Recore App legal & support
Privacy Delete account Support Terms
Last updated · 21 July 2026

Privacy Policy.

This policy explains what personal information the Recore mobile app and the Church Flow mobile app (together “the Apps”, each “the App”; “we”, “us”, “our”) collect about you, why we collect it, who we share it with, and the choices and rights you have. It applies to the Recore app and to the Church Flow app on iOS and Android and to the Church Flow church platform they connect to.

The Responsible Party for your personal information under South Africa's Protection of Personal Information Act, 2013 (“POPIA”) is Recore Church, whose registered legal name is Recore Church NPC (registration number 2024/161411/08), of 36c Voortrekker Road, Southcrest, Alberton, South Africa.

For the Church Flow app, your church is the responsible party for your personal information under POPIA: the church you pick and sign in to decides why and how it is processed, and Church Flow (Pty) Ltd processes it on that church's behalf as its operator. For the Recore app, Recore Church is the responsible party as set out above. Contact details for your church appear on its own website and inside the app; the platform contacts below reach Church Flow (Pty) Ltd.

Our Information Officer is Andre de Klerk. You can reach our Information Officer about anything in this policy at [email protected].

We built the App so members, volunteers, and staff can take part in the life of the church: view sermons, read the Bible, give, join groups, check children in and out, message their teams, and share prayer. We only collect the information we need to do that. We do not sell your personal information, and we do not use it for third-party advertising.

1. What we collect

We collect the following categories of personal information.

Account and identity information. Your name, email address, and phone number. If you create an account with an email and password, we store your email and a secure hash of your password. If you sign in with Apple, Google, or Microsoft, we receive your name and email address from that provider so we can create or match your account.

Family and children's information. If you manage a family, we store the names, dates of birth or ages, grades, and relationships of the family members you add, including children. This lets you check children in and out of church programmes and manage who may collect them. When you add or edit a child you may also choose to record allergies and medical notes. These fields are optional, and we use them only so that the people caring for your child during a programme know about the child's needs (for example, they may be printed on the child's check-in label). See section 6 for how we handle children's information.

Church membership information. Because the App is a church app, the fact that you use it, and the groups, ministries, and services you take part in, can reveal your religious beliefs. Information that reveals religious belief is “special personal information” under POPIA. See section 5.

Giving and payment information. If you give through the App, we record the amount, date, fund, and frequency of your gifts so you can see your giving history and so the church can keep proper records. Card payments (including through Apple Pay or Google Pay, where you choose that) are processed by our payment provider, Paystack. We do not receive or store your full card number or bank account number; we receive a payment reference and the result of the transaction from Paystack.

Content you create. Messages you send in group chats and direct messages, prayer requests you submit, notes you write on sermons, and comments or reactions you post. Voice notes you record in chat or with push-to-talk, and photos you choose to share in chat or set as your profile picture.

Location information (optional). If you allow it, we use your device location to suggest checking your children in when you arrive at the church building. Depending on the permission you grant, this may include checking your location in the background so the App can prompt you as you arrive. We use location only for this purpose, you can decline the permission without losing access to the rest of the App, and you can turn it off at any time in your device settings.

Camera. We use the camera to scan QR codes for event check-in, child pickup, and giving links. QR scans are processed on your device.

Microphone. We use the microphone when you record a voice note in chat or use push-to-talk for serving teams. We only access the microphone while you are recording.

Face ID, Touch ID, and fingerprint. If you enable biometric unlock, your device handles the biometric check. Your fingerprint and face data never leave your device and are never sent to us.

Notifications. If you allow notifications, we store a push notification token for your device so we can send you reminders and updates. The token is delivered through Apple Push Notification service on iOS and Firebase Cloud Messaging on Android.

Device and diagnostic information. We collect basic device information (such as device model, operating system version, and app version) and crash reports so we can find and fix problems. Crash reports are handled by Sentry and are configured to exclude the contents of your requests and responses.

2. Why we process your information

We process your personal information for these purposes:

  • To create and manage your account and keep it secure.
  • To let you take part in church activities: sermons, Bible reading, groups, events, serving schedules, messaging, and prayer.
  • To check children in and out safely and to control who may collect them.
  • To process and record your giving, and to give you a record of your gifts.
  • To send you the notifications and reminders you have asked for.
  • To keep the App working, diagnose crashes, and improve it.
  • To keep the App and its users safe, including moderating content and acting on reports of abuse.
  • To comply with our legal and record-keeping obligations.

The lawful bases we rely on under POPIA are your consent, the performance of our arrangement with you as a member or user, our legitimate interests in running the church and keeping the App safe, and our legal obligations. For special personal information and children's information we rely on the specific grounds described in sections 5 and 6.

3. How we collect your information

We collect information directly from you when you register, complete your profile, add family members, give, message, submit prayer, write notes, or use a feature. We collect information automatically from your device (such as crash reports and your push token) when you use the App. We receive information from third parties when you sign in with Apple, Google, or Microsoft, and when Paystack tells us the result of a payment.

