Back to Home

Privacy Policy

Effective September 16, 2026

1. Introduction

Jethro Software, LLC, doing business as Ministry Planner, provides a cloud-based church management platform at ministryplanner.church. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our services. It applies to our website, dashboard, mobile apps, church website builder, and any related tools or integrations (collectively, the “Services”).

By using the Services, you agree to the practices described in this policy. This policy should be read alongside our Terms of Service, Cookie Policy, and Acceptable Use Policy.

2. Our Role: Platform vs. Church

This is an important distinction, so we want to be clear about it:

  • For staff accounts (the people who sign up, log in, and use the dashboard): Ministry Planner is the data controller. We decide what data we collect from you and how we use it.
  • For congregation data (people directory records, children’s check-in information, donor records, etc.): your church is the data controller, and Ministry Planner is the data processor. We process this data only on the church’s instructions and as described in this policy. We do not use congregation data for our own purposes.

Churches are responsible for their own compliance with applicable privacy laws regarding their congregation members’ information. If you are a congregation member and have questions about how your church handles your data, please contact your church directly.

3. Information We Collect

Account Information

When you sign up or are invited to the platform, we collect your name, email address, role, and organization affiliation.

Church Data

This includes service plans, teaching calendars, documents, team rosters, and volunteer information (name, email, phone, title, tags, and photo).

People & Directory Data

Names, contact information, tags, and campus assignment. Some people records include an is_public flag that allows the church to display selected profiles on their church website.

Children’s Information

For check-in and event registration features, churches may store children’s names, birthdates, grade, gender, allergies, medications, medical notes, authorized pickup contacts, guardian/emergency contacts, and photo release consent. This is the most sensitive data in our system and is treated accordingly (see Section 10).

Giving & Donor Data

Donor names, email addresses, mailing addresses, gift amounts, fund designations, and giving history. For saved payment methods, we store only the card brand, last four digits, and expiration date — Stripe holds the actual payment credentials. We never store full card numbers, CVVs, or bank account numbers.

Chat Messages

Messages sent through our built-in chat are encrypted end-to-end using XSalsa20-Poly1305 before being stored. We cannot read message contents.

Church Website Data

If a church uses our website builder, public-facing content (service times, location, staff bios) is published by the church. Contact form submissions (name, email, message) from site visitors are stored so the church can follow up.

Sermon Notes

Congregation members may fill in sermon notes on a church’s public site. These may be linked to a logged-in user or stored with an anonymous identifier.

Device & Technical Data

For push notifications, we store your device platform (iOS, Android, or web), FCM token, app version, and subscribed notification topics. We do not collect device hardware IDs, location data, or contacts.

Usage Data (Platform Pages Only)

On Ministry Planner’s own marketing and app pages, we use PostHog for product analytics and optional session replay. All form inputs are masked in recordings. PostHog is completely disabled for visitors from EU, UK, EEA, and Switzerland (detected via the mp_region cookie). PostHog is never loaded on church website pages — we do not track your congregation’s visitors.

4. How We Use Your Information

  • Provide, maintain, and improve the Services
  • Process subscription billing through Stripe
  • Send transactional emails — receipts, invitations, and notifications, delivered via Resend
  • Deliver push notifications you have opted into
  • Power the AI assistant (“Ask Jethro”) — when you use this feature, your prompt and relevant context are sent to Anthropic’s Claude API. Anthropic does not use this data to train models. The AI assistant is opt-in and only activated when you choose to use it.
  • Sync data with third-party integrations you connect (Planning Center, Google Workspace)
  • Prevent fraud and abuse

We do NOT sell your data. We do NOT use congregation data for advertising. We do NOT serve ads.

5. Giving & Payments (Stripe Connect)

When a church enables online giving, donations are processed through Stripe Connect using a direct charge model. Funds go directly to the church’s own Stripe account. Ministry Planner never holds, pools, or has access to donated funds.

