Privacy Policy
Last updated: 5 August 2026
Asore is a church management system. Because we handle member records on
behalf of churches, this policy is important. We follow the Ghana Data
Protection Act, 2012 (Act 843) and similar principles for members outside
Ghana. If any part of this policy conflicts with the Data Protection Act
in Ghana, the Act prevails.
1. Who is the data controller?
For member records uploaded by a workspace: the church or organisation
that owns the workspace is the data controller. Asore is the data processor,
acting only on instructions from the workspace owner.
For account data (owner emails, admin logins, payment records): Asore is
both the controller and processor.
2. What data we collect
- Account data: names, email addresses, hashed passwords, login timestamps.
- Member data (uploaded by workspaces): names, contact numbers, emails, DOB, gender, marital status, family members, address, GPS, occupation, church history, photos.
- Communications: SMS content sent through the platform, plus delivery status returned by the SMS provider.
- Payment data: we do not store card numbers. Paystack handles all card details; we only store the transaction reference, amount, and status.
- Technical data: IP addresses, browser user-agent, and PHP error logs, retained for security and debugging.
3. How we use it
- To operate the service you signed up for (member records, reports, SMS).
- To bill and support you (Paystack payments, receipts, low-balance notifications).
- To protect the service (rate limiting, fraud detection, security logging).
- To improve the service (aggregated metrics — never linked back to individuals outside your workspace).
We do not sell your data. We do not use member data to train AI models. We
do not share member data across workspaces.
4. Who we share it with
We use the following processors, each contractually bound to protect your data:
- Arkesel — SMS delivery. Recipient phone numbers and message bodies are sent to Arkesel to deliver SMS.
- Paystack — payments. Card details go directly to Paystack (never to us).
- Our hosting provider — server infrastructure. Data is stored on their servers.
5. How long we keep it
- Member data: for as long as your workspace is active.
- Closed workspaces: soft-deleted for 30 days (recoverable on request), then permanently purged.
- Payment records: retained for 7 years (tax record-keeping).
- PHP error logs: retained for up to 90 days.
- SMS delivery logs: retained for 12 months.
6. Your rights
As a member whose data is in a workspace, you have the right to:
- Access the data your church holds about you.
- Correct inaccuracies.
- Request erasure ("right to be forgotten") — subject to the church's legitimate record-keeping needs.
- Withdraw consent to receive SMS at any time.
Direct these requests to your church (the data controller). If your church
does not respond, you may contact us at
privacy@asore.net.
If you are the workspace owner, you can exercise the same rights on your
account data by emailing us.
7. Security
We use TLS/HTTPS everywhere, password hashing (bcrypt), CSRF tokens on
forms, rate limiting on public endpoints, and prepared SQL statements to
block injection. Passwords are never stored in plain text or logged.
8. Cookies
We set exactly one cookie: a session cookie so you stay logged in. It is
HttpOnly, SameSite=Lax, and Secure when served over HTTPS. It expires when
you close the browser (or log out).
9. Changes
Material changes to this policy will be notified via email to the workspace
owner and shown as a banner in the app for 30 days.
10. Contact
privacy@asore.net
Draft template — not legal advice. Please have this reviewed by a
Ghanaian lawyer familiar with Act 843 before relying on it. Adapt anything
that doesn't match how you actually operate. Delete this notice when you're
ready.