Privacy Policy
Effective July 21, 2026 · Version privacy-2026-07-21
Information Shepherd processes
Shepherd processes account identifiers, verified contact information, church membership and role records, communication preferences, consent evidence, pastoral-care records, audit events, and technical security data. A participating church may also enter information about its members and ministry activity.
Why information is used
Information is used to authenticate users, enforce church and role boundaries, provide requested church features, deliver authorized communications, record consent, protect youth, prevent abuse, recover failed workflows, support users, and maintain security and audit evidence.
Church control and sharing
Participating churches control their church-scoped records. Information is shared only with authorized church users, service providers needed to operate Shepherd, or others when required by law or necessary to protect safety and security. Shepherd does not sell personal information.
Youth privacy
Public self-signup is unavailable to children under 13. Youth communications require the configured guardian and staff safeguards. Guardian consent, youth access, and transcript visibility are scoped to the applicable church and consent record.
Retention and security
Records are retained according to the applicable church agreement, operational need, safeguarding duties, and legal requirements. Shepherd uses access controls, tenant scoping, encryption where supported, audit logging, and other safeguards, but no system can guarantee absolute security.
Choices and requests
Users may update account information and communication choices in the available product controls. Text recipients may reply STOP to opt out. Requests to access, correct, export, or delete church-controlled information should be directed to the participating church; Shepherd support can assist with platform-account requests.
Policy updates
Material updates to this policy will use a new document version. The current effective version is shown on this page and recorded when a user accepts it during onboarding.