Privacy Policy
What we hold, who can see it, and what we will never do with it.
GetWoven LLC ("Woven," "we," "us") provides a relational-intelligence platform for churches. This policy explains what personal information we handle, why, and what choices you have.
Woven handles personal information in two distinct roles, and your rights depend on which one applies to you.
Your church directs this
Your church chose to use Woven and directs how your information is used. We process it on your church's behalf and on its instructions. In the language of privacy law, your church is the controller and Woven is the processor.
Requests about your information should go to your church first. We support the church in responding.
This policy governs directly
If you are church staff, a commissioned volunteer, a visitor to this website, or someone contacting us directly, we decide how your information is handled.
You can reach us about it at any time at [email protected].
1 Information we handle
1.1 Congregational data, processed on behalf of your church
When a church connects Woven to its existing church management system ("ChMS"), we receive and process the following on the church's behalf:
- Identity information: name, photograph reference, household relationships
- Contact information: email address and telephone number
- Engagement information: attendance, group membership, serving roles, and the engagement signals we derive from them (see Section 3.1)
- Giving information: gift amount, date, fund, and recurring schedule; transaction records only
- Pastoral notes: notes entered by church staff and volunteers
All ChMS connections are read-only. Woven cannot write to, modify, or delete records in your church's source system.
Payment card numbers, bank account details, government identification numbers, and health information. Payment instruments always remain with your church's giving provider.
1.2 Church-supplied web addresses
A church may ask Woven to look at a web address it supplies: its own public website, or the address of a church management system it hosts itself. We fetch and analyze what is publicly available at that address. We do not use this to gather information about individuals.
1.3 Account data, handled by Woven directly
For church staff and commissioned volunteers who use Woven, we maintain account information: name, email address or phone number used for sign-in, role and permissions, and a log of consequential actions taken in the application.
Woven does not use passwords. Sign-in is by single-use code sent to your registered address.
1.4 Website and support data
When you visit getwoven.church or contact us, we collect what you provide: your name, email address, church, and the contents of your message. We also collect standard server information such as IP address, browser type, and the pages requested.
2 Cookies and tracking
2.1 On getwoven.church
Our marketing site sets no cookies, loads no third-party scripts, and runs no analytics, advertising, or tracking service of any kind. There is nothing to opt out of, because nothing is collecting.
2.2 In the Woven application
The application sets two cookies, both strictly necessary and neither used for tracking: a signed session cookie that keeps you logged in, and a token used to protect against cross-site request forgery. Both are removed when your session ends or you sign out.
2.3 Analytics
We use no analytics or advertising service on any Woven property.
2.4 Global Privacy Control
We honor the Global Privacy Control ("GPC") signal and similar browser-level opt-out preferences where applicable law requires. Because we neither sell personal information nor share it for advertising, a GPC signal does not change how we handle your data. We recognize it all the same, and we do not act contrary to it.
3 How we use information
We use congregational data solely to provide the service to your church: identifying connection opportunities within the congregation, surfacing engagement and pastoral trends for church leadership, and facilitating volunteer-led outreach that the church has commissioned.
We use account, website, and support data to operate and secure the service, respond to inquiries, and communicate with churches about their accounts.
3.1 Engagement signals and automated analysis
Woven's central function is to derive engagement signals from records the church already holds, and to place each person somewhere in the life of the congregation: recently arrived, present but not yet connected, growing, carrying a heavy load, or gradually disengaging. These signals are produced by applying rules and statistical analysis to attendance, group membership, and serving history. They are Woven's assessment, not the church's judgment, and they are visible to church leadership rather than to the congregation.
Two limits apply:
- No automated decision produces a legal or similarly significant effect. A signal results in a suggestion to a human being, who decides whether to act. Woven does not determine eligibility for anything, does not restrict access to anything, and does not act on a person without a human choosing to.
- Giving never influences these signals. Giving information is not used to generate, rank, or route outreach, and it plays no part in matching one person to another.
3.2 What we do not do
- We do not sell personal information, and we have never sold it.
- We do not share personal information for advertising, and we do not advertise to congregants or anyone else based on it.
- We do not use one church's congregational data to serve or benefit another church. Each church's data is isolated to that church. The sole exception is aggregate operational counts, which we use to monitor the health and capacity of the platform. These are totals with no name, contact detail, or identifying attribute attached.
- We do not use congregational data to train machine-learning models, whether our own or anyone else's.
- We do not contact congregants. Woven sends email only to church staff and to volunteers the church has commissioned. Ordinary congregants receive no communication from Woven under any configuration.
