RaphaRise ChurchOS
Privacy Policy
Effective date: [EFFECTIVE DATE REQUIRED]
RaphaRise ChurchOS ("RaphaRise", "we", "us") is a software platform that churches use to manage administration, finance, membership, ministry, and related records. This policy explains what information the platform collects, how it is used, and how it is protected. It applies to church staff, leaders, and members who use RaphaRise, and to visitors who submit information through a church's public forms (for example, a newcomer welcome form reached by scanning a church's QR code).
RaphaRise is provided to churches as the "data controller" for their own congregation's records — each church manages its own member data inside its own account, and RaphaRise acts as the technology provider (a "data processor") that stores and operates the platform on the church's behalf. If you have a question about your personal information, your first point of contact should be your church's administrator, who can also reach us directly.
Information We Collect
Depending on how a church configures its account and how you use it, this can include:
- Account information — name, username, email address, phone number, and a securely hashed password (never stored or logged in plain text).
- Membership and pastoral records — household and family relationships, membership journey status, baptism records, and care/follow-up notes entered by church leaders.
- Ministry and volunteer records — department involvement, serving assignments, and event participation.
- Financial records — for the staff who use the Finance module, this can include claims, petty cash requests, and statements they submit or that are entered on their behalf.
- Files and attachments — documents, receipts, presentation slides, and photos that a church chooses to upload (for example, to an announcement or membership record).
- Newcomer / visitor information — when someone fills out a church's public welcome form, we collect the fields that form asks for (typically name, contact details, and answers about how they connect to the church) and pass them to that specific church's records.
- Technical information — session identifiers (a browser cookie on web, and an encrypted token stored in your device's Keychain on iOS) used to keep you signed in, and standard request metadata (such as timestamps) used for security and audit logging.
- Push notification tokens — only if you opt in to notifications, a token identifying your browser or device is stored so we can deliver alerts (for example, approval requests).
How We Use Information
- To operate the features a church has enabled — records, approvals, reporting, and scheduling.
- To send notifications you or your church have opted into (in-app, browser push, and Apple push notifications for the iOS app).
- To keep an audit trail of sensitive actions (such as approvals and record changes) for accountability inside a church's own account.
- To maintain security — detecting misuse, rate-limiting abuse, and protecting accounts.
- To operate legally required or church-requested data retention and deletion.
We do not use member or visitor data for advertising, and we do not run third-party analytics or tracking scripts on the platform.
WhatsApp announcements
A church's Communications feature can prepare an announcement and open a WhatsApp link ("wa.me") pre-filled with that message. Sending happens inside the staff member's own WhatsApp app on their own device — RaphaRise does not transmit the message content to WhatsApp or Meta on the church's behalf, and does not use the WhatsApp Business API to send messages automatically.
Where Data Is Stored
RaphaRise runs on Cloudflare's infrastructure: records are stored in Cloudflare D1 (a managed database) and uploaded files are stored in Cloudflare R2 (object storage). Every church's data is logically separated from every other church's data ("multi-tenant" isolation) — church staff can only see records that belong to their own church, according to the roles and permissions their church has assigned them. [DATA RESIDENCY / REGION COMMITMENT REQUIRED]
Data Sharing
We do not sell personal data. We do not share member or visitor information with other churches, or with third parties for their own marketing purposes. Data may be shared only with:
- Infrastructure providers (such as Cloudflare and Apple, for push notifications) strictly to operate the service.
- Your own church's authorized leaders and staff, according to the access your church has granted them.
- Authorities, where we are required to by law.
[ADDITIONAL SUB-PROCESSOR DISCLOSURES REQUIRED, IF ANY]
Newcomers and Minors
Public welcome forms are intended for visitors providing their own information to a specific church.[POLICY REQUIRED FOR DATA SUBMITTED ABOUT OR BY MINORS]
Data Retention and Deletion
A church's records are retained for as long as the church's account remains active. If a church's subscription lapses, its data is scheduled for deletion after a 30-day grace period, during which the church can be reactivated. [FULL RETENTION / EXPORT POLICY REQUIRED]
Your Choices
You can review and, where your church allows it, update certain profile details from inside the app. For corrections to pastoral, financial, or membership records, or to request deletion of your personal information, please contact your church's administrator, or write to us at [CONTACT EMAIL REQUIRED].
Security
Passwords are stored using industry-standard hashing, never in plain text. Sessions use rotating, single-use refresh tokens with automatic revocation on password change or suspected reuse. Sensitive administrative actions are recorded in an audit log visible to the church's own leaders.
Contact
Questions about this policy can be directed to your church administrator or to [CONTACT EMAIL REQUIRED].
Changes to This Policy
We may update this policy as the platform changes. Material changes will be reflected by an updated effective date above.
RaphaRise