Privacy Policy

How ShepherdCloud collects, uses, stores, and protects your data. We take your privacy seriously.

Last updated: June 2026

On this page

1. Who We Are

ShepherdCloud is a cloud-based church management platform built and maintained by the ShepherdCloud team. Our platform operates at shepherdcloud.org and all associated subdomains. The ShepherdCloud team is not a registered legal entity.

We act as a data processor for the churches and organizations ("tenants") that use our platform. Each tenant is the data controller for the personal data they upload about their members, workers, and congregants. This Policy explains both how we handle data on behalf of tenants and how we handle data about tenant administrators and users.

2. Data We Collect

Account & Profile Data

When you create a ShepherdCloud account or are added as a user by your church, we collect:

Full name, username, email address, and phone number
Your church/organization name and custom subdomain slug
Password

Encrypted using bcrypt hashing — never stored in plaintext.

MFA preferences

TOTP authenticator secret, SMS MFA preference.

Church Member Data

When your church registers members, the following personal data may be stored:

Personal Identity

First, middle, and surname; gender; nationality; date of birth; marital status; occupation

Contact Details

Phone number; digital/GPS address; hometown; location

Church Affiliation

Church group; baptism status; position held; QR code token for attendance; biometric user ID

Media

Profile photograph; uploaded documents and receipts

Financial Data

We store financial transaction records entered by your church, including:

Tithes, offerings, welfare contributions, harvest contributions, and pledges
Expense records

With category, amount, date, description, and receipt images.

Transaction references

Payment gateway confirmations and billing records.

Payment cards: We do not store your credit/debit card details on our servers. All payment processing is handled directly by Paystack through secure, Payment Card Industry Data Security Standard (PCI-DSS) Level 1 certified gateways.

Device & Session Data

To protect your account security, we track session information:

IP address, browser type and version, operating system, device type
Approximate geolocation

Country, region, city based on IP address.

Device fingerprint

Combination of device type, browser, and OS.

Login timestamps, session duration, and security scores

Communication Data

SMS message content

Text sent through the platform.

Email content and recipient addresses
Recipient phone numbers

For SMS delivery.

3. How We Use Your Data

We use the collected data exclusively to provide and improve the ShepherdCloud service:

Service delivery

Processing member records, financial transactions, attendance tracking, event management, and report generation.

Authentication & security

Verifying your identity, enforcing MFA, detecting suspicious logins, and protecting accounts from unauthorized access.

Communication

Sending SMS notifications, email alerts, password reset links, security notifications, and administrative announcements.

Billing & payments

Processing add-on purchases and maintaining billing records.

Improvement

Analyzing platform usage to fix bugs, improve performance, and develop new features.

We do not: Rent, sell, or trade your personal data for monetary consideration. We may share limited data with service providers strictly as described in Section 5. We do not use your data for advertising purposes or share member data with anyone outside your tenant organization.

5. Third-Party Services

We work with trusted third-party providers to deliver core functionality. Data shared with these providers is limited to what is strictly necessary. The specific third-party providers we use may change from time to time. We will update this list for material changes but reserve the right to add or replace service providers without prior notice where those changes do not materially alter the privacy protections described herein.

Paystack

Payment processing for add-on purchases. Sends: email, amount, transaction reference. Paystack is Payment Card Industry Data Security Standard (PCI-DSS) Level 1 certified.

SMS Online GH

Ghana-based SMS gateway for notifications and announcements. Sends: phone number (233-format), message content.

Gmail SMTP

Transactional email delivery (password resets, login alerts, admin notifications). Uses STARTTLS encryption.

Contabo

Infrastructure hosting provider. All application data, databases, files, and backups reside on Contabo servers.

ipapi.co & ip-api.com

IP-to-location lookup for session security. Sends: IP address only. Used to detect suspicious login locations.

Infrastructure & Monitoring

PostgreSQL

Self-hosted database storing all application data.

Redis

In-memory cache and task queue broker. Does not persistently store personal data.

Celery

Background task processing for scheduled reports, SMS/email delivery, and data backups.

Cloudflare CDN

Optional content delivery network for static assets (JavaScript, CSS, images).

Sentry

Error monitoring capturing application exceptions and performance traces (10% sampling). May include request URLs in error context.

6. Data Storage & Retention

Where Your Data Lives

All ShepherdCloud data is hosted on Contabo servers. Your data is logically separated from other tenants through our subdomain-based multi-tenant architecture — each church's database records are automatically filtered by tenant ID, ensuring that no tenant can access another tenant's data.

