Information We Collect
Passport is committed to protecting your privacy. Passport is a multi-tenant church management and visitor retention platform. We collect information you provide directly to us or that churches using Passport collect when you visit their services, register as a visitor, or interact with a church through our platform.
This may include:
- Name and contact information (email address, phone number)
- Physical address (for member profiles where provided)
- Visitor registration and check-in information
- Church attendance and engagement data
- Notes and follow-up information churches record about your visits
- Any other information you or a church voluntarily provides through the platform
How We Use Your Information
We use the information we collect to:
- Provide and improve our church management and visitor retention platform
- Enable churches to communicate with visitors (if you opt-in)
- Support churches in follow-up and visitor retention efforts
- Respond to your inquiries and requests
- Comply with legal obligations
- Protect our rights and the rights of others
SMS Text Messaging
Important: Passport may send SMS text messages for account-related purposes when you have a platform account. If you provide your mobile phone number when registering as a visitor/member or checking in at a church using Passport, you are also opting in to receive SMS messages from that church via the Passport platform. These messages may include:
- Account notifications: login alerts, password reset confirmations, security alerts, and account activity notifications
- 2FA: OTP codes such as two-factor authentication and one-time password codes for secure account access
- Customer care: follow-up messages and communications related to recent visits
- Public Service Announcements: service reminders and schedule updates from churches
- Marketing: promotional messages regarding church fundraisers, invitations to church events, revivals, group/ministry opportunities, incentives, engagement promotions
SMS Privacy and Opt-Out
Your mobile phone number will NOT be shared with third parties for marketing purposes. We respect your privacy and will only use your number for the purposes described above.
To opt out of SMS messages: Reply STOP to any church-related message you receive. Note that account notifications and 2FA/OTP codes are transactional and cannot be opted out of, as they are required for account security.
For help with SMS messages: Reply HELP to any message you receive from us.
Message and data rates may apply. Message frequency may vary based on church communications and your participation.
Information Sharing
We do not sell, trade, or otherwise transfer your personal information to third parties without your consent, except as described in this policy. We may share your information:
- With the church or ministry that collected your information through Passport
- With service providers who assist us in operating our platform and conducting our business
- When required by law or to protect our rights
- With your explicit consent
Data Retention
We retain your personal information for as long as your church account is active on our platform. Upon account cancellation, church administrators may export all congregation data within 30 days. After 30 days from cancellation, data is permanently deleted from our systems.
Donation and giving records may have additional retention periods; for full Giving disclosures, see the Privacy Policy in the Passport application. We may retain limited technical and security logs and encrypted backup copies for a short period where required for security, fraud prevention, or legal compliance.
We may retain de-identified or aggregated information that cannot reasonably be linked to you for analytics and service improvement.
Your Privacy Rights
You have the right to: (a) access the personal information we hold about you, (b) request correction of inaccurate information, (c) request deletion of your personal information. To exercise these rights, contact [email protected]. Note: churches are the data controller for congregation data; requests may be forwarded to the relevant church.
Depending on where you live, you may have additional rights regarding personal information we process as a business (for example, portability or opt-out of certain processing). Applicable laws vary by state and country.
You may also have the right to:
- Access — Request confirmation of whether we process your personal information and obtain a copy in accordance with applicable law.
- Correction — Request correction of inaccurate or incomplete information.
- Deletion — Request deletion of your personal information, subject to exceptions (such as legal retention, security, or records we must maintain for churches).
- Portability — Request a copy of certain information in a structured, commonly used format where technically feasible.
- Opt-out of marketing — Unsubscribe from marketing emails or SMS as described in this policy (transactional and security messages may continue where permitted).
- Appeal — Where required by law, appeal a decision if we deny a request.
Churches that use Passport often decide what visitor or member data is collected and why. For information a church entered about you, you may need to contact that church directly; we will assist where we are permitted and able.
To exercise these rights, contact [email protected]. We will respond within a reasonable time and as required by applicable law (often within approximately forty-five (45) days; we may extend where permitted with notice). We may need to verify your identity before fulfilling certain requests.
California Residents — Additional Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information. We do not sell personal information. California residents have the right to: (a) know what personal information we collect and how it is used; (b) request deletion; (c) opt-out of the sale of personal information (we do not sell); (d) non-discrimination for exercising your rights. To exercise these rights, contact [email protected]. We will respond within 45 days.
Data Security
We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure.
Security Incidents and Breach Notification
In the event of a data breach affecting your personal information, we will notify affected users and applicable regulatory authorities within 72 hours of becoming aware of the breach, as required by applicable law.
If we become aware of a breach of security that materially affects personal information under our control, we will investigate, work to mitigate harm, and notify affected churches and/or individuals when required by applicable law or when we reasonably believe notice is appropriate. Notification may be delayed if a law enforcement agency or regulator requests a delay, or when notice could impede a security investigation.
Churches using Passport may have separate legal obligations to their members and visitors. We encourage churches to maintain their own incident response and notification practices consistent with applicable law.
Cookies and Tracking
Our platform may use cookies and similar tracking technologies to enhance your experience and analyze usage. You can control cookie settings through your browser preferences.
Third-Party Links
Our platform may contain links to third-party websites, including church websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
Children's Privacy
Some Passport features allow churches to record information about minors in connection with ministry programs. How that information is collected and used is described in Children's Ministry Data below.
Children's Ministry Data
Passport includes a Children's Ministry Check-In feature used by churches to manage attendance and check-in/check-out records for minors. Data recorded through this feature (such as child name, date of birth, guardian contacts, and check-in/out logs) is entered by the church and controlled by the church. Passport processes this data solely to provide the Check-In service to the church. Churches are responsible for obtaining appropriate parental or guardian consent in accordance with applicable law, including COPPA where applicable. Parents or guardians who wish to review, correct, or request deletion of their child's records should contact their church directly.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date below.
Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
Passport
Email: [email protected]
