ChurchPathways Cookie Policy
Effective date: 22 July 2026
Last updated: 22 July 2026
1. About this policy
This Cookie Policy explains how ChurchPathways uses cookies and similar storage and access technologies on churchpathways.com and within the ChurchPathways application.
ChurchPathways is operated by CHURCHPATHWAYS LTD, trading as ChurchPathways, of 128 City Road, London, UK, EC1V 2NX.
Contact: support@churchpathways.com
This policy should be read with our Privacy Notice.
2. What cookies and similar technologies are
A cookie is a small text file placed on or read from a browser or device. Similar technologies include local storage, session storage, authentication tokens, pixels, scripts, software-development-kit identifiers and other methods of storing information on, or accessing information from, a device.
We use the term cookies in this policy to include these similar technologies unless the context requires otherwise.
3. How the UK rules work
The Privacy and Electronic Communications Regulations (PECR) regulate storage of information on, and access to information from, a person's device. The UK GDPR and Data Protection Act 2018 apply where the information is personal data.
We provide clear information about the technologies we use. We obtain consent before using technologies that require it. Certain technologies may be used without consent where a PECR exception applies, including where they are:
- used solely to transmit a communication;
- strictly necessary to provide a service the user requests;
- used solely to collect aggregate statistical information to improve the service, provided the legal conditions and a simple free objection mechanism are met; or
- used solely to adapt appearance or functionality to a user's preference, provided the legal conditions and a simple free objection mechanism are met.
If our use goes beyond an exception, we ask for consent before it begins.
4. Categories of technology we use
4.1 Strictly necessary and communication technologies
These technologies are required to deliver, secure and operate the Service. They may be used without consent where the legal exception applies.
They can include:
- authentication and session cookies used to keep a user signed in;
- secure sign-in, magic-link and account-verification tokens;
- load balancing and network-routing technologies;
- fraud, abuse, CSRF and security controls;
- cookies that remember a user's cookie choice;
- temporary state needed to complete a requested form, checkout or account action; and
- technologies needed to record a user's explicit selection within the Service.
Disabling these technologies may prevent sign-in or core features from working.
4.2 Functional and interface-state technologies
ChurchPathways uses limited first-party browser storage to remember user-requested or operational state within the Service. Depending on the feature, this may include:
- authentication or login-gate state;
- navigation or dashboard state;
- the most recently selected pathway;
- journey or session continuation state; and
- other non-advertising interface selections made by the user.
Where storing a selection is strictly necessary to provide the feature the user requested, we may use it without consent under the applicable PECR exception. If we introduce functionality that relies instead on the PECR appearance exception, we will provide clear information and a simple, free way to object.
4.3 Analytics and performance technologies
ChurchPathways does not currently use a third-party browser analytics package, behavioural analytics package or advertising tracker on the public website. Hosting, security and application logs may still be generated by our infrastructure providers and are described in our Privacy Notice.
If we introduce browser-based analytics in future, we will assess the technology before deployment. Where the PECR statistical-purpose exception applies, we will meet its conditions, including providing clear information and a simple, free way to object. Analytics or tracking that goes beyond an exception will be used only with consent.
4.4 Embedded forms and media
ChurchPathways may embed:
- Tally forms, including the Discipleship Score;
- videos or media selected by ChurchPathways or a Church Customer; and
- other interactive content.
An embedded provider may set its own technologies. We aim to use privacy-friendly settings and, where appropriate, delay non-essential technologies until a person consents or actively chooses to load or play the content.
When a Church Customer adds third-party media to a pathway, that church is responsible for ensuring its use is appropriate and transparent. A participant may be offered an external link instead of an embedded player where practical.
4.5 Payment and billing technologies
When an authorised church user chooses checkout or billing management, Stripe may set cookies or similar technologies on its pages for security, fraud prevention, payment processing and user-requested checkout functions. Stripe's own notices apply to its independent processing.
4.6 Email technologies
Service and trial emails may contain pixels or tracked links that record delivery, bounce, open or click events where enabled. These are not always browser cookies, but they can access device or message information and are described in our Privacy Notice. Marketing emails include an opt-out.
4.7 Advertising technologies
ChurchPathways does not currently use behavioural advertising cookies or cross-site advertising profiles. If this changes, we will update this policy and obtain consent before such technologies are used.
5. Current technology and provider inventory
This section reflects the current ChurchPathways implementation. Exact cookie or storage names can change when browsers or providers update their services, so we keep this inventory under review.
| Provider or source | Current use | Current treatment |
|---|---|---|
| ChurchPathways / Supabase | Authentication, session continuity, secure sign-in and account state; Supabase authentication storage names may begin with sb- | Strictly necessary for requested account and authentication functions |
| ChurchPathways | First-party local or session storage for login-gate state, navigation/dashboard state, pathway selection and journey/session continuation | Used for requested service functionality and user selections; not used for advertising |
| Vercel | Hosting, network delivery, security and infrastructure operation | No Vercel Analytics package is currently deployed on the public website |
| Tally | Discipleship Score popup/form functionality | Third-party form functionality; we keep its live browser behaviour under review and do not use it for behavioural advertising |
| Stripe | Checkout, billing portal, fraud prevention and payment security when an authorised church user chooses a payment or billing action | Used in connection with the requested payment function; Stripe's own notices apply on its pages |
| Resend / email links | Delivery, bounce and, where enabled, open or click events in service and trial emails | Email technology rather than a general website analytics or advertising cookie system |
ChurchPathways does not currently use behavioural advertising cookies, cross-site advertising profiles or a general third-party browser analytics package on the public website.
6. Consent and objection choices
ChurchPathways does not currently operate a general cookie-consent banner or cookie-preference centre because the current public website does not deploy optional advertising or general browser analytics technologies that require such a mechanism.
If we introduce a technology that requires consent, we will not use it until the required consent has been obtained, and we will provide an appropriately easy way to refuse or later withdraw that consent.
If we rely on the PECR statistical-purpose or appearance exception for a future technology, we will provide the clear information and simple, free means of objecting required by that exception.
7. Browser and device controls
Most browsers allow you to view, block or delete cookies and other stored website data. Blocking or deleting strictly necessary authentication or service state may sign you out, reset preferences or prevent core functions from working until the relevant information is stored again.
For embedded content or third-party pages, you may also need to use the provider's controls.
8. Church Customer responsibilities
A Church Customer that adds third-party videos, forms, scripts or integrations to its pathways must:
- understand what the technology does;
- use privacy-friendly settings;
- avoid loading non-essential tracking before consent;
- provide clear participant information;
- ensure the provider is covered by the church's privacy and processor arrangements where required; and
- remove technology that is unnecessary or disproportionate.
9. Changes to this policy
We may update this policy and the live cookie inventory when providers, purposes or law change. We will update the date and seek fresh consent where required.
10. Contact
Questions about cookies or choices may be sent to:
ChurchPathways CHURCHPATHWAYS LTD 128 City Road, London, UK, EC1V 2NX Email: support@churchpathways.com