How ShepherdCloud collects, uses, stores, and protects your data. We take your privacy seriously.
Last updated: June 2026On this page
ShepherdCloud is a cloud-based church management platform built and maintained by the ShepherdCloud team. Our platform operates at shepherdcloud.org and all associated subdomains. The ShepherdCloud team is not a registered legal entity.
We act as a data processor for the churches and organizations ("tenants") that use our platform. Each tenant is the data controller for the personal data they upload about their members, workers, and congregants. This Policy explains both how we handle data on behalf of tenants and how we handle data about tenant administrators and users.
When you create a ShepherdCloud account or are added as a user by your church, we collect:
Encrypted using bcrypt hashing — never stored in plaintext.
TOTP authenticator secret, SMS MFA preference.
When your church registers members, the following personal data may be stored:
First, middle, and surname; gender; nationality; date of birth; marital status; occupation
Phone number; digital/GPS address; hometown; location
Church group; baptism status; position held; QR code token for attendance; biometric user ID
Profile photograph; uploaded documents and receipts
We store financial transaction records entered by your church, including:
With category, amount, date, description, and receipt images.
Payment gateway confirmations and billing records.
Payment cards: We do not store your credit/debit card details on our servers. All payment processing is handled directly by Paystack through secure, Payment Card Industry Data Security Standard (PCI-DSS) Level 1 certified gateways.
To protect your account security, we track session information:
Country, region, city based on IP address.
Combination of device type, browser, and OS.
Text sent through the platform.
For SMS delivery.
We use the collected data exclusively to provide and improve the ShepherdCloud service:
Processing member records, financial transactions, attendance tracking, event management, and report generation.
Verifying your identity, enforcing MFA, detecting suspicious logins, and protecting accounts from unauthorized access.
Sending SMS notifications, email alerts, password reset links, security notifications, and administrative announcements.
Processing add-on purchases and maintaining billing records.
Analyzing platform usage to fix bugs, improve performance, and develop new features.
We do not: Rent, sell, or trade your personal data for monetary consideration. We may share limited data with service providers strictly as described in Section 5. We do not use your data for advertising purposes or share member data with anyone outside your tenant organization.
You provide explicit consent when creating an account and uploading data. You may withdraw consent at any time.
Processing is necessary to provide the Service you requested under our Terms of Service.
Security monitoring, fraud prevention, and service improvement are in our legitimate interest and do not override your rights.
We may process data where we believe in good faith it is necessary to comply with applicable laws or respond to valid legal requests.
We work with trusted third-party providers to deliver core functionality. Data shared with these providers is limited to what is strictly necessary. The specific third-party providers we use may change from time to time. We will update this list for material changes but reserve the right to add or replace service providers without prior notice where those changes do not materially alter the privacy protections described herein.
Payment processing for add-on purchases. Sends: email, amount, transaction reference. Paystack is Payment Card Industry Data Security Standard (PCI-DSS) Level 1 certified.
Ghana-based SMS gateway for notifications and announcements. Sends: phone number (233-format), message content.
Transactional email delivery (password resets, login alerts, admin notifications). Uses STARTTLS encryption.
Infrastructure hosting provider. All application data, databases, files, and backups reside on Contabo servers.
IP-to-location lookup for session security. Sends: IP address only. Used to detect suspicious login locations.
Self-hosted database storing all application data.
In-memory cache and task queue broker. Does not persistently store personal data.
Background task processing for scheduled reports, SMS/email delivery, and data backups.
Optional content delivery network for static assets (JavaScript, CSS, images).
Error monitoring capturing application exceptions and performance traces (10% sampling). May include request URLs in error context.
All ShepherdCloud data is hosted on Contabo servers. Your data is logically separated from other tenants through our subdomain-based multi-tenant architecture — each church's database records are automatically filtered by tenant ID, ensuring that no tenant can access another tenant's data.
We provide multiple data deletion pathways:
Most records (members, events, attendance, financial records) are initially soft-deleted — they are marked as deleted but remain recoverable. Soft-deleted records are excluded from all queries and reports.
For permanent removal requests, we support immediate hard deletion of individual records, including associated files and database entries. This deletion is permanent from active systems. Data in existing backups will age out per our backup retention schedule.
Upon tenant account termination, all data is deleted from active systems. Backup copies may persist for up to 30 days per our backup retention policy.
Automated database backups are maintained (up to 10 per tenant), with oldest backups purged when new ones are created. Backups are encrypted and checksum-verified.
Active session records retained for the life of the session + 7 days after expiry for security auditing.
Auto-expire after 72 hours.
Retained for the duration of your account plus 7 years, or longer where required by law.
Retained for the duration of your account plus a reasonable period thereafter for record-keeping purposes.
We implement comprehensive, defense-in-depth security measures to protect your data:
All passwords hashed with bcrypt. HTTPS enforced in production. TLS for email transport. Session cookies secured (Secure, HttpOnly, SameSite).
TOTP authenticator app (Google Authenticator compatible) + SMS-based MFA. 10 single-use backup codes per user.
Role-Based Access Control (RBAC) with 50+ granular permissions and 11 predefined roles. Subdomain-based tenant isolation.
Session monitoring with device fingerprinting, geolocation tracking, security scoring, and new-device email alerts.
API rate limiting (100/min), login rate limiting (50/5 min), SMS send limits (60/min, 500/hr, 2000/day).
CSRF protection, Content Security Policy, XSS prevention, bot detection, malicious payload scanning, IP blocking.
All create, update, delete, login, and permission change operations are logged with user ID, IP address, and timestamp.
X-Content-Type-Options, X-Frame-Options (DENY), X-XSS-Protection, HSTS (max-age=31536000), Referrer-Policy, Permissions-Policy.
Minimum 12 characters, requiring uppercase, lowercase, digits, and special characters. Blocks 50+ common passwords and username-in-password patterns.
3 sessions for regular users, 5 for administrators. Oldest session auto-terminated when exceeded.
Under applicable data protection laws, you have the following rights:
Request a copy of your personal data we hold.
Correct inaccurate or incomplete data.
Request deletion of your data ("right to be forgotten").
Limit how we use your data.
Export your data in a machine-readable format (Excel, CSV, or PDF via our Reports module).
Object to processing based on legitimate interests.
Withdraw previously given consent at any time.
To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by applicable data protection laws. In most cases, this is within 30 calendar days. For tenant-specific member data, please contact your church administrator (the data controller) directly.
ShepherdCloud is designed for use by church administrators and staff. While churches may record data about children (e.g., children's ministry members, Sunday school attendees), this data is entered and managed by the church — the data controller. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided us with personal data without parental consent, please contact us immediately.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
Sending an email to the address associated with your account.
Displaying a prominent notice within the Service upon login.
Updating the "Last updated" date at the top of this page.
Your continued use of the Service after changes take effect constitutes your acceptance of the revised Policy.
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a privacy concern: