Privacy and cookies

Last updated: 8 March 2026

Note: You are viewing a draft policy used during our pilot phase. We welcome feedback before final publication.

Who we are

This website and service (“Church Cashbook”) is provided for participating churches to record and report church finances. For data protection purposes, the data controller is: See your administrator. If you have questions, contact: support@example.org.

What personal data we collect

  • User account details: username, name, email address, login timestamps.
  • Operational audit data: records of significant actions (e.g., creating/editing transactions) for accountability.
  • Financial record content: transaction descriptions may sometimes contain personal information if entered by users.
  • Gift Aid data (where used): donor name and address details needed to support Gift Aid claims.
  • Attachments: receipts/invoices uploaded by users may contain personal data depending on the document.

How we use your data

  • To provide the service: record transactions, produce reports, and support Gift Aid workflows (if enabled).
  • To keep the service secure: authentication, access control, and audit logging.
  • To support users: responding to support requests and investigating issues.

Lawful basis

We process data as necessary for the legitimate interests of churches in keeping proper financial records, and where applicable to meet legal obligations (e.g., charity accounting and Gift Aid claim evidence). If you add special-category or unnecessary personal data into descriptions or uploads, please avoid doing so.

Who can see what

Access is controlled by roles. Users can only see churches and functions they have permission for. Gift Aid information is restricted and may be masked for some roles.

Tip: If you believe you have inappropriate access (too much or too little), contact your administrator.

Cookies and local storage

This service uses essential session cookies to keep you signed in and protect the site from security risks (e.g. CSRF). Some accessibility preferences may be stored in your browser (cookie or local storage depending on configuration).

We do not use advertising cookies. We do not sell your data.

Data sharing

Data is shared only with authorised users of the relevant church/organisation and (where applicable) service providers who host or maintain the system. We do not share data for marketing.

Your rights

You have rights under UK GDPR, including access, rectification, and (in some cases) erasure or restriction. Some records (e.g., audit logs and accounting evidence) may need to be retained for governance/legal reasons.

To request access or raise concerns, email: support@example.org.

Gift Aid data — additional information

Where churches use the Gift Aid feature, we collect and store donor personal data (full name, home address, and postcode) as required by HMRC to support Gift Aid claims. This data is processed under our legal obligation as claim administrators and the legitimate interest of the church in maximising Gift Aid income.

Encryption at rest: Gift Aid donor personal data is encrypted in the database using authenticated encryption (XSalsa20-Poly1305). The encryption key is held separately from the database, outside the web root, and is not included in database backups.

Access controls: Gift Aid personal data is accessible only to users with explicit PII permission for the relevant church (typically the Gift Aid Administrator and Treasurer). Other authorised users see masked values only.

Retention: HMRC requires Gift Aid declarations to be retained for six years after the date of the last claim submission to which a declaration relates. We cannot delete or anonymise donor records within this window even if requested.

Withdrawal: Donors may withdraw their Gift Aid declaration at any time by contacting the church treasurer or Gift Aid Administrator. Withdrawal closes the declaration (no further donations are linked to it). If the declaration has been used in a submitted HMRC claim, the personal data is retained in encrypted form until the six-year HMRC window has elapsed, after which anonymisation is completed. If no claim has been submitted, data can be anonymised immediately on request.

Retention

We keep data only as long as needed for operational, governance, and legal purposes. Please see Data retention for the current retention approach, including the specific HMRC six-year rule for Gift Aid declarations.