Trust and transparency

Privacy

A plain-language overview of how information is handled, protected, retained, and requested during the Church Member Connect pilot.

Pilot notice

Effective August 7, 2026. This engineering pilot notice is not the final jurisdiction-approved production privacy notice. Independent privacy and legal approval remains a production release gate.

Who this notice covers

Voirtech Inc. operates Church Member Connect. This notice describes the platform-level processing used to provide the pilot service. A participating church, school, conference, mission, union, or other organization may also be responsible for information it enters and for its own notices and policies.

The service is designed for members, donors, parents or guardians, organization staff, auditors, and platform administrators. Access depends on the person’s relationship and assigned permissions.

Information we handle

The exact information depends on the feature used. We minimize public responses and do not make private member, donor, student, invoice, or account information publicly searchable.

  • Account identifiers, contact details, authentication status, roles, and security events.
  • Organization hierarchy, onboarding, configuration, and administrator records.
  • Membership, household, communication preference, and directory-consent information when an organization uses those features.
  • Giving, invoices, school balances, accounting, reconciliation, receipt, refund, and audit metadata needed to provide and evidence financial workflows.
  • Support requests, device and request metadata, and diagnostic references needed to investigate reliability or security problems.

How information is used

Information is used to provide authorized workflows, protect accounts, maintain tenant separation, process hosted payments, generate records and reports, prevent abuse, reconcile activity, support users, and meet approved accounting, audit, security, and legal obligations.

Church Member Connect does not sell personal information or rank organizations based on donation volume. Payment-card and bank credentials are collected by approved hosted payment providers and are not stored by Church Member Connect.

Service providers and organizational access

Information may be processed by contracted infrastructure, authentication, email, object-storage, monitoring, and payment providers only for the service they supply. Provider access is restricted by contract, credentials, and technical controls where available.

A parent organization paying for a descendant’s subscription does not automatically receive access to that descendant’s member, donor, school, payroll, accounting, or audit records. Detailed access requires a separate authorization grant and is audited.

Retention, correction, and deletion

Profile and directory information should be corrected, hidden, deactivated, exported, suppressed, or deleted when an approved request and policy permit. Financial postings, receipts, payment evidence, reconciliation records, and audit facts may need to be retained and corrected through reversal, adjustment, or redaction-at-read rather than deletion.

Formal retention periods and jurisdiction-specific legal holds remain subject to named privacy, accounting, and legal approval before production collection. The pilot therefore fails closed: required financial and audit evidence is not automatically purged.

Your choices and privacy requests

You may ask for access to, correction of, export of, deactivation of, or permitted deletion or suppression of information associated with you. We may need to verify identity and organizational authority before acting. We will explain when an accounting, audit, fraud-prevention, security, or legal requirement limits the requested action.

Until the in-product privacy-request workflow completes its independent review, email support@churchmemberconnect.org. Do not include passwords, authenticator codes, recovery codes, full payment credentials, or unnecessary sensitive records.

Security and contact

The platform uses role-based authorization, tenant isolation, step-up authentication for privileged actions, encryption, signed provider events, idempotent processing, audit evidence, vulnerability checks, backups, and recovery controls. No internet service can guarantee absolute security.

For a privacy question, suspected exposure, or request concerning your information, contact support@churchmemberconnect.org and include only the organization name, your contact information, and a concise description. Security-sensitive reports are prioritized and should not contain credentials.