No data selling
Supabase security stack
You control retention
1. Who We Are
Conversion Catalyst LLC d/b/a ChurchSecurityPlanner (“ChurchSecurityPlanner,” “we,” “our,” or “us”) provides software that helps churches coordinate security volunteers, manage incidents, and communicate during events.
This Privacy Policy explains how we collect, use, and safeguard information when you use the ChurchSecurityPlanner platform, websites, and applications (collectively, the “Service”).
2. Information We Collect
We collect only the information needed to operate the Service effectively:
- Account details such as name, email address, phone number, church affiliation, and volunteer role.
- Operational data entered by your team—availability forms, shift assignments, incident reports, attachments, and message history. Users are strictly prohibited from submitting Protected Health Information (PHI), as the Service is not a HIPAA-compliant medical record system.
- Payment information (billing contact, plan details) processed through Stripe. ChurchSecurityPlanner does not store full payment card numbers.
- Technical data automatically captured when you use the Service, including device type, browser version, IP address, and diagnostic logs.
3. How We Use Information
We process information to:
- Authenticate users, enforce role-based permissions, and secure church-specific data partitions.
- Deliver scheduling, messaging, incident management, and reporting features requested by church administrators.
- Provide customer support, investigate suspicious activity, and resolve issues reported by your team.
- Process payments, manage subscriptions, and send essential billing or service notifications.
- Analyze aggregate usage to improve performance and prioritize product enhancements.
- Comply with applicable laws, enforce our agreements, and protect the rights and safety of ChurchSecurityPlanner, our customers, and the public.
4. How We Share Information
We never sell personal information. We share data only with:
- Supabase, our managed database and authentication provider, operating in SOC 2–ready infrastructure.
- Stripe, our PCI-DSS compliant payment processor.
- Operational vendors that assist with logging, analytics, customer support, and email delivery—each bound by confidentiality and security obligations.
- Law enforcement or other parties if required by law or to protect our legal rights.
5. Data Retention
We retain information while your church subscription is active and for a limited period afterward to satisfy legal and audit requirements.
Church administrators can request deletion or export of data by contacting info@churchsecurityplanner.com. When a subscription ends and the account is suspended, data is preserved for 90 days before being permanently deleted, unless a longer retention is legally required.
6. International Data Transfers
ChurchSecurityPlanner hosts data in the Supabase US-East region. If you access the Service from another country, your information will be transferred to the United States. We rely on safeguards such as Standard Contractual Clauses where required.
7. Security Practices
We implement administrative, technical, and physical safeguards to protect information entrusted to us:
- Supabase Row Level Security for strict church-by-church data isolation.
- Encryption at rest (AES-256) and in transit (TLS 1.3).
- Audit logging, daily encrypted backups, and continuous infrastructure monitoring.
- Access to production systems is restricted to the company principal under least-privilege controls.
No security control is flawless. If we discover an incident that affects your data, we will notify the designated church contacts without undue delay and follow applicable legal requirements.
8. Analytics & Advertising
On our marketing website, we use Google Analytics and Google Ads to understand how visitors interact with our pages and to measure the effectiveness of our advertising campaigns. These tools use cookies and similar technologies to collect anonymous usage data such as pages visited, time on site, and referral source.
These tools operate ONLY on anonymous website-visitor data. They do not receive account information, member records, mobile numbers, or text-messaging consent data. No mobile information or SMS opt-in data is ever shared with advertising or analytics providers, for any purpose — see section 9.
We do not load analytics or advertising scripts inside our native iOS or Android applications. Tracking is limited to the public-facing website only.
You can opt out of Google’s use of cookies by visiting Google’s Ads Settings (https://adssettings.google.com) or by installing the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout).
9. Text Messages (SMS)
ChurchSecurityPlanner sends operational text messages to volunteers and staff whose mobile numbers have been added by a church administrator. These are account and scheduling messages — invitations to join a church team, credentials for first sign-in, and service notifications. We do not send marketing or promotional text messages, and we never sell or share mobile numbers with third parties for their own marketing.
Mobile numbers are entered by church administrators, who confirm at the time of entry that the individual has agreed to receive account messages from their organization. Consent to receive text messages is not a condition of purchasing or using the Service; every function of ChurchSecurityPlanner remains available by email alone.
Message frequency varies by church activity and is typically limited to account and schedule events. Message and data rates may apply. Reply STOP to any message to opt out of further text messages, or HELP for assistance. Opting out is recorded against the mobile number and honored permanently; it does not affect email delivery or access to your account.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Text messages are delivered through Twilio, our messaging provider, which processes mobile numbers and message content solely to deliver messages on our behalf. Questions about text messaging can be directed to info@churchsecurityplanner.com.
10. Your Rights
Depending on your location, you may have rights to access, correct, delete, or restrict the processing of certain personal information. Requests can be submitted through your church administrators or by emailing info@churchsecurityplanner.com.
You can opt out of optional marketing email at any time. Operational emails related to security, billing, or service delivery are considered essential and cannot be disabled while your account is active.
11. Children’s Privacy
ChurchSecurityPlanner is designed for adult staff and volunteers. We do not knowingly collect personal information from children under 16 years of age. If we become aware that a child has submitted data, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy to reflect product enhancements, regulatory requirements, or operational adjustments. When we make material changes we will notify account owners and revise the “Last updated” date above. Your continued use of the Service after an update constitutes acceptance of the revised policy.
13. Contact
Questions or requests concerning privacy can be directed to:
Conversion Catalyst LLC d/b/a ChurchSecurityPlanner
Attn: Data Protection Officer
4546 Chapman Hwy #3025 Knoxville, TN 37920
Email: info@churchsecurityplanner.com