Privacy Policy
How River of Life Church collects, uses, shares and protects your personal information when you use our website and the Faith Connect app, and the rights you have over it.
Version 1.0 · Effective [date of publication]
1. Who we are
River of Life Church ([registered name of the church trust or association]) is the data controller for personal information in our website and the Faith Connect app. We are licensed as a data controller by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), licence number [POTRAZ data controller licence number].
Our Data Protection Officer is [Data Protection Officer name]. Contact them at [DPO email] or by post at [physical address], Harare, Zimbabwe.
We handle your information under the Cyber and Data Protection Act [Chapter 12:07] ("the CDPA") and its regulations.
2. What we collect and why
We collect only what we need to care for our church family. Most of it comes from you; some is created as you use the app (such as attendance and check-in times).
| Information | Examples | Why we use it | Lawful basis | Who can see it |
|---|---|---|---|---|
| Profile | Name, phone, email, photo, date of birth, site attended | Running your account, keeping in touch, birthday greetings | Our agreement with you; consent for birthday greetings | You and Leaders with access |
| Groups and serving | Small groups, rotas, attendance, event RSVPs | Organising groups, rotas and events | Our agreement with you; legitimate interests | Group and ministry leaders |
| Prayer, testimonies and announcements | Prayer requests, testimonies, reactions, life-event announcements | Praying for you and encouraging others | Consent | Only the audience you choose |
| Children's ministry | Child's name, age, allergies, medical notes, authorised collectors, check-in times, and consents for photos, first aid, media and activities | Keeping Children safe and following parents' wishes | Parent's or guardian's consent; protecting life and safety | Parents and guardians, children's team |
| Giving and tickets | Amount, fund, currency, date, payment reference | Processing payments, your giving history, our accounts | Our agreement with you; legal duty | You and finance staff |
| Pastoral and welfare | Welfare notes, meal support, safeguarding records | Pastoral care and safeguarding | Consent; protecting life and safety; legal duty | Authorised pastors and safeguarding leads only |
| Technical | Device type, app version, push token, sign-in times, audit logs | Security, notifications and fixing problems | Legitimate interests | Technical administrators |
3. Sensitive information
Information about your religious life, health and Children is Sensitive Data under the CDPA. We ask for your consent to process it separately from accepting our Terms & Conditions, and we only use it for the purposes above.
You can withdraw consent at any time in the app or by contacting our Data Protection Officer. Withdrawing does not affect what was done before, but some features (such as children's check-in) need this information and will stop being available.
5. Transfers outside Zimbabwe
Our main database and files are hosted in [hosting country / data centre]. Push notifications pass through Google's servers outside Zimbabwe; these carry a device token and the message text, not your profile.
We transfer information abroad only where section 28 of the CDPA is met: the recipient ensures an adequate level of protection, or another lawful ground under section 29 applies.
6. How long we keep it
| Information | How long |
|---|---|
| Account and profile | While your account is active, then 12 months, then deleted or anonymised |
| Prayer requests, testimonies, messages | Until you delete them or close your account |
| Giving and payment records | 6 years, to meet accounting and tax duties |
| Children's check-in records | While the Child attends, then 12 months |
| Safeguarding and welfare records | As long as the law and good safeguarding practice require |
| Security and audit logs | 24 months |
7. How we protect it
Access is role-based, so Leaders see only what their role needs. Passwords are stored securely hashed, connections are encrypted, and Leaders' actions are logged. Our Security Policy gives more detail.
If a breach affects your information, we will notify POTRAZ within 24 hours of becoming aware of it. Where it poses a high risk to you, we will tell you within 72 hours, with steps you can take.
9. Your rights
Under the CDPA you may:
- ask what information we hold about you and get a copy;
- ask us to correct information that is wrong or incomplete;
- ask us to delete your information, unless we must keep it by law;
- object to our use of your information, or withdraw consent;
- manage push, SMS and email preferences in the app at any time.
To use these rights, contact our Data Protection Officer at [DPO email]. We will respond within 30 days. Parents and guardians exercise these rights for their Children. If you are unhappy with our response, you may complain to POTRAZ as the Data Protection Authority.
10. Changes to this policy
- 10.1Updates. We will post any changes here with a new version number and date, and tell you in the app about significant changes.
- 10.2Contact. Questions about this policy: [DPO email] · [phone number].