Legal

Privacy Policy

Effective Date: April 7, 2025

1. Introduction

FaithLedger, LLC ("FaithLedger," "we," "us," or "our") operates the FaithLedger church treasury management platform, accessible at faithledgerapp.com and related subdomains (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information about the churches, organizations, and individuals ("you" or "your") who use our Service.

We take the privacy of church financial data seriously. FaithLedger is designed for stewardship teams who handle sensitive congregational and organizational information, and we hold ourselves to a high standard of data protection. Please read this policy carefully. By accessing or using the Service, you agree to the practices described herein.

2. Information We Collect

We collect information in three ways: information you provide directly, information collected automatically through your use of the Service, and information received from third-party integrations you authorize.

2.1 Information You Provide

CategoryExamples
Account & IdentityName, email address, phone number, password (hashed)
Church / OrganizationChurch name, address, congregation size, denomination
Financial RecordsTransaction data, chart of accounts, budgets, vendor details, bank account metadata (not account numbers)
Donor & Giving DataDonor names, giving history, pledge records imported by your church
Payroll & PersonnelStaff names, compensation data entered by church administrators
Contact InquiriesName, church, message, and phone number submitted via the Request More Info form

2.2 Information Collected Automatically

When you use the Service, we automatically collect certain technical information, including your IP address, browser type and version, operating system, pages visited, time spent on pages, referring URLs, and device identifiers. We use this data solely for security monitoring, performance optimization, and aggregate analytics. We do not sell or share this data with advertisers.

2.3 Information from Third-Party Integrations

If you connect a bank account via Plaid, we receive transaction data, account balances, and account metadata from Plaid's API. We do not store your bank login credentials. If you import data from QuickBooks, Planning Center, Pushpay, or other platforms via CSV or API, that data is stored in your church's isolated database partition. FaithLedger does not share this data across church accounts.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the FaithLedger platform and its features
  • Authenticate users and enforce role-based access controls within your church account
  • Process and display financial transactions, budgets, reports, and approvals
  • Send transactional communications such as approval notifications, password resets, and account alerts
  • Respond to support requests and contact form submissions
  • Monitor for security threats, fraud, and unauthorized access
  • Comply with applicable legal obligations
  • Improve our machine-learning assisted transaction classification (using anonymized, aggregated patterns only — never your raw transaction data)

We do not use your church's financial data to train AI models, sell to third parties, or target advertising. Your congregation's data is yours.

4. Church Data Isolation

FaithLedger is a multi-tenant platform. Each church or organization is assigned a unique client_id and all data — transactions, budgets, donors, users, and documents — is strictly scoped to that identifier. Row-Level Security (RLS) policies enforced at the database layer ensure that no end user can ever query, view, or modify another church's records through the application, regardless of their role or permissions within their own organization.

FaithLedger staff access. FaithLedger personnel retain direct database-level access to all client data. This access exists solely to provide customer support, verify that transactions are posting correctly, investigate and correct data errors, perform platform maintenance, and carry out other administrative tasks necessary to operate the service reliably. Staff access is not mediated by the application's RLS policies; it is controlled through separate, privileged credentials that are restricted to authorized personnel.

We treat your data with the same care we expect from our own vendors. Staff access to church data is limited to what is necessary to resolve a specific issue or perform a specific operational task. We do not browse, analyze, or share your organization's financial records for any purpose outside of operating and improving the FaithLedger platform.

5. Financial Data and Plaid

FaithLedger uses Plaid Technologies, Inc. ("Plaid") to connect your financial institution accounts to our Service. By connecting a bank account, you acknowledge that your financial data will be handled in accordance with both this Privacy Policy and Plaid's End User Privacy Policy.

When you connect a bank account through FaithLedger:

  • You will interact with Plaid Link, a secure interface operated by Plaid
  • Plaid will authenticate your credentials directly with your financial institution — FaithLedger never sees or stores your banking username or password
  • Plaid provides us with access to transaction history, account balances, and account metadata (account name, institution, last four digits) as needed to power the Service
  • Plaid access tokens, which enable ongoing data access, are stored securely server-side and are never exposed to the browser or frontend application
  • Plaid access tokens are revoked and deleted upon account disconnection or cancellation

For full details on how Plaid collects, uses, and protects your data, please review Plaid's End User Privacy Policy.

6. Data Sharing and Disclosure

We do not sell, rent, or trade your personal or church data. We share data only in the following limited circumstances:

RecipientPurposeData Processing Agreement
Supabase (database & auth)Hosts the database and authentication infrastructureYes
Plaid TechnologiesFacilitates bank account connections; governed by Plaid's own privacy policyYes
Resend / TwilioDelivers transactional email and SMS notifications; no financial data is transmittedYes
Stripe (if applicable)Processes subscription payments; FaithLedger does not store full card numbersYes
Law enforcement / courtsWhen required by valid legal process, subpoena, or court orderN/A
Business transfersIn the event of a merger, acquisition, or sale of assets, subject to confidentiality obligationsN/A

All sub-processors listed above are bound by data processing agreements or equivalent contractual obligations requiring them to protect your data in a manner consistent with this Privacy Policy.

7. Data Security

We take the security of your data seriously. Our security practices include:

  • All data is encrypted in transit using TLS 1.2 or higher
  • All data is encrypted at rest using AES-256 encryption
  • Access to your organization's data is enforced by row-level security controls — users can only access data belonging to their organization
  • Administrative access to production systems requires multi-factor authentication
  • Service credentials and API keys are stored securely and never committed to source code

No method of transmission or storage is 100% secure. In the event of a data breach affecting your information, we will notify you within 72 hours of becoming aware of the incident, consistent with applicable law. We encourage you to use strong, unique passwords and to report any suspected security incidents to [email protected].

8. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account and organization data is retained for the life of your subscription
  • Financial records and transaction history are retained for a minimum of 7 years to support audit and compliance needs common to nonprofit organizations
  • Security logs, access logs, and support interaction records are retained for a minimum of 12 months and deleted thereafter unless required for an ongoing investigation or legal matter
  • Upon account cancellation, you may request a full export of your data. Following export, your data will be deleted from our systems within 30 days, except where retention is required by law
  • Plaid access tokens are revoked and deleted upon account disconnection or cancellation

You may request an export of all your church's data at any time by contacting us at [email protected]. We will provide a machine-readable export within 10 business days.

9. Cookies and Tracking

FaithLedger uses essential session cookies to maintain your authenticated state. We do not use third-party advertising cookies or cross-site tracking technologies. We use privacy-respecting analytics (aggregate page views and feature usage) to improve the product. No personally identifiable information is included in analytics data.

10. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at [email protected] and we will promptly delete it.

11. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you
CorrectionRequest correction of inaccurate or incomplete data
DeletionRequest deletion of your personal data (subject to legal retention obligations)
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to certain processing activities
Withdrawal of consentWithdraw consent where processing is based on consent

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

12. Governing Law

This Privacy Policy is governed by the laws of the State of Florida. FaithLedger complies with applicable U.S. federal and state privacy laws. We will update this policy as new state privacy frameworks take effect in jurisdictions where our subscribers are located.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify account administrators via email and display a notice within the application at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

FaithLedger, LLC

Fleming Island, FL

Email: [email protected]

Website: www.faithledgerapp.com