Privacy Policy
Last updated:
1. Introduction & Scope
Welcome to Parish Glow. We build software to help Catholic parishes and their music ministries organize, schedule, and worship together. Because our tools handle information about your parish community, we believe in being entirely transparent about what data we collect, where it goes, and how we protect it.
This Privacy Policy applies to the Service, which includes the application served at parishglow.com, all features described in our Terms of Service, and any official API or MCP server. It does not include the parishglow.com marketing site, which is governed by a separate notice.
To keep things clear, we use a few specific terms throughout this document:
- Parish: The Catholic parish or comparable religious community that subscribes to the Service.
- Subscriber / Customer: The legal entity (the Parish, or its authorized representative) that agrees to the Terms and pays for the Service.
- Parish Administrator: The person at the Parish who manages Parish Glow—typically the music director or designated administrator.
- Musician / Member: Anyone whose personal data is processed through Parish Glow because they participate in the Parish's music ministry (choir members, cantors, instrumentalists, volunteers).
- Content: Anything uploaded to or generated within the Service, including sheet music PDFs, audio reference files, lyrics, rosters, and scheduling assignments.
- Sub-Processor: A third-party vendor we engage to help process data securely.
- Controller / Processor: Legal terms under the GDPR and CCPA. The Parish is generally the Controller for Musician data. Parish Glow is a Processor acting on the Parish's instructions for Musician data, and a Controller for the limited Parish-Administrator account and billing data we need to run the Service.
2. Information We Collect — Parish Administrators (Controller-Side)
If you are a Parish Administrator setting up or managing a Parish Glow account, we act as a Data Controller for the information necessary to provide you with the Service and bill your Parish.
We collect the following categories of information from Parish Administrators:
- Identity & Auth Data: Your email address, hashed password, OAuth tokens, display name, and avatar URL.
- Account & Role Data: Your role at the parish, permission overrides, and last-login timestamps.
- Billing Information: Stripe customer references, subscription state, and metered usage.
What we specifically DO NOT collect: We do not collect or store payment-card data (PAN or CVV). All payment processing is handled via Stripe-hosted Checkout, meaning your credit card or bank account numbers never touch Parish Glow servers. We also do not collect biometric data, precise geolocation, social security numbers, or tax IDs.
3. Sub-Processors
To provide a reliable, modern application, we rely on specialized third-party service providers. We engage these vendors to process data only as needed to operate the Service, and we work to bind them, where applicable, to terms that limit their use of personal data to providing services to us.
Below is our list of Sub-Processors. We update it as our vendors change.
| Sub-processor | Role | Data category processed |
|---|---|---|
| Supabase | Database, authentication, and file storage | Authoritative store: authentication credentials and substantially all Service application data, including parish-private storage. |
| Vercel | Application hosting | HTTP request logs, edge cache, build artifacts, and server-rendered output. |
| Vercel Analytics | Aggregate usage analytics | Aggregated, cookie-less page-view metrics. |
| Sentry | Error monitoring | Application error events, including URLs, stack traces, and runtime metadata. |
| Stripe | Payments and billing | Billing identifiers, billing email, and subscription metadata. No payment-card data touches Parish Glow servers. |
| Twilio | SMS messaging | Recipient phone number and message body for Service-originated SMS. |
| Resend | Transactional and safety email | Recipient email address, subject, and message body. |
| LiveKit | Listening Room audio/video | Meeting participant identifiers and display names, participant roles, and live audio and video, including any session recordings. |
| OpenRouter | AI model gateway | Prompts, message history, and generated output for AI features, routed to the model providers described in the AI note below. |
| OpenAI | AI processing (summaries, translation) | Message text and related metadata for chat digests, prayer-request summaries, and translation. |
| Anthropic | AI content moderation and safety classification | Message text processed to detect harmful content and to support our safety and mandated-reporting workflows. |
| Microsoft (Azure AI Content Safety) | AI content moderation | Message text processed to detect harmful content. |
| Microsoft | Optional sign-in provider | Email and basic profile at sign-in, only if a user chooses to sign in with a Microsoft account. |
| AI processing, calendar integration, and optional sign-in | Prompts and generated output for certain AI features (via the Google Gemini API); calendar tokens and event details for parishes that connect a Google Calendar; and email and basic profile at sign-in for users who choose to sign in with a Google account. | |
| Cloudflare (Turnstile) | Bot / abuse protection on public forms | A verification token and related browser signals, including requester IP address, on public intake forms. |
| Web push services (Apple, Google, Mozilla) | Browser push notification delivery | Push endpoint, encryption keys, and notification payload for users who enable push notifications. The specific provider depends on the user’s browser. |
| Upstash | Rate limiting | Per-IP and per-user rate-limit counters and share-link revocation cache. No persistent user profile is stored. |
| Inngest | Background job processing | Background-job orchestration events, which may include job-payload metadata. |
| iPostal1 * | Business mailing address | Inbound postal mail addressed to our business mailing address. |
* iPostal1 operates our registered business mailing address and processes only inbound physical mail. Service user data is not routed through iPostal1.
