This Privacy Policy explains how Tech Oasis Systems (Pty) Ltd (“Tech Oasis”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information when you visit our website, contact us, or use Churches Software (the “Service”).
We are committed to protecting personal information in line with the Protection of Personal Information Act, 2013 (POPIA) in South Africa and, where applicable, the EU General Data Protection Regulation (GDPR) and other relevant laws.
Please read this policy together with our Terms of Service.
1. Who we are
Responsible party / data controller (for our own business data):
Tech Oasis Systems (Pty) Ltd
Building 6, Manhattan Office Park, South Africa
For general privacy enquiries, use our secure contact form. We do not publish direct email addresses on this website to reduce spam.
2. Scope of this policy
This policy applies to:
- visitors to https://www.thechurches.software;
- users of https://app.thechurches.software;
- church administrators and staff with Accounts; and
- prospective customers who contact us through our forms.
This policy does not replace the privacy notices of individual churches. Each church using the Service is responsible for telling its members how their Congregation Data is handled.
3. Definitions
- Personal Information / Personal Data — information relating to an identifiable person.
- Congregation Data — member, donor, volunteer, staff, and household information that a church uploads or manages in the Service.
- Church Customer — a church or organisation that uses the Service.
- Processing — any operation performed on personal information, including collection, storage, use, disclosure, or deletion.
- Service — Churches Software website, application, and related support services.
4. Information we collect
4.1 Information you provide directly
Depending on how you interact with us, we may collect:
- name and contact details (email, phone);
- church name, country, and congregation size;
- account login details and role information;
- messages sent through our contact form;
- billing and subscription information; and
- support requests and correspondence.
4.2 Congregation Data processed on behalf of churches
When a Church Customer uses the Service, we process Congregation Data that may include:
- names, contact details, addresses, and household relationships;
- membership, attendance, and life-event records;
- pastoral care notes and ministry involvement;
- donation, tithe, pledge, and financial transaction records;
- event registrations and communications preferences; and
- photos or documents uploaded by authorised church users.
The church decides what data to collect and is responsible for having a lawful basis to do so.
4.3 Information collected automatically
We may automatically collect:
- IP address, browser type, device information, and operating system;
- pages viewed, dates/times of access, and referral URLs;
- log files, diagnostic data, and security events; and
- usage analytics to improve performance and reliability.
4.4 Cookies and similar technologies
We use cookies and similar technologies to operate the website, remember preferences, measure traffic, and protect against abuse. You can control cookies through your browser settings. Some features may not work correctly if cookies are disabled.
We may use services such as Google Analytics / Google Tag Manager and Google reCAPTCHA on our website and forms for analytics and spam prevention.
5. How we use information
We use personal information to:
- provide, operate, and maintain the Service;
- create and manage Accounts;
- process subscriptions, trials, and payments;
- respond to enquiries and support requests;
- send service-related notices and security alerts;
- improve features, performance, and user experience;
- detect, prevent, and address fraud, abuse, or security incidents; and
- comply with legal obligations.
We do not sell personal information.
6. Lawful basis for processing
6.1 Under POPIA (South Africa)
We process personal information where permitted under POPIA, including where processing is necessary to:
- perform a contract with you or take steps at your request before entering a contract;
- comply with a legal obligation;
- protect a legitimate interest of ours or a third party (balanced against your rights); or
- based on your consent, where required.
6.2 Under GDPR (where applicable)
Where GDPR applies, we rely on lawful bases such as contract, legitimate interests, legal obligation, and consent where appropriate.
7. Church Customers and Congregation Data
For Congregation Data entered into the Service by a Church Customer, we generally act as an operator / processor processing data on the church’s instructions to deliver church management functionality.
Church Customers are responsible for:
- providing privacy notices to their members and staff;
- ensuring a lawful basis for processing Congregation Data;
- responding to data subject requests from their congregants, where they are the responsible party; and
- managing user access and permissions within their organisation.
We assist Church Customers with appropriate technical and organisational measures and will reasonably cooperate with lawful requests related to data protection, subject to our legal obligations.
8. How we share information
We may share personal information with:
- Service providers — hosting, infrastructure, email/SMS delivery, payment processing, analytics, security, and support tools, bound by confidentiality and data protection obligations;
- Professional advisers — lawyers, auditors, or insurers where necessary;
- Authorities — where required by law, court order, or to protect rights and safety; and
- Business transfers — in connection with a merger, acquisition, or sale of assets, with appropriate safeguards.
We require processors to handle personal information securely and only for authorised purposes.
9. International transfers
Your information may be processed in South Africa and other countries where we or our service providers operate. Where personal information is transferred across borders, we take steps designed to ensure appropriate safeguards consistent with POPIA, GDPR (where applicable), and contractual protections.
10. Retention
We retain personal information only for as long as necessary for the purposes described in this policy, including to:
- provide the Service;
- meet legal, tax, and accounting obligations;
- resolve disputes and enforce agreements; and
- maintain security and backup integrity.
Congregation Data is retained according to the Church Customer’s use of the Service and our retention practices described in our Terms. Inactive accounts without an active licence may be deleted within 30 days after closure or expiry, unless longer retention is required by law.
Usage logs and analytics data are generally retained for shorter periods unless needed for security investigations.
11. Security
We implement administrative, technical, and organisational safeguards, including:
- encryption in transit (SSL/TLS);
- access controls and role-based permissions;
- regular backups;
- monitoring for abuse and unauthorised access; and
- PCI-compliant payment processing through third-party providers for card transactions.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
12. Your rights
Depending on your location and role, you may have rights to:
- access personal information we hold about you;
- request correction of inaccurate information;
- request deletion, subject to legal exceptions;
- object to or restrict certain processing;
- withdraw consent where processing is consent-based; and
- lodge a complaint with a supervisory authority.
POPIA (South Africa): you may request access to or correction of your personal information and complain to the Information Regulator.
GDPR (where applicable): you may have additional rights including data portability.
If you are a church member seeking access to Congregation Data held by your church, please contact your church first. We will support the Church Customer in responding where appropriate.
To exercise rights relating to information we control directly, use our secure contact form.
13. Marketing communications
We may send product updates, service notices, and information about Churches Software. You can opt out of non-essential marketing communications at any time by following unsubscribe instructions or contacting us through the contact form.
Churches are separately responsible for obtaining proper consent before sending SMS or email communications to their members through the Service.
14. Children’s information
Our marketing website and account registration are not directed at children under 13. We do not knowingly collect personal information from children under 13 through our contact forms or account sign-up without appropriate authority.
Churches may lawfully record information about minors (for example baptism, confirmation, or youth ministry) as part of Congregation Data. In those cases, the church is responsible for compliance with child protection and privacy laws and for obtaining parental or guardian consent where required.
15. Third-party links and services
Our Service may contain links to third-party websites or integrate with external services (for example payment gateways). We are not responsible for the privacy practices of third parties. We encourage you to review their policies.
16. Automated decision-making
We do not use personal information for automated decision-making that produces legal or similarly significant effects without human involvement.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may also be communicated through the Service or by email where appropriate.
18. Contact us
Questions about this Privacy Policy or how we handle personal information? Please use our secure contact form.
© 2022–2026 Churches Software · Tech Oasis Systems. All rights reserved.