Church Admin
Church Admin
Church Operations Simplified
Privacy Policy
Church Admin
Effective Date: August 27, 2026
Provider: Davola Technologies LLC

1. Overview and Scope

This Privacy Policy explains how Davola Technologies LLC (“Davola,” “we,” “us,” or “our”) collects, uses, discloses, and retains information in connection with Church Admin, including our websites, applications, public forms, and related services (collectively, the “Service”).

Church Admin helps churches, ministries, fellowships, nonprofits, and similar organizations (“Organizations”) manage people, attendance, finances, forms, communications, schedules, reports, and related administration.

This Policy applies to account users, Organization representatives, website visitors, support contacts, and people who submit information through a Church Admin-hosted form. An Organization may provide additional privacy notices governing how it uses information.

2. Our Data-Processing Role

For records an Organization enters or collects through Church Admin, the Organization generally determines why and how the information is used. The Organization is typically the controller or business, and Davola acts as its processor or service provider.

Organizations are responsible for their notices, legal basis, permissions, consent practices, data accuracy, user roles, and responses to members, visitors, donors, volunteers, employees, and form respondents.

Davola acts as a controller or business for information we use for account administration, billing, security, fraud prevention, support, legal compliance, and operation of our own website and business.

3. Information We Collect

Depending on how the Service is used, we may process:

Account and Organization Information

  • Name, email address, authentication data, role, and account identifiers
  • Organization name, logo, timezone, settings, plan, and user memberships
  • Invitations, access changes, onboarding responses, and support communications

People and Ministry Records

  • Member, first-timer, visitor, volunteer, group, and department information
  • Names, contact details, addresses, dates of birth or partial birthdays, gender, age group, and demographics
  • Membership, baptism, conversion, attendance, schedule, assignment, and follow-up information
  • Custom fields, notes, tags, status, profile changes, merge history, and processing audits

Financial and Reporting Records

  • Income, giving, expense, category, method, vendor, donor, and transaction information
  • Published and draft entries, revisions, reports, exports, and report filters
  • We do not use Church Admin to store donor bank credentials or payment-card numbers

Forms and Communications

  • Form definitions, fields, versions, links, submissions, answers, exports, and field mappings
  • Email addresses, phone numbers, recipient selections, message content, templates, delivery events, and suppressions
  • Consent attestations, opt-in evidence, opt-out events, campaign purpose, and communication history

Billing and Transaction Information

  • Plan, billing interval, customer and subscription identifiers, invoices, payment status, and billing address
  • Messaging-credit purchases, usage, adjustments, provider charges, and related transaction metadata
  • Our payment processor—not Church Admin—handles full payment-card details

Technical and Usage Information

  • IP address, browser and device information, timestamps, referring pages, and diagnostic logs
  • Feature usage, security events, rate-limit events, errors, and performance information
  • Approximate location inferred from IP or billing information where needed for security, tax, or service operation

4. Public Forms and Respondents

Organizations may publish Church Admin forms or intake links that can be opened without signing in. The Organization chooses the questions, requested information, purpose, availability, and how a response is processed.

A submission may remain in a form inbox, be exported, or be reviewed and mapped into a member, first-timer, visitor, or custom-field record. Church Admin does not automatically know that the respondent is the same person as an existing record merely because names or contact details resemble each other.

If you submitted a form for an Organization and wish to access, correct, or delete the response, contact that Organization first. Davola may assist the Organization where appropriate.

5. How We Use Information

We use information to:

  • Provide, personalize, maintain, and support the Service
  • Authenticate users and enforce Organization, role, and finance-window permissions
  • Store, search, organize, merge, display, export, and report Organization records
  • Process form submissions and user-approved record changes
  • Prepare and deliver authorized email or SMS communications
  • Operate subscriptions, enforce plan limits, process purchases, and provide billing support
  • Prevent abuse, enforce suppressions, investigate incidents, and protect users and the Service
  • Measure reliability, troubleshoot errors, and improve functionality and user experience
  • Comply with law and enforce our agreements

We may create aggregated or de-identified information that does not reasonably identify an Organization or person and use it for service operation, security, analytics, and improvement.

6. Nikky AI Assistant

Nikky is an optional, read-only conversational assistant available to authorized Organization roles. Church Admin uses the OpenAI API to interpret natural-language requests and present information obtained through a restricted set of approved Church Admin tools.

OpenAI does not receive Church Admin database credentials, unrestricted database access, arbitrary SQL access, or authority to browse an Organization’s records. To answer a request, Church Admin may send the user’s message, limited recent conversation context, and compact results returned by approved queries to the OpenAI API.

Church Admin stores saved conversations so a user can reopen them. Conversations remain until that user deletes them. Separate audit logs record safe metadata about access and tool usage rather than full donor lists, member profiles, or financial datasets, and are generally retained for one year. Temporary generated-report artifacts are generally scheduled to expire after 24 hours.

We do not train or fine-tune Nikky on Organization records. OpenAI states that inputs and outputs from its API platform are not used to train its models by default unless the API customer explicitly opts in. Learn more in OpenAI’s business data privacy statement.

AI-generated responses can still be incorrect. Users should verify important information against current Church Admin records and generated reports.

7. Email and SMS Data

When an Organization uses communication features, we process message content, sender information, recipient details, audience filters, delivery metadata, and suppression or opt-out records to prepare, send, secure, and document communications.

If SMS becomes active for an Organization, phone numbers, message content, sender and campaign identifiers, consent evidence, opt-out status, and delivery events may be shared with messaging providers, registration partners, aggregators, and mobile carriers as necessary to register senders, deliver messages, prevent abuse, calculate charges, and comply with law and carrier requirements.

