Privacy Policy
HomeField Directory is a private member directory for churches. This policy explains what information the service holds, who can see it, what we do and do not do with it, and how it is deleted. We have tried to write it so that a church admin or a member can read it in one sitting.
- Who we are
- The church is the controller
- What we hold
- How it is used
- What we never do
- Who can see directory data
- Children
- Where data lives
- Service providers
- Security
- Retention and deletion
- Export and portability
- Your choices and rights
- Cookies
- If something goes wrong
- If HomeField closes
- Changes to this policy
- Contact
1. Who we are
HomeField Directory is operated by Whitened Fields Ministries, a sole proprietorship in North Carolina, United States ("we", "us", "HomeField"). You can reach us at support@homefielddirectory.com or by post at Whitened Fields Ministries, [Mailing address to be added].
2. The church is the controller
Each church that uses HomeField decides what goes into its directory, who is added to it, and how long it is kept. In privacy terms, the church is the controller of its members' information and HomeField is the processor. We store and display the data on the church's instructions, and we act on the church's behalf.
If you are a member with a question about why you are in a directory or what is recorded about you, your church admin is the right first contact. They can see and change everything about your record. We will help if your church cannot.
3. What we hold
Directory information, entered by churches and members
- People: names (first, last, middle, preferred), role (adult or child), birthday, mobile phone, email address, allergies, photo, and any custom fields or tags the church has defined.
- Families: family name, address, home phone, anniversary, family photo and family custom fields.
- Admin notes: free-text notes that only the church's admins can see.
- Privacy settings: which fields each member has chosen to hide from other members.
Account information
- Email address, a hashed password (we never store the password itself), whether a Google account is linked, and the times of recent sign-ins.
- Sign-in attempts, including the originating IP address, kept briefly for rate limiting and lockout.
Church information
- Church name, logo, accent colour, timezone, contact email, settings, and billing status.
- Billing is handled by Stripe. We keep a reference to the Stripe customer and subscription and the status of invoices. We never see or store card numbers.
Records of activity
- An audit log of changes made in a church's directory: who changed what, when, and from which IP address. Church admins can read their own church's log.
- Standard server logs, retained for a short period for troubleshooting and security.
Messages you send us
- If you use the contact form or email support, we keep the message and your reply address so we can answer.
4. How it is used
We use directory and account information only to run the service: to show the directory to the right people, to send the emails the service needs (invitations, verification, password resets, approval notices, trial and billing reminders), to keep accounts secure, to support churches, and to bill them.
Aggregate, non-identifying counts (for example, how many churches are on a trial) are used to run the business. They contain no names or directory contents.
5. What we never do
- We never sell directory or account information to anyone.
- We never use it for advertising, ours or anyone else's.
- We never use it to train AI or machine-learning models, and we do not permit our service providers to.
- We never share it with other churches. Each church's data is visible only to that church's members and admins.
- We never send marketing email to members. Members receive only the emails the directory needs to function.
6. Who can see directory data
- Members of the same church can see the directory, minus any fields a member has chosen to hide. Names are always visible.
- Church admins can see every field for every person in their church, including hidden fields and admin notes.
- HomeField staff can access a church's data only to provide support, investigate abuse, or maintain the service. Such access is logged. Staff never browse directory contents for any other purpose.
- Nobody else. Directory pages and photos require a signed-in member of that church. A church's logo is the only public asset.
7. Children
Children appear in a directory as part of a family. Their information is entered by parents or by church admins, never by the child. Children do not have accounts, cannot sign in, and are not sent email. A child's birthday is hidden from other members unless the church has chosen to show it. Admins always see it, because they need it to know when a child reaches adulthood.
When a child turns 18, nothing changes automatically. A church admin is asked to review the record and decide whether to convert it to an adult member, at which point an invitation may be sent if an email address has been added.
Because children's information is collected from parents and churches rather than from children directly, HomeField does not knowingly collect personal information online from anyone under 13.
8. Where data lives
The service is hosted in the United States on DigitalOcean. Database disks and object storage (photos, logos, backups) are encrypted at rest. Backups are taken daily and kept in the same region.
9. Service providers
We use a small number of providers to run the service, each of which processes only what it needs:
| Provider | What it does | What it sees |
|---|---|---|
| DigitalOcean | Hosting, storage, backups | Everything, encrypted at rest |
| Stripe | Payments | Church name, admin email, card details (which we never see) |
| Email delivery provider | Sends the emails the service needs | Recipient address and the message |
| Optional "Sign in with Google" | Only that a sign-in was attempted; Google tells us the verified email address |
We do not use analytics or advertising trackers on the directory or on this website.
10. Security
All traffic uses TLS. Passwords are hashed with bcrypt. Sessions are httpOnly cookies with CSRF protection. Sign-in is rate limited and locked after repeated failures. Cross-church isolation is tested automatically on every code change. Church admins can review an audit log of changes. More detail is in our security overview.
No system is perfectly secure. If you believe you have found a vulnerability, please write to us before publishing it.
11. Retention and deletion
- While a church is active, its data is kept for as long as the church keeps it. Admins can delete people and families at any time.
- When a church cancels or its trial ends without a subscription, the directory is paused. The data is kept for 90 days so the church can export it or come back. After 90 days it is permanently deleted, including photos.
- Backups roll off within a further 30 days of that deletion.
- Audit logs and server logs are kept for a limited period and then removed.
- Support messages are kept as long as needed to resolve them and for our records.
A church can ask us to delete its data sooner than 90 days by writing to support from an admin address.
12. Export and portability
Church admins can export the full directory as CSV at any time from the admin app, and can download birthday and anniversary lists as CSV or PDF. A complete backup, including photos, is available on request. Members can export the version of the directory they are allowed to see.
13. Your choices and rights
Members can see and edit their own record, hide individual fields from other members, upload or remove their photo, change their email address, and ask their church admin to correct or delete anything else. A member who wants to leave a directory entirely should ask their church admin, who can remove the record.
Churches control their own data and can export or delete it as described above.
Depending on where you live, you may have legal rights to access, correct, delete, restrict or port your personal information, or to object to certain processing. Because the church is the controller, we will generally route such requests to your church admin, and we will assist the church in meeting them. If you believe your church has not responded appropriately, contact us.
We do not discriminate against anyone for exercising a privacy right.
14. Cookies
We use only the cookies the service needs to work: a session cookie that keeps you signed in, and a CSRF token that protects forms. Choosing "Stay signed in" extends the session cookie to 30 days. We do not use tracking or advertising cookies.
15. If something goes wrong
If we become aware of a security breach that affects a church's data, we will notify that church's admins by email within 72 hours of confirming it, tell them what we know, and keep them updated. We will also notify authorities where the law requires it.
16. If HomeField closes
If we ever decide to shut the service down, every church will receive at least 90 days notice, a full export of its data, and a prorated refund of any prepaid period. We will not sell or transfer directory data to a third party as part of closing down.
17. Changes to this policy
If we change this policy in a way that matters, we will email church admins before the change takes effect and note the date at the top of this page. Continuing to use the service after that date means the new policy applies.
18. Contact
Whitened Fields Ministries
[Mailing address to be added]
North Carolina, United States
support@homefielddirectory.com