Last updated July 19, 2026
This policy explains how SundayHQ handles personal information. Churches use SundayHQ to manage their people, giving, kids ministry, and services. For most of the information in the app, the church is responsible for the information and SundayHQ acts on the church's behalf as its service provider — this policy describes both roles and what they mean for you.
SundayHQ is church-management software operated by SundayHQ ("SundayHQ," "we," "us"). We are based in Calgary, Alberta, Canada, and serve churches in Canada and the United States.
When a church uses SundayHQ to manage its congregation's information— member profiles, giving records, check-in data, and so on — the church decides what to collect and why. In Canadian terms the church is the organization accountable for that personal information under PIPEDA; in U.S. terms the church is the data controller. SundayHQ processes that information only to provide the service, on the church's instructions. If you are a congregant and have a question about your information, your church is the first point of contact; we will support the church in responding.
When you interact with SundayHQ directly — visiting this marketing site, signing up, corresponding with us, or administering a church account — we handle that information as the responsible organization ourselves, as described below.
We do notsell personal information, and we do not use a church's congregant data to advertise to those congregants.
Donations made through SundayHQ are processed on the church's own payment account with Helcim. Funds settle directly to the church; SundayHQ does not hold, route, or take a cut of donated money, and full card details are handled by Helcim, not by us. The church is the merchant of record for its giving. Subscription fees you pay to SundayHQ are processed separately by Stripe. Each of these providers handles cardholder data under its own PCI-compliant systems.
Donation receipts generated in SundayHQ are issued by the church as the registered charity or tax-exempt organization — the church is the legal issuer, and its registration number, name, and authorized signatory appear on the receipt. SundayHQ provides the software that produces them.
This marketing site uses Google Analytics and the Meta pixel to understand traffic and measure advertising, and the SundayHQ application uses PostHog for product analytics. These tools set cookies or similar identifiers. You can control cookies through your browser settings, and where required we will offer a consent mechanism. If you are in a region with specific consent rules (for example, Quebec under Law 25 or the EU), contact us about your choices.
We rely on trusted service providers to run SundayHQ. Each is bound by contractual data-protection obligations, and each processes only what is needed for its function:
| Provider | Purpose |
|---|---|
| Convex | Application database and backend hosting |
| Vercel | Web application hosting |
| Clerk | User authentication |
| Stripe | Subscription billing |
| Helcim | Donation and event payment processing (on the church's own account) |
| Resend | Transactional and broadcast email delivery |
| Expo | Push notification delivery to the member app |
| PostHog | Product analytics |
| Google, Meta | Marketing-site analytics and advertising measurement |
SundayHQ's infrastructure and several of our subprocessors are located in the United States. If your church or its congregants are in Canada, personal information may be stored and processed in the United States and may be accessible to U.S. authorities under applicable law. Canadian law permits these transfers where handled transparently and with comparable protection, which is why we disclose it here.
We keep church data for as long as the church maintains its account, plus a reasonable period afterward, unless the church asks us to delete it sooner or the law requires longer (donation and tax-receipt records, for example, carry legal retention periods that belong to the church). Demonstration sandboxes are automatically deleted after 14 days. Churches can export their data at any time from within the app. Police-check documents should be retained only as long as a church's screening policy requires; churches control whether a document is stored or only its status and expiry.
We use industry-standard measures to protect information, including encryption in transit, role-based access controls within each church account, permission-checked access to sensitive documents, and audited support access. No system is perfectly secure, but we work to protect your information and to notify affected parties and regulators of a material breach as required by law.
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to withdraw consent. For information a church holds about you in SundayHQ, please contact your church, which controls that information; we will assist the church. For information we hold about you directly, contact us and we will respond as the law requires. You can unsubscribe from any marketing email using the link in the message.
SundayHQ is used by churches to record information about children for ministry purposes, entered by church staff — not by children themselves. The service is not directed to children as users. Churches are responsible for parental consent and for handling children's information in line with their policies and applicable law.
We may update this policy from time to time. Material changes will be reflected in the "last updated" date, and we will provide notice where appropriate.
Questions or requests about this policy can be sent through our contact page. If you are a congregant asking about information your church holds, please contact your church first.