Skip to main content
Parish Glow

Cookie Policy

Last updated:

1. What Cookies Are & What We Use

To make Parish Glow work, we need to store a small amount of information in your browser. We use cookies, local storage, and similar technologies to keep you logged in, secure your parish's data, and help us understand when the application crashes so we can fix it.

Scope of this Policy: This Cookie Policy applies strictly to the Parish Glow software application served at parishglow.com. The separate marketing website used to promote Parish Glow is out of scope for this document and is governed by its own distinct Cookie Policy.

Below is the exact taxonomy of cookies and trackers deployed by the Parish Glow application:

NameSet ByPurposeTypeDurationSub-processor
sb-<project-ref>-auth-tokenSupabaseManages OAuth and PKCE JSON Web Token access and refresh tokens to maintain secure user authentication across requests.EssentialSessionSupabase
_vercel_jwtVercelEnforces edge-level access control, deployment protection, and internal application routing within the Vercel infrastructure.EssentialSessionVercel
__stripe_mid, __stripe_sidStripeDetects fraudulent transaction patterns, ensures 3D Secure checkout compliance, and prevents financial loss during payment flows.Essential1 Year / SessionStripe
CSRF noncesParish GlowCryptographic nonces utilized strictly for Cross-Site Request Forgery (CSRF) protection.EssentialSessionNone
sentryReplaySessionSentryDisabled by default unless explicit upfront consent is captured. Replay-capable SDK code is dynamically imported only after consent state is resolved. When enabled, records only masked DOM and interactions needed for debugging and does not capture text input contents, passwords, payment fields, pastoral notes, minor profiles, or other sensitive fields.AnalyticsUp to 60 MinsSentry
sentry-trace, baggageSentryFacilitates distributed tracing to link frontend user actions with backend database latency and server errors.AnalyticsSessionSentry

2. Essential Cookies

In plain English: These are the cookies that keep the lights on. Without them, you couldn't log in, pay for your parish subscription, or use the app securely.

Under the ePrivacy Directive, the General Data Protection Regulation (GDPR), and the California Privacy Rights Act (CPRA), cookies categorized as "Strictly Necessary" or "Essential" are exempt from prior consent requirements and cannot be disabled via opt-out mechanisms. Our essential cookies include Supabase tokens for authentication, Vercel tokens for secure infrastructure routing, and Stripe tokens for fraud prevention.

Stripe cookies are treated as essential only to the extent they are used for checkout security, fraud prevention, payment processing, and related compliance. Parish Glow maintains merchant and data-processing terms restricting Stripe from using Parish Glow checkout telemetry for independent advertising, sale, or sharing purposes outside those payment and security functions.

3. Analytics Cookies

We use Sentry to monitor application health. Sentry error monitoring may capture technical diagnostics such as stack traces, browser metadata, and performance traces. Sentry Session Replay remains off by default unless and until the user has given explicit, upfront consent; replay-capable SDK code is dynamically imported only after consent state is resolved; when enabled, text inputs, passwords, payment fields, pastoral notes, minor profiles, and other sensitive fields are masked or blocked so Parish Glow does not intentionally record keystroke contents or sensitive page content.

Because Sentry Session Replay records interaction telemetry that is not strictly necessary to provide the requested Service, Parish Glow does not initialize replay code on page load. Replay-capable SDK code is dynamically imported only after consent state is resolved and the user has affirmatively opted in, and it remains disabled for users who opt out, broadcast GPC, or are identified as minors.

4. Marketing Cookies

We do not use marketing cookies in the Parish Glow application.

You are here to manage your parish's music ministry, not to be tracked across the internet. Unless a third-party integration is misconfigured, the Parish Glow application deploys zero marketing or cross-context behavioral cookies. We do not use Facebook Pixels, Google Ads trackers, or similar advertising technologies within the logged-in application.

5. Server-Side Tracking

To measure aggregate page views (such as how many times a particular song's sheet music is accessed), we use Vercel Web Analytics. This is a server-side tracking methodology that does not place third-party cookies on your device. Instead, it tracks unique visitors by generating a temporary hash of the incoming request, combining your IP address and User-Agent. This hash is automatically discarded after 24 hours.

In plain English: Even though we don't put a cookie on your computer for this, the law still considers it tracking.

We recognize that server-side tracking does not bypass privacy legislation. Under the CCPA and CPRA, IP addresses and persistent device hashes are explicitly defined as Personal Information. Routing telemetry through a first-party server before forwarding it to an analytics endpoint still constitutes the active collection of personal data.

6. Your Choices, GPC, and Do Not Sell or Share

Depending on your jurisdiction, you have specific rights regarding how tracking technologies are deployed on your device.

Global Privacy Control (GPC)

Parish Glow explicitly recognizes and honors the Global Privacy Control (GPC) browser signal. As of January 1, 2026, twelve US states mandate the automated recognition of GPC signals:California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas.

If your browser broadcasts a GPC signal, our application will automatically treat it as a valid request to opt out of data sales and sharing, overriding any default opt-in states without requiring you to interact with a banner.

Do Not Sell or Share My Personal Information

The California Privacy Rights Act (CPRA) broadly defines a "sale" as exchanging personal information for valuable consideration, and "sharing" as transferring personal information for cross-context behavioral advertising.

While we do not sell your data to data brokers, the use of certain analytics tools may be considered a "share" under California law. To exercise your right to opt out of sale or sharing, use the Do Not Sell or Share My Personal Information homepage link, the cookie/account privacy control, or email privacy@parishglow.com. The application presents equally prominent Accept All and Decline All choices, makes declining analytics no more difficult than accepting them, honors GPC as an automatic opt-out signal, and blocks analytics or replay trackers until the relevant consent or opt-out state is resolved.

Open Cookie Settings

7. Changes to This Policy

As Parish Glow expands its feature set and as privacy regulations evolve, we will dynamically update this cookie inventory. We will notify Parish Administrators of material changes to this policy via email or an in-app announcement. Your continued use of the Service after such updates constitutes acknowledgment of the revised policy.

8. Contact

Parish Glow, operated by Jeff Bonilla as a California sole proprietorship; LLC formation in progress.

Mailing Address:
Parish Glow
1014 Broadway #2014
Santa Monica, CA 90401

Email Channels:

  • Privacy & Data Requests: privacy@parishglow.com, the cookie/account privacy control, and the Do Not Sell or Share My Personal Information homepage link. Postal notices may be sent to the mailing address above once mail intake is active, but email and web/account controls are the operative privacy-request channels while mail verification is pending.
  • Legal Notices: legal@parishglow.com
  • General Support: support@parishglow.com