Privacy Policy
Effective and last updated: September 6, 2026
1. About this policy
ChurchBeacon is operated by Ronald Kaylor doing business as Church Beacon App, 8852 Daly Rd, Cincinnati, Ohio 45231. ChurchBeacon helps participating churches communicate with and serve their members, administrators, pastors, and visitors. This Privacy Policy explains how ChurchBeacon handles information through ChurchBeaconApp.com, church onboarding, and the ChurchBeacon mobile applications for Android and Apple devices (collectively, the “Services”). The initial release is offered in the United States.
A participating church controls the church content and member information entered into its church environment, determines which ChurchBeacon features it enables, and manages access for its congregation. ChurchBeacon operates the platform, central account and licensing services, and supporting infrastructure. If a question concerns information submitted to a particular church, that church may also need to respond.
2. Information we collect
Account and authentication information
We collect information used to create, secure, and administer an account, such as name, email address, authentication provider, user identifier, email-verification status, church memberships, membership status, and church role. Passwords and third-party sign-in credentials are processed by Firebase Authentication, Google, or Apple as applicable; ChurchBeacon does not receive a readable copy of a Google or Apple password.
Profile, directory, and family information
You or your church may provide a display name, phone number, mailing address, city, state, postal code, profile photo, directory-sharing choices, birthday, anniversary, and optional names and birthdays of children. Directory contact information and annual milestones are shown to other approved church members only when the relevant sharing option is enabled. Authorized church administrators can access membership information needed to administer their church.
Church and onboarding information
Church onboarding may collect the church’s name, legal name, pastor and administrator contacts, address, service schedule, website, logo, feature selections, launch date, prayer categories, giving funds, pricing choice, Firebase project information, Stripe setup choice, and related confirmations. We also collect waitlist and support information that you submit, such as your name, church, email address, church size, message, and correspondence with us.
Church content and communications
Depending on the features a church enables, the Services process events and assignments, announcements, notification content, sermons and links, prayer requests and responses, visitor forms, directory contacts, service information, and administrative notes or audit information. A prayer marked anonymous is displayed without the requester’s name to ordinary members, but it may remain linked internally to an account for administration, safety, and account-deletion processing.
Photos, camera, QR codes, and device location
With permission, the app may use the camera to scan a church QR code or take a contact photo, and may access a photo you select. A selected contact photo is cropped, reduced in size, and re-encoded to remove source metadata before upload. ChurchBeacon does not retain camera imagery used only to scan a join code.
When you choose “Use location,” the app requests your current location to compare it with participating churches and identify a nearby church. This is an optional foreground action; you can enter or scan a church code instead. ChurchBeacon does not use device location for advertising or background tracking, and the current app does not store the location used for this comparison.
Notifications and technical information
If notifications are enabled, we process a device registration token, account and church routing identifiers, notification preferences, delivery results, and notification-read state. Our infrastructure and service providers may also automatically process IP address, device or browser type, app instance identifiers, request timestamps, security events, and diagnostic or server-log information needed to authenticate users, deliver the Services, prevent abuse, and troubleshoot failures.
Payments, subscriptions, and giving
Stripe processes payment methods, card or bank details, identity verification, and connected-account information on Stripe-hosted pages. ChurchBeacon does not store full payment-card or bank-account credentials. We receive and retain information needed to administer church subscriptions and giving, such as customer and transaction identifiers, donor account and email where applicable, church and fund, intended donation amount, processing-cost coverage choice, gross amount, frequency, status, application fee, refunds, disputes, and timestamps. Choosing anonymous giving is intended to prevent member-facing recognition of the donor; it does not conceal the transaction from Stripe or restricted backend records needed to process and document it.
3. Google services and Google Calendar
Google Sign-In provides ChurchBeacon with the identity information needed to authenticate the user, such as the Google account identifier, name, and email address made available through the approved sign-in scope.
If an authorized church administrator voluntarily connects Google Calendar, ChurchBeacon receives an authorization token and permission to create, update, and delete ChurchBeacon-originated events on the connected church account’s primary calendar. ChurchBeacon stores the refresh token and mappings between ChurchBeacon events and the Google events it creates in that church’s protected environment. The current integration does not import or display the account’s existing Google Calendar events. Disconnecting revokes the token and removes ChurchBeacon’s stored connection and mappings; events already sent to Google Calendar remain in that Google account unless the account owner deletes them there.
ChurchBeacon’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing sign-in and calendar features the user or church administrator chooses. It is not used for advertising, sold, or used to build advertising profiles.
4. How we use information
We use information to:
- Create and authenticate accounts and maintain secure sessions.
- Verify church membership, roles, licenses, and access permissions.
- Provide directories, events, sermons, prayer features, visitor follow-up, announcements, notifications, calendar synchronization, giving, and other enabled features.
- Process church onboarding, subscriptions, donations, refunds, reporting, and support requests.
- Protect users, churches, and the Services; prevent misuse; investigate errors; and maintain security and operational audits.
- Communicate service, account, membership, administrative-recovery, billing, support, and launch information.
- Comply with applicable legal, accounting, tax, and regulatory obligations.
ChurchBeacon does not use personal information for third-party targeted advertising and does not sell or rent personal information.
