Pewly provides attendance, member-care, communication, and administrative tools for churches. This Privacy Policy explains what personal information Pewly handles, why we handle it, where it is processed, and the choices available to you.
Pewly operates from Ontario, Canada and aims to handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act, commonly known as PIPEDA.
In this policy, “Pewly,” “we,” “us,” and “our” refer to Pewly, 3050 Yorkville St, London, ON N6P 0J3, Canada. You can contact us at [email protected].
Pewly’s role and your church’s role
Churches use Pewly to manage information about their members, visitors, services, attendance, prayer requests, reminders, and follow-up care.
For most church-member information, the church decides why the information is collected and how it is used. Pewly provides the platform that stores and processes that information on the church's behalf.
Pewly separately decides how to handle information needed to operate its own business, including team accounts, authentication, support requests, security records, website analytics, waitlist registrations, and marketing-consent records.
If you are a church member or visitor with a question about information entered or managed by your church, you may need to contact the church first. Pewly can assist the church and will also respond to privacy requests sent directly to us.
Information we collect
Church administrators and team members
When someone creates or uses a Pewly account, we may collect:
- Name, email address, phone number, and profile photo.
- Church association, team role, and access permissions.
- Account creation, status, and revocation information.
- Invitation details, including the invited email, role, inviter, expiry, and acceptance status.
- Church billing-owner association.
Password credentials are handled by Supabase Auth. Pewly does not receive or store plaintext passwords.
If you choose Google sign-in, Google may provide Pewly with your name, email address, profile picture, and other basic account information you approve. Pewly does not receive your Google password.
Church information
- Church name and public subdomain.
- Contact email, phone number, and physical or mailing address.
- Church logo and timezone.
- Service names, dates, times, and recurring schedules.
- Plan, trial, and billing-owner information.
Some church information is organizational rather than personal, but church contact and billing details may identify an individual. Church logos are intentionally public because they appear on public church pages and check-in experiences.
Church members and visitors
Churches and people using a church's public join form may provide:
- Name, email address, phone number, home address, and occupation.
- Role within the church and household or family association.
- Whether the person identifies as a visitor or member.
- Membership and internal account status, join date, and record source.
Member spreadsheets are read in the browser during import. Pewly saves the resulting member records, but it does not separately upload or retain the original spreadsheet as a file.
Attendance and check-in information
- Services attended and attendance dates.
- Check-in time and check-in method.
- Contact details used to match someone during public self-check-in.
Attendance can reveal religious participation and should be treated as sensitive information.
Prayer requests and follow-up care
- Prayer request text, status, and associated person where applicable.
- Follow-up reasons, status, and internal care notes.
- The team member who completed a follow-up and relevant dates.
- Reminder or follow-up message content and delivery channels.
Prayer requests and care notes may contain highly sensitive information, including information about health, family, relationships, finances, or religious beliefs. People should avoid entering information about someone else unless they have an appropriate reason and authority to do so.
Communications
- Email and SMS recipient information.
- Reminder and follow-up message content and subject lines.
- Delivery status, communication channel, SMS segment count, and timestamps.
- The service or occurrence connected to a reminder.
Support, contact, and waitlist information
- Name, email address, subject, and message content.
- Church and account context when the person is signed in.
- Support-ticket status, timestamps, and waitlist registration details.
Please do not include unnecessary sensitive personal information in a support message.
Marketing-consent records
Where an optional marketing-consent checkbox is shown, Pewly records:
- The email address connected to the choice and whether the person opted in or declined.
- The date, time, source, and capture method of the choice.
- The exact consent wording and version presented.
- Consent and withdrawal timestamps where applicable.
We record both opt-in and declined choices so we can respect and demonstrate the person's decision.
Technical and security information
- IP address, browser, operating system, and device category.
- Request timestamps, requested pages, and referring pages.
- Error, diagnostic, authentication-cookie, and session information.
- Rate-limiting and abuse-prevention records.
Public check-in rate-limit information is retained for approximately one day. Support-form rate limiting stores a hash derived from the submitted email address and IP address rather than storing the raw IP in the support record.
How we use information
We use personal information to:
- Create and authenticate accounts.
