Church Base Cloud ← Back to churchbasecloud.com
Privacy Policy

Your church's data belongs to your church. Full stop.

Last updated: 27 July 2026

The short version

1Who we are

Church Base Cloud (“CBC”, “we”) is operated by DigitAI Solutions LLC (USA). For anything in this policy, write to hello@churchbasecloud.com — a human answers.

2Two roles: your church, and us

For the people records inside a church's space, the church decides what is stored and who may see it — in data-protection terms, the church is the controller and we are its processor: we store and process that data only to provide the service, on the church's instructions, and for nothing else.

For the small amount of data we need ourselves — the church's contact person, billing details, support emails — we are the controller.

3What data is stored

We deliberately run no third-party analytics, no tracking pixels and no advertising scripts — on this website and inside the apps.

4Where your data lives

The platform runs on servers of Hetzner Online GmbH in the European Union (Finland), an ISO-27001-certified hosting provider. Transactional email is delivered through a German email provider. Encrypted daily backups are kept on the same EU infrastructure for 14 days.

Each church's data lives in its own, separate database — isolation is built into the architecture, not just into permissions.

5Who else touches data — and who doesn't

We use a deliberately short list of service providers, each only for what it says:

ProviderPurposeLocationPersonal data involved
Hetzner Online GmbHHosting & backupsEU (Finland/Germany)All platform data (encrypted in transit, isolated per church)
All-inkl.com (Neue Medien Münnich)Email deliveryGermanyRecipient address and email content
MIPS LtdOnline card payments — only if your church enables online giving, under the church's own merchant accountMauritiusPayment details, handled by MIPS as payment processor
Google (Gemini)Optional AI writing help — only the draft text an admin explicitly asks to polishUSA/EUThe draft text; never your member database
Crossway (ESV API)Verse of the dayUSANone

That is the whole list. We never sell data, never share it for advertising, and never use your church's data to train AI models.

6Cookies

We set only what the service technically needs: a session cookie to keep you signed in and a security token against request forgery. No marketing cookies, hence no cookie banner theatre.

7What members control themselves

Privacy is designed into the member app, not bolted on:

8Security

9Your rights, export & deletion

Members exercise their rights (access, correction, deletion) with their church — the church controls its records, and the tools to answer are built in. For our own records (billing contacts, support mail), write to us directly.

Churches can export their data at any time (people lists as CSV, giving statements, calendar feeds). When a church leaves, its database and uploaded files are deleted within 30 days of the end of the contract — backups roll out of retention within a further 14 days.

10Changes to this policy

If this policy changes in a way that matters, we notify church admins by email before the change takes effect. The current version always lives at this address.

11Contact

Questions, concerns, or a request about your data: hello@churchbasecloud.com.