Legal
Privacy Policy
This policy explains what data EJAD collects, why, and the rights you and your church have over it.
1. Scope & roles
EJAD ("EJAD", "we", "us") provides church management software to religious organizations ("Churches", "Customers"). This policy covers two audiences: (a) visitors to this marketing website, and (b) the people whose data Churches manage inside EJAD — members, donors, volunteers, guests, and children. For data entered into the app by a Church, EJAD generally acts as a data processor on the Church's behalf; the Church is the data controller. See Section 12.
2. Information we collect
We collect information in three ways:
- Data a Church uploads or enters: names, contact details, household relationships, attendance, group membership, donation and pledge records, notes, custom fields, and — where the Church enables kids ministry check-in — limited information about children (name, age, allergies/medical notes, authorized pickup persons) entered by parents or staff.
- Account & billing data: login credentials (hashed, never stored in plain text), two-factor authentication status, and subscription/billing details processed via Stripe.
- Usage & device data: IP address, browser type, pages visited, timestamps, and error logs, collected automatically to operate and secure the service.
We do not buy data from data brokers, and this website does not run third-party advertising trackers.
3. How we use information
We use information solely to provide, secure, and improve the service: authenticating users, rendering church data inside the app, processing payments and donations, sending transactional email/SMS (e.g. receipts, password resets, workflow notifications) on a Church's behalf, responding to support requests, and detecting abuse or security incidents. We do not sell personal data, and we do not use Church data to train third-party AI models.
4. Legal bases (GDPR)
Where GDPR applies, we rely on: performance of a contract (operating the subscription you or your Church signed up for), legitimate interests (security, fraud prevention, service improvement), consent (where a Church or individual opts into optional communications), and legal obligation (e.g. tax and accounting records).
5. Children's data
EJAD is a business-to-business platform used by Church staff and volunteers — it is not directed at children, and we do not knowingly collect data directly from children through this website. Where a Church uses the Kids Check-in module, limited information about minors (name, age, guardian/pickup information, allergy or medical notes) is entered by the Church or a parent/guardian, not by the child, and is used only to operate safe check-in and pickup at that Church's own events. That data remains under the Church's control as data controller, and we apply the same encryption and access controls described in Security.
6. Cookies
We use a small number of strictly necessary and functional cookies — no third-party advertising or analytics trackers. See the full Cookie Policy.
7. Sharing & subprocessors
We share data only with service providers ("subprocessors") who help us run EJAD, under contract and only to the extent needed — for example, payment processing, email/SMS delivery, and cloud hosting. We never share data with third parties for their own marketing purposes. See the full list and roles in our Data Processing Addendum.
8. Retention
Church data is retained for as long as the Church's subscription is active, plus a limited window after cancellation to allow export or reactivation, after which it is deleted or anonymized — except where we must retain records longer to comply with law (e.g. financial/tax records). Churches can request export or deletion at any time; see Section 11.
9. Security
We encrypt data in transit (TLS) and at rest, enforce role-based access control, and offer optional two-factor authentication. Full detail is in our Security page.
10. International transfers
EJAD's infrastructure is hosted in the United States. If your Church is located outside the U.S. — including in Latin America — and your use of EJAD involves transferring personal data of members or donors into the U.S., we can make available a signed Data Processing Addendum with contractual safeguards for that transfer. Contact privacy@ejad.app to request one.
11. Your rights (GDPR & CCPA)
Depending on where you live, you may have the right to: access the personal data we (or a Church, as controller) hold about you; correct inaccurate data; request deletion; restrict or object to processing; receive a portable copy of your data; and, under CCPA, know what categories of data are collected and opt out of any "sale" or "sharing" of personal data — which EJAD does not do. To exercise these rights for data held inside a Church's account, please contact that Church directly, since they control the record. To exercise rights over your own EJAD account or website data, email privacy@ejad.app; we respond within 30 days.
12. Church as data controller
Each Church decides what information to collect from its members and how to use it inside EJAD. EJAD processes that data only on the Church's instructions, as described in our Terms of Service and Data Processing Addendum. If you are a member, donor, or guest of a Church using EJAD and have questions about your data, please contact that Church first.
13. Changes to this policy
We may update this policy as the service evolves. Material changes will be posted here with an updated "Last updated" date, and where required by law we will notify Churches by email.
14. Contact
Questions about this policy or a request related to your data: privacy@ejad.app.
Questions about
your data?
We're glad to walk through this policy with your board or compliance team.