ChurchPathways Privacy Notice
Effective date: 22 July 2026
Last updated: 22 July 2026
1. Who this notice is for
This Privacy Notice explains how ChurchPathways handles personal information when people:
- visit churchpathways.com;
- take the Discipleship Score;
- request information, early access, a demonstration or support;
- start or administer a church workspace, free plan, trial or paid subscription;
- join and use a pathway as a participant;
- use leader dashboards, shared thoughts, notes and follow-up tools;
- receive service, trial or marketing emails; or
- otherwise interact with ChurchPathways.
ChurchPathways is operated by CHURCHPATHWAYS LTD, trading as ChurchPathways (ChurchPathways, we, us or our), of 128 City Road, London, UK, EC1V 2NX, company number 17323299.
Contact: support@churchpathways.com
2. ChurchPathways' privacy model
ChurchPathways handles personal information in two different ways depending on the activity.
2.1 When a church decides how information is used
For participant and ministry information held within a church workspace, the relevant church or ministry organisation will normally decide why that information is collected and how it is used.
For example, the church decides which participants to invite, which pathways to assign, which authorised leaders may access information, how pastoral follow-up takes place and how long church-controlled information should be retained.
In data-protection law, this normally means the church is the controller.
ChurchPathways will normally act as the church's processor, handling that information on the church's documented instructions and in accordance with our Data Processing Agreement (DPA).
If you are a participant and your question concerns how your church uses your pathway information, you should normally contact the church first. We will assist the church where required.
2.2 When ChurchPathways decides how information is used
For some activities, CHURCHPATHWAYS LTD decides why and how personal information is used. In data-protection law, this means we act as the controller.
This includes information we use to:
- operate and secure the ChurchPathways website and Service;
- respond to enquiries and support requests;
- provide the Discipleship Score and deliver its results;
- create and administer requested trials;
- manage church customer accounts;
- administer subscriptions, billing and payment records;
- prevent fraud, misuse and security incidents;
- send essential service and trial communications;
- comply with legal and regulatory obligations;
- understand and improve the performance of the Service; and
- send marketing where permitted by law.
The exact data-protection role therefore depends on what the information is being used for, rather than simply who stores it.
3. Special-category and sensitive information
Use of ChurchPathways may reveal or strongly imply religious or philosophical beliefs. Reflections may also contain information about health, disability, ethnicity, sexual life or orientation, relationships, trauma, criminal allegations or other highly sensitive matters. UK data protection law gives special protection to certain categories of information.
Where a church is controller, that church is responsible for identifying and documenting:
- an Article 6 lawful basis;
- an Article 9 condition for special-category data;
- any Schedule 1 Data Protection Act 2018 condition and appropriate policy document that is required;
- whether explicit consent is appropriate;
- whether a Data Protection Impact Assessment (DPIA) is required; and
- safeguards appropriate to its ministry context.
Where ChurchPathways is controller and directly processes special-category information, we rely on explicit consent where required or another documented Article 9 condition that applies to the specific purpose.
You should share only information that is relevant and necessary for the pathway. Do not use ChurchPathways for emergencies, crisis disclosures, counselling, abuse-recovery casework or medical treatment.
4. Information we collect
4.1 Church and leader account information
We may collect:
- name, email address and contact details;
- church or organisation name, denomination or network, website and location;
- role, permissions and workspace membership;
- logo, branding preferences and church settings;
- subscription plan, trial dates and billing status;
- communications, support requests and feedback; and
- authentication, login and security-event information.
4.2 Participant information
Depending on the church's configuration, we may process:
- name and email address;
- church/workspace membership and pathway assignments;
- access requests and invitation status;
- pathway progress, day/week/session completion and timestamps;
- reflections and action responses;
- the participant's choice to keep a reflection private or share a thought;
- shared thoughts and leader responses;
- participant-visible messages;
- follow-up status and internal leader notes;
- completion records and engagement signals; and
- account, device and security information.
4.3 Pathway and church content
We may process teaching text, Bible references, questions, actions, uploaded or linked media, pathway names, descriptions, rhythms, categories and other church-created materials.
4.4 Discipleship Score and trial information
When a leader takes the Discipleship Score, we may collect:
- answers to the 10 assessment questions;
- the resulting score, category and recommendations;
- leader name, email, church name and other submitted details;
- form metadata and submission time;
- trial-workspace details created from the submission;
- email delivery, bounce, unsubscribe and, where enabled, open or link-click events; and
- duplicate, fraud-prevention or manual-review signals.