4. Who we share it with

We share your personal information only as described here. Everyone who processes personal information on our behalf is an Operator under POPIA and is bound to process it only on our instructions and to keep it secure.

  • Our church platform provider, Church Flow (Pty) Ltd, hosts the servers and database that run the App and the church platform behind it, and processes your information on our behalf so the App can work.
  • Paystack processes card payments when you give. Paystack receives the payment details you enter and returns the result to us. See Paystack's own privacy policy for how it handles that data.
  • Apple (Apple Push Notification service) and Google (Firebase Cloud Messaging) deliver the notifications you have asked for.
  • Sentry receives crash reports so we can fix errors. We configure Sentry to avoid collecting unnecessary personal information.
  • Other members and leaders, where you choose to share. Messages, prayer requests, group posts, and profile details are visible to the people you share them with (for example the members of a group you join or the leaders of a ministry you serve in).
  • Authorities or advisors, where we are required by law, or where it is necessary to protect the rights, safety, or property of the church, our members, or others.

We do not sell your personal information. We do not share it with advertising networks or data brokers.

5. Special personal information (religious belief)

Because this is a church app, your use of it can reveal your religious beliefs, which is special personal information under POPIA. POPIA allows a spiritual or religious organisation to process information about the religious beliefs of its members, and of others who take part in its activities, where that is necessary to achieve the organisation's aims. We process this information for that reason and to give you access to the church community. We do not share it outside the church except as set out in section 4.

6. Children's information

The App supports family management and children's check-in, so we process information about children (such as a child's name, date of birth, check-in records, and any optional allergy or medical notes a parent or guardian chooses to record). Health information is special personal information under POPIA; we process it only with the consent of a competent person and only to keep the child safe during church programmes. Under POPIA, a child's personal information may be processed with the consent of a competent person, usually a parent or legal guardian.

If you add a child to your family or check a child in, you confirm that you are the child's parent or legal guardian, or that you have that person's permission to provide the child's information. A parent or guardian may ask us to access, correct, or delete a child's information at any time using the contact details in section 12. We collect only the information needed for family management and safe check-in, and we do not use children's information for marketing.

7. Payments

When you give through the App, the payment is processed by Paystack. You enter your card details into Paystack's secure flow. We do not receive or store your full card number, card security code, or bank account number. We store the record of your gift (amount, date, fund, and frequency) so you and the church have an accurate giving history.

8. Security

We take reasonable technical and organisational steps to protect your personal information against loss, damage, and unauthorised access, as required by POPIA. These include encryption of data in transit, secure storage of credentials, access controls limiting who can see your information, and optional biometric unlock on your device. No system is perfectly secure, but we work to keep your information safe and to respond quickly if a security problem arises. If a breach affects your personal information, we will notify you and the Information Regulator as the law requires.

9. How long we keep your information

We keep your personal information for as long as you have an account and for as long as we need it for the purposes in this policy, including to keep proper church and financial records and to meet our legal obligations. Giving records are kept for the period required by South African financial record-keeping law. When we no longer need information, we delete it or make it anonymous. You can ask us to delete your account and personal information as described in section 10 and on our Delete your account & data page.

10. Your rights

Under POPIA you have the right to:

  • Ask what personal information we hold about you and request a copy of it.
  • Ask us to correct or update information that is wrong or out of date.
  • Ask us to delete or destroy information we no longer have a lawful reason to keep.
  • Object to processing that relies on our legitimate interests, and withdraw a consent you have given (this will not affect processing that already happened).
  • Ask us not to use your information for direct marketing.

You can exercise any of these rights by contacting us at [email protected]. We may need to confirm your identity before we act on a request. Where the law allows a reasonable fee for an access request, we will tell you before we proceed.

You can also control several things from your device: turn off location, camera, microphone, and notification permissions in your device settings, and manage or delete your profile photo, notes, and messages inside the App.

11. Cross-border transfers

Some of the operators we use (for example the services that deliver push notifications and receive crash reports) process information on servers outside South Africa. Where your information is transferred outside South Africa, we do so only where POPIA allows it, for example where the receiving party is subject to laws or agreements that provide a comparable level of protection, or where the transfer is necessary to provide the App to you.

12. Complaints and contact

If you have a question or concern about how we handle your personal information, please contact us first so we can try to resolve it:

Email: [email protected]

General support: [email protected]

Information Officer: Andre de Klerk, Recore Church, 36c Voortrekker Road, Southcrest, Alberton

You also have the right to lodge a complaint with the Information Regulator:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Email: [email protected]
POPIA complaints: [email protected]
Website: inforegulator.org.za

13. Changes to this policy

We may update this policy from time to time. When we make a material change, we will update the date at the top and, where appropriate, let you know in the App. Please check this page from time to time so you stay informed.

Privacy policy Delete account & data Support Terms of use

The Recore app is the mobile app of Recore Church; the Church Flow app is the shared church app of Church Flow (Pty) Ltd. Both run on the Church Flow platform. · church-flow.com

© 2026 Recore Church and Church Flow (Pty) Ltd