Privacy
Data protection is not an afterthought at Churchpoint. We collect as little data as possible, deliver this page from Frankfurt and do without tracking and advertising. The app reports technical errors to a service in the EU so that we can fix crashes (section 6.1). This policy applies to the website churchpoint.de and to the Churchpoint app.
Last updated: September 2026
English translation
This English version is a translation provided for easier understanding. The binding and legally authoritative version is the German one: Datenschutzerklärung (German version).
1. Controller
The controller for the processing of personal data within the meaning of the GDPR is:
Louis Saks
Palisadenstraße 53
10243 Berlin
Germany
Email: info@churchpoint.de
We are not required to appoint a data protection officer. For any data protection matter you can reach us directly at the address above.
2. Scope
This policy applies to:
- the website churchpoint.de, including the event overview, event registration and contact form,
- the Churchpoint app for iPhone and Android,
- the servers, databases and emails behind them (tickets, reminders).
The website and the app use the same database. What you do in the app you will also find in the browser, and the other way round.
3. At a glance
- No account needed: you can discover events without registering at all, and for a ticket we only ask for your name and email address. Individual organisers can request further fields in the app (see section 6.1).
- No tracking, no advertising: no third party analytics services, no ad networks, no profiling, no disclosure for advertising purposes. In the app we count anonymously how often individual areas are used, without any link to a person (section 6.7). In addition, the app reports technical error messages to Sentry (EU region) so that we learn about crashes, and it checks Expo for updates (section 6.1).
- No cookies that would require consent: that is why there is no cookie banner here either (details under Cookies).
- EU hosting: database in Ireland, delivery of this website from Frankfurt am Main.
- No external fonts or scripts: everything comes from our own server.
4. Who is responsible for what?
Churchpoint is a platform. The events are published by churches, congregations and Christian organisations (“organisers”) themselves.
- We are responsible for operating the platform: website, app, database, ticket delivery, payment processing.
- The respective organiser receives the registration data of the participants of their event (name, email address, number of places, ticket status and the additional fields they requested) and is themselves responsible under data protection law for any further use of that data, such as the participant list, admission, export and messages to participants.
So if you want to know what a particular organiser does with your data, contact them directly. After registering you can reach them through the reply address of your ticket email. In the Churchpoint app you can also open their profile beforehand. If their contact details are shown on the event page, you can use those as well. We are happy to help if you cannot get through.
4a. Registrations for religious events (Art. 9 GDPR)
Churchpoint arranges tickets for Christian events. The information that a particular person has registered for a church service or a prayer evening can therefore indicate their religious belief. Under Art. 9 GDPR such information belongs to the special categories of personal data and enjoys particular protection.
We handle this accordingly on the technical side:
- Stripe receives neither the event title nor your name. On the payment page the line item reads only “Ticket” with the date. Your name stays in our database in the EU, not with Stripe.
- Your bank statement shows no congregation name, only a fixed, neutral descriptor.
- The subject line of the ticket email contains no event title, only “Your ticket” with the date. That way it does not appear in logs or mailbox previews.
- Participant data is anonymised automatically 90 days after the event (see section 10).
A note in our own cause: which exception under Art. 9(2) GDPR the processing relies on is currently being reviewed by a lawyer and will be added here. Until then the following applies: you decide yourself whether to register, and you can withdraw your registration at any time and have your data deleted (section 11).
5. The website churchpoint.de
5.1 Visiting the website (server log files)
When you visit the site, technically necessary access data is processed: IP address, date and time, the address requested, the amount of data transferred, browser type and operating system. This is necessary for delivering the page and for its security (Art. 6(1)(f) GDPR, legitimate interests in stable and secure operation). This data is not merged with other data and is not used to analyse your behaviour.
5.2 Contact and organiser enquiries
When you write to us, we process the details you enter: name, email address, message, and for organiser enquiries additionally the congregation or organisation and the location, in order to answer your enquiry (Art. 6(1)(b) or (f) GDPR). Name, email and message are mandatory fields. If you select “I am an organiser”, the congregation or organisation becomes mandatory as well. The location remains optional.
5.3 Registering for an event in the browser
You can register for an event here without an account. For this we process your name, email address and the number of places in order to carry out the registration and send you the digital ticket (Art. 6(1)(b) GDPR, performance of a contract). Your details are passed on to the organiser of the event in question. They keep the participant list and scan the ticket at the entrance.
