ChurchPathwaysBack to churchpathways.com

ChurchPathways Cookie Policy

Effective date: 22 July 2026

Last updated: 22 July 2026

1. About this policy

This Cookie Policy explains how ChurchPathways uses cookies and similar storage and access technologies on churchpathways.com and within the ChurchPathways application.

ChurchPathways is operated by CHURCHPATHWAYS LTD, trading as ChurchPathways, of 128 City Road, London, UK, EC1V 2NX.

Contact: support@churchpathways.com

This policy should be read with our Privacy Notice.

2. What cookies and similar technologies are

A cookie is a small text file placed on or read from a browser or device. Similar technologies include local storage, session storage, authentication tokens, pixels, scripts, software-development-kit identifiers and other methods of storing information on, or accessing information from, a device.

We use the term cookies in this policy to include these similar technologies unless the context requires otherwise.

3. How the UK rules work

The Privacy and Electronic Communications Regulations (PECR) regulate storage of information on, and access to information from, a person's device. The UK GDPR and Data Protection Act 2018 apply where the information is personal data.

We provide clear information about the technologies we use. We obtain consent before using technologies that require it. Certain technologies may be used without consent where a PECR exception applies, including where they are:

  • used solely to transmit a communication;
  • strictly necessary to provide a service the user requests;
  • used solely to collect aggregate statistical information to improve the service, provided the legal conditions and a simple free objection mechanism are met; or
  • used solely to adapt appearance or functionality to a user's preference, provided the legal conditions and a simple free objection mechanism are met.

If our use goes beyond an exception, we ask for consent before it begins.

4. Categories of technology we use

4.1 Strictly necessary and communication technologies

These technologies are required to deliver, secure and operate the Service. They may be used without consent where the legal exception applies.

They can include:

  • authentication and session cookies used to keep a user signed in;
  • secure sign-in, magic-link and account-verification tokens;
  • load balancing and network-routing technologies;
  • fraud, abuse, CSRF and security controls;
  • cookies that remember a user's cookie choice;
  • temporary state needed to complete a requested form, checkout or account action; and
  • technologies needed to record a user's explicit selection within the Service.

Disabling these technologies may prevent sign-in or core features from working.

4.2 Functional and interface-state technologies

ChurchPathways uses limited first-party browser storage to remember user-requested or operational state within the Service. Depending on the feature, this may include:

  • authentication or login-gate state;
  • navigation or dashboard state;
  • the most recently selected pathway;
  • journey or session continuation state; and
  • other non-advertising interface selections made by the user.

Where storing a selection is strictly necessary to provide the feature the user requested, we may use it without consent under the applicable PECR exception. If we introduce functionality that relies instead on the PECR appearance exception, we will provide clear information and a simple, free way to object.

4.3 Analytics and performance technologies

ChurchPathways does not currently use a third-party browser analytics package, behavioural analytics package or advertising tracker on the public website. Hosting, security and application logs may still be generated by our infrastructure providers and are described in our Privacy Notice.

If we introduce browser-based analytics in future, we will assess the technology before deployment. Where the PECR statistical-purpose exception applies, we will meet its conditions, including providing clear information and a simple, free way to object. Analytics or tracking that goes beyond an exception will be used only with consent.

4.4 Embedded forms and media

ChurchPathways may embed:

  • Tally forms, including the Discipleship Score;
  • videos or media selected by ChurchPathways or a Church Customer; and
  • other interactive content.

An embedded provider may set its own technologies. We aim to use privacy-friendly settings and, where appropriate, delay non-essential technologies until a person consents or actively chooses to load or play the content.

When a Church Customer adds third-party media to a pathway, that church is responsible for ensuring its use is appropriate and transparent. A participant may be offered an external link instead of an embedded player where practical.

4.5 Payment and billing technologies

When an authorised church user chooses checkout or billing management, Stripe may set cookies or similar technologies on its pages for security, fraud prevention, payment processing and user-requested checkout functions. Stripe's own notices apply to its independent processing.

4.6 Email technologies

Service and trial emails may contain pixels or tracked links that record delivery, bounce, open or click events where enabled. These are not always browser cookies, but they can access device or message information and are described in our Privacy Notice. Marketing emails include an opt-out.

4.7 Advertising technologies

ChurchPathways does not currently use behavioural advertising cookies or cross-site advertising profiles. If this changes, we will update this policy and obtain consent before such technologies are used.

5. Current technology and provider inventory

This section reflects the current ChurchPathways implementation. Exact cookie or storage names can change when browsers or providers update their services, so we keep this inventory under review.

Provider or sourceCurrent useCurrent treatment
ChurchPathways / SupabaseAuthentication, session continuity, secure sign-in and account state; Supabase authentication storage names may begin with sb-Strictly necessary for requested account and authentication functions
ChurchPathwaysFirst-party local or session storage for login-gate state, navigation/dashboard state, pathway selection and journey/session continuationUsed for requested service functionality and user selections; not used for advertising
VercelHosting, network delivery, security and infrastructure operationNo Vercel Analytics package is currently deployed on the public website
TallyDiscipleship Score popup/form functionalityThird-party form functionality; we keep its live browser behaviour under review and do not use it for behavioural advertising
StripeCheckout, billing portal, fraud prevention and payment security when an authorised church user chooses a payment or billing actionUsed in connection with the requested payment function; Stripe's own notices apply on its pages
Resend / email linksDelivery, bounce and, where enabled, open or click events in service and trial emailsEmail technology rather than a general website analytics or advertising cookie system

ChurchPathways does not currently use behavioural advertising cookies, cross-site advertising profiles or a general third-party browser analytics package on the public website.

6. Consent and objection choices

ChurchPathways does not currently operate a general cookie-consent banner or cookie-preference centre because the current public website does not deploy optional advertising or general browser analytics technologies that require such a mechanism.

If we introduce a technology that requires consent, we will not use it until the required consent has been obtained, and we will provide an appropriately easy way to refuse or later withdraw that consent.

If we rely on the PECR statistical-purpose or appearance exception for a future technology, we will provide the clear information and simple, free means of objecting required by that exception.

7. Browser and device controls

Most browsers allow you to view, block or delete cookies and other stored website data. Blocking or deleting strictly necessary authentication or service state may sign you out, reset preferences or prevent core functions from working until the relevant information is stored again.

For embedded content or third-party pages, you may also need to use the provider's controls.

8. Church Customer responsibilities

A Church Customer that adds third-party videos, forms, scripts or integrations to its pathways must:

  • understand what the technology does;
  • use privacy-friendly settings;
  • avoid loading non-essential tracking before consent;
  • provide clear participant information;
  • ensure the provider is covered by the church's privacy and processor arrangements where required; and
  • remove technology that is unnecessary or disproportionate.

9. Changes to this policy

We may update this policy and the live cookie inventory when providers, purposes or law change. We will update the date and seek fresh consent where required.

10. Contact

Questions about cookies or choices may be sent to:

ChurchPathways CHURCHPATHWAYS LTD 128 City Road, London, UK, EC1V 2NX Email: support@churchpathways.com

Related documents

  • Privacy Notice
ChurchPathways
PrivacyTermsCookiesAcceptable Use

ChurchPathways is operated by CHURCHPATHWAYS LTD, registered in England and Wales (Company No. 17323299). Registered office: 128 City Road, London, EC1V 2NX, United Kingdom.