- Associate team members with the correct church and role.
- Operate church member, attendance, prayer, follow-up, and reminder features.
- Provide public church join and self-check-in forms.
- Send account confirmations, password resets, invitations, service reminders, follow-ups, and support responses.
- Help churches identify members who may need follow-up care.
- Respond to support and contact requests.
- Maintain security, prevent abuse, and investigate errors.
- Improve reliability and usability using privacy-conscious analytics.
- Maintain consent records and send future product updates only where the recipient expressly opted in.
Pewly does not sell personal information and does not use church member or prayer-request information for advertising.
We may access or disclose information when reasonably necessary to operate and secure the service, investigate misuse, comply with legal obligations, or respond to valid legal process.
Transactional communications
Account confirmations, password resets, invitations, support replies, church reminders, and follow-up messages are transactional or service-related communications.
These messages are sent because they are necessary to provide the requested service or because a church is using Pewly to communicate with its members. They do not depend on Pewly marketing consent.
A church is responsible for ensuring that its use of member email addresses and phone numbers complies with its own legal and consent obligations.
Marketing communications and consent
Pewly's marketing opt-in is optional and unchecked by default. Declining marketing does not prevent someone from creating an account, joining a waitlist, contacting support, or receiving transactional communications.
Pewly is not currently sending marketing-email campaigns.
Although Pewly records marketing-consent decisions, the automated unsubscribe and suppression system has not yet been built. Pewly will not begin sending marketing campaigns until each marketing email includes:
- A clear unsubscribe link and no-login unsubscribe process.
- Appropriate email unsubscribe headers.
- A suppression mechanism that prevents future sends after someone unsubscribes.
- Pewly's mailing address and sender identification.
Until self-service withdrawal is available, you can withdraw a marketing opt-in by emailing [email protected]. Withdrawing consent will not affect transactional communications or actions taken before the withdrawal.
Where information is stored
Pewly's primary database, authentication system, and file storage are provided by Supabase.
The Supabase project is hosted in East US (Ohio), United States, in the us-east-2 region. Pewly does not currently provide Canadian data residency.
Information may also be processed in other countries where Pewly's service providers and their subprocessors operate. Information processed outside Canada may be subject to the laws of those countries, including lawful access by courts, law-enforcement agencies, or government authorities.
How we protect information
All churches currently share one Supabase project and database. Pewly does not operate a separate physical database for each church.
Instead, tenant information is logically separated using:
- A church identifier on tenant records.
- PostgreSQL Row Level Security and role-based permissions.
- Restricted public database access and server-side validation for public forms.
- Account-revocation checks enforced at the database level.
- Short-lived signed URLs for private team profile photos.
Church administrators and sub-administrators can access the information their role permits within their church. Ushers and other roles receive more limited access.
Pewly's trusted server processes and authorized operators may use privileged access when needed to operate, secure, troubleshoot, or support the service. Privileged credentials are not exposed to ordinary users.
Team profile photos are stored privately and displayed through temporary signed links. Church logos remain public because they are intended for public-facing church pages.
No online system can guarantee complete security. We take reasonable steps to protect information, but cannot promise that unauthorized access, loss, or misuse will never occur.
Service providers
Supabase
Supabase provides PostgreSQL database hosting, authentication, session management, Google OAuth integration, and file storage. It processes account, church, member, attendance, prayer, follow-up, support, consent, and related platform information on Pewly's behalf. Pewly's primary Supabase project is hosted in Ohio, United States.
Vercel
Vercel hosts the Pewly web application and runs server-side application code, API routes, and scheduled jobs. Vercel may process IP addresses, request information, runtime logs, errors, and infrastructure diagnostics needed to deliver and secure the application.
Vercel Web Analytics
Vercel Web Analytics helps Pewly understand general site usage. According to Vercel, it does not use third-party analytics cookies or associate analytics records with a directly identifying profile or raw IP address. It uses a request-derived visitor identifier discarded after approximately 24 hours and may collect page path, referrer, time, approximate location, browser, operating system, and device category.