A note on Artificial Intelligence (AI): Some Service features use AI models. Depending on the feature, we send the relevant input to a model provider to generate the output you requested. This includes generation features (such as the Sunday brief and cantor welcomes), which route prompts through OpenRouter or to Google’s Gemini API, and community-safety features, which send message text to Anthropic and to Microsoft Azure AI Content Safety to help detect harmful content. Through OpenRouter, a prompt may be handled by one of several underlying model providers, which currently include Anthropic, OpenAI, Google, and DeepSeek. We aim to send only the data needed for each feature. We do not use parish or member data to train our own models, and we are reviewing each provider’s data-retention and training practices; we will update this notice as those arrangements are confirmed.
Where a minor participates in parish chat, that message content may be processed by the same AI safety providers described above when our community-safety workflows run.
Embedded content and fonts. Some pages load content from third parties, such as embedded videos and web fonts. When they do, those third parties may receive your IP address and browser information. See our Cookie Notice for details.
4. Information We Collect — Musicians & Members (Data-Subject-Side)
If you are a Musician or Member participating in a Parish's music ministry, your Parish Administrator adds your information to Parish Glow to schedule and coordinate worship. In this context, your Parish is the Data Controller, and Parish Glow is the Data Processor.
The information processed on behalf of your Parish includes:
- Musician Roster Data: Your name, contact information (email, phone number), ensemble affiliations, availability windows, and household relationships.
- Scheduling & Content: Which Masses you are scheduled for, your signups, and any comments or reactions you post on parish announcements.
- Telemetry: Per-member page-view logs (to help administrators understand practice telemetry) and aggregate song usage.
Just like with Parish Administrators, we do not collect biometric data, precise geolocation, social security numbers, or government IDs from Musicians.
5. Your Rights (CCPA/CPRA, GDPR, State-by-State)
In plain English: Depending on where you live, you have specific legal rights regarding your personal data, including the right to know what we have, the right to correct it, and the right to delete it. Because we act as a Service Provider to your Parish, the fastest way to exercise these rights is to contact your Parish Administrator directly. However, you may also contact us, and we will route your request appropriately.
California Residents (CCPA/CPRA): Parish Glow operates primarily as a Service Provider to non-profit religious organizations (which are exempt from the CCPA). We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
State-by-State Applicability (Texas, Nebraska, Connecticut, Maryland, etc.): We comply with the rapidly expanding landscape of state privacy laws taking effect in 2026. If you reside in a state with comprehensive privacy legislation, you have the right to access, correct, delete, and obtain a copy of your personal data. Furthermore, we strictly adhere to state-specific prohibitions regarding the sale of sensitive data and data minimization mandates (such as the Maryland Online Data Privacy Act).
European Economic Area (GDPR): Parish Glow is designed for and marketed exclusively to Catholic parishes within the United States. We do not intentionally target data subjects within the European Union. However, if the GDPR applies to your data, you have the right to request access, rectification, erasure, restriction of processing, and data portability under Chapter 3 of the GDPR.
