Definitions & Roles
Understanding who controls and who processes your data is foundational to this policy. Under applicable US and international privacy frameworks, the following roles apply on the AGAPAY platform:
The Orthodox parish, monastery, or skete registered with AGAPAY that directs the collection and use of donor data within its community. The Organization determines the purposes for which donor data is collected.
We process personal data on behalf of the Data Controller solely to provide platform services. We do not use donor data for our own commercial purposes beyond what is necessary to operate the platform.
Any individual who submits personal or financial information through the AGAPAY platform in connection with a gift, offering, or account registration.
For the purposes of this policy, "personal data" or "personal information" means any information that identifies or could reasonably be used to identify a natural person, directly or indirectly.
Information We Collect
We collect only the information necessary to provide the platform's services. The categories of personal data we collect are:
| Category | Examples | How Collected |
|---|---|---|
| Identity Data | Full name, display name | Provided by you at registration or checkout |
| Contact Data | Email address, mailing address, phone number | Provided by you at registration or checkout |
| Financial / Transaction Data | Gift amounts, dates, designated funds, giving frequency | Generated automatically at transaction time |
| Payment Instrument Data | Card type, last four digits, expiration (tokenized) | Processed directly by Stripe - AGAPAY does not store full card numbers |
| Liturgical / Memorial Data | Names and intentions submitted for commemoration | Provided by you at checkout or in donor dashboard |
| Account Data | Login credentials (hashed), account preferences | Created at account registration |
| Legal Acceptance Data | Name, email, organizational role, account or Organization identifier, server timestamp, Terms version and hash, exact disclosure accepted, transaction reference, IP address, and user-agent metadata | Recorded when you affirmatively accept or reaccept the Terms |
| Technical / Usage Data | IP address, device type, OS, browser, pages visited, session duration | Collected automatically via server logs and analytics |
| Communications Data | Emails, support messages, and parish outreach requests | Provided by you through support or public interest forms |
| Household & Directory Data | Household relationships, preferred or legal names, contact details, birth dates, biological sex when supplied, photos, parish affiliation, directory notes, and publication preferences | Provided by adult account holders or authorized parish personnel and reviewed through Directory workflows |
| Child & Education Data | A child's first name, age, grade or form, courses, assignments, attendance, scores, grades, parent notes, report cards, transcripts, and household plans | Entered and managed by a parent or legal guardian through AGAPAY Learn |
| Organization Operations Data | Accounting records, vendors, bills, supporting documents, inventory, ministry records, and tax-exemption information | Entered by authorized Organization personnel or generated while they use Organization services |
| Connected-Service Data | Google authorization tokens and the calendar events selected or created for optional calendar synchronization | Received when an authorized user chooses to connect Google Calendar |
Legal Basis for Processing
AGAPAY processes personal data on the following legal bases under applicable law:
- Contractual necessity. Processing required to fulfill our obligations to you under our Terms of Service - including processing donations, transmitting memorial names to clergy, and providing account services.
- Legal obligation. Processing required to comply with applicable law - including IRS record-keeping requirements for charitable organizations (7-year retention of financial records), anti-money-laundering obligations, and applicable state charity registration laws.
- Legitimate interests. Processing necessary for AGAPAY's legitimate business interests where not overridden by your privacy rights - including platform security, fraud prevention, and aggregate analytics to improve the platform.
- Consent. Where required by applicable law, we obtain your consent before processing your data for specific purposes (such as marketing communications). You may withdraw consent at any time by contacting hello@agapay.app, without affecting the lawfulness of prior processing.
How We Use Your Data
We collect and process personal data solely for the following purposes, and we do not use your data for any purpose incompatible with those listed here without your consent:
- Transaction processing. Processing and recording charitable gifts on behalf of the recipient parish or monastery, including generating receipts and confirmation emails.
- Memorial transmission. Transmitting liturgical memorial and intention names to designated clergy for commemoration at the proskomedia, panikhida, or parastas.
- Requested parish outreach. When you explicitly ask us to contact a prospective parish, storing the request, sending a one-time introduction to the public parish contact you provide, notifying the AGAPAY team, and confirming the request with you. We do not share your email address with the parish.
- Giving records. Generating annual giving statements and year-end commemoration records for donors, for tax substantiation and personal record-keeping purposes.
- Legal compliance. Complying with applicable tax, accounting, charitable reporting, anti-money-laundering, and financial record-keeping requirements.
