Legal
Privacy Policy
The short version
- What we collect This website collects nothing about you. ChurchFlow holds what a church puts into it: member records, giving, attendance, events and child check-in.
- Who sees it The church that owns the account, and the service providers named in section 08. We do not sell personal information, we do not use it for advertising, and we do not use it to train machine learning models.
- How long For as long as the church keeps its account, and then it is deleted. The exact periods are in section 07.
- Deleting it Email developer@usewired.com. You do not need to install anything. Section 10 sets out what happens next.
Who we are
This policy is issued by 14698428 Canada Inc., a federal corporation incorporated in Canada on 22 January 2023, corporation number 1469842-8, with its registered office in Calgary, Alberta. The company operates under the name Wired Technologies. "We" and "us" below mean that company.
The policy covers two things:
- usewired.com, this website.
- ChurchFlow, our church administration platform, including its web applications and its mobile app (Android package com.usewired.churchflow).
ChurchFlow is in build. It has no customers today and its first pilot is planned for October 2026. We are publishing this policy before the first church joins, not after.
Our other products, SmartWaste Pro and wim, are operated under their own agreements and are not covered by this policy.
Privacy contact: developer@usewired.com.
Who is responsible for what
ChurchFlow is multi-tenant. Each church has its own account and its own data, and no church can see another's.
The church is the controller of its data. It decides what to collect, who in the church may see it, and how long to keep it. We are the processor. We hold and process that data to run the platform, on the church's instructions, and for no purpose of our own. If you are a church member and you want your record changed or removed, the church decides; section 10 explains how we help.
For this website, and for email you send us, we are the controller.
We use "controller" and "processor" because they are the words most readers and app stores expect. Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) the equivalent relationship is an organization and a third-party service provider, and the church remains accountable for the personal information it transfers to us.
This website
usewired.com collects nothing about you. There are no cookies, no analytics, no tracking pixels, no advertising tags, no embedded video, no social widgets and no JavaScript. The fonts are served from this server, not from Google Fonts or any other third party, so loading this page does not disclose your IP address to anyone but our host.
Two records exist as a consequence of the site being served at all:
- Server access logs, kept by our hosting provider, Railway. They contain your IP address, the time of the request, the path requested, the response status and your browser's user-agent string. We use them only to keep the site running and to investigate abuse. We do not combine them with anything else and we do not attempt to identify you from them.
- Email you choose to send us. If you email developer@usewired.com, we hold your address and what you wrote, in order to reply.
ChurchFlow: the data it holds
A church puts the following categories into ChurchFlow. We do not generate them and we do not buy them from anyone.
| Category | What it contains |
|---|---|
| Member records | Names, email addresses, phone numbers, postal addresses, photographs, household and family links, membership status. |
| Attendance | Which services, events and groups a member attended, and when. |
| Giving and pledges | Donation amounts, dates, funds and methods; pledge commitments; and the records needed to issue a tax receipt. This is financial information about an identifiable person and we treat it as sensitive. |
| Events and volunteers | Event registrations, volunteer rosters, serving schedules, departments and budgets. |
| Child check-in | A child's name, the linked guardian, check-in and check-out times, and any care or allergy note the church chooses to record. See section 05. |
| Prayer requests | Free text written by a member, which may describe health, family or other sensitive circumstances. Visibility is set by the church. |
| Payment identifiers | Tokens and reference identifiers returned by our payment processor. We never store card numbers. Card details are entered with the processor and never reach our servers. |
| Account and access | Login email, a hashed password, assigned roles, and an audit record of administrative actions. |
| Mobile app | A push notification token and the device platform, so notifications reach the right device. If you set a profile photo, the app uploads that photo and we store it. The app does not collect your location, contacts or advertising identifier, and it contains no crash reporting and no analytics: error monitoring runs on the server only, so nothing about a crash is sent from your phone. |
ChurchFlow's AI features
ChurchFlow includes optional AI assistance. Where a church turns it on, the text a user submits to that feature is sent to an external model provider to generate a response. That provider is Anthropic, which provides the Claude models. Under its commercial terms, inputs sent through the API are not used to train its models. We do not use church data to train any model, ours or anyone else's.
What we never do
- We do not sell personal information.
- We do not share it with advertisers or data brokers.
- We do not build profiles for marketing.
- We do not read a church's data except when asked to fix a fault.
Children's data
ChurchFlow has a children's ministry check-in feature, so it holds records about minors. This section says exactly how that works, because it deserves its own answer rather than a line in a table.
- Children do not have accounts. ChurchFlow is not directed at children and no child signs in. Every child record is created by an adult volunteer or member of church staff.
- The church is responsible for consent. It obtains any parental or guardian consent required where it operates. We cannot obtain that consent on its behalf and we do not attempt to.
- Access is restricted to the church. Child records are visible only to users the church has authorised, within that church's own account.
- The data is used only for check-in and safety. Matching a child to a guardian at pick-up, recording a care or allergy note, and producing attendance for the church's own records. It is never used for advertising, profiling, analytics or model training.
- A parent can have a child's record removed. Ask the church. If you cannot reach the church, email developer@usewired.com and we will contact the church and tell you what happened. Section 10 has the timings.
Why we process it
- To provide the service. We process a church's data because our contract with that church requires us to run the platform it has bought.
- To meet legal obligations. Donation and receipt records are kept because charitable and tax law requires the church to keep them.
- To keep the service secure and working. Access logs, error reports and rate limiting exist to prevent abuse and to fix faults.
- With consent, where consent is the right basis. For example, a member choosing to submit a prayer request, or to receive messages. Consent can be withdrawn at any time, through the church.