Data Deletion

We provide multiple data deletion pathways:

Soft delete

Most records (members, events, attendance, financial records) are initially soft-deleted — they are marked as deleted but remain recoverable. Soft-deleted records are excluded from all queries and reports.

Hard delete (GDPR)

For permanent removal requests, we support immediate hard deletion of individual records, including associated files and database entries. This deletion is permanent from active systems. Data in existing backups will age out per our backup retention schedule.

Account deletion

Upon tenant account termination, all data is deleted from active systems. Backup copies may persist for up to 30 days per our backup retention policy.

Backups

Automated database backups are maintained (up to 10 per tenant), with oldest backups purged when new ones are created. Backups are encrypted and checksum-verified.

Retention Periods

Session data

Active session records retained for the life of the session + 7 days after expiry for security auditing.

Security alerts

Auto-expire after 72 hours.

Audit logs

Retained for the duration of your account plus 7 years, or longer where required by law.

Billing records

Retained for the duration of your account plus a reasonable period thereafter for record-keeping purposes.

7. Security Measures

We implement comprehensive, defense-in-depth security measures to protect your data:

Encryption

All passwords hashed with bcrypt. HTTPS enforced in production. TLS for email transport. Session cookies secured (Secure, HttpOnly, SameSite).

Multi-Factor Auth

TOTP authenticator app (Google Authenticator compatible) + SMS-based MFA. 10 single-use backup codes per user.

Access Control

Role-Based Access Control (RBAC) with 50+ granular permissions and 11 predefined roles. Subdomain-based tenant isolation.

Device Tracking

Session monitoring with device fingerprinting, geolocation tracking, security scoring, and new-device email alerts.

Rate Limiting

API rate limiting (100/min), login rate limiting (50/5 min), SMS send limits (60/min, 500/hr, 2000/day).

Threat Protection

CSRF protection, Content Security Policy, XSS prevention, bot detection, malicious payload scanning, IP blocking.

Additional Protections

Audit logging

All create, update, delete, login, and permission change operations are logged with user ID, IP address, and timestamp.

Security headers

X-Content-Type-Options, X-Frame-Options (DENY), X-XSS-Protection, HSTS (max-age=31536000), Referrer-Policy, Permissions-Policy.

Password policy

Minimum 12 characters, requiring uppercase, lowercase, digits, and special characters. Blocks 50+ common passwords and username-in-password patterns.

Concurrent session limits

3 sessions for regular users, 5 for administrators. Oldest session auto-terminated when exceeded.

8. Cookies & Tracking

ShepherdCloud uses only essential cookies required for the Service to function. We do not use third-party analytics, advertising trackers, or marketing cookies.

Session cookie

Maintains your authenticated session. Secure (HTTPS-only), HttpOnly (not accessible to JavaScript), SameSite=Lax. Expires after 7 days or on logout.

CSRF token

Protects against cross-site request forgery attacks. Per-session, auto-generated.

Remember Me

Optional persistent cookie that extends your login session. Only set when you explicitly check "Remember Me."

No tracking: We do not currently use third-party analytics or behavioral tracking services. We will update this Policy before introducing any such services. Your usage patterns within the app are not shared with any external analytics provider.

9. Your Rights

Under applicable data protection laws, you have the following rights:

Right to access

Request a copy of your personal data we hold.

Right to rectification

Correct inaccurate or incomplete data.

Right to erasure

Request deletion of your data ("right to be forgotten").

Right to restrict processing

Limit how we use your data.

Right to data portability

Export your data in a machine-readable format (Excel, CSV, or PDF via our Reports module).

Right to object

Object to processing based on legitimate interests.

Right to withdraw consent

Withdraw previously given consent at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by applicable data protection laws. In most cases, this is within 30 calendar days. For tenant-specific member data, please contact your church administrator (the data controller) directly.

10. Children's Privacy

ShepherdCloud is designed for use by church administrators and staff. While churches may record data about children (e.g., children's ministry members, Sunday school attendees), this data is entered and managed by the church — the data controller. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided us with personal data without parental consent, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:

Email notification

Sending an email to the address associated with your account.

In-app notice

Displaying a prominent notice within the Service upon login.

Updated date

Updating the "Last updated" date at the top of this page.

Your continued use of the Service after changes take effect constitutes your acceptance of the revised Policy.

12. Contact Us

If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a privacy concern:

Privacy Inquiries

[email protected]