Legal

Privacy Policy

Last updated 14 August 2026

Church Visitor Flow (“we”, “us”) is a business based in South Africa. We are the responsible party for the personal information described below.

This policy explains what we do with personal information. It is written to meet the Protection of Personal Information Act, 2013 (POPIA), and where it applies, the UK and EU GDPR.

The two kinds of information we handle

This distinction matters, because our responsibilities differ in each case.

1. Information about churches and their staff

When someone creates an account we collect their name, email address, mobile number, church name and password. We are the responsible party for this information, and we decide how it is used.

2. Information about church visitors

When a visitor fills in a church’s form, we store what they entered — typically name, mobile number, and any other questions that church chose to ask.

For this information the church is the responsible party and we are an operatoracting on their instructions. We do not decide what is collected, we do not use it for our own purposes, we do not sell it, and we do not use it to market anything. Each church’s data is isolated from every other church’s.

If you are a visitor and want your information corrected or deleted, contact the church you visited. If you cannot reach them, contact us at pnel53@gmail.com and we will help.

Why we process it

  • To provide the service — accounts, the visitor form, follow-up tracking
  • To send service messages such as email confirmation and password resets
  • To send the reminders a church has configured, to the people it nominates
  • To keep the service secure, including rate limiting to prevent abuse
  • To meet legal obligations

Consent to contact visitors

Churches use this service to contact people. It is the church’s responsibility to have a lawful basis for doing so, and to make clear on their form what contact a visitor should expect. We provide the tools; we cannot obtain that consent on a church’s behalf.

Who else processes it

We use a small number of providers, each only for what it says here:

  • Supabase — database and authentication. Data is stored in the European Union.
  • Vercel — application hosting.
  • Resend — transactional email such as confirmations and invitations.
  • Twilio and Meta Platforms — delivering WhatsApp reminders to church team members.
  • Paddle — payments. Paddle is the merchant of record and handles card details directly. We never see or store your card number.

We do not sell personal information, and we do not share it with anyone else except where the law requires it.

Where it is stored

Our database is hosted in the European Union. If you are in South Africa, this means your information is transferred outside the country. The EU has data-protection laws that provide a comparable level of protection, which is the basis on which we make that transfer under section 72 of POPIA.

How long we keep it

  • Account information: while the account is open, then up to 90 days after closure.
  • Visitor information: for as long as the church keeps it. A church can delete a visitor at any time, and deleting a church account deletes its visitors with it.
  • Security logs used for rate limiting: automatically deleted after two hours, and the network address is stored only as a salted hash, never in a readable form.

How we protect it

  • Encrypted in transit (HTTPS) and at rest
  • Database-level isolation between churches, so a query for one church cannot return another’s data
  • Passwords are hashed and never stored in readable form
  • Access to production systems limited to those who need it

No system is perfectly secure. If a breach affects your information we will notify you and the Information Regulator as POPIA requires.

Your rights

You may ask us to:

  • Tell you what information we hold about you
  • Correct anything inaccurate
  • Delete it, where we are not required to keep it
  • Provide it in a portable format
  • Stop processing it for a particular purpose

Write to pnel53@gmail.com. We will respond within 30 days.

If you are unhappy with our response you may complain to the Information Regulator of South Africa at inforegulator.org.za.

Cookies

We use a small number of strictly necessary cookies to keep you signed in and to keep the service secure. We do not use advertising or tracking cookies, and there is no third-party analytics on the signed-in portal.

Children

Our service is for churches, not children. A church may collect information about a minor through its visitor form; where it does, the church is responsible for obtaining the consent of a parent or guardian as POPIA requires.

Changes

If we change this policy materially we will tell account holders by email before it takes effect.

Contact

Information Officer: Paul Nel
Email: pnel53@gmail.com