Privacy Policy
How Gather Hub handles the personal information churches and their members entrust to it.
Who we are
Gather Hub is software that churches use to run their membership, events, volunteer scheduling and giving. It is operated by Anatoli Railean, doing business as Gather Hub, based in Spokane, Washington, USA. Questions about this policy can be sent to privacy@gather-hub.com.
Two different relationships
This policy covers two groups of people, and our responsibilities to them differ. The first is church staff, who hold an account with us and are our direct customers. The second is congregation members, whose records a church stores in the platform. For member records the church decides what is collected and why; we hold and process that information on the church's instructions. If you are a congregation member with a question about your record, your church can answer it faster than we can, and can correct or remove it themselves.
What we hold
About church staff: name, email address, the role they were given, and the workspace they belong to. About people a church records: name and preferred name, email address, phone number, contact preferences, date of birth, gender, membership status, household, ministry involvement, tags the church applies, and notes staff write about interactions. About giving: the amount, currency, fund, date, the donor's name and email, an optional message the donor attached, and whether a gift was refunded. About participation: event registrations and attendance, group membership and attendance, survey responses, volunteer availability and scheduling responses, and connect card submissions.
What we never hold
Card numbers and bank details never reach us. Giving is processed by Stripe using their own hosted checkout, so payment details go from the donor to Stripe directly; we receive only the outcome of a payment and never the instrument used. We do not collect location data, we do not track people across other websites, and we do not build advertising profiles.
How a church found us
When a church signs up, we record which of our links brought it -- a campaign or search ad, the "Powered by Gather Hub" line on another church's page or email, or another website -- and which plan it was looking at. Our website keeps that in the visitor's own browser for up to 30 days, so a church that reads about us today and signs up next week is still counted, and it keeps nothing else about the visit. We use this only to learn which ways of reaching churches work.
Why we hold it
To provide the service the church is paying for: keeping a membership directory, running events, scheduling volunteers, recording gifts and issuing receipts and annual statements, and sending the messages a church asks us to send. We do not use congregation data for any purpose of our own, we do not sell it, and we do not use it to train machine learning models.
Who can see it
A church's data is visible only to that church's own staff, and what each of them can see depends on the role their administrator gave them. No church can see another church's data; the separation is enforced in the system itself, not by policy alone. Our own staff can access data only where it is necessary to operate or support the service.
Children and young people
Churches record children as part of family and youth ministry, so this platform necessarily holds information about minors. Those records are created by the church, which is responsible for having the consent of a parent or guardian, and we hold them under the same terms as any other member record. Event check-in produces a security code intended to control who may collect a child. If you are a parent or guardian and want your child's record corrected or removed, ask the church directly.
Companies that process data for us
Amazon Web Services hosts the platform and stores its data, and delivers the email and SMS we send. Stripe processes payments and holds the card details we never see. Sentry receives error reports when something goes wrong; personal data is removed before those reports leave the browser or the server, so an error tells us what broke without telling us who it happened to. PostHog receives a count of which modules a workspace opens, attributed to the workspace rather than to a person, with no page content, no names and no addresses. Each of these processes data on our instructions and for no purpose of their own.
Where it is held
In the United States, in the AWS US West (Oregon) region. Backups and error reports stay within the same providers. If you are outside the United States, using the service means your information is transferred there.
How long we keep it
While the church's account is active, we keep its data so the church can use it. A free trial that ends without a subscription becomes read-only and is kept for 90 days after the trial ends; the church's owners and admins are emailed a month, a week and a day before, and the workspace is then deleted with everything in it -- people, gifts, events, uploaded files and staff logins. A paid subscription that ends, whether cancelled or not renewed after its payments failed, becomes read-only in the same way and is kept for 180 days after it ends; the owners and admins are emailed the day it ends and again 60, 30 and 7 days and one day before, and the workspace is then deleted in the same way, on the date those emails give and never sooner. Choosing a plan again before then restores full use, and until then the owners and admins can download a complete copy of the workspace from its settings. Short-lived items are deleted automatically: verification codes, rate limiting records and one-time links expire within hours or days of being created, and a downloaded copy is removed from our storage seven days after it was made. A church that deletes its own workspace has it deleted at once, after which point-in-time backups age out on their own schedule. A church can also delete individual records at any time.
Messages we send
Email that a church sends to its members carries an unsubscribe link, which stops further messages of that kind to that person. Email that is a direct reply to something the recipient just did -- a giving receipt, a registration confirmation, a password reset -- does not, because it is not promotional and stopping it would break the thing the person asked for. SMS is only ever sent to people who ticked a consent box themselves, and replying STOP to any message stops all of them. Church staff can also mark any person as do-not-contact, which we check before every message.
Your rights
You can ask for a copy of the information held about you, ask for it to be corrected, or ask for it to be deleted. For a congregation member, the fastest route is the church that holds the record, as they can act immediately and we act on their instructions. Church staff can contact us directly. Depending on where you live you may have additional rights, including to object to processing or to complain to a data protection regulator; we will honour those regardless of where you are.
Security
Data is encrypted in transit and at rest. Access within a church is limited by role. Sign-in supports multi-factor authentication, and administrative access to our infrastructure requires it. Backups are continuous, and the database is protected against accidental deletion. Errors are monitored so that failures are noticed rather than discovered later. No system is perfectly secure, and we would rather say that plainly than claim otherwise.
If something goes wrong
If personal data is exposed in a way that presents a risk to the people it describes, we will tell the affected churches without undue delay, and give them what they need to inform their own members and any regulator that requires it.
Changes to this policy
If we change this policy in a way that materially affects how information is handled, we will tell account holders before the change takes effect. The date below records when it was last updated.
Contact
Write to privacy@gather-hub.com with any question about this policy, or any request about your information.
Last updated October 8, 2026