  • Ministry Planner collects a small platform fee (a percentage of each transaction) at the time of charge, as disclosed to the church during onboarding.
  • Stripe handles all PCI compliance, fraud detection, and KYC/KYB verification for the church.
  • Donation receipts are issued in the church’s name, not Ministry Planner’s.
  • We store only the minimum payment method identifiers needed to display saved cards and accounts to donors (brand, last four digits, type). Full payment credentials are held exclusively by Stripe.

6. Third-Party Services

We use the following third-party services to operate the platform. Each receives only the data necessary for its purpose:

  • Supabase — Database hosting, authentication, and file storage (US-hosted)
  • Stripe — Subscription billing for Ministry Planner accounts
  • Stripe Connect — Donation payment processing for churches
  • Resend — Transactional and campaign email delivery
  • Anthropic (Claude) — AI assistant and document import features
  • Firebase / FCM — Mobile push notifications
  • PostHog — Product analytics on Ministry Planner platform pages only (disabled for EU/UK visitors, never loaded on church sites)
  • Vercel — Application hosting and deployment
  • Upstash Redis — Rate limiting to prevent abuse
  • Google APIs — OAuth integration for Google Drive and Workspace sync (only when connected by user)
  • Planning Center — Data sync integration (only when connected by church)
  • MojoTxt — SMS messaging (optional, uses the church’s own credentials)
  • Web Push (VAPID) — Browser push notifications for staff

7. Data Security

We take the security of your data seriously:

  • All data in transit is encrypted via TLS/HTTPS.
  • Our database is hosted on Supabase with encryption at rest.
  • Chat messages are encrypted end-to-end (XSalsa20-Poly1305) before storage.
  • Multi-factor authentication (TOTP) is available for all accounts.
  • Row-Level Security (RLS) is enforced at the database level — each church’s data is isolated, and cross-organization access is cryptographically impossible through the API.
  • Sensitive tables (payment methods, donor retention archive, app installations) are restricted to service-role access only and are not accessible through the client API.
  • Children’s data fields (allergies, medications, medical notes) are marked private and accessible only to authorized staff.

8. Data Retention

  • We retain your data for as long as your account is active or as needed to provide the Services.
  • When a church cancels its subscription, we retain data for 90 days to allow reactivation, then schedule it for deletion.
  • Giving records may be retained longer as required by IRS regulations for tax-deductible contributions.
  • Donor retention archives are sealed and accessible only under a formal break-glass procedure.
  • You may request deletion of your data at any time by contacting us at hello@ministryplanner.church.

9. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data
  • Object to processing

For congregation members: because your church is the data controller for your information (see Section 2), please contact your church directly for data requests. Your church can then work with us if needed.

To exercise any of these rights, email us at hello@ministryplanner.church.

10. Children’s Privacy

Ministry Planner is not directed at children under 18. Only adults (church staff and administrators) create accounts and use the platform.

However, churches may use our check-in and event registration features to manage information about children in their programs. This data is entered and managed by authorized church staff or guardians, not by children themselves.

We treat children’s data with the highest level of care:

  • It is stored in restricted-access fields visible only to authorized staff.
  • It is never used for marketing.
  • It is never shared with third parties beyond what is strictly necessary to provide the service.

Churches using these features are responsible for obtaining appropriate parental consent in accordance with applicable laws (including COPPA where relevant).

11. International Users

The Services are hosted in the United States. By using the Services, you consent to the transfer of your data to the US.

For visitors from the EU, UK, EEA, and Switzerland: we disable persistent analytics tracking (PostHog) based on geographic detection. We do not currently serve churches outside the United States, but if you access the platform from abroad, US data protection laws apply.

12. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you via email or a notice within the platform. Your continued use of the Services after changes are posted constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, we would love to hear from you:

Jethro Software, LLC (DBA Ministry Planner)

5504 Tittlebaugh Rd, Marion, OH 43302

hello@ministryplanner.church

(+1) 419-515-8289