Privacy Policy
Last updated 28 August 2026
This policy explains what data Discuva collects, why, and how it’s protected. It applies to discuva.org, the Discuva admin application, and the Discuva member application (together, the “Service”), operated by Discuva (“we”, “us”).
Who this applies to, and who controls the data
Discuva is software a church subscribes to and configures. Each subscribing church (a “Tenant”) is the data controller for the information it enters about its own members, workers, and guests — it decides what to collect and why. Discuva acts as the data processor: we store and process that data on the church’s behalf, under their instruction, and do not sell it or use it for our own purposes unrelated to operating the Service.
If you’re a member, worker, or guest of a church using Discuva, your church is who to contact first about your data — Discuva processes it on their instructions and can’t unilaterally change or delete a record on your behalf without your church’s involvement, except where this policy or law says otherwise (see “Your rights” below).
What we collect
Depending on which modules a church turns on, the Service may hold:
- Identity & contact details — name, email, phone, address, and profile details a member or worker adds (occupation, business, skills, photo).
- Account credentials— your password, stored as an Argon2 hash, never in plain text. We can’t see your password.
- Attendance & participation — service check-ins, class enrollments, group membership, prayer meeting rosters.
- Giving & finance— donation/tithe records and transaction references. Card and bank details are handled directly by our payment processors (Paystack, Flutterwave, or Korapay, depending on the church’s setup) — Discuva does not store full card numbers or bank credentials.
- Guests & visitors— name, email, phone, and notes for people who aren’t yet members (e.g. attending a class or event).
- Children’s check-in data— a child’s name, guardian information, and check-in/pickup codes, where a church uses Children’s Church check-in.
- Form submissions — responses to forms a church publishes, public or members-only.
- Communications — SMS and email sent through the Service, and prayer requests, incident reports, and facility rental or asset requests a church chooses to collect.
- Connected social accounts — where a church connects a Facebook Page, Instagram account, or similar, we store an access token scoped to what that connection needs (e.g. publishing posts), not your personal social media password.
- Device & usage data — sign-in device fingerprints (to flag unrecognized logins), audit logs of admin actions, and standard technical logs (IP address, browser, timestamps).
How we use it
- To provide and operate the features a church has enabled.
- To secure accounts — device verification, rate-limiting login attempts, and audit logging admin actions.
- To send communications a church configures (service reminders, giving receipts, class notifications) and essential account emails (password resets, security alerts).
- To provide support when a church or member contacts us.
- To maintain and improve the Service’s reliability and security.
We do not sell personal data, and we do not use it to serve ads.
How data is isolated and secured
- Every church’s records live in their own isolated database schema — never shared rows filtered by a tenant column.
- Passwords are hashed with Argon2, never stored in plain text.
- Logins from an unrecognized device are blocked until verified, with an alert sent to the account.
- If a church brings its own SMS or email provider keys, they’re encrypted at rest.
- Every admin action is recorded in an audit log.
- Login and password-reset endpoints are rate-limited.
Who we share data with
We share data only with service providers that help us run the Service, bound by their own confidentiality and security obligations:
- Payment processors (Paystack, Flutterwave, Korapay) — to process giving/donations.
- Communication providers(e.g. Termii for SMS; SendGrid, Mailgun, or a church’s own email provider) — to deliver messages a church sends.
- Cloudinary — to store uploaded files, images, and documents.
- Meta, Google, X, and TikTok — only where a church explicitly connects a social account, to publish the posts that church schedules.
- Infrastructure providers (hosting, database) — to run the Service.
We disclose data if required by law, or to protect the rights, safety, or property of Discuva, a church, or the public.
Data retention
We retain data for as long as a church’s subscription is active, plus a reasonable period after cancellation in case the church wants to export or reactivate. A church can request deletion of specific records at any time through the admin app, and full account data deletion is described on our Data Deletion page.
Your rights
Depending on your location and applicable law (including Nigeria’s Data Protection Act 2023), you may have the right to access, correct, export, or request deletion of your personal data. Start with your church’s admin, since they control the underlying record; if you need to reach Discuva directly, contact us using the details below.
Children’s data
Children’s check-in data is entered and managed by a church’s workers on behalf of parents/guardians, not collected directly from children. Access to this data is restricted to authorized church workers.
Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by updating the date at the top of this page.
Contact
Questions about this policy or your data: contact@discuva.org.