Before an analytics event is sent, Pewly removes query strings and replaces sensitive route information such as invitation tokens, member IDs, church slugs, service IDs, and church subdomains with non-identifying placeholders. Vercel's infrastructure and diagnostic logs are separate and may still process IP addresses and request metadata.
Resend
Pewly uses Resend for team invitations, service reminders, follow-up messages, support notifications and confirmations, and account-related email where configured through Supabase. Resend processes recipient and sender addresses, subject lines, message content, timestamps, and delivery information. Open and click tracking is not enabled for Pewly's outbound email.
Twilio
Pewly uses Twilio to send SMS reminders and follow-up messages. Twilio processes recipient and sender phone numbers, message contents, timestamps, routing information, and delivery status. Mobile carriers and telecommunications intermediaries may also process these messages.
Pewly uses Google for optional Google account sign-in and Google Workspace business email. If you choose Google sign-in, Google supplies the profile information you authorize. Messages sent to or from Pewly business addresses, including [email protected], may be processed and stored through Google Workspace.
Retention and deletion
Pewly provides billing owners with a self-service way to close a church workspace. This is a soft deletion: access, public forms, invitations, check-in, and unattended messaging stop immediately, while the church's records remain preserved for a possible support-led restoration. Restoration is manual and is not available as a self-service action.
Generally:
- Church and account information remains while the church uses Pewly and, after a soft deletion, while reasonably needed to support restoration, legal obligations, security, and dispute resolution.
- Removing a team member revokes access but preserves the account row and historical activity.
- Deleting a member currently removes associated attendance, follow-up, and reminder records.
- A prayer request may remain as an unlinked church record after its associated member is deleted unless separately removed.
- Marketing-consent records may be retained as evidence of the choice presented and recorded.
- Short-lived rate-limit records are automatically pruned.
- Service providers may retain operational or delivery records under their own retention policies.
Churches and individuals can request access, correction, or deletion by emailing [email protected]. Pewly will verify the request and handle it manually. Where the information is controlled by a church, Pewly may need to coordinate with that church.
We may retain limited information where reasonably required for legal obligations, security, fraud prevention, dispute resolution, or evidence of consent and withdrawal. We will not claim that information has been deleted until the applicable records have actually been identified and handled.
Children and youth information
Pewly is not directed at children and does not knowingly invite children to create Pewly team accounts.
Churches may use Pewly to manage information about children or youth who participate in church activities. The church is responsible for deciding what youth information is appropriate to enter and for obtaining parental or guardian authorization where required.
Public church forms are provided for use by the church. Because those forms do not currently include an age-verification system, it is possible that a minor could submit information directly.
If you believe a child submitted personal information without appropriate authorization, contact [email protected]. Pewly will review the request and coordinate with the relevant church where necessary.
Your choices and rights
Depending on the circumstances, you may ask to:
- Access personal information Pewly holds about you.
- Correct inaccurate or incomplete information.
- Withdraw marketing consent.
- Request deletion of personal information.
- Ask how information has been used or disclosed.
- Raise a concern about Pewly's privacy practices.
Send requests to [email protected]. We may need to verify your identity before providing access or changing information. If your request concerns information managed by a church, we may refer the request to or coordinate with that church.
If you are not satisfied with Pewly's response, you may contact the Office of the Privacy Commissioner of Canada or another privacy regulator with jurisdiction over your concern.
Churches and users outside Canada
Pewly is operated from Canada, while its primary Supabase-hosted data is stored in Ohio, United States.
Churches and users outside Canada should understand that their information may be transferred to and processed in Canada, the United States, and other countries where Pewly's service providers operate.
A church using Pewly outside Canada remains responsible for understanding and meeting the privacy and communication requirements that apply to its own collection and use of member information.
Changes to this policy
Pewly may update this Privacy Policy as the service, its providers, or legal requirements change.
If a change is significant, we will provide reasonable notice through the service, by email, or by another appropriate method. The “Last updated” date at the top will show when the policy was most recently revised.
Contact us
Questions, concerns, access requests, correction requests, consent withdrawals, and deletion requests can be sent to:
Pewly3050 Yorkville St
London, ON N6P 0J3
Canada
Email: [email protected]