1. Purpose of this policy
This Security & Data Protection Policy explains how MinistryCount works to protect information processed through the platform. It is intended to help churches understand our approach to security, privacy, access control and operational protection.
MinistryCount stores and processes information such as church details, members, visitors, users, assemblies, attendance, announcements, SMS/email activity, reports, billing details and related administrative records.
2. Tenant separation
MinistryCount is designed as a multi-tenant church management system. Each church has its own church account and church records should be linked to that church’s tenant space.
- Church data is separated by church account identifiers.
- Users should only access records connected to their church, assembly, ministry or assigned role.
- Super administrator access is reserved for platform-level support, setup, billing, maintenance and security administration.
3. Role-based access control
The platform uses role-based access control to limit what each user can see and do. A church may assign users as Church Admin, Assembly Admin, Attendance Officer, Reports Officer, Ministry Leader or another approved role.
- Church Admins may manage broader church information depending on the enabled permissions.
- Assembly-based users may be limited to assigned assemblies.
- Ministry Leaders may be restricted to members under their assigned ministry and assembly.
- Sensitive administrative tools are restricted to approved roles only.
4. Login and session protection
MinistryCount uses authenticated access for dashboards and protected church pages. Users are responsible for keeping passwords, PINs and login details confidential.
- Inactive sessions may be timed out for safety.
- Repeated failed login attempts may be limited or locked.
- Users should not share login credentials with other people.
- Church admins should remove or suspend users who no longer serve in a role requiring access.
5. Activity monitoring and logs
The platform may keep activity logs to support accountability, troubleshooting, audit review and security investigation. These logs may include user identifiers, actions, timestamps, pages visited, IP addresses and technical browser details.
Activity logs help churches and MinistryCount investigate unusual access, user mistakes, support issues and possible misuse.
6. Data protection safeguards
MinistryCount applies practical technical and organisational measures to reduce unauthorised access, accidental loss, misuse or inappropriate disclosure of church data.
- Access is restricted to authorised users and approved administrative roles.
- Database access is limited to operational needs.
- Uploaded files and records should be stored only for legitimate church administration.
- Security-related updates and fixes may be applied as needed to protect the service.
7. Church responsibilities
Churches also play an important role in protecting their own data. Each church should appoint responsible administrators and review user access regularly.
- Only add trusted people as system users.
- Use strong passwords and keep login details private.
- Remove access when a user leaves office or no longer needs the platform.
- Ensure that member and visitor information entered into the system is collected lawfully and used respectfully.
- Avoid exporting or sharing member data unless there is a genuine church purpose.
8. Security incidents
If MinistryCount becomes aware of a security issue affecting church data, we will investigate, contain the issue where possible, and communicate with affected churches when appropriate.
Churches should report suspected unauthorised access, lost credentials or unusual activity to us quickly through the contact details on this page.
9. Contact
For security questions, access concerns or suspected misuse of MinistryCount, contact us at support@ministrycount.com.