5. When information is shared
We disclose information only as needed for the purposes described in this policy:
- Within a participating church. Authorized pastors and administrators can access information needed to administer their church. Approved members can see shared directory fields, church content, and other information according to feature settings and your privacy choices.
- Service providers. Google and Firebase provide authentication, cloud databases, file storage, server functions, and push messaging. Stripe provides subscription billing, connected-account services, Checkout, and payment processing. Apple and Google support optional sign-in. Website hosting and email providers support the website, onboarding, and communications. These providers process information under their own terms and privacy commitments.
- At your direction. Information is sent to Google Calendar only after an authorized administrator connects it, and external links such as church websites, livestreams, Google Docs, or Stripe pages open at the user’s direction.
- Legal and safety reasons. We may disclose information when reasonably necessary to comply with law, enforce agreements, protect rights or safety, investigate fraud or abuse, or respond to a lawful request.
- Business changes. Information may be transferred as part of a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable law and protections consistent with this policy.
6. Storage, security, and international processing
ChurchBeacon separates central identity, licensing, and membership routing from ordinary church content. Each production church is designed to use a separate church environment for its member and operational data. We use access controls, server-authoritative permissions, encrypted network connections, credential isolation, and security logging to protect information. Contact photos may also be cached on a user’s device and can be disabled and cleared through the app. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
ChurchBeacon and its providers may process information in the United States and other locations where those providers operate. Those locations may have data-protection rules different from the place where you live.
7. Retention and deletion
We retain personal information only for as long as reasonably necessary to provide the Services, administer a church relationship, fulfill the purposes described here, and meet legal, accounting, tax, fraud-prevention, dispute, and security obligations. Retention depends on the type of information and the reason it is held. Temporary security and server logs are retained according to provider and operational schedules. Church content generally remains while the church uses the Services or until an authorized church administrator deletes it, subject to required financial and security retention.
An account holder can initiate permanent account deletion from Member Options in the app. Deletion removes the central sign-in, memberships, church authorization profiles, private profile and milestone records, private contact photos, personal notifications, and device registrations. Existing sessions are revoked. If cleanup in a church environment cannot finish immediately, it is queued for retry.
Church-owned content, the church subscription, completed giving records, and security audits are not deleted merely because one individual leaves. Where those records refer to the departing account, ChurchBeacon deletes the link or replaces it with a non-account identifier when practicable. Limited pseudonymous information may remain where necessary to preserve financial records, security audits, church records, or legal obligations. Deleting a ChurchBeacon account does not by itself cancel a recurring Stripe donation or a church’s ChurchBeacon subscription.
A final primary administrator may transfer technical administration to an eligible active administrator who accepts it, or delete the account without a transfer. Deletion without a transfer places the church in administrator recovery and notifies appropriate church administrators, the verified church contact when available, and ChurchBeacon support. It does not assign the spiritual title of Pastor to another person.
You may also request access, correction, or deletion by emailing info@churchbeaconapp.com. We may need to verify your identity. Some church-controlled information may require coordination with the participating church, and some records may be retained where permitted or required by law. Backup copies may remain until overwritten through normal backup cycles.
8. Your choices
- Control whether your contact information, birthday, anniversary, and eligible family milestones are visible to approved church members.
- Add, change, or remove an optional contact photo and disable contact-photo downloads on a device.
- Choose notification categories and change device permissions in system settings.
- Decline location access and use a church join code or QR code instead.
- Disconnect Google Calendar, which revokes ChurchBeacon’s connection but does not delete events already written to Google.
- Sign out or permanently delete your account in Member Options.
Depending on where you live, you may also have legal rights to access, correct, delete, obtain a copy of, restrict, or object to certain processing of personal information. Contact us to exercise an applicable right. We will not discriminate against you for making a privacy request.
9. Children’s privacy
ChurchBeacon may be used in church settings by people of different ages, but the current Services are not designed to collect personal information directly from children under 13. We ask that children under 13 not create their own ChurchBeacon accounts or submit personal information directly. An adult church member may optionally enter a child’s name and birthday for church milestone features only when authorized to do so. If you believe a child provided personal information directly without appropriate permission, contact us so we can investigate and delete it as appropriate.
A registered-account or personal-submission experience for children under 13 will require an approved parental notice and verifiable parental-consent process before it is offered. A parent or legal guardian may ask to review, correct, or delete a child’s information, or withdraw permission for further collection, by using the contact information below.
10. Website storage and external services
The website and onboarding flow may use cookies, local storage, or session storage required for authentication, security, and preserving progress during a session. ChurchBeacon does not currently use this information for third-party advertising. The Services may link to websites and services operated by churches or other organizations. Their privacy practices are governed by their own policies.
11. Changes to this policy
We may update this policy as ChurchBeacon changes. We will post the revised policy at this address and update the effective date. If a change materially affects how previously collected personal information is used, we will provide additional notice or request consent when required.
12. Contact us
For privacy questions, requests, or complaints, contact:
Ronald Kaylor DBA Church Beacon App8852 Daly Rd
Cincinnati, OH 45231
United States
Email: info@churchbeaconapp.com
Phone: (844) 424-2327 or (844) 4CH-BEAP
Website: www.churchbeaconapp.com