- Account services. Maintaining donor and administrator accounts, providing support, and communicating regarding your use of the platform when requested.
- Contract records. Preserving reliable, append-only evidence of the Terms and disclosure affirmatively accepted by an account holder or authorized Organization representative.
- Platform security. Detecting, investigating, and preventing fraudulent transactions, unauthorized access, and other harmful activity.
- Platform improvement. Using aggregated, de-identified analytics data to understand usage patterns and improve the platform. Individual user data is not used for this purpose.
Cookies & Tracking Technologies
AGAPAY uses limited browser storage and provider-hosted security or payment technologies to operate the platform. We do not use them for cross-site behavioral advertising or third-party ad targeting.
- Essential browser storage. AGAPAY uses first-party local storage for donor sign-in state and selected preferences, and session storage for parish and administrator sign-in state. Donor server sessions expire after 14 days; parish and administrator server sessions expire after 12 hours. Browser values may remain on a device until logout, browser-data deletion, or application cleanup, but an expired server session cannot authorize access.
- Provider-hosted technologies. Cloudflare Turnstile and Stripe-hosted checkout may use cookies or similar technologies on their own widgets or pages for fraud prevention, security, and payment processing under their respective privacy notices.
- Analytics. We use Cloudflare Web Analytics, a privacy-preserving tool that does not use cookies, fingerprinting, or cross-site tracking to collect personally identifiable data. Analytics data is aggregate and anonymized. No user-level behavioral profiles are created.
- No advertising cookies. AGAPAY does not serve advertisements and does not place or permit third-party advertising, retargeting, or behavioral tracking cookies on our platform. We do not use Google Analytics, Meta Pixel, or comparable advertising tools.
You may configure your browser to refuse cookies or clear cookies and site data. Login, checkout, security checks, and session persistence may not operate correctly when required browser storage or provider technologies are blocked.
We do not currently respond to browser Do Not Track (DNT) signals, as no uniform standard for DNT has been established. We do not engage in cross-site tracking regardless of DNT status.
Third-Party Service Providers
AGAPAY shares limited personal data with the following service providers, each engaged under contractual data protection obligations. We conduct due diligence on providers' privacy and security practices before engagement.
We do not share personal data with any party beyond those listed above, except as required by law (see Section 7 below).
Data Sharing & Disclosure
Beyond the service providers listed in Section 6, AGAPAY may share your personal data only in the following limited circumstances:
- With your Organization. Donor transaction records, memorial submissions, and giving history are shared with the registered administrator(s) of the recipient Organization. This sharing is inherent to the platform's purpose and is the basis on which you donate through AGAPAY.
- Legal process. We may disclose personal data in response to a valid subpoena, court order, or other legal process, or when required by applicable law or regulation. Where legally permitted, we will notify affected users before disclosure.
- Protection of rights. We may disclose personal data when we reasonably believe disclosure is necessary to prevent fraud, protect our legal rights, or protect the safety of any person.
- Business transfers. In the event of a merger, acquisition, or sale of all or substantially all of AGAPAY's assets, personal data may be transferred to the successor entity, subject to the same privacy protections described in this policy. We will provide notice of such a transfer and, where required, obtain consent.
- With your consent. We may share data for any other purpose with your explicit prior consent.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The following retention periods apply:
Upon expiration of the applicable retention period, data is securely deleted or irreversibly anonymized using industry-standard methods. You may request early deletion of non-legally-required data under Section 10-11 below.
Security
AGAPAY employs administrative, technical, and physical safeguards designed to protect your personal data against unauthorized access, disclosure, alteration, or destruction.
No method of transmission over the internet or electronic storage is completely secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security against all threats. You also play a role: keep your account credentials confidential and notify us immediately at hello@agapay.app if you suspect unauthorized access.
California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) affords you the following rights regarding your personal information:
Request disclosure of the categories and specific pieces of personal information collected about you, and how it is used and shared.
Request deletion of your personal information, subject to exceptions including our legal obligation to retain financial records.
Request correction of inaccurate personal information we maintain about you.
AGAPAY does not sell or share personal information as defined by CCPA/CPRA. No opt-out is required, but we disclose this affirmatively.
AGAPAY does not use sensitive personal information for purposes beyond those required to provide services.
We will not discriminate against you - in pricing, service quality, or otherwise - for exercising any CCPA/CPRA right.
To exercise any California privacy right, submit a verifiable written request to hello@agapay.app with subject line "California Privacy Request." We will verify your identity before processing any request and respond within 45 days as required by law, with a possible 45-day extension for complex requests with prior notice.
