Security Policy
How River of Life Church keeps Faith Connect and your information secure, what we expect of Leaders with admin access, and how to report a security concern.
Version 1.0 · Effective [date of publication]
1. Our commitment
River of Life Church protects the information our members entrust to us with technical safeguards built into Faith Connect and clear rules for everyone who has admin access. This policy works alongside our Data Protection Policy and Privacy Policy.
2. Access control
- 2.1Role-based access. Every admin account has a role (such as pastoral, finance or general admin) and specific permissions. Leaders see and change only what their role needs; finance staff, for example, see giving records but not pastoral notes.
- 2.2Checked on every request. Permissions are enforced by our servers on every request, not just hidden in the app. The database itself also limits which records each signed-in user can reach.
- 2.3Least privilege. Access is granted by the Church's leadership, reviewed regularly, and removed promptly when a Leader's role ends.
- 2.4Check-in kiosks. Children's check-in kiosks are locked with a PIN that is blocked after repeated wrong attempts, and volunteers can only use them while they are on the published rota.
3. Sign-in and sessions
- Passwords are never stored in readable form; we store only a strong one-way hash.
- One-time sign-in and reset codes expire after 10 minutes and are blocked after 5 wrong attempts.
- Sessions use short-lived access tokens (15 minutes) that renew automatically, and sign-ins end after 30 days without use.
- Admin console session cookies cannot be read by scripts on the page.
- Repeated requests to sign-in and other sensitive endpoints are rate-limited to slow down guessing attacks.
4. Protecting data
- All connections to Faith Connect are encrypted in transit using HTTPS.
- Card and mobile-money details are entered with Paynow Zimbabwe; we never see or store full card numbers or PINs.
- Uploaded images and documents are shared through time-limited links, except material published for everyone, such as bulletins.
- Data is hosted in [hosting country / data centre] by [platform operator name], under a written agreement that requires it to be kept secure and confidential.
- Exports of member or giving data are limited to authorised roles.
5. Logging and monitoring
Significant admin actions, such as changes to members, permissions, children's records and finances, are recorded in an audit log with who did what and when. The audit log can be reviewed only by senior administrators and is kept for 24 months.
6. What we expect of Leaders
Everyone with admin access must:
- 6.1use a strong password that is not used anywhere else, and never share it or a sign-in code;
- 6.2lock phones and computers used for Faith Connect with a PIN, password or biometrics;
- 6.3sign out of shared or public computers, and never leave the admin console open unattended;
- 6.4not download, screenshot, print or forward member information unless their role requires it, and delete copies once finished;
- 6.5not move member information into personal email, messaging apps or spreadsheets;
- 6.6report a lost device, suspicious message or possible breach to the DPO ([DPO email]) immediately.
7. Keeping your own account safe
- Choose a password you do not use anywhere else.
- The Church will never ask for your password or sign-in code by phone, SMS or WhatsApp.
- Keep the Faith Connect app updated, and lock your phone.
- If you think someone else has used your account, change your password and tell us at [general email].
8. Security incidents
Security incidents are handled under the breach procedure in our Data Protection Policy. We contain the problem, assess the impact, notify POTRAZ within 24 hours where personal data is affected, and tell affected people within 72 hours where there is a high risk to them.
9. Reporting a vulnerability
If you find a security weakness in Faith Connect or our website, please email [security contact email] with enough detail for us to reproduce it. Please do not access, change or share other people's information, and give us reasonable time to fix the issue before telling anyone else. We will acknowledge your report and keep you informed.
10. Review
The Church's leadership, with the DPO and Platform Operator, reviews this policy at least once a year and after any significant incident or change to Faith Connect.