AGAPAY Privacy

Privacy Policy

Last updated: June 18, 2026. Effective: June 18, 2026.

Your privacy matters. This policy explains what personal data AGAPAY collects, how we use it, who we share it with, how long we keep it, and what rights you have. We process data only as necessary to operate the platform and fulfill our obligations to the parishes, monasteries, and donors we serve. We do not sell your personal data. Ever.
AGAPAY Learn and Google Calendar Sync. AGAPAY Learn is an Orthodox homeschool planning app for families. If you choose to connect Google Calendar, AGAPAY Learn requests access only to help create or sync homeschool planning events to your Google Calendar, such as lesson blocks, term dates, feast days, reminders, or household planning events that you choose to send. Google Calendar connection is optional, and AGAPAY Learn can be used without connecting Google Calendar. AGAPAY does not sell Google user data, does not use Google Calendar data for advertising, and does not transfer Google user data except as necessary to provide the calendar sync feature you request or as required by law.
Section 1

Definitions & Roles

Understanding who controls and who processes your data is foundational to this policy. Under applicable US and international privacy frameworks, the following roles apply on the AGAPAY platform:

Data Controller
The Parish or Monastery

The Orthodox parish, monastery, or skete registered with AGAPAY that directs the collection and use of donor data within its community. The Organization determines the purposes for which donor data is collected.

Data Processor
AGAPAY

We process personal data on behalf of the Data Controller solely to provide platform services. We do not use donor data for our own commercial purposes beyond what is necessary to operate the platform.

Data Subject
The Donor

Any individual who submits personal or financial information through the AGAPAY platform in connection with a gift, offering, or account registration.

For the purposes of this policy, "personal data" or "personal information" means any information that identifies or could reasonably be used to identify a natural person, directly or indirectly.

Section 2

Information We Collect

We collect only the information necessary to provide the platform's services. The categories of personal data we collect are:

Category Examples How Collected
Identity Data Full name, display name Provided by you at registration or checkout
Contact Data Email address, mailing address, phone number Provided by you at registration or checkout
Financial / Transaction Data Gift amounts, dates, designated funds, giving frequency Generated automatically at transaction time
Payment Instrument Data Card type, last four digits, expiration (tokenized) Processed directly by Stripe - AGAPAY does not store full card numbers
Liturgical / Memorial Data Names and intentions submitted for commemoration Provided by you at checkout or in donor dashboard
Account Data Login credentials (hashed), account preferences Created at account registration
Technical / Usage Data IP address, device type, OS, browser, pages visited, session duration Collected automatically via server logs and analytics
Communications Data Emails and messages sent to AGAPAY support Provided by you
We do not collect: Social Security numbers, government ID numbers, full payment card numbers, sensitive demographic data (race, religion, national origin), or any data beyond what is listed above.
Section 4

How We Use Your Data

We collect and process personal data solely for the following purposes, and we do not use your data for any purpose incompatible with those listed here without your consent:

We do not use your personal data for: marketing profiling, behavioral advertising, sale to third parties, cross-context behavioral tracking, or any purpose beyond those listed above.
Section 5

Cookies & Tracking Technologies

AGAPAY uses a minimal, purposeful set of cookies and similar technologies to operate the platform. We do not use cookies for cross-site behavioral advertising or third-party ad targeting.

You may configure your browser to refuse or delete cookies. Essential platform functionality (login, checkout, session persistence) may not operate correctly if essential cookies are disabled.

We do not currently respond to browser Do Not Track (DNT) signals, as no uniform standard for DNT has been established. We do not engage in cross-site tracking regardless of DNT status.

Section 6

Third-Party Service Providers

AGAPAY shares limited personal data with the following service providers, each engaged under contractual data protection obligations. We conduct due diligence on providers' privacy and security practices before engagement.

S
Stripe, Inc.
Payment processing and financial data handling. Stripe collects, processes, and stores payment instrument data under its own Privacy Policy and PCI-DSS Level 1 compliance framework. AGAPAY does not receive or store full card numbers or banking credentials. Data shared: name, email, transaction amounts.
stripe.com/privacy ->
CF
Cloudflare, Inc.
DNS resolution, content delivery network (CDN), DDoS protection, and privacy-preserving web analytics. Cloudflare processes IP addresses and technical request metadata as traffic passes through its network infrastructure. Cloudflare Web Analytics does not use cookies or fingerprinting. Data shared: IP addresses, request metadata (automatically, as part of network routing).
cloudflare.com/privacypolicy ->
ML
MailerLite
Email list management for parishes and prospective users who voluntarily subscribe to AGAPAY communications. MailerLite processes name and email address for this purpose only. Transactional emails (receipts, notifications) may be sent via this infrastructure. Data shared: name, email address (subscribers only).
mailerlite.com/legal/privacy-policy ->
GH
GitHub Pages
Static frontend hosting for the AGAPAY web application. GitHub Pages may log IP addresses and request metadata as part of standard web server operation. No personal data beyond standard request logs is shared with GitHub for this purpose.
GitHub Privacy Statement ->

We do not share personal data with any party beyond those listed above, except as required by law (see Section 7 below).

