AGAPAY Privacy

Privacy Policy

Last updated: August 30, 2026. Effective for new Users: August 30, 2026. Effective for existing Users upon notice, no earlier than September 29, 2026.

Your privacy matters. This policy explains what personal data AGAPAY collects, how we use it, who we share it with, how long we keep it, and what rights you have. We process data only as necessary to operate the platform and fulfill our obligations to the parishes, monasteries, and donors we serve. We do not sell your personal data. Ever.
AGAPAY Learn and Google Calendar Sync. AGAPAY Learn is an Orthodox Christian homeschool planning application for parents. If you choose to connect Google Calendar, AGAPAY Learn requests the Google Calendar events permission only to create and update homeschool planning events in your primary calendar, such as selected lesson blocks, term dates, feast days, reminders, and household planning events. AGAPAY Learn checks for events it previously created so a later sync can update them rather than create duplicates. The connection is optional, and AGAPAY Learn can be used without Google Calendar. AGAPAY does not sell Google user data, use Google Calendar data for advertising, or transfer Google user data except as necessary to provide the sync you request or as required by law. AGAPAY's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You may disconnect the integration in AGAPAY Learn or revoke AGAPAY Learn access at any time from your Google Account permissions.
Section 1

Definitions & Roles

Understanding who controls and who processes your data is foundational to this policy. Under applicable US and international privacy frameworks, the following roles apply on the AGAPAY platform:

Data Controller
The Parish or Monastery

The Orthodox parish, monastery, or skete registered with AGAPAY that directs the collection and use of donor data within its community. The Organization determines the purposes for which donor data is collected.

Data Processor
AGAPAY

We process personal data on behalf of the Data Controller solely to provide platform services. We do not use donor data for our own commercial purposes beyond what is necessary to operate the platform.

Data Subject
The Donor

Any individual who submits personal or financial information through the AGAPAY platform in connection with a gift, offering, or account registration.

For the purposes of this policy, "personal data" or "personal information" means any information that identifies or could reasonably be used to identify a natural person, directly or indirectly.

Section 2

Information We Collect

We collect only the information necessary to provide the platform's services. The categories of personal data we collect are:

Category Examples How Collected
Identity Data Full name, display name Provided by you at registration or checkout
Contact Data Email address, mailing address, phone number Provided by you at registration or checkout
Financial / Transaction Data Gift amounts, dates, designated funds, giving frequency Generated automatically at transaction time
Payment Instrument Data Card type, last four digits, expiration (tokenized) Processed directly by Stripe - AGAPAY does not store full card numbers
Liturgical / Memorial Data Names and intentions submitted for commemoration Provided by you at checkout or in donor dashboard
Account Data Login credentials (hashed), account preferences Created at account registration
Legal Acceptance Data Name, email, organizational role, account or Organization identifier, server timestamp, Terms version and hash, exact disclosure accepted, transaction reference, IP address, and user-agent metadata Recorded when you affirmatively accept or reaccept the Terms
Technical / Usage Data IP address, device type, OS, browser, pages visited, session duration, referral or campaign tags, and selected interactions on AGAPAY marketing pages Collected automatically via server logs and analytics
Communications Data Emails, support messages, and parish outreach requests Provided by you through support or public interest forms
Household & Directory Data Household relationships, preferred or legal names, contact details, birth dates, biological sex when supplied, photos, parish affiliation, directory notes, and publication preferences Provided by adult account holders or authorized parish personnel and reviewed through Directory workflows
Child & Education Data A child's first name, age, grade or form, courses, assignments, attendance, scores, grades, parent notes, report cards, transcripts, and household plans Entered and managed by a parent or legal guardian through AGAPAY Learn
Organization Operations Data Accounting records, vendors, bills, supporting documents, inventory, ministry records, and tax-exemption information Entered by authorized Organization personnel or generated while they use Organization services
Connected-Service Data Google authorization tokens and the calendar events selected or created for optional calendar synchronization Received when an authorized user chooses to connect Google Calendar
We do not request or store: Social Security numbers, government identification numbers, or full payment card or bank-account credentials. Stripe receives payment instrument information directly. Use of an Orthodox parish and faith-formation platform can itself reveal religious affiliation, so we protect that information as personal data rather than claiming it is not collected.
Section 4

How We Use Your Data

We collect and process personal data solely for the following purposes, and we do not use your data for any purpose incompatible with those listed here without your consent:

We do not use your personal data for: marketing profiling, behavioral advertising, sale to third parties, cross-context behavioral tracking, or any purpose beyond those listed above.
Section 5

Cookies & Tracking Technologies

AGAPAY uses limited browser storage and provider-hosted security, payment, analytics, and campaign-measurement technologies to operate and evaluate the platform. AGAPAY does not use these technologies to sell personal information or conduct cross-context behavioral advertising.

