Security & Data Privacy

Your members’ trust is the whole ministry. We treat their data that way.

A church database holds things a business database never does — a family’s prayer request, a child’s allergy, a widow’s giving history. This page explains, plainly, how TimelyChurch protects it. Written for pastors, boards, and trustees deciding whether to say yes.

app.timelychurch.com/roles-permissions
Roles and permissions screen in TimelyChurch showing role-based access control for church staff and volunteers

Written to be shared. If your board or trustees are evaluating church software, send them this page — it answers the questions they will ask.

Four commitments, in plain language

No jargon, no vague promises. Here is what protecting your congregation actually looks like inside TimelyChurch.

Pillar 1 · Member Privacy

Private by default. Shared by choice.

Most church software assumes everyone wants to be in the directory. We assume the opposite. In TimelyChurch, nothing about a member is visible to the congregation until it is deliberately shared — by the church, and by the member themselves.

The member directory starts off

For every church, the congregation-wide member directory is off by default. No new church accidentally publishes its people to each other. If your church wants a directory, you ask us to enable it — a deliberate decision, not a checkbox someone missed during setup.

Members control what they share

Even when a directory is enabled, each member decides what appears — phone, email, address, photo. Sharing is per-person consent, not an all-or-nothing switch flipped by the office. A member who wants to stay private simply stays private.

Children’s contact info is never exposed

Minors’ contact details are never shown publicly — not in a directory, not in the member portal, not on people widgets your church puts on its website. That rule is enforced by the software itself, so it does not depend on a volunteer remembering a setting.

Your data stays yours

GDPR-style rights are built in: your church can export its data, and members can have their information deleted on request. If you ever leave TimelyChurch, your records leave with you. A church should never feel locked in by its own membership list.

app.timelychurch.com/check-in
TimelyChurch check-in kiosk screen used for secure child check-in with security codes and guardian pickup
Pillar 2 · Child Safety

The nursery door is a security checkpoint

Parents hand you their children every Sunday. TimelyChurch’s check-in system is built so that trust is never casual — every child is accounted for from drop-off to pickup, and only the right person can collect them.

  • Security codes at check-in — each child gets a unique code when checked in, and pickup requires it. No code, no release
  • Guardian-matched pickup — children are released to the guardians on their record, so your volunteers are never guessing who is authorized
  • Allergy alerts — allergies and medical notes surface right at check-in, where the classroom volunteer will actually see them
  • Name-tag printing — printed tags with the child’s name and matching pickup code, so drop-off is quick and pickup is verifiable
  • Real-time headcounts — leaders see who is in every room right now, which matters most on an ordinary Sunday and even more in an emergency

Read more about the full check-in workflow on the Check-In feature page.

Pillar 3 · Access Control

Everyone sees what their ministry needs. No one sees more.

A church runs on volunteers, and volunteers need access — but the sound tech does not need the giving records, and the greeter does not need the pastoral notes. TimelyChurch draws those lines with roles and permissions, not with hoping people don’t click around.

  • Role-based permissions — every user gets a role, and every role defines exactly which modules they can view and which they can change
  • Team-level scoping — a worship leader manages their own team’s schedule and people, without seeing the books, the giving records, or other ministries’ data
  • Two-factor authentication for admins — the accounts with the most access can be protected with a second factor, not just a password
  • Activity logging — changes are recorded, so when something looks off you can see what happened and who did it, instead of wondering

Permissions matter most when leadership changes hands. When a volunteer steps down or a staff member moves on, one role change removes their access — you never have to remember every place they could log in.

app.timelychurch.com/roles-permissions
Roles and permissions management in TimelyChurch, where each role defines which modules a person can view or edit
Pillar 4 · Security Practice

Security is a habit, not a page on a website

Features protect your people; practice protects the features. Here is how the platform itself is built and maintained — stated honestly, without borrowed badges.

Audited, module by module

In 2026 we ran a comprehensive security audit across every module of the platform — authentication, permissions, people, giving, check-in, and the rest — probing for the ways access rules can fail, and fixing what we found. To be clear about what that is: it was our own engineering audit, not a third-party certification, and we won’t pretend otherwise. Security review is now part of how every change ships.

Each church’s data is isolated

TimelyChurch is multi-tenant, and every record belongs to exactly one church. Isolation is enforced at the application’s core, on every query — your congregation’s data is never visible to another church, and theirs is never visible to you.

Card data never touches our servers

Online giving is processed by Stripe, one of the world’s most trusted payment processors. Card numbers go directly to Stripe and are never stored on — or even pass through — TimelyChurch servers. Stripe charges its standard card processing; TimelyChurch adds no platform fee on top.

Encrypted in transit, everywhere

Every connection to TimelyChurch uses HTTPS — the admin dashboard, the member portal, check-in kiosks, giving pages, and your church website. There is no unencrypted way to reach your data.

Questions your board will ask

The four questions that come up in almost every board conversation about church software — answered straight.

“Who can see our members’ personal information?”

Only the people your church explicitly gives a role to — and each role only sees the modules it has been granted. Volunteers see their own ministry, not the whole database. The congregation-wide directory is off by default, and even when your church enables it, each member chooses what to share. Children’s contact details are never publicly visible at all.

“Has the software actually been security-tested?”

Yes — and here is the honest version. In 2026 we ran a comprehensive security audit of every module, hunting specifically for permission gaps and access-control failures, and fixed what we found. It was our own thorough engineering audit; we do not currently hold third-party certifications such as SOC 2, and we will not claim credentials we don’t have. If your board wants specifics about our practices, ask us — we would rather answer a hard question than dodge it.

“How is our giving and card data handled?”

All card payments are processed by Stripe. Card numbers never touch TimelyChurch servers — they go straight to Stripe, which handles them under the strictest payment-industry standards. Inside TimelyChurch, giving records are protected like everything else: visible only to the roles your church grants giving access to, such as your treasurer.

“What happens to our data if we ever leave?”

It leaves with you. Your church can export its data, and members can have their personal information deleted on request. Your membership records belong to your church — switching software should be a decision about tools, never a hostage negotiation over data.

Have a question that isn’t here? Ask us directly — or email [email protected].

Take this to your board with confidence

Try TimelyChurch free with your real workflows, or bring your board’s questions to a demo — we are glad to answer the hard ones.

See plans & pricing →