This policy is available in English, Spanish and Portuguese. If the versions differ, the English version prevails.
1. Who we are
HolyCRM.app ("HolyCRM", "we", "us") is a web application that helps churches care for their people: members, visitors, small groups, ministries, events, serving teams and giving. HolyCRM is operated by Pablo Gorosito, an individual registered in Argentina as a sole trader (monotributista) under the trade name HolyCRM.
This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the choices and rights you have. It applies to the HolyCRM web application (app.holycrm.app), this website (www.holycrm.app) and the public pages churches publish with HolyCRM.
2. Our role: controller and processor
Account and billing data. For the accounts of people who sign in to HolyCRM, and for billing, we decide how the data is used, so we are the data controller.
Church records. For the information a church enters about its members, visitors and activities, the church is the data controller and we are its data processor: we store and process that data only to provide the service to the church and following its instructions. If you are a member or visitor of a church, please contact your church first about your data.
3. Data we collect
- Account data: name, email address, a securely hashed password (if you set one), preferred language, an optional profile picture, and the church(es) and role(s) you have access to.
- Google sign-in data: if you choose “Continue with Google”, the data described in section 4.
- Church records: information a church enters about people and activities, for example names, contact details, birth dates, addresses, attendance, small group and ministry participation, serving schedules, prayer requests and giving records.
- Public form submissions: what a visitor sends through a church's public pages (for example a “New here?” card or a prayer request), typically a name, contact details and a message.
- Billing data: subscription plan, payment amounts, dates and status. Payments are handled by our payment provider; we never receive or store card or bank credentials.
- Technical and usage data: IP address, browser and device information and server logs needed to run and secure the service, plus aggregate usage analytics.
4. Signing in with Google
You can sign in to HolyCRM with your Google account instead of a password. Google sign-in only works for an email address a church has already invited to HolyCRM; it never creates a new account by itself.
What we receive from Google. Only your basic profile: your name, email address, profile picture and Google account identifier. We request only the openid, email and profile scopes. We do not access your Gmail, contacts, Google Drive, calendar or any other Google data.
How we use it. Only to identify you and sign you in to your existing HolyCRM account, to link your Google account to it so you can sign in again, to confirm your email address, and to show your name and picture inside the app. We do not use Google user data for advertising, we do not sell it, and we do not use it to train artificial intelligence or machine-learning models.
How we store it. Your Google account identifier is stored with your HolyCRM account, and your name and a copy of your profile picture are saved to your profile, on the servers described in section 8 and protected as described in section 11.
Who we share it with. No one, except the infrastructure providers listed in section 7 that host the service on our behalf, or when the law requires it. It is never visible to other churches.
Keeping or deleting it. We keep this data while your account exists. You can disconnect HolyCRM from your Google account at any time at myaccount.google.com/permissions and keep signing in with a password. To have the link and your account data deleted, email privacy@holycrm.app and we will delete it within 30 days.
HolyCRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. How we use data, and our legal bases
- To provide the service: create and secure accounts, sign you in, and make each church's data available only to the people it chooses (performance of a contract).
- To send service emails such as invitations, password links, serving reminders and billing notices (performance of a contract; legitimate interest).
- To protect the service against abuse, fraud and spam, including bot checks on public forms (legitimate interest).
- To understand aggregate usage and fix problems (legitimate interest). Our analytics are privacy-friendly and never used for advertising.
- To bill subscriptions and keep accounting records (performance of a contract; legal obligation).
- To process church records on each church's instructions, as its processor. The church determines its own legal basis, such as its members' consent.
We do not sell personal data, we do not use it for advertising, and we do not make decisions about you based solely on automated processing.
6. Sensitive data and minors
Church membership and related records (attendance, groups, giving) can reveal religious affiliation, which is treated as a sensitive or "special category" of data under most data protection laws that apply to our users, including the EU's GDPR, Brazil's LGPD and Argentina's Law No. 25,326. Several of these laws include a specific allowance for religious organisations to process this kind of data about their own members, but the church remains responsible, as the controller of the records it enters, for having a proper basis (such as the consent of its members) for that data.
Church records may include information about minors, for example through a children's or youth ministry. The church is responsible for obtaining any parental or guardian consent required by law before entering a minor's information, and for deciding who at the church may access it. HolyCRM does not independently verify this consent; it provides the role-based access controls a church uses to restrict who can see this information.
7. Who we share data with
We share personal data only with the following providers, which process it on our behalf, under contract, and only to deliver the service:
- Fasthosts (United Kingdom): hosts our application servers and database.
- Cloudflare: DNS, network protection, bot checks on public forms, churches' custom domains, and encrypted backup storage in the European Union.
- Microsoft Azure Static Web Apps: serves the web application's files.
- Mailgun (Sinch): sends account and service emails.
- Tianji: privacy-friendly usage analytics.
- GalioPay (Argentina): processes subscription payments in Argentine pesos.
- Google: only if you choose to sign in with Google (see section 4).
We may also disclose data when the law requires it, or to protect the rights and safety of our users. If HolyCRM is ever transferred to a successor, this policy will continue to apply to your data. One church's data is never shared with another church.
8. Where your data is stored
Our main servers and database are in the United Kingdom, and our encrypted backups are stored in the European Union. Some of the providers above may process data in other countries, including the United States. When data is transferred outside the country where it was collected, we rely on adequacy decisions where they exist, or on our providers' contractual safeguards such as standard contractual clauses.
9. How long we keep data
- Church records are kept while the church's subscription is active. When a church cancels, its data is deleted within 30 days (sooner if the church asks), and it then disappears from our backups within a further 30 days as they expire.
- Backups are encrypted and kept for 30 days.
- Your user account is kept while it has access to at least one church, or until you ask us to delete it.
- Billing records are kept for as long as Argentine tax and accounting law requires, even after a church cancels.
- Server logs are kept only as long as needed for security and troubleshooting.
10. Your rights
Depending on where you live, including under the EU GDPR, the UK GDPR, Brazil's LGPD and Argentina's Law No. 25,326, you may have the right to access, correct, delete or export your personal data, to object to or restrict some processing, and to withdraw your consent at any time.
To exercise these rights, email privacy@holycrm.app. We reply within 15 days. If your data is part of a church's records, we will pass your request on to that church, which controls the data.
You can also complain to your data protection authority, for example Argentina's Agencia de Acceso a la Información Pública (AAIP), Brazil's ANPD, the UK's ICO, or your local authority in the European Union.
11. Security
We protect data with encryption in transit (HTTPS), hashed passwords, encrypted backups, strict separation between churches enforced on our servers, role-based access within each church, and bot checks on public forms. No system is perfectly secure; if you find a vulnerability, please report it to security@holycrm.app.
12. Cookies and local storage
The app keeps your sign-in session and preferences (such as language and theme) in your browser's local storage. We do not use advertising or cross-site tracking cookies. Our bot check (Cloudflare Turnstile) may use cookies or similar technologies strictly for security.
13. Children
HolyCRM accounts are meant for church staff and volunteers and are not intended for children under 16. Information about minors may appear only in church records, as described in section 6.
14. Changes to this policy
If we make important changes, we will update the date at the top of this page and, where appropriate, let church administrators know by email.
15. Contact
HolyCRM, Argentina. Email: privacy@holycrm.app