Nahalio

Privacy Policy

Last updated: July 7, 2026

This Privacy Policy explains how Nahalio ("Nahalio," "we," "us," or "our") collects, uses, and protects information in connection with our church management platform (the "Service").

1. Two Kinds of Data, Two Roles

It's helpful to understand two categories of information:

  • Organization & Staff Data — information about the church itself and its staff accounts (name, login email, role, billing details). Nahalio is the data controller for this information.
  • Member Data — information your Organization enters about its own members, attendees, donors, volunteers, and children (names, contact details, attendance, giving records, notes, etc.). Your Organization is the data controller for Member Data; Nahalio processes it solely on your Organization's behalf and instructions, as described in our Terms of Service.

2. Information We Collect

  • Account information: name, email, password (stored hashed, never in plain text), role/permissions.
  • Member Data entered by your Organization: names, emails, phone numbers, addresses, birthdates, group/attendance records, form submissions, notes, and — for churches using child check-in — a child's name, date of birth, and the name of the accompanying guardian, entered by church staff or the guardian at check-in.
  • Payment & giving information: subscription billing and donation transactions are handled directly by Stripe. Nahalio does not receive or store full card numbers.
  • Usage & technical data: IP address, browser type, and access logs, used for security (e.g. rate-limiting) and troubleshooting.

3. How We Use Information

We use information to operate and secure the Service, process payments and subscriptions, send transactional emails (password resets, receipts, staff invitations), and provide customer support. We do not sell your data or your Organization's Member Data to third parties.

4. Children's Information

Nahalio's child check-in feature is a tool for churches to track which children are present in their care during a service or event. This information is entered by church staff or a parent/guardian at the point of check-in — Nahalio does not knowingly collect information directly from children, and does not market to or knowingly allow children to create their own accounts. Organizations are responsible for obtaining any consent from parents/guardians required by applicable law before entering a child's information into the Service.

5. How We Share Information

We share information only with service providers who help us operate the Service ("subprocessors"), under contracts requiring them to protect it:

  • Stripe — subscription billing and online giving/payment processing.
  • Postmark — transactional email delivery.
  • Cloudflare — network security and content delivery.

We may also disclose information if required by law, or to protect the rights, property, or safety of Nahalio, our customers, or others.

6. Data Security

We use industry-standard safeguards, including encryption of data in transit, hashed passwords, rate-limiting on authentication endpoints, and encrypted, access-controlled backups. No method of transmission or storage is 100% secure, but we work to protect information appropriate to its sensitivity.

7. Data Retention & Deletion

We retain Organization and Member Data for as long as the Organization's account is active. If an Organization cancels its subscription, we retain data for a limited period afterward in case the Organization wishes to reactivate, after which it is deleted. To request deletion of your Organization's data, or of specific Member Data, contact us at the email below.

8. Your Choices

Recipients of email communications from an Organization can unsubscribe using the link included in every message. Church staff can update or remove Member Data directly within the Service. Individuals who want their information corrected or removed from a specific church's records should contact that church directly, as the church controls that data; we're glad to assist a church in fulfilling such a request.

9. Where Data Is Stored

The Service and its data are hosted in the United States.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new "Last updated" date, and material changes will be communicated to Organization admins by email.

11. Contact

Questions about this Privacy Policy, or requests regarding your data, can be sent to [email protected].

Terms of Service  ·  Privacy Policy