Stewara

Privacy Policy

Last updated: August 26, 2026

This Privacy Policy explains how Stewara, operated by Abounding Media LLC ("Stewara," "we," "us"), handles information when a church ("Church") uses our church-management software (the "Service"). Stewara is provided to Churches as a tool to manage their congregations.

Controllers and processors

For the personal information a Church collects about its members and gives, the Church is the data controller and Stewara is the data processor, acting on the Church's instructions. Each Church is responsible for having a lawful basis to collect member information and for its own privacy notices to its members.

Information we process

  • Account data: names, email addresses, and login identifiers for the people who sign in to Stewara.
  • Member records (PII): the people, family, and contact information a Church enters into its directory (Flock), including pastoral care notes a Church chooses to record.
  • Giving data: contributions, pledges, and statements a Church records. Giving data is treated as sensitive and is shown only to the giver and to Church roles authorized to view it.
  • Group, attendance, event, and service data a Church creates while using the modules it has enabled.
  • Billing data: subscription status and customer identifiers; full card details are handled by our payments processor, not stored by Stewara.
  • Usage and device data: basic logs needed to operate the Service securely.

How we use information

We use information only to provide and secure the Service for the Church: to authenticate users, store and display the Church's records to the right roles, process subscription billing, send transactional and administrative messages, and prevent abuse. We do not sell personal information, and we do not use member data to train advertising profiles.

Marketing communications

With your consent, Abounding Media LLC may send product news, tips, and offers about Stewara to the account and administrator contacts who create or manage a Stewara account. You can opt in or out at any time in your church setup, and every such email includes a one-click unsubscribe link; opt-outs are honored immediately and permanently. These messages come from Abounding Media LLC, whose physical mailing address appears in each email.

We never use a Church's congregation member data for our marketing. Member records belong to the Church (the data controller); Abounding Media markets only to the signup/administrator contacts described above, never to a Church's congregants.

Text messaging consent

Where a Church enables text messaging, consent is a stored record rather than a remembered conversation: one row per person, per channel, marked pending or confirmed. Every send is checked against that record on our servers before a message is handed to the provider. An automated text requires a confirmed opt-in, and no record at all counts as no consent rather than as permission. A number given on a public form is written as pending and stays pending until the person opts in themselves. Replying STOP (or UNSUBSCRIBE, CANCEL, END, QUIT) is recorded on our side as well as honored by the carrier, and it outranks every other rule we have, including a message the Church would otherwise be entitled to send such as a balance owed on an event the person signed up for. START or JOIN clears it and records the opt-in; HELP answers with how to stop and how to start again. Email works the other way round (it sends unless the person has unsubscribed), and that unsubscribe is enforced at the same gate. Recipients held back by any of these checks are counted and reported back to the Church that sent, so a message we did not send is visible rather than silent.

Location in the mobile app

The Stewara member app asks for location permission for exactly one feature: emergency campus alerts. When a Church raises an alert, the people standing on the campus need a louder, more urgent notification than the people who are miles away, and the app has to know which group you are in.

No coordinates ever leave your phone. The Church's campus boundaries are sent down to your device; your phone compares its own position against them locally; and the only thing sent back to Stewara is a true or false answer to "am I on campus right now?", plus a label saying how the phone worked it out. No latitude or longitude is put into a request, a log line, or a crash report — anywhere in the app — and that is enforced by a guard test that fails the build if one ever is.

Declining the permission is a supported answer, not a degraded one: with no location the app reports nothing at all, and an alert reaches you with wording that assumes you might be on site. Background location ("Allow all the time" on Android) is never requested on its own — it is offered only on a settings row you opened yourself, and only so that arriving at campus can be noticed while the app is closed.

Tenant isolation and access

Each Church's data is logically isolated; one Church cannot access another Church's records. Within a Church, access is shaped by role. For example, giving data and pastoral care notes are restricted to authorized roles, and a member only ever sees their own giving.

Subprocessors

We rely on a small set of trusted infrastructure providers to run the Service:

  • Google Firebase (Google Cloud): authentication, application hosting, and the managed database where Church records are stored.
  • Stripe: subscription billing and payment processing.
  • Resend: transactional and administrative email delivery.
  • Twilio: text-message delivery for Churches that enable messaging.
  • Sentry: crash and error reporting for the Stewara mobile app. Stewara does not use Sentry's standard SDKs, deliberately: those collect request bodies, local variables and browsing breadcrumbs by default, and in this app a request body can be a gift or a prayer request. Instead a report is assembled from a fixed allowlist — the error type, the error message with identifying text redacted, the code locations in the stack, and six labels (which app, which screen, which function, an error code, the module, and the Church). The Church's identifier travels as a one-way hash, never as a name, and there is no field a developer can attach anything else to.
  • Giphy: GIF search in the mobile app's chat, for Churches that use it. Giphy receives the words someone types into the GIF picker and, unavoidably, their device's network address. It receives no member record, no name, and no Stewara account identifier, and every search is fixed to Giphy's PG rating.

Website analytics

We measure the public stewara.com marketing pages so we can tell which of them actually help a church decide. Those tools run on the marketing pages only. They are not present on any signed-in screen, and that is a matter of where the code lives rather than a setting we remembered to switch off: the collectors are mounted inside the public site and are physically absent from the application that holds Church records.

  • Vercel Web Analytics and Speed Insights: page views and real-world page speed. Cookieless, and the page address is reported as a pattern rather than a real one, so an invitation link or a church code can never reach it.
  • Microsoft Clarity: anonymized recordings of how visitors move through the marketing pages, so we can see where a page loses people. It sets cookies. It runs only on the pages a search engine is allowed to crawl: never on a sign-in page, never on an invitation or join link, never on the account-creation form, and never inside the application. It receives no Church record, no member, and no account identifier.

We do not use advertising trackers, and we do not sell or share any of this. Browser do-not-track and tracker-blocking settings are respected by both tools; blocking them changes nothing about how Stewara works.

Data retention

We retain a Church's data for as long as the Church's account is active and as needed to provide the Service. When a Church closes its account, we delete or de-identify its data within a commercially reasonable period, except where retention is required by law or for legitimate record-keeping (such as financial and tax records).

Security

We use industry-standard safeguards including encryption in transit, role-based access controls, and signed, verified webhooks for billing events. None of that adds up to a guarantee, and we would rather say so than imply one. What we commit to is the part we control: if a material incident affects a Church's data, that Church hears about it from us.

Your rights

Your Stewara account is yours to delete, and we do it — we do not send you elsewhere for it. Your sign-in, and the things that exist only because you had one, can be deleted from inside the member app in under a minute, and we will delete them for you by email if you cannot sign in. Delete your Stewara account gives both paths in full, and states exactly what is removed and what your Church keeps.

Requests about the Church's own records of you — its roster entry, your contact details, attendance, and its giving history — go to the Church, because the Church is the controller of that data and it is not ours to erase on its behalf. Where Stewara processes such requests for a Church, we will assist the Church in responding. Depending on your location, you may have additional rights under applicable privacy laws.

Children

Churches may record information about children (for example, for check-in) under their own authority and consent practices. Stewara processes this information solely as the Church's processor.

Changes

We may update this Policy as the Service evolves. We will post the new date above and, for material changes, notify Church administrators.

Contact

Questions about this document? Email support@stewara.com.

Stewara is operated by Abounding Media LLC.