Privacy Policy
Last updated: August 4, 2026
Threefold Technology, LLC (“ChurchKit,” “we,” “us”) builds tools that connect a church’s Planning Center account to its website, screens, and congregation. This policy explains what we collect, why, and what control you have over it.
1. Who this policy covers
This policy applies to two groups of people, and the difference matters:
- Church administrators — staff or volunteers who create a ChurchKit account, connect Planning Center, and configure embeds, displays, assessments, or syncs.
- Congregants and visitors — people who interact with something a church published using ChurchKit, such as an embedded calendar, a lobby display, a form, or a spiritual gifts assessment. If you are in this group, the church is the party that decides what to collect and why; we process that information on their behalf.
2. Information we collect
Account information. When you create an account we collect your name, email address, and profile image through our authentication provider. We do not store your password — authentication is handled by Clerk.
Planning Center data we read. When you connect Planning Center, you authorize ChurchKit to access data through Planning Center’s official API. Depending on which modules you enable, what we read can include people records, groups, calendar events and rooms, registrations, forms, and publishing content.
Planning Center data we write. Some features write back to your Planning Center account. They are off unless your church turns them on, and ChurchKit only ever writes on your instruction — never on its own initiative, and never to another church’s account. Specifically, when the relevant feature is enabled we may:
- create a person record, when someone submits a form or assessment and no matching person already exists;
- create a ChurchKit tab and its custom field definitions on your account, so results have somewhere to live;
- write assessment results into those custom fields on a person’s profile;
- add a person to a workflow you have selected;
- add a note to a person’s profile.
We do not delete anything in your Planning Center account. Because Planning Center’s permissions are granted per product rather than separately for reading and writing, the access you approve at connection time is broader than the operations listed above — those are the only ones ChurchKit performs. Disconnecting Planning Center stops all of it; data already written stays in your account, where you control it.
Assessment responses. If your church publishes a Spiritual Gifts Assessment, we store each respondent’s answers and computed results so the church can view, export, and act on them. Because these responses can reveal information about a person’s religious beliefs, we treat them as sensitive and restrict access to the church that published the assessment.
Form and embed activity. Embeds record aggregate views and clicks so churches can see what their congregation engages with. Where an embed or form accepts a submission — such as joining a group — we store what the person submitted and pass it to the church.
Billing information. Payments are processed by Stripe. We receive subscription status, plan, and usage counts. We never receive or store full card numbers.
Technical and usage data. Standard server logs (IP address, browser type, pages requested) and product analytics about how the application is used, associated with your account while you are signed in.
3. How we use information
- To operate the modules you turn on — rendering embeds, driving displays, scoring assessments, and running syncs.
- To authenticate you and keep your account secure.
- To bill you accurately, including metering synced items against your included allowance.
- To provide support when you ask for it.
- To diagnose errors, monitor reliability, and improve the product.
- To send service messages about your account, billing, or material changes to the product.
We do not sell personal information. We do not use your Planning Center data, your congregation’s information, or assessment responses to train machine learning models, and we do not share them with advertisers.
4. How we share information
We share information only with service providers that help us run ChurchKit, and only to the extent needed to do their job:
- ClerkAccount creation, authentication, and session management
- ConvexApplication database and file storage
- VercelWebsite and application hosting, plus aggregate traffic analytics
- PostHogProduct analytics and browser error tracking
- StripeSubscription billing and payment processing
- Planning CenterThe source system you connect; we read the data you authorize us to read
- WebflowDestination for Actions syncs, when you connect a Webflow site
- ResendDelivery of transactional email, including form confirmations and notifications, assessment results, billing notices, and replies to contact-form inquiries
- Cloudflare R2 / Amazon S3Storage and delivery of images you upload
We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights and safety of our users. If ChurchKit is acquired, information may transfer as part of that transaction; we will give notice before your information becomes subject to a different policy.
5. Data about minors
Church data frequently includes information about children. ChurchKit is not directed to children, and we do not knowingly let children create accounts. Where a church connects Planning Center data that includes minors, the church is responsible for having appropriate consent, and for deciding what is displayed publicly through embeds and displays. We recommend churches avoid publishing information about minors through public embeds or unauthenticated screens.
6. Retention and deletion
We keep account information for as long as your account is active. Planning Center data is cached only as long as needed to render what you have configured, and is refreshed from Planning Center rather than maintained as a permanent copy.
Disconnecting Planning Center revokes our access immediately and stops further reads. When you close your account, we delete or anonymize your account data and your church’s stored content within 30 days, except where we must retain records for legal, tax, or accounting purposes. Deleting your ChurchKit account never deletes anything from Planning Center.
Churches can delete individual form responses and uploaded images at any time from their dashboard. Assessment responses are deleted with the assessment they belong to, and we will delete individual responses on request.
7. Security
Data is encrypted in transit and at rest by our infrastructure providers. Access to production systems is limited to people who need it. OAuth tokens for Planning Center and Webflow are stored encrypted and are scoped to the permissions you granted.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you promptly and as required by applicable law.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA and UK have these rights under the GDPR; California residents have comparable rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
To exercise any of these, write to privacy@churchkit.io. If your request concerns data a church collected about you — an assessment response, for example — we will refer you to that church, which controls the information, and support them in responding.
9. International transfers
ChurchKit is operated from the United States, and our service providers process data there. If you access ChurchKit from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection law may differ from your own.
10. Cookies
We use cookies that are necessary to keep you signed in and to remember preferences such as your light or dark theme. We use first-party analytics cookies to understand traffic, diagnose errors, and improve the product. For signed-in users, this analytics data is associated with their account. We do not use advertising or cross-site tracking cookies.
11. Changes to this policy
We may update this policy as the product changes. When we make material changes, we will update the date at the top of this page and notify account holders by email or in the application before the change takes effect.
12. Contact us
Questions about this policy or how we handle information: privacy@churchkit.io.
Threefold Technology, LLC
2733 Chickering Rd., Pensacola, FL 32514