Your information

Privacy Policy

This policy explains how information is handled when you use the Givelitics mobile app, customer portal and connected services.

Effective date:

1. Who this policy covers

This policy applies to the Givelitics mobile app, the customer portal at givelitics.uk and the supporting Givelitics services. A participating church or charity may give you an additional privacy notice explaining its own purposes, legal bases and retention rules. That organisation's notice also applies to information it controls.

2. Our roles and your organisation's role

A participating church or charity generally acts as the data controller for information about its members, donors, groups, volunteers, events, directory and community activity. It decides why that information is needed, who can access it and how long it should be retained. Givelitics usually acts as its data processor by hosting and handling that information on its instructions.

Givelitics acts as a controller where it decides how information is used for its own service administration, account authentication, fraud and security monitoring, technical diagnostics, support, legal compliance and product operation. If your request concerns an organisation's membership, donation or safeguarding record, contact that organisation first. For Givelitics-controlled processing, email support@givelitics.com.

3. Information we handle

Depending on the features your organisation enables, we may handle:

  • Account and identity information: name, email address, authentication data, organisation membership, role, invitation and account status. Passwords are stored only in a cryptographically protected form by the authentication provider.
  • Profile and preferences: contact details, profile information, onboarding choices, notification settings and directory visibility choices.
  • Community information: group membership and requests, volunteering interests and applications, opt-in directory details, prayer posts, reactions, reports and moderation decisions. Prayer or safeguarding content can reveal highly sensitive information; only share what is necessary.
  • Content and engagement: events, announcements, livestream and media activity, including saved items, completion status and the date an item was last opened.
  • Giving and Gift Aid information: donation intent, amount, fund, checkout and payment status, receipt and refund details, giving history, taxpayer declaration information and Gift Aid eligibility where the Giving feature is used.
  • Notifications and device information: push token, device platform, notification inbox and delivery state, preferences, app version and limited technical data needed to deliver and troubleshoot notifications.
  • Service, security and support information: IP address, request and audit logs, session and device identifiers, error diagnostics, support correspondence and information you provide when reporting a problem.

4. Why we use information

We use information to:

  • create and secure accounts, keep sessions working and link members to the correct organisation;
  • provide the features selected by a participating church or charity;
  • process and reconcile Giving activity and produce receipts and records;
  • deliver requested notifications and remember your choices;
  • moderate community content, respond to reports and protect users and organisations;
  • answer support requests, diagnose faults, prevent misuse and improve reliability; and
  • meet legal, regulatory, accounting, tax, Gift Aid and safeguarding obligations.

Depending on the processing and who controls it, the lawful basis may be performance of a contract, a legal obligation, legitimate interests, consent or another basis available under UK data protection law. The participating organisation is responsible for identifying an appropriate basis for the member and community information it controls, including an additional condition where religious belief, health, prayer or other special category information is used.

We do not sell personal information or use mobile app activity for third-party advertising.

5. Giving and Stripe test mode

As at this policy's effective date, mobile Giving uses Stripe test mode. It must not be used to make a real donation, and test transactions are not charitable gifts. If a participating organisation later enables live Giving, the app will identify that during the checkout journey.

Stripe hosts the checkout experience and handles payment credentials. Givelitics does not store full card numbers or card security codes. Givelitics receives transaction identifiers, status, amount, receipt and refund information needed to operate Giving and maintain records. Stripe processes information under its own privacy policy.

6. Service providers and external media

We use carefully selected providers to operate the service, including:

  • Supabase for database, authentication and related platform services. Core app data is currently hosted in a UK region.
  • Vercel for web and API hosting and operational delivery.
  • Expo, together with Apple Push Notification service or Firebase Cloud Messaging as applicable, to route optional push notifications to your device.
  • Stripe for test-mode Giving and, only if separately enabled in future, live payment processing.

Published media can link to a trusted HTTPS page operated by an external provider, such as a video, podcast or livestream service. Playback opens in your device's browser. When you open the link, that provider may receive your IP address, browser or device information and cookies under its own privacy policy. Givelitics does not control the external provider's processing.

We may also disclose information where required by law, to professional advisers, during a properly managed business transfer, or where necessary to protect people, the service or legal rights. An organisation's authorised leaders and administrators can access the records their roles permit.

7. International processing

Although core app data is currently hosted in a UK region, some providers or their support operations may process information in the UK, European Economic Area, United States or other countries. Where UK law requires it, the responsible controller uses an adequacy decision, approved contractual safeguards or another lawful transfer mechanism and considers any additional safeguards needed.

8. Retention and account deletion

We keep information only for as long as needed for the purposes described above, the participating organisation's documented instructions and applicable law. Technical logs and support records have operational retention periods appropriate to security and troubleshooting.

A confirmed in-app account deletion request enters a 30-day grace period. You can cancel the request during that period. At the end of the period, Givelitics deletes or anonymises the mobile account, active authentication sessions, push tokens and private app state where it is able and permitted to do so. Residual encrypted backups expire through the normal backup cycle.

Deleting an app account does not necessarily erase every record held by your church or charity. Financial, Gift Aid, membership, fraud-prevention, safeguarding, dispute and audit records may be retained where law or a documented policy requires it. Charity accounting and Gift Aid records commonly need to be kept for at least six years where applicable. Access will be limited and records will not be used for unrelated purposes. Read the full account deletion guidance before submitting a request.

9. Security

We use measures designed to protect information, including encrypted network connections, secure mobile credential storage, rotating session tokens, role and tenant access controls, database row-level security, restricted administrative access, audit logging and monitoring. No online system can be guaranteed completely secure. Keep your password private, protect your device and report suspected account misuse promptly.

10. Your UK data protection rights

Depending on the circumstances, you may have rights to be informed, access your information, correct it, erase it, restrict or object to processing, receive portable data and complain about how it is used. You can also withdraw consent where consent is the basis for processing. These rights are not absolute; an organisation may lawfully retain or continue using some records.

Contact your church or charity for organisation-controlled information. Contact support@givelitics.com for Givelitics-controlled processing or if you are unsure who to contact. We may need to verify your identity and organisation before responding. You can also complain to the UK Information Commissioner's Office.

11. Children and safeguarding

Organisations must only invite or register younger users where they have an appropriate lawful basis, permissions and safeguarding arrangements. Givelitics is not an emergency or safeguarding reporting service. If someone is at immediate risk, contact the emergency services and your organisation's safeguarding lead using its established process.

12. Changes and contact

We may update this policy as the product, providers or law change. We will change the effective date and provide an appropriate notice for material changes. Questions can be sent to support@givelitics.com.