You may configure your browser to refuse cookies or clear cookies and site data. Login, checkout, security checks, and session persistence may not operate correctly when required browser storage or provider technologies are blocked.

We do not currently respond to browser Do Not Track (DNT) signals, as no uniform standard for DNT has been established. Browser privacy settings, content blockers, and Meta's activity controls may limit or block Pixel requests without affecting the referral page or demo-request form.

Section 6

Third-Party Service Providers

AGAPAY shares limited personal data with the following service providers, each engaged under contractual data protection obligations. We conduct due diligence on providers' privacy and security practices before engagement.

S
Stripe, Inc.
Payment processing and financial data handling. Stripe collects, processes, and stores payment instrument data under its own Privacy Policy and PCI-DSS Level 1 compliance framework. AGAPAY does not receive or store full card numbers or banking credentials. Data shared: name, email, transaction amounts.
stripe.com/privacy ->
CF
Cloudflare, Inc.
Application hosting through Cloudflare Workers, static asset delivery, D1, KV and R2 storage, DNS, DDoS protection, Turnstile security checks, and privacy-preserving web analytics. Cloudflare processes stored application data and technical request metadata as needed to provide these services. Data shared: application data stored for the service, IP addresses, and request metadata.
cloudflare.com/privacypolicy ->
R
Resend
Delivery of transactional and Organization-authorized email, including verification, registration, receipt, invitation, notification, and parish communications. Data shared: recipient name and email address, message content, and delivery metadata.
resend.com/legal/privacy-policy ->
M
Meta Platforms, Inc.
Limited measurement of visits and selected referral or demo-request actions on designated AGAPAY Give marketing pages. AGAPAY uses the resulting reports solely for its own internal campaign analysis and does not sell the information. Depending on browser and Meta settings, data shared may include page URL, event name, IP address, browser or device information, and cookie or similar identifiers. AGAPAY does not send names, email addresses, parish names, or form-message contents through the Pixel.
facebook.com/privacy/policy ->
G
Google
Optional Google Calendar synchronization for a parent or authorized parish user who chooses to connect an account. Data shared: authorization information and the event details needed to create, update, or reconcile the selected calendar events. Calendar connection is optional.
policies.google.com/privacy ->

We do not share personal data with any party beyond those listed above, except as required by law (see Section 7 below).

Section 7

Data Sharing & Disclosure

Beyond the service providers listed in Section 6, AGAPAY may share your personal data only in the following limited circumstances:

We never sell personal data. AGAPAY does not sell, rent, trade, or otherwise transfer your personal data to third parties for their own commercial use. This is an unconditional commitment.
Section 8

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The following retention periods apply:

Financial and transaction records (donation amounts, dates, funds) 7 years minimum
Liturgical memorial and intention names 7 years (with transaction record)
Donor account and profile data (active accounts) Duration of relationship + 3 years
Donor account data (closed or inactive accounts) 3 years post-closure
Organization account data Duration of registration + 7 years
AGAPAY Learn child and education records While maintained by the parent or guardian account, subject to deletion requests and legal obligations
Directory household, person, and publication records While maintained by the household or Organization, plus records needed for safety, audit, or legal obligations
Technical usage logs and server logs 90 days (unless active security investigation)
Support and communications data 3 years from last communication
Terms versions and legal acceptance records The accepted Terms version is retained permanently; acceptance evidence is retained for the account relationship plus 7 years, or longer when reasonably necessary for a known legal claim

Upon expiration of the applicable retention period, data is securely deleted or irreversibly anonymized using industry-standard methods. You may request early deletion of non-legally-required data under Section 10-11 below.

Parish exports, closure, and retained copies

Current availability, August 30, 2026: Parish data exports are available. Automatic parish closure and deletion are not enabled. Preparing or downloading an export does not cancel billing, close the parish account, or delete parish data.

