GoshenPay

Privacy Policy

Effective

Giving is personal. This policy explains what GoshenPay collects when you give to a church or work in a church's workspace, why we collect it, who can see it, and the choices you have. The short version: your giving history is private to you, each church sees only the gifts made to it, we never see your card number, and we do not sell personal information.

1. Who this policy covers

This policy applies to the GoshenPay platform: the giving site, church giving pages we host (including pages served from a church's own domain), the church workspace, and the emails we send. It covers donors, church staff, and visitors. It is part of our Terms of Service.

2. Our role and the church's role

Two organizations handle information when you give through the Service, and each is accountable for its part:

  • The church is responsible for the gifts made to it and the donor records it keeps — including gifts its staff record from cash, cheques, and Interac e-Transfers — and for the official donation receipts it issues. We process that information on the church's behalf and instructions.
  • GoshenPay is responsible for your giving account, your cross-church giving history, sign-in, our websites, and the operation and security of the platform itself.

One church never sees your gifts to another church. Your giving account is the only place your history across churches comes together, and only you can see it.

3. What we collect

We collect only what the Service needs to record a gift, run your account, and let churches meet their obligations:

  • Identity and contact details — your name and email address, and your legal name and mailing address when a church needs them to issue a donation receipt.
  • Gift details — the church, amount, fund or campaign, date, one-time or recurring schedule, whether you chose to cover processing costs, and the status of the payment (succeeded, refunded, disputed).
  • Payment information — collected by Stripe, not by us. Stripe shares with us only what is needed to record and reconcile the gift, such as a payment reference, the card brand and last four digits, and fee and payout data. We never receive your full card number, bank credentials, or security code.
  • Offline gifts — when a church records a cash, cheque, or e-Transfer gift, its staff may enter your name, envelope number, cheque number, or the sender name, email, and reference from the church's bank statement.
  • Account and sign-in data — your email address and sign-in events through our authentication provider, and, for church staff, your role and the actions you take in the workspace, which are kept for the church's audit history.
  • Technical data — IP address, browser type, device information, pages visited, and server logs, used for security, debugging, and to keep the Service running.
  • Correspondence — messages you send to support.

4. How we use it

  • to process your gift and pass it to the church's Stripe account;
  • to run recurring gifts: schedule charges, retry failed payments, and let you change or cancel;
  • to keep the church's contribution ledger accurate and reconciled against its bank deposits and Stripe payouts;
  • to prepare official donation receipts on the church's behalf and make them available to you;
  • to show you your private giving history and let you claim earlier gifts made as a guest;
  • to send transactional email — payment problems, receipts, sign-in and claim links, staff invitations, and operational alerts to church staff;
  • to measure how features are used and improve the Service;
  • to detect fraud and abuse and secure the Service; and
  • to meet our legal obligations and the church's record-keeping duties.

We do not use your information for advertising, we do not sell or rent it, and we do not send marketing email on behalf of churches. Any church communication beyond the transactional messages above is the church's own, under its own consent.

6. Who we share it with

  • The church you give to — your name, contact details, and the gifts you made to that church, so it can record, thank, receipt, and reconcile. It sees nothing about your giving elsewhere.
  • Stripe — to process payments, on the church's connected Stripe account. Stripe's handling of your information is governed by Stripe's own privacy policy.
  • Service providers who host and run the Service for us: cloud hosting and database infrastructure, our authentication provider, our email delivery provider, and PostHog for analytics and error monitoring. Each processes information only to provide its service to us and under contractual confidentiality obligations.
  • Legal requirements — when required by law, court order, or a lawful request from a public authority, or to protect the rights, safety, and property of donors, churches, or the Service.
  • A successor — if GoshenPay is acquired or merges, information may transfer to the successor, who must honour this policy.

7. Where information is stored

GoshenPay is operated from Canada. Some of our service providers store and process information in the United States and other countries. While information is outside Canada it is subject to the laws of that country and may be accessible to its courts and authorities. We choose providers with strong security practices and contractual protections, and we are working toward keeping church records in Canadian regions.

8. How long we keep it

We keep information for as long as it is needed for the purposes above and to meet legal obligations. Records of gifts and donation receipts are part of a registered charity's books and records and are retained for the periods the Income Tax Act and Canada Revenue Agency require; the ledger is designed so approved records are never silently altered or erased. You can ask us to remove information that is no longer needed — see section 11.

9. How we protect it

  • encryption in transit and at rest;
  • payment credentials handled only by Stripe, a PCI DSS Level 1 service provider;
  • tenant isolation enforced in the database itself, so one church's data is never returned in another church's queries;
  • role-based access for church staff, with sensitive actions approver-gated and recorded; and
  • sign-in by verified email through our authentication provider, with sessions that expire.

No system is perfectly secure. If we learn of a breach that creates a real risk of significant harm, we will notify affected people and the Office of the Privacy Commissioner of Canada as the law requires.

10. Cookies and similar storage

We use a session cookie to keep you signed in, a time zone cookie, and a browser setting for your colour theme. We automatically collect analytics through PostHog, which stores a random browser identifier to measure visits, navigation, feature use, performance, and errors. For signed-in visitors, we use an account identifier, without a name or email, to understand returning use. We exclude form contents, payment details, URL parameters, and error messages. Session recordings are disabled. We honour Do Not Track, Global Privacy Control, and any previously saved analytics decline for this browser and website. Server monitoring records operation types, timing, and scrubbed errors without linking those records to your account. We do not use advertising cookies. Stripe sets its own cookies on its checkout pages.

11. Your choices and rights

You may, at any time:

  • See your giving — your giving account shows every gift recorded to you across churches, and your recurring gifts.
  • Access and correct — ask us for the personal information we hold about you and to correct anything inaccurate. Receipt details (legal name and address) can also be corrected by the church, which will void and reissue an affected receipt.
  • Change or cancel recurring gifts and update your payment method from your giving account.
  • Withdraw consent or request deletion — ask us to delete or anonymize the personal information we hold about you. We confirm the request came from you, review it against the retention rules in section 8, act on it, stop all further email to your address, and tell you what was removed and what had to be kept — for example, gifts a church has receipted remain part of that church's records. Where the information belongs to a church's records, we act on the church's instruction.
  • Complain — to us first, and if you are not satisfied, to the Office of the Privacy Commissioner of Canada.

To exercise any of these, email support@goshenpay.com. We will acknowledge your request within five business days and respond within 30 days, and we may ask you to confirm the request from the email address on your records.

12. Children

The Service is not directed to children under 13 and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the Service and the law change. The effective date at the top always reflects the current version, and we will give churches reasonable notice of material changes.

14. Contact

Our privacy officer can be reached at support@goshenpay.com — mark your message “Attention: Privacy”.