detect or receive a report of apparent CSAM or child exploitation, We are required to preserve relevant records, submit a report to NCMEC including relevant account information and content, and cooperate with law enforcement as required by law.

Information submitted to NCMEC may be forwarded to federal, state, and local law enforcement agencies. These disclosures are legally required and do not constitute a breach of this Privacy Policy. We will not provide advance notice to an account holder before submitting a NCMEC CyberTip report or complying with related law enforcement requests.

Law Enforcement Requests

We may disclose information about you, including message content and account data, in response to valid legal process, requests from governmental authorities, mandatory reporting obligations, or exigent circumstances involving a risk of death or serious physical harm to any person. Where permitted by law, We will endeavor to notify users of requests for their data prior to disclosure, using the contact information provided when registering the account, except where legally prohibited or where doing so could obstruct an investigation.

 

Updates

Our Privacy Policy may change from time to time and all updates will be posted on this page. Changes and clarifications will take effect immediately upon their posting on the website. Where required by applicable law, We will provide notice of material changes before they take effect.

 

Contact

If you have questions or concerns about this Privacy Policy, please contact us at:

Mailing address: 12973 SW 112th St, Ste 240, Miami, FL 33186, United States

Email: legal@onechurchsoftware.com

Phone: (855) 932-0007

Website: https://onechurchsoftware.com

A church management tool you can trust for a lifetime.

30-day trial. No credit card required.