Requesting an export. Authorized parish administrators may use Data portability in the parish dashboard after signing in and completing the required identity verification. Exports provide eligible parish-scoped CSV and JSON records, supported uploaded files, and a manifest listing the export window, included files, checksums, and exclusions. They may contain sensitive parish, directory, giving, or accounting information. Authentication credentials, independent donor accounts, parent-owned Learn records, and other parishes' private data are excluded; shared identities contain limited fields. External media may be listed as links. An ordinary export is not a complete inventory of every stored or third-party copy. Contact hello@agapay.app if an export exceeds the limits shown in the dialog, needs unsupported media, fails, or is unavailable.

Temporary archives and downloaded copies. Export archives are held in private storage and downloaded through authenticated access. Download access expires seven days after the request, at the deadline shown in the dashboard. Expired archives are scheduled for cleanup; expiration of access is not a claim that every stored or recovery copy was erased at that instant. Export status and integrity metadata may remain after archive cleanup. Save and inspect the archive before the deadline, keep it secure, and share it only with authorized recipients. AGAPAY cannot recall copies already downloaded or transferred by the parish.

Cancellation and deletion are separate. Subscription cancellation remains available through the billing controls or support. It does not automatically delete records, and an export does not cancel the subscription. Contact us to request closure or deletion while the automated workflow is unavailable. These requests remain subject to identity and authority checks, applicable rights, and lawful retention exceptions; the disabled automated workflow does not suspend an individual's privacy rights or applicable response deadlines.

Retained records. A future automated closure would remove only eligible active parish data after a saved and verified final export, separate confirmation, and required safeguards. Accounting books, transactions, supporting financial or legal evidence, relevant support correspondence, legal holds, and minimal closure records may need to remain with restricted access. Independent donor accounts, parent-owned Learn records, and identities needed by another parish are not erased as part of one parish's closure. The applicable categories, retention periods, and any review dates must be disclosed before closure is authorized. A review date is not confirmation of automatic deletion. The draft automated-closure retention schedule is not approved by publication of this notice, and this notice does not replace the retention periods above with that draft schedule.

Backups and restoration. Deleting active records is separate from expiry of backups and provider recovery history. Strict backup expiry for automatic parish closure is not yet enabled: the current recovery process can preserve the newest recovery copy when all copies are past the normal expiry period. We therefore do not promise that downloading an export or cancelling a subscription immediately erases every backup. Automatic closure remains unavailable until backup expiry, recovery-copy inventory, and restoration safeguards are verified. Those safeguards require replaying the independent closure record before restored service resumes so that a completed closure is not undone by a restore. Records legitimately retained after closure may also appear in later backups until approved disposal.

Copies outside the parish purge. Records independently held by Stripe, email delivery providers, external media services, the parish, or other recipients follow their own applicable retention and deletion controls. AGAPAY's parish export or active-data purge does not itself erase those copies. We remain responsible for applicable obligations concerning providers processing data on our behalf.

Individual requests. Parish-wide portability is separate from your right to request access, correction, or deletion of your own information. Use the contact and request methods below or the My AGAPAY account deletion page; you do not need parish administrator access to submit an individual request.

Section 9

Security

AGAPAY employs administrative, technical, and physical safeguards designed to protect your personal data against unauthorized access, disclosure, alteration, or destruction.

Encryption at Rest Encryption at rest provided by Cloudflare-managed D1, KV, and private R2 storage used by the platform.
Encryption in Transit TLS 1.2 / 1.3 encryption for all data transmitted between your device and the platform.
PCI-DSS Compliance Payment processing via Stripe's PCI-DSS Level 1 certified infrastructure. AGAPAY never handles raw card data.
Access Controls Personal data access is limited through application authorization checks, tenant scoping, and role or capability checks appropriate to the feature.
DDoS & Threat Protection Cloudflare network-level protection against distributed denial-of-service attacks and malicious traffic.
Incident Response In the event of a confirmed data breach affecting your personal data, we will notify you and applicable authorities within 72 hours where required by law.

No method of transmission over the internet or electronic storage is completely secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security against all threats. You also play a role: keep your account credentials confidential and notify us immediately at hello@agapay.app if you suspect unauthorized access.

Section 10

California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) affords you the following rights regarding your personal information:

Right to Know

Request disclosure of the categories and specific pieces of personal information collected about you, and how it is used and shared.

Right to Delete

Request deletion of your personal information, subject to exceptions including our legal obligation to retain financial records.

Right to Correct

Request correction of inaccurate personal information we maintain about you.