The score is an educational assessment of a church's discipleship systems. It is not a decision about an individual's faith, character or legal rights.
4.5 Billing information
Our payment provider may collect card, bank and billing details. We normally receive limited transaction information such as customer identifier, payment status, plan, amount, invoice details and card brand/expiry indicators rather than full payment-card numbers.
4.6 Technical and usage information
We may collect:
- IP address;
- browser, device, operating system and language;
- log-in and session information;
- pages, features and actions used;
- error, performance and security logs;
- referral source and campaign information;
- cookie or local-storage identifiers; and
- aggregated usage statistics.
4.7 Information from third parties
We may receive information from:
- the church that invites or administers you;
- Tally or another form provider;
- Make or another workflow provider;
- Supabase authentication and database services;
- Stripe payment services;
- Resend email services;
- Vercel hosting and delivery services;
- Microsoft Bookings for requested Fit Call appointment scheduling;
- media providers selected by a church; and
- public sources or people who contact us about an account, security issue or legal concern.
5. What leaders can see
ChurchPathways uses role-based access, but the church controls who receives each role. The following describes the intended product model.
5.1 Participants
A participant can normally see their own assigned pathways, progress, responses, sharing choices and leader responses intended for them.
5.2 Church owners and administrators
Authorised owners and administrators may see and manage church settings, leaders, participants, assignments, pathway content, progress, access requests, shared thoughts, responses, notes, follow-up indicators, reports and billing information, subject to product permissions.
5.3 Church leaders
Authorised leaders may see participants, pathway progress, shared thoughts, relevant context, leader responses, internal notes and follow-up indicators according to the access granted by the church.
5.4 Viewers or read-only users
A viewer may see the read-only information permitted by the church's configuration. The church should grant this role only where there is a genuine ministry need.
5.5 Private reflections
A reflection marked or kept private is not displayed to church leaders through the ordinary leader interface. If the participant chooses to share a thought, that shared content becomes visible to authorised church users.
Private content may still be technically processed and stored by ChurchPathways. A very limited number of authorised personnel or service providers may access it only where necessary for support, security, data recovery, legal compliance or another lawful purpose. We do not routinely read participant reflections.
5.6 Internal leader notes
Internal leader notes are not ordinarily shown to participants in the product interface. They remain personal data and may be subject to access, correction, disclosure, safeguarding or legal obligations. Leaders must write notes that are factual, necessary, respectful and appropriate for potential disclosure.
6. Why we use information and our lawful bases
The lawful basis depends on our role and purpose.
| Purpose | Typical information | Article 6 basis | Additional condition where special-category data is involved |
|---|---|---|---|
| Provide and administer the Service | Account, workspace, pathway and usage data | Contract; legitimate interests | Church-determined Article 9 condition when we act as processor; explicit consent or another documented condition when we act as controller |
| Authenticate users and protect accounts | Email, session, device and security logs | Contract; legitimate interests; legal obligation | Not normally applicable unless the security event contains sensitive content |
| Deliver church-controlled pathways and leader visibility | Participant identity, progress, reflections, shared thoughts and notes | Church's chosen lawful basis; our processing under contract/DPA | Church's chosen and documented Article 9 condition |
| Provide the Discipleship Score and create a requested trial | Form answers, contact and church details | Consent; contract steps at the person's request; legitimate interests | Explicit consent where the answers reveal religious belief or other special-category data |
| Process payments and subscriptions | Account, invoice and transaction data | Contract; legal obligation; legitimate interests | Not normally applicable |
| Send essential service and trial messages | Email, account and trial data | Contract; legitimate interests | Not normally applicable; sensitive content should not be included unnecessarily |
| Send marketing | Contact details and preferences | Consent or legitimate interests, subject to PECR | We do not use sensitive pathway content for marketing |
| Support, diagnose and improve the Service | Support messages, logs and usage data | Contract; legitimate interests | Access to sensitive content is limited to what is necessary |
| Prevent fraud, abuse and security incidents | Account, device, log and activity data | Legitimate interests; legal obligation | Substantial public interest or another condition may apply in exceptional cases |
| Handle complaints, rights and legal claims | Identity, correspondence and relevant records | Legal obligation; legitimate interests | Legal claims, substantial public interest or another applicable condition |
| Safeguarding or prevention of serious harm | Relevant content and contact details | Vital interests; legal obligation; legitimate interests, depending on circumstances | Vital interests, safeguarding of individuals at risk, legal claims or another applicable condition |
When we rely on legitimate interests, our interests include operating a secure and useful service, supporting customers, preventing misuse, improving performance and managing our business. We consider the likely impact on individuals and do not rely on legitimate interests where their rights override our interests.