6. Children's Privacy & Minor Musicians (COPPA)
Catholic parishes routinely include youth in music ministry, such as children's choirs and adolescent sacrament-preparation ministers. Protecting the privacy of these young musicians is a foundational priority for Parish Glow, aligning with both federal law and diocesan Safe Environment (VIRTUS) policies.
In plain English: We treat the data of anyone under 16 with extreme caution. We turn off all tracking, disable AI processing for their profiles, and require parental consent for children under 13.
The federal Children's Online Privacy Protection Act (COPPA) strictly mandates that operators of commercial websites and online services obtain verifiable parental consent before the collection, use, or disclosure of any personal information from children under the age of 13.
When a user is identified as a minor (under 16 years of age) during onboarding or by a Parish Administrator, Parish Glow triggers automated data quarantine protocols. These protocols programmatically disable third-party tracking pixels, strip the user's sessions from behavioral analytics aggregations, and definitively sequester the minor's profile from any downstream artificial intelligence processing or automated decision-making engines.
7. Sensitive Information & Religious Affiliation
Because Parish Glow is a platform built for Catholic music ministries, the mere fact that you have a profile on our Service indicates a religious affiliation.
Under the California Privacy Rights Act (CPRA), the Connecticut Data Privacy Act (CTDPA), the Maryland Online Data Privacy Act (MODPA), and GDPR Article 9, information revealing an individual's religious beliefs is classified as Sensitive Personal Information or Special Category Data.
We treat all ministry scheduling assignments, liturgical preferences, and sacrament-preparation participation as highly sensitive data. We process this data strictly to provide the requested scheduling and worship-planning services to your Parish. We will never sell this data, nor will we use it to profile you for advertising purposes.
Sacramental Confidentiality Boundary: Parish Glow does not, and must not, store information protected by the seal of confession or analogous sacramental confidences. Our platform is designed for liturgical planning and music ministry coordination, not pastoral counseling records.
8. Retention & Deletion
We keep your data only as long as necessary to provide the Service to your Parish or to comply with our legal obligations.
- Identity & Auth Data: Retained until account deletion.
- Musician Roster & Scheduling Data: Persisted for the duration of the Parish's active subscription, as curated by the Parish Administrator.
- Communications & Audit Logs: Retained for security, compliance, and incident-response purposes.
- Billing Data: Retained as required for tax and financial reconciliation purposes.
When a Parish cancels its subscription, or when a Parish Administrator deletes a Musician's profile, the associated data is queued for deletion from our active databases and subsequent removal from our encrypted backups in accordance with our data lifecycle policies.
9. Security
We implement commercially reasonable technical and organizational measures to protect your data against unauthorized access, loss, or alteration. All data is encrypted in transit (via TLS) and at rest (within Supabase's Postgres infrastructure). Access to parish-private storage buckets (such as publisher-licensed sheet music) is strictly scoped using Row Level Security (RLS) policies to ensure data never leaks across parishes.
While we strive to use enterprise-grade security practices, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we commit to notifying Parish Administrators promptly in the event of a confirmed data breach.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will notify Parish Administrators via email or through a prominent notice within the Service before the changes take effect. Your continued use of the Service after the effective date constitutes your acknowledgment of the updated policy.
11. Contact + Do Not Sell or Share My Personal Information
Do Not Sell or Share My Personal Information: Parish Glow does not sell your personal information for monetary consideration, nor do we share it for cross-context behavioral advertising. If you have questions about our data practices or wish to submit a privacy request under the CCPA or other state laws, please contact us using the information below.
Entity Information:
Parish Glow, operated by Jeff Bonilla as a California sole proprietorship; LLC formation in progress.
Mailing Address:
Parish Glow
1014 Broadway #2014
Santa Monica, CA 90401
Contact Emails:
- Privacy & Data Subject Requests: privacy@parishglow.com
- Legal Notices: legal@parishglow.com
- General Support: support@parishglow.com