4 Who can see what
Woven structurally limits what each type of user can see. These limits are properties of how the system is built, described in detail in our Security Overview.
| Who | What they see | Giving |
|---|---|---|
| Volunteers | A first name and last initial, the reason the connection was suggested, and shared-affinity facts that make the approach natural. The reason may include general participation context: that someone has been attending for a while, or is not yet part of a group. Never attendance figures or engagement scores, under any configuration. Contact details are released only after the volunteer accepts the request, and only for that one individual. | Never, under any configuration |
| Church staff | Records within their church, or within a single campus if so assigned. | Denied by default; available only by explicit per-user grant from the church |
| Church owners | Full access within their own church. | Granted |
| Woven personnel | Our cross-tenant operations console is restricted by automated controls to aggregate counts. It is read-only, cannot return a name or contact detail, and cannot reach a congregant-identifying attribute of any kind. | No access |
Separately from the operations console, a small number of Woven personnel hold administrative access to production systems for maintenance, support, and incident response. That access is limited to what the task requires, and is used only to keep the service running or to answer a church's request for help.
5 How we share information
We share personal information only as follows:
- With your church. Congregational data belongs to the church; we process it on the church's behalf and return it to authorized church users per the access model above.
- When required by law, such as in response to a valid subpoena or court order. Where lawful, we will notify the affected church before disclosure.
- In a business transition, such as a merger or acquisition, in which case this policy would continue to apply to previously collected information.
We never share personal information with data brokers, advertisers, or analytics services for their own use.
5.1 Service providers
Running the service requires vendors who hold or transmit data on our behalf: the managed platform our database runs on, the service that delivers sign-in codes, and our error monitoring. This is not sharing in any ordinary sense. They act only on our instructions, are bound by contract to use the data solely to provide their service to us, and may never use it for their own purposes. A current list is available at [email protected].
6 Sensitive information
We recognize that a person's association with a religious congregation is sensitive information, as are details like attendance, serving, and giving. Most state privacy laws classify religious belief as sensitive personal information.
We treat all congregational data accordingly: it is used only to provide the service to the church, protected by the technical controls described in our Security Overview, and never used for advertising, profiling outside the church's own pastoral purposes, or disclosure to any third party except as described in Section 5.
Where a law requires consent before sensitive information is processed, that obligation belongs to the church as controller, since the church holds the relationship with its congregation. We support churches in meeting it, and we process sensitive information only on the church's instructions.
7 Children
Church records may include information about minors, such as household membership or attendance in children's ministry, where the church's ChMS contains it. This information comes to us from the church, not from children directly, and is processed only on the church's behalf. We use it for no purpose beyond providing the service to the church, and never for advertising or commercial profiling.
Woven's application is intended for use by church staff and adult volunteers; we do not knowingly create accounts for children under 13 or direct any part of the service to them. If you believe a child's information has been provided to us in error, contact your church or [email protected].
8 Security
We apply technical and organizational controls appropriate to the sensitivity of church data, including field-level encryption of contact details and integration credentials, encryption in transit throughout, strict tenant isolation verified at build time, and audit logging that itself excludes names, contact details, and credentials.
Our published Security Overview describes these controls in detail, and we answer reviewer questions directly at [email protected].
If we learn of a breach affecting personal information, we will notify affected churches without undue delay and support their obligations to notify congregants and regulators as applicable law requires.
9 Retention, export, and deletion
We retain congregational data for as long as the church maintains its Woven account and as its instructions require.
- Export. A church may request an export of its data at any time, for as long as its account is active and during the offboarding period below.
- Deletion. When a church ends its relationship with Woven, we delete the church's congregational data from our live systems within 30 days, including the engagement signals and pastoral notes derived from or stored alongside it.
- Backups. Encrypted backups are retained on a rolling cycle and then overwritten. Data deleted from live systems may persist in backup until that cycle completes. Backups are not used to restore individual records, and restored data is re-deleted.
We retain data longer than the periods above only where a legal obligation requires it. Account and support records are retained as long as needed for the purposes described in this policy and to meet legal, tax, and accounting obligations.
10 Your choices and rights
Congregants. Because your church controls this data, direct requests to access, correct, or delete your information to your church. We provide churches the ability to fulfill these requests, and we will refer any request we receive directly to your church.
Staff and volunteers. You may access or correct your account information in the application, or contact us at [email protected].
Depending on where you live, you may have rights under state privacy laws, such as the right to know, correct, or delete personal information, or to opt out of its sale or of targeted advertising. We honor such requests as the law requires, in our role as either business or service provider as applicable. Woven does not sell personal information or engage in targeted advertising, so those particular opt-outs have nothing to act on. We do not discriminate against anyone for exercising privacy rights.
Woven is operated from the United States and the service stores data in the United States. It is intended for churches located in the United States.
11 Contracts with churches
The commitments in this policy are supported by our written agreement with each church, which restricts our use of congregational data to providing the service, prohibits retaining, using, or disclosing it for any other purpose, and binds us to the confidentiality and security obligations described here.
12 Changes to this policy
When we make material changes, we will update the date above and notify churches through the application or by email before the changes take effect. For churches and account holders, continued use of Woven after the effective date constitutes acceptance of the updated policy.
Congregants are not asked to accept anything; their relationship remains with their church, which directs how their information is used.
13 Contact us
GetWoven LLC
[email protected]
Questions from church staff, from reviewers advising a church, or from congregants are all welcome.
getwoven.church/privacy · Woven Privacy Policy, effective 1 August 2026