Legal

Privacy notice

Last updated 14 August 2026 · hello@chapelhq.com

1Who holds your data

The church that gave you your account. ChapelHQ holds no congregation of its own — each church holds its own records, and this page names yours once you are signed in. For anything about your own record, the church office is who to ask.

Under Malaysia’s Personal Data Protection Act 2010, your church is the data user — it decides what is held about you and why. ChapelHQ is the software your church uses to hold it, and acts as its data processor, on its instructions.

2What we collect, and why

Your name, contact details (email, phone), household links, group memberships, event sign-ups, serving schedule and availability, any room or equipment bookings you request, anything you send us through one of our forms, language and WhatsApp preferences, a log of messages we’ve sent you, and any giving the office has recorded for you. If you are a parent or guardian in our children’s programme, we also record which children you may collect and your relationship to them. We keep any request you make to join a group until it is answered, a note of any serving date we have taken you off, and a registration for each device you turn notifications on for. We also keep internal pastoral notes — these are not shown anywhere in the member app, but they are part of your record, so they are included if you download your data or ask us for it.

Why: solely to run church life — organising groups, events and serving rotas, and communicating with you about them. We do not sell your data and we do not share it for marketing.

We message you about church activities you are part of, by email. Your profile has a WhatsApp preference for a channel we have not switched on — leaving it on now sends you nothing, and you can change it at any time.

3Children’s records

For children in our care we hold a profile (date of birth, allergies, medical notes and photo consent), the guardians authorised to collect them, and a check-in/out history. This is used solely to keep children safe during church activities.

Access is restricted to authorised staff, every action on a child’s record is logged, pickup is verified with a one-time code, and children’s data is never included in another member’s data download. Parents may review or update their child’s record through the office.

4Where it is held, and under whose law

In a secured PostgreSQL database hosted in Singapore (ap-southeast-1), which is the region closest to Malaysia our hosting offers, chosen so the app is quick for a church in Kuala Lumpur rather than for anyone else. The application runs in the same region. Email is sent through Resend, whose nearest region is Tokyo.

Your church remains the data user under Malaysia’s PDPA wherever the servers sit, and the people responsible for this software are in your time zone.

Each church’s data is separated from every other church’s. No church can see, search or report on another church’s people.

5Seeing, downloading and deleting your data

You can view and download everything we hold on you, and request correction or deletion, at any time from your profile. If you would rather ask the office by phone, email or in person, that works too — we log it the same way and the same 30 days apply. We action deletion requests within 30 days after verifying your identity.

What deletion does and doesn’t remove. Your name, contact details, birthday, household links, pastoral notes and message history are erased, your sign-in is deleted, and you come off every group, rota date and sign-up. Giving records are kept — the church needs them to keep its accounts straight for past years — but they are no longer linked to your name, and totals for past years do not change.

6Who else can see it

Inside your church, access follows the role someone has been given, and it is enforced in the software rather than by hiding a menu. Giving records are visible to church administrators only — staff accounts cannot see finances at all, and you can always see your own giving on your profile. A group leader sees their own group. A team coordinator sees their own team’s rota. Children’s medical detail is kept away from the people running the check-in desk.

Outside your church, nobody. We do not sell your data, we do not share it for marketing, and we do not use it to train anything.

The suppliers that make the service work handle your data only to run it, on our instructions, and hold none of it for their own purposes: Supabase (the database), Vercel (running the application) and Resend (sending email). If we ever add another, this list changes before it does.

7How to contact us

Your church office first. Your church is the data user, and anything about your own record — a correction, a download, a deletion — is fastest from there.

About the software itself — where data is held, how it is separated, anything technical — write to hello@chapelhq.com. You will get an answer from the person who wrote it.

This notice forms part of our terms of service.