Section 7

Data Sharing & Disclosure

Beyond the service providers listed in Section 6, AGAPAY may share your personal data only in the following limited circumstances:

We never sell personal data. AGAPAY does not sell, rent, trade, or otherwise transfer your personal data to third parties for their own commercial use. This is an unconditional commitment.
Section 8

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The following retention periods apply:

Financial and transaction records (donation amounts, dates, funds) 7 years minimum
Liturgical memorial and intention names 7 years (with transaction record)
Donor account and profile data (active accounts) Duration of relationship + 3 years
Donor account data (closed or inactive accounts) 3 years post-closure
Organization account data Duration of registration + 7 years
Technical usage logs and server logs 90 days (unless active security investigation)
Support and communications data 3 years from last communication

Upon expiration of the applicable retention period, data is securely deleted or irreversibly anonymized using industry-standard methods. You may request early deletion of non-legally-required data under Section 10-11 below.

Section 9

Security

AGAPAY employs administrative, technical, and physical safeguards designed to protect your personal data against unauthorized access, disclosure, alteration, or destruction.

Encryption at Rest AES-256 encryption for all stored personal data in Cloudflare D1 and KV data stores.
Encryption in Transit TLS 1.2 / 1.3 encryption for all data transmitted between your device and the platform.
PCI-DSS Compliance Payment processing via Stripe's PCI-DSS Level 1 certified infrastructure. AGAPAY never handles raw card data.
Access Controls Personal data access limited to authorized AGAPAY personnel with a need-to-know basis. Role-based permissions enforced at the infrastructure level.
DDoS & Threat Protection Cloudflare network-level protection against distributed denial-of-service attacks and malicious traffic.
Incident Response In the event of a confirmed data breach affecting your personal data, we will notify you and applicable authorities within 72 hours where required by law.

No method of transmission over the internet or electronic storage is completely secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security against all threats. You also play a role: keep your account credentials confidential and notify us immediately at hello@agapay.app if you suspect unauthorized access.

Section 10

California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) affords you the following rights regarding your personal information:

Right to Know

Request disclosure of the categories and specific pieces of personal information collected about you, and how it is used and shared.

Right to Delete

Request deletion of your personal information, subject to exceptions including our legal obligation to retain financial records.

Right to Correct

Request correction of inaccurate personal information we maintain about you.

Right to Opt Out

AGAPAY does not sell or share personal information as defined by CCPA/CPRA. No opt-out is required, but we disclose this affirmatively.

Right to Limit Sensitive Data Use

AGAPAY does not use sensitive personal information for purposes beyond those required to provide services.

Right to Non-Discrimination

We will not discriminate against you - in pricing, service quality, or otherwise - for exercising any CCPA/CPRA right.

To exercise any California privacy right, submit a verifiable written request to hello@agapay.app with subject line "California Privacy Request." We will verify your identity before processing any request and respond within 45 days as required by law, with a possible 45-day extension for complex requests with prior notice.

You may designate an authorized agent to submit requests on your behalf by providing written authorization. We may require direct verification from you if an agent submits a request.

Section 11

Texas Privacy Rights (TDPSA)

If you are a Texas resident, the Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, affords you the following rights regarding your personal data:

Right to Access

Confirm whether we process your personal data and request access to the specific data we hold about you.

Right to Correction

Request correction of inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.

Right to Deletion

Request deletion of personal data you have provided or that we have collected about you, subject to our lawful retention obligations.

Right to Data Portability

Obtain a copy of your personal data in a portable, readily usable format, to the extent technically feasible.

Right to Opt Out

AGAPAY does not engage in targeted advertising, sale of personal data, or profiling for consequential decisions. No opt-out is required, but we disclose this affirmatively.

To exercise any Texas privacy right, submit a written request to hello@agapay.app with subject line "Texas Privacy Request." We will respond within 45 days, with a possible 45-day extension for complex requests.

Appeals. If we decline to act on your request, you may appeal by responding in writing to our decision email. If your appeal is denied, you may contact the Texas Attorney General to submit a complaint.

Section 12

Children's Privacy (COPPA)

AGAPAY is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA). Our platform is intended for use by adults - parish administrators, clergy, and adult donors - on behalf of their communities.

If you believe we have inadvertently collected personal information from a child under 13, please contact us immediately at hello@agapay.app. We will promptly investigate and delete such information from our records.

If you are between the ages of 13 and 17, you must obtain verifiable parental or guardian consent before submitting any personal information through this platform. By submitting information, you represent that you have obtained such consent.

Memorial names submitted for liturgical commemoration may include the names of minors; this data is treated with the same protections as all personal data under this policy, and is transmitted only to the designated clergy of the recipient Organization.

Section 13

Policy Updates & Notification

We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or platform features. When we make material changes, we will:

Non-material changes - such as typographical corrections, clarifications that do not change our practices, or updated contact information - may be made without advance notice and will be effective upon posting.

Your continued use of the AGAPAY platform following notice of material changes constitutes your acceptance of the updated policy. If you do not agree, you may terminate your account before the effective date by contacting hello@agapay.app.

Section 14

Dispute Resolution & Arbitration

Any dispute arising out of or relating to this Privacy Policy or AGAPAY's handling of your personal data shall be resolved as follows:

Section 15

Contact & Privacy Requests

For privacy-related questions, concerns, data access requests, or to exercise any right described in this policy, please contact AGAPAY at:

We will respond to all privacy-related inquiries within 30 days of receipt. For requests under California or Texas law, we will respond within the statutory timeframe (45 days, with possible extension). We will request identity verification before processing any data access, correction, or deletion request.

^