You may designate an authorized agent to submit requests on your behalf by providing written authorization. We may require direct verification from you if an agent submits a request.
Texas Privacy Rights (TDPSA)
If you are a Texas resident, the Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, affords you the following rights regarding your personal data:
Confirm whether we process your personal data and request access to the specific data we hold about you.
Request correction of inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.
Request deletion of personal data you have provided or that we have collected about you, subject to our lawful retention obligations.
Obtain a copy of your personal data in a portable, readily usable format, to the extent technically feasible.
AGAPAY does not engage in targeted advertising, sale of personal data, or profiling for consequential decisions. No opt-out is required, but we disclose this affirmatively.
To exercise any Texas privacy right, submit a written request to hello@agapay.app with subject line "Texas Privacy Request." We will respond within 45 days, with a possible 45-day extension for complex requests.
Appeals. If we decline to act on your request, you may appeal by responding in writing to our decision email. If your appeal is denied, you may contact the Texas Attorney General to submit a complaint.
Children's Privacy (COPPA)
AGAPAY's accounts and administrative tools are intended for adults. Children are not permitted to create their own AGAPAY account or independently submit personal information to the platform.
AGAPAY Learn is a parent-managed homeschool service. A parent or legal guardian may enter information about a child, including the child's first name, age, grade or form, learning plans, attendance, academic work, scores, grades, notes, report cards, and transcripts. Parish Directory households and authorized parish personnel may also maintain limited information about minors, including household relationships, contact or profile information, photos, and carefully controlled publication settings. These features are operated by adults on behalf of their children or communities.
By entering information about a minor, the adult represents that they are the child's parent or legal guardian, or are otherwise authorized by the parent or legal guardian and the Organization to provide and manage that information. AGAPAY does not use child data for advertising or sell it. A parent or guardian may contact hello@agapay.app to request access, correction, or deletion, subject to identity verification, Organization responsibilities, and lawful retention requirements.
If you believe a child has used AGAPAY independently, or that child information was entered without appropriate authority, contact us immediately at hello@agapay.app. We will investigate and take appropriate action, which may include restricting access or deleting information that is not required to be retained.
Memorial names submitted for liturgical commemoration may include the names of minors; this data is treated with the same protections as all personal data under this policy, and is transmitted only to the designated clergy of the recipient Organization.
Policy Updates & Notification
We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or platform features. When we make material changes, we will:
- Post the updated policy on this page with a revised "Last Updated" date.
- Provide notice to affected account holders before or when material changes take effect when required by law or reasonably practicable.
- Display an in-product notice or send email when a change materially affects how account data is handled.
Non-material changes - such as typographical corrections, clarifications that do not change our practices, or updated contact information - may be made without advance notice and will be effective upon posting.
When a material change requires renewed agreement, AGAPAY will request affirmative acceptance from affected registered account holders and preserve evidence of that acceptance. We will not apply a material change to a dispute of which AGAPAY had actual notice before the change. If you do not agree, you may terminate your account before the change takes effect for you by contacting hello@agapay.app.
Dispute Resolution
Disputes arising out of this Privacy Policy or AGAPAY's handling of personal data are governed by Section 24 of the Terms of Service, including its 30-day good-faith informal-resolution process, small-claims option, court process, voluntary post-dispute alternatives, and limits on retroactive changes. AGAPAY does not require arbitration or a class-action waiver.
- Governing law. This Privacy Policy is governed by the laws of the State of Texas, without regard to conflict of law provisions.
- Regulatory rights preserved. Nothing in this section limits your right to lodge a complaint with applicable state or federal privacy regulators, including the Texas Attorney General or the FTC.
Contact & Privacy Requests
For privacy-related questions, concerns, data access requests, or to exercise any right described in this policy, please contact AGAPAY at:
Account deletion: My AGAPAY users may initiate deletion from Account Settings or use the dedicated My AGAPAY account deletion page.
- Privacy requests: hello@agapay.app - include "Privacy Request" or your applicable right (e.g., "California Privacy Request") in the subject line
- Parish support: parishes@agapay.app
- Technical support: support@agapay.app
- Platform: agapay.app
We will respond to all privacy-related inquiries within 30 days of receipt. For requests under California or Texas law, we will respond within the statutory timeframe (45 days, with possible extension). We will request identity verification before processing any data access, correction, or deletion request.