Right to Opt Out

AGAPAY does not sell or share personal information as defined by CCPA/CPRA. No opt-out is required, but we disclose this affirmatively.

Right to Limit Sensitive Data Use

AGAPAY does not use sensitive personal information for purposes beyond those required to provide services.

Right to Non-Discrimination

We will not discriminate against you - in pricing, service quality, or otherwise - for exercising any CCPA/CPRA right.

To exercise any California privacy right, submit a verifiable written request to hello@agapay.app with subject line "California Privacy Request." We will verify your identity before processing any request and respond within 45 days as required by law, with a possible 45-day extension for complex requests with prior notice.

You may designate an authorized agent to submit requests on your behalf by providing written authorization. We may require direct verification from you if an agent submits a request.

Section 11

Texas Privacy Rights (TDPSA)

If you are a Texas resident, the Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, affords you the following rights regarding your personal data:

Right to Access

Confirm whether we process your personal data and request access to the specific data we hold about you.

Right to Correction

Request correction of inaccuracies in your personal data, taking into account the nature of the data and our purposes for processing it.

Right to Deletion

Request deletion of personal data you have provided or that we have collected about you, subject to our lawful retention obligations.

Right to Data Portability

Obtain a copy of your personal data in a portable, readily usable format, to the extent technically feasible.

Right to Opt Out

AGAPAY does not engage in targeted advertising, sale of personal data, or profiling for consequential decisions. No opt-out is required, but we disclose this affirmatively.

To exercise any Texas privacy right, submit a written request to hello@agapay.app with subject line "Texas Privacy Request." We will respond within 45 days, with a possible 45-day extension for complex requests.

Appeals. If we decline to act on your request, you may appeal by responding in writing to our decision email. If your appeal is denied, you may contact the Texas Attorney General to submit a complaint.

Section 12

Children's Privacy (COPPA)

AGAPAY's accounts and administrative tools are intended for adults. Children are not permitted to create their own AGAPAY account or independently submit personal information to the platform.

AGAPAY Learn is a parent-managed homeschool service. A parent or legal guardian may enter information about a child, including the child's first name, age, grade or form, learning plans, attendance, academic work, scores, grades, notes, report cards, and transcripts. Parish Directory households and authorized parish personnel may also maintain limited information about minors, including household relationships, contact or profile information, photos, and carefully controlled publication settings. These features are operated by adults on behalf of their children or communities.

By entering information about a minor, the adult represents that they are the child's parent or legal guardian, or are otherwise authorized by the parent or legal guardian and the Organization to provide and manage that information. AGAPAY does not use child data for advertising or sell it. A parent or guardian may contact hello@agapay.app to request access, correction, or deletion, subject to identity verification, Organization responsibilities, and lawful retention requirements.

If you believe a child has used AGAPAY independently, or that child information was entered without appropriate authority, contact us immediately at hello@agapay.app. We will investigate and take appropriate action, which may include restricting access or deleting information that is not required to be retained.

Memorial names submitted for liturgical commemoration may include the names of minors; this data is treated with the same protections as all personal data under this policy, and is transmitted only to the designated clergy of the recipient Organization.

Section 13

Policy Updates & Notification

We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or platform features. When we make material changes, we will:

Non-material changes - such as typographical corrections, clarifications that do not change our practices, or updated contact information - may be made without advance notice and will be effective upon posting.

When a material change requires renewed agreement, AGAPAY will request affirmative acceptance from affected registered account holders and preserve evidence of that acceptance. We will not apply a material change to a dispute of which AGAPAY had actual notice before the change. If you do not agree, you may terminate your account before the change takes effect for you by contacting hello@agapay.app.

Section 14

Dispute Resolution

Disputes arising out of this Privacy Policy or AGAPAY's handling of personal data are governed by Section 24 of the Terms of Service, including its 30-day good-faith informal-resolution process, small-claims option, court process, voluntary post-dispute alternatives, and limits on retroactive changes. AGAPAY does not require arbitration or a class-action waiver.

Section 15

Contact & Privacy Requests

For privacy-related questions, concerns, data access requests, or to exercise any right described in this policy, please contact AGAPAY at:

Account deletion: My AGAPAY users may initiate deletion from Account Settings or use the dedicated My AGAPAY account deletion page.

We will respond to all privacy-related inquiries within 30 days of receipt. For requests under California or Texas law, we will respond within the statutory timeframe (45 days, with possible extension). We will request identity verification before processing any data access, correction, or deletion request.

^