Mobile phone information, SMS opt-in data, and consent records are not sold or shared with third parties for their own marketing or promotional purposes. They may be disclosed to service providers and carriers solely to operate and support the messaging program, enforce consent and opt-outs, or as required by law.

Suppression records may be retained after other records are deleted so that we and the Organization can continue honoring an opt-out and avoid sending unwanted messages.

Optional church-email preferences are kept separately for each Organization. We also process safe delivery metadata and provider events such as acceptance, hard bounce, complaint, and suppression. A provider-level hard bounce or complaint may prevent delivery across Church Admin, while a church-topic opt-out applies only to that Organization. We do not retain complete email contents in preference or suppression audit records.

8. How We Disclose Information

We may disclose information:

  • To Organization users according to current roles and permissions
  • To vendors that provide hosting, authentication, storage, email, AI, payments, anti-abuse, support, document generation, and messaging services
  • To payment networks, financial institutions, tax services, and fraud-prevention partners for billing and transactions
  • To messaging providers, registration partners, aggregators, and carriers for approved SMS services
  • When directed or authorized by the Organization
  • When required by law or reasonably necessary to protect rights, safety, security, and service integrity
  • In connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards

Key providers may include Supabase for database, authentication, and storage infrastructure; Stripe for subscriptions and payments; Resend for email delivery; Cloudflare for form anti-abuse checks; OpenAI for Nikky; and one or more future Messaging Providers for SMS. Providers may change as the Service evolves.

9. No Sale or Behavioral Advertising

We do not sell Organization Data or personal information submitted to Church Admin. We do not share Organization Data with third parties for their own direct marketing, and we do not use it for cross-context behavioral advertising.

A purchase of messaging capacity from a provider, or resale of messaging credits to an Organization, is a service transaction and does not constitute the sale of recipient personal information.

10. Retention and Deletion

We retain information for as long as reasonably necessary to provide the Service, fulfill the purposes described in this Policy, comply with law, resolve disputes, enforce agreements, and protect the Service. Retention depends on the record and context:

  • Organization records generally remain until an authorized user deletes them or a confirmed Organization-deletion process is completed.
  • Subscription cancellation or downgrade does not automatically delete Organization records.
  • Forms and submissions remain until deleted under available Organization controls.
  • Nikky conversations remain until their owner deletes them; Nikky audit metadata is generally retained for one year.
  • Billing, transaction, consent, suppression, security, merge, and other audit records may be retained longer where needed for legal, accounting, safety, or fraud-prevention purposes.
  • Temporary files, expired links, previews, and report artifacts may use shorter operational retention periods.

Deletion from active systems may not immediately remove information from backups. Backup copies are isolated and removed or overwritten on normal schedules unless retention is legally required.

11. Security

We use reasonable administrative, technical, and organizational measures designed to protect information. Measures may include authentication, role-based authorization, organization isolation, database row-level security, encryption in transit, restricted service credentials, audit logging, rate limits, and provider security controls.

No method of storage or transmission is completely secure. Users and Organizations must protect credentials, configure roles carefully, secure exports and public links, and notify us promptly of suspected misuse.

12. Rights and Choices

Depending on your location and relationship with us, you may have rights to request access, correction, deletion, portability, restriction, or information about how personal information is used. You may also have the right to appeal a decision or lodge a complaint with a regulator.

Account users can update certain information through the Service and may unsubscribe from optional product communications. Church-email recipients may use a no-sign-in preference center to control broadcasts, follow-ups, form invitations, and giving statements for each Organization. Service, account invitation, billing, security, and material legal notices may still be sent when necessary.

Requests concerning Organization-controlled records should be directed to the relevant Organization first. For information Davola controls, contact hello@churchadmins.com. We may verify identity and authority before fulfilling a request.

13. Children and Sensitive Information

Organizations may use Church Admin to store information about minors, religious affiliation, giving, attendance, pastoral follow-up, and other potentially sensitive matters. The Organization is responsible for deciding what to collect, obtaining any required parental or guardian consent, providing notices, and complying with COPPA and other applicable laws.

Church Admin is not directed to children for independent account creation, and Davola does not knowingly collect personal information directly from children apart from an Organization’s use of the Service. If you believe information was collected improperly, contact the Organization or Davola.

14. Cookies and Anti-Abuse Tools

We use cookies, local storage, tokens, and similar technologies that are necessary for sign-in, security, organization selection, preferences, and Service operation. We may also use limited diagnostics to understand errors and performance.

Public forms may use Cloudflare Turnstile or similar anti-abuse technology. That provider may process IP address, browser, device, challenge, and security information to distinguish legitimate use from automated abuse under its own privacy terms.

15. International Access

Davola operates Church Admin from the United States, and primary service infrastructure is currently located in the United States. If you access the Service from another country, information may be transferred to and processed in the United States or other locations where our providers operate. Those locations may have different data protection laws.

Organizations are responsible for determining whether their use of Church Admin complies with applicable local law and whether additional notices, agreements, or transfer safeguards are required.

16. Third-Party Services and Links

The Service may link to or integrate with third-party websites and services. Their privacy practices are governed by their own policies, not this Policy. Stripe may act as a processor and/or controller for payment and fraud-prevention information. Messaging Providers and carriers may process communications under their own legal duties and policies.

We encourage Organizations and users to review relevant provider policies, particularly before enabling payments, AI, public forms, or messaging.

17. Changes to This Policy

We may update this Privacy Policy as the Service, providers, or laws change. If changes are material, we will provide reasonable notice through the Service, by email, or by updating the Effective Date. Where required, we will seek additional consent.

18. Contact

Davola Technologies LLC
Email: hello@churchadmins.com