Privacy Policy
Your privacy and the privacy of your congregation matter deeply to us.
Version 1.0.0 · Effective Date: April 9, 2026
1. Introduction
Pax App (“Company,” “we,” “us,” or “our”) operates Pax, a cloud-based church management platform. This Privacy Policy explains how we collect, use, protect, and handle information in connection with the Service. By using the Service, you agree to the practices described in this Policy.
This Policy applies to: (1) Organizations (churches and other entities that hold accounts); (2) Administrators and Staff who access the Service on behalf of an Organization; and (3) Congregation Members whose information is entered into the Service by an Organization.
2. Information We Collect
2.1 Account and Organizational Information
When an Organization creates an account, we collect information such as:
- Organization name, address, and contact information
- Administrator name, email address, and phone number
- Payment and billing information (processed securely through our third-party payment processor)
- Account login credentials
2.2 Congregation and Staff Data
Organizations may enter information about their staff and congregation members into the Service. This may include names, contact information, photos, and other profile details. This data belongs to the Organization. We process it only as a data processor on behalf of the Organization.
2.3 Usage and Technical Data
We automatically collect certain technical data when you use the Service, including IP address, browser type, device information, and usage logs. This data is used for security, troubleshooting, and service improvement.
3. How We Use Your Information
We use account and organizational data exclusively for regular business operations directly related to providing and maintaining the Service. These operations include, but are not limited to:
- Payment processing and billing
- Sending invoices, receipts, and account notifications
- Sending service-related emails and communications
- Maintaining and administering user accounts
- Providing customer support
- Conducting routine and unexpected maintenance activities
- Ensuring the security and integrity of the Service
- Complying with legal obligations
WE DO NOT USE ACCOUNT OR ORGANIZATIONAL DATA FOR MARKETING PURPOSES. WE DO NOT SELL, RENT, LEASE, OR TRADE CUSTOMER DATA OR CONGREGATION DATA TO ANY THIRD PARTY FOR ANY PURPOSE.
4. Data Access by Company Personnel
We take the privacy of your data seriously and have implemented internal controls to minimize exposure:
- Our personnel may access your account data when providing direct customer support at your request.
- Our personnel may access account data during routine or unexpected maintenance activities necessary to ensure Service stability and security.
- Access to Customer data is restricted to employees whose job responsibilities require such access.
- We maintain internal logging of data access by personnel for accountability purposes.
- We provide privacy training to all personnel with access to Customer data.
- We do not access, read, or use Customer data for any purpose beyond those described in this Policy.
5. Sensitive Information — Special Notice
5.1 No Confidential or Privileged Communications
The Service is not designed for and should not be used to store legally privileged communications, pastoral confessions, protected counseling records, or any information that carries religious, legal, or therapeutic confidentiality protections. THE COMPANY STRONGLY ADVISES ORGANIZATIONS NOT TO ENTER SUCH INFORMATION INTO THE SERVICE. What God has forgiven and forgotten, this database should as well.
5.2 Sensitive Personal Information
Customers are advised not to store highly sensitive personal data within the Service, including Social Security Numbers, government identification numbers, financial account details, full medical records, immigration-related information, or detailed criminal history. While we implement security measures described below, no system can be guaranteed completely secure, and liability for the unauthorized disclosure of such information is limited as stated in our Terms and Conditions.
6. Data Sharing With Third Parties
We do not sell or share Customer data with third parties for commercial purposes. We may share limited data only in the following circumstances:
- Service Providers: We engage trusted third-party vendors (such as payment processors, email delivery services, and cloud hosting providers) who process data solely on our behalf and under data processing agreements that prohibit them from using data for their own purposes.
- Legal Requirements: We may disclose data if required to do so by applicable law, court order, or governmental authority.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, Customer data may be transferred. We will notify affected Customers before data is transferred and becomes subject to a different privacy policy.
7. Data Security
We have implemented technical and organizational security measures to protect Customer data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using industry-standard TLS protocols
- Encryption of data at rest
- Access controls and role-based permissions
- Regular security reviews and vulnerability assessments
- Restricted internal data access with logging
HOWEVER, NO METHOD OF TRANSMISSION OVER THE INTERNET OR ELECTRONIC STORAGE IS 100% SECURE. WHILE WE STRIVE TO PROTECT YOUR DATA, WE CANNOT GUARANTEE ABSOLUTE SECURITY. PRIVATE OR SENSITIVE INFORMATION THAT SHOULD NOT BE DISCLOSED SHOULD NOT BE STORED IN THE SERVICE.
8. Data Retention
We retain Customer data for as long as an account remains active. Upon account termination, Customers may request an export of their data within thirty (30) days. After this period, we will delete Customer data from our systems in accordance with our data retention schedule, except where retention is required by applicable law.
9. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information directly from children under 13 without verifiable parental consent. Organizations that maintain data about minors are responsible for obtaining any necessary consents and for complying with applicable laws regarding minors' data.
10. Your Rights
Depending on your jurisdiction, you may have rights regarding your personal data, including the right to access, correct, or request deletion of data we hold about you. Organizations wishing to exercise these rights on behalf of their members should contact us using the information below.
11. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will notify account holders via email or through a notice within the Service at least fourteen (14) days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
12. Contact Us
For privacy-related questions or requests, please contact our Privacy Contact:
Pax App
privacy@paxapp.org
Terms · Privacy · Subscription Agreement · Acceptable Use · Data Processing