Stewardship of data is stewardship of people.
A church database holds stories people trusted you with. This page says, specifically, how we protect them. No badges, no vague reassurance: just the actual behavior of the platform, in plain language.
How your data is protected.
Encrypted, both directions
Every church, strictly separate
Permissions per person
Abuse kept out
Backups that are actually tested.
- Backed up nightly, every night, automatically.
- Encrypted before leaving the server, then stored off-site in a separate location from production.
- Multiple restore points retained: daily, weekly and monthly generations.
- Backup integrity is verified on a weekly schedule, not assumed.
- Monitoring alerts us if a backup run is ever missed, and documented restore procedures exist for the day we hope never comes.
POPIA-first, and close to home.
We operate POPIA-first: your congregation's information is processed only to run your workspace, and you can export or delete it at any time.
Under POPIA, your church remains the responsible party for its congregation's personal information, and Church Flow acts as an operator: we process it on your instructions, to provide the service, and for nothing else. We do not sell, mine or advertise against your data.
Your data is hosted in a cloud data centre in South Africa, so it stays under the same sky as your congregation.
What happens if you leave.
Your church owns its data, full stop. Export your people, giving and attendance any time. If you cancel, you keep access until the end of your paid period, take everything with you, and we purge our copy after the 90-day retention window. No lock-in, no hostage-taking.
No certification theater.
We do not hold SOC 2 or ISO 27001 certification, and we will not imply otherwise with borrowed badges. Almost nobody serving churches at this price point does. What you get instead is this page: specific, verifiable behavior, kept current. Found something that worries you? Write to us and a real person will answer.