Privacy
Privacy Policy
Last reviewed 19 August 2026
This policy covers The Ecclesia Embassy website and mobile app, wherever they are hosted. It is written to be read, not to be survived — if anything here is unclear, ask us and we will fix the wording.
In short
The short version
The detail below matters, but this is the substance of it.
- We do not sell your personal information, and we never have.
- We do not share it with advertisers, data brokers or analytics networks.
- There are no advertising or tracking cookies on this site, and no third-party analytics script.
- We do not use your giving history to decide what you see, or make it visible to anyone outside the finance team.
- We do not record your screen. Session replay is deliberately switched off in our error reporting, because these screens show giving amounts and prayer requests.
The Ecclesia Embassy, at Km 6 Law School Road, New, Bwari 910103, Federal Capital Territory, Nigeria, is the data controller for the information described here — meaning we decide why it is collected and what happens to it. You can reach us at support@theecclesiaembassy.org.
What we collect
The information we hold, and why you gave it to us
Grouped by the part of the app that asks for it. Nothing here is gathered silently in the background — each category comes from something you filled in, or something the app needs to function.
Your account
Your email address, and either a password (stored only as a irreversible hash, never as text we can read) or the identifier your Google account returns if you sign in that way. We also record whether your email has been verified and, if sign-in attempts fail repeatedly, a temporary lock.
Your profile
Whatever you choose to fill in: first and last name, phone number, date of birth, address, city, state, country, occupation, marital status, a photo, and the ministry areas you are involved in. Only your name is required; the rest of the form works perfectly well left blank.
Giving
The amount, currency, category and a payment reference for each gift, plus a receipt. If you give without an account we keep the name and email you supply so the receipt can reach you. Card and bank details never reach our servers — they are entered on Paystack's or PayPal's own pages.
Prayer requests and testimonies
The request or testimony itself, with your name, email and phone number. Each prayer request is private unless you mark it as public; private requests are seen only by the pastoral team who respond to them.
First contact forms
If you plan a visit, register as a first timer or record a decision, we keep the name, email, phone number and how you heard about us, so someone can follow up.
Community activity
Posts, comments, likes, direct messages, and which hubs, squads and groups you belong to. Direct messages are stored so they can be delivered; treat them as private between you and the recipient rather than as encrypted end to end.
Learning and engagement
Course enrolments, modules completed, exam submissions, event and class registrations, sermon feedback, watch streaks and badges earned.
On the mobile app
A push notification token identifying your device, and the platform it runs on, so reminders can reach you. That is the whole of it — the app has no access to your camera, photo library, contacts, calendar or location, and asks for none of them.
Your profile photo
If you add one, it is uploaded from the website and stored with your profile. Only you and the church team can change it. It is optional, and an account without one works exactly the same.
Technical records
Server logs carrying a correlation id for each request, and automated error reports when something breaks. Error reports are stripped of passwords, tokens, cookies, email addresses, phone numbers and query strings before they leave our servers — an account id is kept so a fault can be traced back to a session.
How it is used
What we do with it
Our lawful bases are performing the service you asked for, our legitimate interest in running a church and keeping it secure, and your consent where we ask for it.
- Running the things you asked for: your account, your giving receipts, your registrations and the services you signed up to.
- Pastoral follow-up — responding to a prayer request, welcoming a first-time visitor, or contacting you about a hub or class you joined.
- Sending service reminders and notifications you have turned on, and the transactional email that account security depends on: verification and password reset.
- Keeping the platform safe and working: rate limiting, locking an account after repeated failed sign-ins, and diagnosing errors.
- Understanding attendance and participation in aggregate, to plan services and programmes. This uses counts and totals, not profiles of individuals.
Who else sees it
The companies that process data for us
We use other services to do things we cannot do ourselves. Each one receives only what it needs for its job, and none of them may use it for their own purposes.
Paystack and PayPal
Take payments. They receive your card or bank details directly and give us back only a reference, an amount and a status.
Resend
Delivers transactional email — verification, password reset, receipts and reminders. It handles the address the message is sent to.
Expo, with Apple and Google
Deliver push notifications to your device using the token described above.
Provides Sign in with Google, if you choose it. Google confirms your identity to us; we do not receive your Google password.
Sentry
Receives automated error reports, scrubbed as described above. Our project is hosted in Sentry's European region.
Railway, Render, Vercel and our database host
Run the servers, the website and the database itself. They hold data on our behalf and act on our instructions.
YouTube and Spotify
Serve embedded sermon players. They set their own cookies once you press play, under their own privacy policies rather than ours.
Some of these operate outside Nigeria, so your information may be processed abroad. We only use providers that commit to protecting it to a comparable standard. We will also disclose information where the law requires it, or to protect someone from harm.
Keeping and removing
How long we keep it
We keep personal information for as long as your account is open and you are in touch with the church.
Close your account and we erase the personal data attached to it. Two things survive that, and it is fairer to say so plainly than to bury it. Records of giving are kept for seven years, because financial and tax law requires it — they are retained as accounting records, not as a profile of you. And anything you posted publicly, such as a testimony you chose to publish, stays up unless you ask us to take it down, since removing it would tear a hole in a conversation other people took part in.
Error reports are deleted after 90 days. Server logs are kept for 30 days. Prayer requests are retained while they are being prayed for and reviewed periodically afterwards.
Your rights
What you can ask us to do
Under the Nigeria Data Protection Act 2023, and under the UK and EU GDPR if you are covered by them. We answer within 30 days and do not charge for it.
See what we hold
Ask for a copy of the personal information attached to your account, and we will send it to the verified email on the account.
Correct it
Most of it you can edit yourself from your profile. Anything you cannot reach, we will correct on request.
Delete it
Ask us to close your account and erase the personal data attached to it. There is a dedicated page explaining exactly what this removes and what has to be kept.
Withdraw consent
Turn off notifications in the app, unsubscribe from a mailing, or ask us to stop contacting you, without losing access to your account.
Object or restrict
Ask us to stop a particular use of your information while a question about it is being resolved.
Complain
If we have not put something right, you can raise it with the Nigeria Data Protection Commission, or with your local supervisory authority if you are in the UK or EU.
Security, children and changes
Three last things
Security. Passwords are hashed rather than stored. Sessions use a cookie that JavaScript cannot read. Traffic is encrypted in transit, access to the admin area is restricted by role, and sensitive values are stripped from logs and error reports. No system is perfect, and we would rather tell you about a breach than manage the news of one — if one affects you, we will say so.
Children. Accounts are intended for people aged 16 and over. Younger children take part in our ministries through a parent or guardian, and we collect their information from that adult rather than from the child. If you believe a child has created an account, tell us and we will remove it.
Changes. When we change something material here we update the review date above, and for a significant change we will tell account holders directly rather than relying on you to notice.
Questions about your data
Ask us anything about this policy, or make any of the requests above.

