Security & privacy

How we look after your church's information

A church holds some of the most personal information there is: people's faith, their children, what they give, what they have asked prayer for. This page explains plainly where that information lives, who can see it, and what we do — and don't — promise.

🇪🇺 GDPR 🇬🇧 UK GDPR 🇧🇷 LGPD 🇦🇷 Law 25,326

Last reviewed: October 2026

🇪🇺

Built for GDPR

Servers in the UK 🇬🇧 and encrypted backups in the EU 🇪🇺, with Europe's privacy standards for every church.

🧱

Each church walled off

Checked by our servers on every request, not just hidden on the screen.

🪪

Access you decide

Roles and your own settings control who sees what.

📦

Yours to take or delete

Download everything to Excel anytime. Cancel, and it's deleted within 30 days.

Where your information lives

Your church's records are stored on servers in the United Kingdom. Encrypted backups are kept in the European Union for 30 days, so we can recover from an accident or a hardware failure. Everything that travels between your browser and our servers is encrypted.

We apply the standards of Europe's data protection law (the GDPR, and its UK version) to every church, wherever it is: a clear legal basis for each use of data, only the providers we need and under contract, data kept no longer than necessary, and people's right to see, correct, delete or take their information. We also follow Brazil's LGPD and Argentina's Law No. 25,326.

Some of the providers that help us run the service may process data in other countries, including the United States. When that happens, we rely on their contractual safeguards. The full list of providers is further down this page.

One church never sees another

HolyCRM serves many churches, and keeping them apart is the first thing we protect. The separation is not just a filter on the screen: on every single request, our servers check that the person asking belongs to that church and is allowed to see that kind of information. Someone from another church can't read your records, even by trying outside the app, and a record can't be moved from one church into another.

The same goes for people who belong to more than one church: what they are allowed to do in one church gives them nothing in another.

Only the people you choose

  • Roles. Each person on your team has a role — administrator, manager, volunteer or member — and sees only the areas that role needs. You can adjust what each role can see, add, change or delete in your church.
  • Personal sign-in. Your team is invited by email and each person sets their own password, so there's no shared church login to pass around. We store passwords in a form nobody can read back, not even us. Signing in with Google is optional, and only works for an email your church has already invited.
  • Instant pause. When someone steps down, pause or remove their access and it stops straight away. There's nothing to collect back.
  • A record of changes. Changes to member records and to giving are logged — who did what, and when — so your administrators can review them. The log keeps the action, not a second copy of the sensitive details.

Information that needs extra care

  • Children. A child's record can be linked to their parents or guardians, and kids check-in gives the child and the guardian matching codes for a safe pick-up. You decide who on your team can see children's information.
  • Prayer requests. Requests sent online or taken in person are seen, by default, only by administrators and managers. If your church has a prayer team, you choose who else can read them.
  • Giving. Tithes and offerings are visible only to the roles you allow, and every change is logged. Gifts go straight from the giver's bank or wallet to the church; no money and no card details pass through HolyCRM.
  • Public forms. Your guest card and prayer request form are open to anyone, so they are protected against spam and automated bots.

Your church decides what it records about people, and is responsible for having their consent, including a parent's or guardian's for children. When you set up your church, an administrator confirms this once. In legal terms, your church is the controller of those records and HolyCRM processes them on its behalf: we give you the tools and the controls, and we only use the information to provide the service to you.

Your data stays yours

  • Never sold. We don't sell your data, we don't use it for advertising, and one church's information is never shared with another.
  • Take it with you. An administrator can download everything your church has entered, at any time, as a single workbook that opens in Excel, Google Sheets or Numbers. No need to ask us.
  • Delete it. An administrator can request deletion from inside the app. When a church cancels, its data is deleted within 30 days (sooner if you ask), and it leaves our backups within a further 30 days as they expire.
  • Requests from your people. If someone asks to see, correct or delete their information, you can do it in the app, and we help when needed. We answer privacy requests within 15 days.

The companies that help us run HolyCRM

We use a small number of providers, each under contract and only to run the service:

  • Fasthosts (United Kingdom): hosts our application servers and database.
  • Cloudflare: DNS, network protection, bot checks on public forms, churches' custom domains, and encrypted backup storage in the European Union.
  • Microsoft Azure Static Web Apps: serves the web application's files.
  • Mailgun (Sinch): sends account and service emails.
  • Tianji: privacy-friendly usage analytics.
  • GalioPay (Argentina): processes subscription payments in Argentine pesos.
  • Google: only if you choose to sign in with Google.

Keeping it running

You can check whether HolyCRM is up, and follow any incident while it's being fixed, on our status page.

What we don't claim

We are a small, independent team, and we would rather tell you exactly what we do than show you badges. HolyCRM doesn't currently hold formal certifications such as ISO 27001 or SOC 2, and no system is perfectly secure. What we do promise: security is part of how every piece of HolyCRM is built, reported problems are fixed as a priority, and if something ever goes wrong with your church's data, we will tell you promptly and honestly.

Who is responsible, and how to reach us

Questions from your IT volunteer?

Send them our way. We're happy to answer anything before your church signs up.