Privacy Policy

How River of Life Church collects, uses, shares and protects your personal information when you use our website and the Faith Connect app, and the rights you have over it.

Version 1.0 · Effective [date of publication]

1. Who we are

River of Life Church ([registered name of the church trust or association]) is the data controller for personal information in our website and the Faith Connect app. We are licensed as a data controller by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), licence number [POTRAZ data controller licence number].

Our Data Protection Officer is [Data Protection Officer name]. Contact them at [DPO email] or by post at [physical address], Harare, Zimbabwe.

We handle your information under the Cyber and Data Protection Act [Chapter 12:07] ("the CDPA") and its regulations.

2. What we collect and why

We collect only what we need to care for our church family. Most of it comes from you; some is created as you use the app (such as attendance and check-in times).

InformationExamplesWhy we use itLawful basisWho can see it
ProfileName, phone, email, photo, date of birth, site attendedRunning your account, keeping in touch, birthday greetingsOur agreement with you; consent for birthday greetingsYou and Leaders with access
Groups and servingSmall groups, rotas, attendance, event RSVPsOrganising groups, rotas and eventsOur agreement with you; legitimate interestsGroup and ministry leaders
Prayer, testimonies and announcementsPrayer requests, testimonies, reactions, life-event announcementsPraying for you and encouraging othersConsentOnly the audience you choose
Children's ministryChild's name, age, allergies, medical notes, authorised collectors, check-in times, and consents for photos, first aid, media and activitiesKeeping Children safe and following parents' wishesParent's or guardian's consent; protecting life and safetyParents and guardians, children's team
Giving and ticketsAmount, fund, currency, date, payment referenceProcessing payments, your giving history, our accountsOur agreement with you; legal dutyYou and finance staff
Pastoral and welfareWelfare notes, meal support, safeguarding recordsPastoral care and safeguardingConsent; protecting life and safety; legal dutyAuthorised pastors and safeguarding leads only
TechnicalDevice type, app version, push token, sign-in times, audit logsSecurity, notifications and fixing problemsLegitimate interestsTechnical administrators

3. Sensitive information

Information about your religious life, health and Children is Sensitive Data under the CDPA. We ask for your consent to process it separately from accepting our Terms & Conditions, and we only use it for the purposes above.

You can withdraw consent at any time in the app or by contacting our Data Protection Officer. Withdrawing does not affect what was done before, but some features (such as children's check-in) need this information and will stop being available.

4. Who we share it with

We never sell or rent your information, or share it for anyone else's marketing. We do not make decisions about you by automated means alone. We share information only with:

  • [platform operator name] which hosts and maintains Faith Connect for us, as our data processor.
  • Paynow Zimbabwe to process gifts and ticket payments.
  • Google Firebase Cloud Messaging to deliver push notifications to your phone.
  • [email / SMS provider] to send emails and text messages, such as sign-in codes.
  • Authorities where the law requires it, or where it is needed to protect someone from serious harm.

Each provider may use your information only to provide its service to us, under a written agreement that requires confidentiality and security.

5. Transfers outside Zimbabwe

Our main database and files are hosted in [hosting country / data centre]. Push notifications pass through Google's servers outside Zimbabwe; these carry a device token and the message text, not your profile.

We transfer information abroad only where section 28 of the CDPA is met: the recipient ensures an adequate level of protection, or another lawful ground under section 29 applies.

6. How long we keep it

InformationHow long
Account and profileWhile your account is active, then 12 months, then deleted or anonymised
Prayer requests, testimonies, messagesUntil you delete them or close your account
Giving and payment records6 years, to meet accounting and tax duties
Children's check-in recordsWhile the Child attends, then 12 months
Safeguarding and welfare recordsAs long as the law and good safeguarding practice require
Security and audit logs24 months

7. How we protect it

Access is role-based, so Leaders see only what their role needs. Passwords are stored securely hashed, connections are encrypted, and Leaders' actions are logged. Our Security Policy gives more detail.

If a breach affects your information, we will notify POTRAZ within 24 hours of becoming aware of it. Where it poses a high risk to you, we will tell you within 72 hours, with steps you can take.

8. Cookies

Our website and admin console use essential cookies to keep you signed in and secure, and to remember your display preference. If we add analytics or other non-essential cookies, we will ask for your consent first.

9. Your rights

Under the CDPA you may:

  • ask what information we hold about you and get a copy;
  • ask us to correct information that is wrong or incomplete;
  • ask us to delete your information, unless we must keep it by law;
  • object to our use of your information, or withdraw consent;
  • manage push, SMS and email preferences in the app at any time.

To use these rights, contact our Data Protection Officer at [DPO email]. We will respond within 30 days. Parents and guardians exercise these rights for their Children. If you are unhappy with our response, you may complain to POTRAZ as the Data Protection Authority.

10. Changes to this policy

  1. 10.1
    Updates. We will post any changes here with a new version number and date, and tell you in the app about significant changes.
  2. 10.2
    Contact. Questions about this policy: [DPO email] · [phone number].