7. Automated processing
ChurchPathways may automatically calculate a Discipleship Score, create a trial workspace, send scheduled messages, flag duplicates, calculate progress and produce engagement indicators.
We do not use ChurchPathways to make solely automated decisions that produce legal or similarly significant effects for participants. Churches must not use scores, progress or engagement indicators as the sole basis for membership, employment, discipline, safeguarding or other significant decisions about a person.
8. How we share information
We may share information with:
8.1 The relevant church
Participant identity, progress, shared thoughts, leader responses, notes and related information may be shared within the relevant church workspace according to role permissions and the participant's sharing choice.
8.2 Service providers and subprocessors
We use providers that may process data on our behalf, including:
| Provider | Main purpose |
|---|---|
| Supabase | Database, authentication, storage and backend services |
| Vercel | Website and application hosting, delivery and infrastructure |
| Resend | Transactional and trial email delivery and related events |
| Stripe | Checkout, subscription billing, invoices and payment management |
| Tally | Discipleship Score and other forms |
| Make | Workflow automation used in trial setup and related processes |
| Microsoft Bookings | Fit Call appointment scheduling when requested by a user |
When ChurchPathways acts as a processor, we may use service providers and subprocessors to help provide the Service. Our current providers include those listed above. Details of authorised subprocessors are set out in our Data Processing Agreement and may also be provided to Church Customers on request.
8.3 Professional and legal recipients
We may share information with professional advisers, insurers, auditors, accountants, prospective investors or acquirers, courts, regulators, law enforcement or public authorities where reasonably necessary and lawful.
8.4 Safeguarding and emergency recipients
If we reasonably believe there is an imminent risk of serious harm, abuse, exploitation or a legal reporting need, we may share necessary information with the church's safeguarding contact, emergency services, law enforcement, local authorities, regulators or another appropriate body. ChurchPathways does not promise to monitor all content or detect every concern.
8.5 Business changes
Information may be transferred as part of a merger, financing, reorganisation or sale, subject to confidentiality and continued data-protection safeguards.
We do not sell personal information.
9. International transfers
Some providers may process information outside the United Kingdom. Where personal data is transferred internationally, we use an available lawful safeguard, such as:
- a UK adequacy regulation;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses;
- another approved transfer mechanism; or
- an applicable legal derogation used only where appropriate.
We also consider provider security, transfer risk and supplementary measures where required. Contact us for more information about a relevant safeguard.
10. Retention and deletion
We keep personal information only for as long as needed for the purpose collected, the church's documented instructions, legal obligations, dispute resolution, security and backup cycles.
The following is the intended baseline and must be confirmed against the live production configuration and DPA before publication:
| Information | Intended retention approach |
|---|---|
| Active church workspace data | For the life of the workspace and according to the church's retention settings or instructions |
| Participant pathway data | Until deleted by the church, the participant relationship ends, or the workspace closes, subject to the church's retention policy and legal requirements |
| Closed workspace data | Normally available for export for up to 30 days, then scheduled for deletion or anonymisation within 90 days, unless another period is agreed or required |
| Secure backups | Removed through rolling backup cycles, normally within a further 90 days after primary deletion |
| Account, billing and tax records | Normally six years after the relevant transaction or relationship, where required for tax, accounting or legal claims |
| Support and complaint records | Normally up to three years after closure, or longer where needed for a legal claim or regulatory duty |
| Security and access logs | Normally 30 to 180 days, depending on the log and risk, unless preserved for an investigation |
| Discipleship Score and trial lead records | Normally up to 24 months after the last meaningful interaction, unless the person opts out earlier or becomes a customer |
| Marketing suppression records | As long as needed to ensure we respect the opt-out |
A church may require a shorter or longer retention period where lawful. A deletion from the live Service may not immediately remove data from encrypted backups. Backup copies remain protected and are not restored except for disaster recovery or legal need.