Under PIPEDA we collect, use and disclose personal information only for purposes a reasonable person would consider appropriate in the circumstances, and only for the purposes set out above.
How long we keep it
Some of the periods below have not been set yet. They are marked, rather than filled with a number we could not stand behind. Every marked period will be fixed before the first church goes live.
| What | How long |
|---|---|
| A church's live data in ChurchFlow | For as long as the church keeps its account. The church can delete an individual record at any time, and that deletion is immediate. |
| After a church closes its account | Data is retained for 30 days so the church can export it, then permanently deleted from live systems. |
| Database backups | Up to 90 days. Railway backs the volumes up daily and keeps those for 6 days, weekly for 27 days, and monthly for 89 days. A record deleted from live systems persists in backups until the last backup containing it expires, after which it is gone. This is our host's schedule, not a period we chose, and we will not claim a shorter one than we can deliver. |
| Website and application access logs | 30 days, which is the retention of our current Railway plan. |
| Error reports | Held by our error monitoring provider for 30 days, which is the retention of our current Sentry plan. They are configured to exclude personal information; see section 08. |
| Email you send us | 12 months, then deleted. Where a message forms part of a contract or a tax record we keep it for as long as Canadian law requires us to. |
| Donation and tax receipt records | Set by the church, which must keep them for as long as its own tax and charitable reporting obligations require. We follow the church's instruction and will not delete these records before it tells us to. |
Who else can see it
We disclose personal information to three groups and no others: the church that owns it, the service providers below, and any authority we are legally compelled to disclose to. Each provider is bound to use the data only to provide its service to us.
| Provider | What it does for us |
|---|---|
| Railway | Hosts this website, the ChurchFlow application and its database. Has access to everything stored in the platform. |
| Sentry | Receives error reports so we can fix faults. It is configured not to send personal information with an error, so member and donor records do not leave the application through it. |
| Stripe | Processes card payments for giving. Card details go to Stripe directly and are never stored by us. Stripe is the processor for the pilot. Donations are charged on the church's own connected Stripe account, so the church is the merchant of record and the funds never pass through ours. |
| Expo | Builds the mobile app, delivers its over-the-air updates, and relays push notifications to your device. |
| Google Play and the Apple App Store | Distribute the mobile app and handle its installation and updates. |
| Email delivery provider | Sends transactional email such as receipts and password resets. Google, over Gmail SMTP. This is the arrangement for the pilot and we expect to move to a dedicated transactional email provider before general availability; this page will say so when we do. |
| SMS and WhatsApp provider | Delivers text and WhatsApp messages where a church enables them. Twilio. |
If we are ever acquired or merged, personal information would transfer with the business. We would tell every affected church before that happened.
Where it is stored
ChurchFlow runs on Railway in its US West region, in California, United States: the database and cache volumes that hold church data are both there. Error monitoring is in Sentry's United States region. Our other providers operate in Canada, the United States and the European Union.
This means personal information is stored and processed outside Canada, in the United States. While it is in another country it is subject to that country's laws, and a court, law enforcement agency or national security authority there may be able to obtain access to it under those laws. We are telling you this because PIPEDA requires an organization to be transparent about transfers for processing, and because a church deciding whether to trust us with donation records is entitled to know.
Access, correction, deletion
You can ask what we hold about you, ask us to correct it, and ask us to delete it. You do not need an account, and you do not need to install the app.
How to ask
Email developer@usewired.com with the subject Data request. Tell us which product, the name of the church if it is a ChurchFlow record, and what you want done. If you would rather write, use the registered office address in section 12.
What happens then
- We acknowledge your request within 5 business days.
- We complete it within 30 days, which is also the period PIPEDA allows for responding to an access request. If we need longer than that, PIPEDA lets us extend once by up to a further 30 days, and we will tell you before the first 30 are up rather than after.
- We may need to confirm who you are before acting, so that we do not disclose someone else's record to you. We will ask for the least we can.
- We do not charge for a request.
If the record belongs to a church
For ChurchFlow the church is the controller, so the church decides. We will pass your request to it, act on its instruction, and tell you what was decided. If the church does not respond within 14 days we will tell you that, so you are never left without an answer.
Deleting a ChurchFlow account
Uninstalling the app does not delete anything. To have an account and its records deleted, follow how to delete your account, or email the address above. When a deletion is carried out the records are removed from live systems immediately and disappear from backups as those backups expire, on the schedule in section 07.
How we protect it
- Traffic to the website and the application is encrypted in transit (TLS).
- Passwords are stored as salted hashes, never in a readable form.
- Access inside ChurchFlow is role-based, and each church's data is separated from every other church's.
- Administrative actions are recorded in an audit log.
- Error monitoring is configured not to transmit personal information, and dependencies are scanned for known vulnerabilities.
An honest limitation. We are a small company. We have not been independently audited and we hold no security certification such as SOC 2. If that matters for your church's decision, ask us what we do have rather than assuming, and we will answer plainly.
If there is a breach. We will tell the affected church without undue delay. Where a breach creates a real risk of significant harm we will notify affected individuals and report it to the Office of the Privacy Commissioner of Canada, and keep a record of it, as PIPEDA requires.
Changes and complaints
If we change this policy we will update the version and date at the top of the page. If a change materially affects how a church's data is handled, we will email the church before it takes effect.
Contact
developer@usewired.com
14698428 Canada Inc., registered office:
153 Sage Bluff Manor NW, Calgary, Alberta T3R 1W1, Canada.
If you are not satisfied
Tell us first and we will try to put it right. If you remain unsatisfied you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376. If you are in the European Economic Area or the United Kingdom you may also complain to your local supervisory authority.