Last updated · 2026-09-17
Sub-processors
This document is shown in English; a translation in your language is in preparation.
The following sub-processors may process personal data to provide the service. We impose data-protection obligations on each and only share the minimum data needed. Transfers outside the EEA rely on the safeguard noted.
Current sub-processors
- Stripe — payment processing (billing + online giving). Data: donor/admin email & name, payment metadata. Location: USA/EU. Safeguard: EU–US DPF / SCCs.
- Resend — transactional email delivery. Data: recipient email & name, message content. Location: USA. Safeguard: SCCs.
- Google — "Sign in with Google" identity verification (optional). Data: sign-in identity (email, name, Google id, profile photo URL). Where the account has no photo of its own, the Google profile picture is shown from Google's servers, so the browser displaying it contacts Google. Location: USA. Safeguard: EU–US DPF.
- Cloudflare R2 — object/file storage (member photos, documents, media). Data: uploaded files and their metadata. Location: configurable (EU recommended). Safeguard: SCCs.
- Browser push services (Google FCM, Mozilla, Apple) — Web Push delivery for staff browser notifications (opt-in). Data: a push endpoint URL plus an end-to-end-encrypted payload the service cannot read. Location: USA. Safeguard: EU–US DPF / SCCs.
- Expo (Expo Application Services) — push notification delivery to the Assemblea mobile app (opt-in, per device). Data: a device push token plus the notification title and body, which may name a member or visitor. Unlike browser push, this payload is NOT end-to-end encrypted: Expo and the underlying platform services (Apple APNs, Google FCM) can read it. Location: USA — non-EU transfer. Safeguard: SCCs. If nobody enables push in the mobile app, no data is shared with Expo.
- Meta Platforms (WhatsApp Business Platform / Cloud API) — WhatsApp message delivery to congregants. Used ONLY when the church enables the WhatsApp channel, and only for recipients who have expressly opted in to WhatsApp messages. Data: recipient phone number and message content. Location: USA — non-EU transfer. Safeguard: Meta’s Standard Contractual Clauses (SCCs). If the WhatsApp channel is not enabled, no data is shared with Meta.
- Hosting provider — application database (PostgreSQL) and cache/queue (Redis). Data: all platform data. Location: per deployment (EU recommended).
Not used
Telegram is NOT used to forward support messages (that transfer is disabled by default). No third-party analytics or advertising processors are used (usage statistics are computed in-house).
Ejerce tus derechos de privacidad →
Questions about this document or your data? Contact [email protected].