11. Security
We use proportionate technical and organisational measures intended to protect confidentiality, integrity and availability. Measures may include:
- multi-tenant separation and role-based access;
- secure authentication and session controls;
- encryption in transit and provider encryption at rest;
- restricted administrative access;
- logging and monitoring;
- secure development, dependency and deployment practices;
- backups and recovery procedures;
- subprocessor due diligence and contracts;
- staff confidentiality obligations; and
- incident and breach-response procedures.
No system is completely secure. Users and churches must protect their accounts, devices and access permissions and report suspected incidents promptly to support@churchpathways.com.
12. Personal-data breaches
We maintain an incident process to identify, contain, assess and document suspected personal-data breaches.
Where ChurchPathways acts as processor, we will notify the relevant Church Customer without undue delay after becoming aware of a breach affecting that church's data and provide reasonable information and assistance under the DPA.
Where ChurchPathways acts as controller, we will assess risk and notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours when the legal threshold is met. Where the breach is likely to result in a high risk to individuals, we will also communicate with affected people without undue delay unless an exception applies.
13. Your data-protection rights
Depending on the circumstances, you may have the right to:
- be informed about use of your information;
- obtain access to your information;
- correct inaccurate or incomplete information;
- request deletion;
- restrict processing;
- object to processing, including direct marketing;
- receive certain information in a portable format;
- withdraw consent at any time, without affecting earlier lawful processing;
- ask for human review of certain automated decisions; and
- complain about how your information is handled.
Rights are not absolute and exemptions may apply.
For church-controlled workspace data, contact the relevant church where possible. You may also contact us at support@churchpathways.com; we may need to refer the request to the church or verify your identity before acting.
We will not charge a fee unless a request is manifestly unfounded or excessive and the law allows it. We normally respond within one month, subject to lawful extensions.
14. Data-protection complaints
You may raise a data-protection complaint by emailing support@churchpathways.com with the subject Data protection complaint. Please explain what happened, which account or church is involved, the outcome you seek and any relevant dates.
We will:
- provide an accessible electronic route for complaints;
- acknowledge the complaint within 30 days;
- take appropriate steps to investigate it;
- respond without undue delay; and
- explain the outcome and any action taken.
Where the matter concerns church-controlled data, we may coordinate with or refer it to the relevant church while continuing to meet our own obligations.
You may also complain to the Information Commissioner's Office. We would appreciate the opportunity to address the concern first, but you are not required to contact us before approaching the ICO.
15. Marketing and email preferences
We send essential messages needed for authentication, invitations, security, trials, pathway activity, billing and service administration. These cannot always be switched off while the relevant account or trial remains active.
We send promotional emails only where permitted by data protection and electronic-marketing law. Each marketing email includes an unsubscribe method. We keep a suppression record so we do not restart marketing after an opt-out.
Where enabled, email technologies may record delivery, bounce, open and link-click events. We use these to operate and improve trial or service communications. We do not use sensitive participant reflections for marketing.
16. Cookies and similar technologies
We use cookies, local storage, authentication tokens, pixels and similar technologies for sign-in, security, preferences, forms, email delivery and service improvement. Our Cookie Policy explains the technologies, consent choices and objection mechanisms.
17. Children
ChurchPathways is currently intended for adults aged 18 and over. We do not knowingly invite or provide participant accounts to children. Churches must not use the Service for under-18s without a separate written arrangement and appropriate age assurance, notices, parental or other permissions, safeguarding design and risk assessment.
If you believe a child has provided information through the Service, contact support@churchpathways.com promptly.
18. Safeguarding and urgent situations
ChurchPathways is not an emergency, crisis, counselling or safeguarding-reporting service and is not continuously monitored. Participants should follow their church's safeguarding process and contact emergency or statutory services where needed.
In an immediate emergency in the United Kingdom, call 999 or 112.
ChurchPathways does not investigate pastoral or safeguarding allegations. The relevant church remains responsible for its safeguarding response. We may preserve and disclose information where lawful and necessary to protect life, prevent serious harm or comply with legal duties.
19. Changes to this notice
We may update this notice to reflect changes in law, technology, providers or the Service. We will post the revised version and update the date. We will give additional notice where a change materially affects how we use personal information.
20. Contact details
ChurchPathways CHURCHPATHWAYS LTD 128 City Road, London, UK, EC1V 2NX Company number: 17323299 Email: support@churchpathways.com