Privacy Policy

Last updated: 5 August 2026

Asore is a church management system. Because we handle member records on behalf of churches, this policy is important. We follow the Ghana Data Protection Act, 2012 (Act 843) and similar principles for members outside Ghana. If any part of this policy conflicts with the Data Protection Act in Ghana, the Act prevails.

1. Who is the data controller?

For member records uploaded by a workspace: the church or organisation that owns the workspace is the data controller. Asore is the data processor, acting only on instructions from the workspace owner.

For account data (owner emails, admin logins, payment records): Asore is both the controller and processor.

2. What data we collect

  • Account data: names, email addresses, hashed passwords, login timestamps.
  • Member data (uploaded by workspaces): names, contact numbers, emails, DOB, gender, marital status, family members, address, GPS, occupation, church history, photos.
  • Communications: SMS content sent through the platform, plus delivery status returned by the SMS provider.
  • Payment data: we do not store card numbers. Paystack handles all card details; we only store the transaction reference, amount, and status.
  • Technical data: IP addresses, browser user-agent, and PHP error logs, retained for security and debugging.

3. How we use it

  • To operate the service you signed up for (member records, reports, SMS).
  • To bill and support you (Paystack payments, receipts, low-balance notifications).
  • To protect the service (rate limiting, fraud detection, security logging).
  • To improve the service (aggregated metrics — never linked back to individuals outside your workspace).

We do not sell your data. We do not use member data to train AI models. We do not share member data across workspaces.

4. Who we share it with

We use the following processors, each contractually bound to protect your data:

  • Arkesel — SMS delivery. Recipient phone numbers and message bodies are sent to Arkesel to deliver SMS.
  • Paystack — payments. Card details go directly to Paystack (never to us).
  • Our hosting provider — server infrastructure. Data is stored on their servers.

5. How long we keep it

  • Member data: for as long as your workspace is active.
  • Closed workspaces: soft-deleted for 30 days (recoverable on request), then permanently purged.
  • Payment records: retained for 7 years (tax record-keeping).
  • PHP error logs: retained for up to 90 days.
  • SMS delivery logs: retained for 12 months.

6. Your rights

As a member whose data is in a workspace, you have the right to:

  • Access the data your church holds about you.
  • Correct inaccuracies.
  • Request erasure ("right to be forgotten") — subject to the church's legitimate record-keeping needs.
  • Withdraw consent to receive SMS at any time.

Direct these requests to your church (the data controller). If your church does not respond, you may contact us at privacy@asore.net.

If you are the workspace owner, you can exercise the same rights on your account data by emailing us.

7. Security

We use TLS/HTTPS everywhere, password hashing (bcrypt), CSRF tokens on forms, rate limiting on public endpoints, and prepared SQL statements to block injection. Passwords are never stored in plain text or logged.

8. Cookies

We set exactly one cookie: a session cookie so you stay logged in. It is HttpOnly, SameSite=Lax, and Secure when served over HTTPS. It expires when you close the browser (or log out).

9. Changes

Material changes to this policy will be notified via email to the workspace owner and shown as a banner in the app for 30 days.

10. Contact

privacy@asore.net

Draft template — not legal advice. Please have this reviewed by a Ghanaian lawyer familiar with Act 843 before relying on it. Adapt anything that doesn't match how you actually operate. Delete this notice when you're ready.