The organiser can enable two further fields for their event: a phone number and a comment field, for example for questions or catering details. Both are switched off by default, and where they do appear they are optional. Whatever you enter there goes to the organiser (Art. 6(1)(b) GDPR). Please enter only what the organiser really needs in the comment field.
In the registration form you can also tick a box: messages from the organiser about this event. This is optional, the box is not pre-ticked, and you get your ticket either way. Only if you tick it may the organiser write to you about this event, for example if the time changes. The legal basis is your consent under Art. 6(1)(a) GDPR. We record the time at which you gave your consent. You can withdraw it at any time with effect for the future: every such message contains an unsubscribe link, and the email header contains an unsubscribe entry that many mail programs show as a separate button. Withdrawing changes nothing about your registration and nothing about your ticket.
5.4 Paid tickets
For paid tickets you are forwarded to the hosted payment page of Stripe. You enter payment data such as card number or bank details exclusively there; we neither see nor store it. From Stripe we only receive a payment reference and the information whether the payment was successful, so that we can assign the ticket to you (Art. 6(1)(b) GDPR). The privacy notices of Stripe apply in addition.
In the other direction we transmit to Stripe: your email address, so that Stripe can send you the payment receipt, plus the identifier of the event and the number of places as a technical reference. Not transmitted are your name, the title of the event, your phone number and your comment. Section 4a explains why it is built this way.
5.5 Protection against misuse (forms and app)
To stop the contact form, the event registration and the functions of the app from being misused automatically, we limit the number of operations. Neither your IP address nor your email address is stored in plain text for this. In each case a fingerprint (SHA-256) is created. The original value cannot be read from it. However, anyone who already knows an email address can check whether it matches a stored fingerprint. We therefore treat these values as personal data and delete them after a short time. This happens in two places, with different storage (Art. 6(1)(f) GDPR):
- Contact form and confirmation links on the website: the fingerprint of the IP address stays exclusively in the working memory of the server, for at most 10 minutes. It is not written to a database.
- Event registration, organiser registration, payment confirmation, ticket recovery, refund and translation: here the fingerprint is stored together with a counter in our database in the EU, because the limit has to work across several servers. For event registration it is the fingerprint of the email address, otherwise that of the IP address. A nightly job deletes these entries, after 2 days at the latest.
Only the fingerprint, the purpose of the limit and the counter value are stored. No log of individual operations is created, and therefore no history of when you did what. Nothing is passed on.
5.6 No cookies, no tracking
We use no tracking or marketing cookies, we run no ad networks and we create no user profiles. Fonts, images and videos are delivered exclusively from our own server. In particular, no call is made to Google Fonts or other external services. Only event images are loaded from our own storage at Supabase (EU).
6. The Churchpoint app
6.1 Which data arises in the app
- Event registration and ticket: name and email address, number of places and the event booked, as in the browser, without an account.
- Additional fields per event: the organiser can additionally request a phone number and a comment field for their event, for example for questions or catering details. Which fields appear is shown in the registration form; they are switched off by default. Whatever you enter there goes to the organiser (Art. 6(1)(b) GDPR). Please enter only what the organiser really needs in the comment field.
- Paid tickets: processed via Stripe, see section 5.4.
- Technical access data when the events are fetched from the server (including IP address and time), necessary for operation.
- Organiser accounts: see section 7.
The app contains no third party analytics or advertising SDKs: no Google Analytics, no Facebook SDK, no ad tracking. We only keep our own anonymous usage statistics without any link to a person, see section 6.7.
Error reporting (Sentry). So that we learn about crashes and errors before anyone complains, the app reports technical error messages to Sentry. The data is stored in the EU region. Transmitted are the error text, the error code and the place in the program. Personal details are removed beforehand. Screenshots, session replay and the content of network requests are expressly switched off. Legal basis: Art. 6(1)(f) GDPR, legitimate interests in a working app.
App updates (Expo). On start and when returning from the background, the app checks whether a new version is available. A persistent device identifier and the IP address are transmitted to Expo in the process. Without this check we could not fix errors promptly. Legal basis: Art. 6(1)(f) GDPR.
6.2 Permissions and what they are for
All permissions are optional, are only requested at the moment they are used and can be withdrawn at any time in the device settings. Without them the app keeps working, only the function in question is unavailable.
- Location: to show events near you first and to centre the map on your surroundings. The location is used on the device for sorting and is not stored by us (Art. 6(1)(a) GDPR, consent).
- Camera: only for organisers, to scan tickets as a QR code at the entrance. No images are taken or transmitted. Only the ticket code is evaluated (Art. 6(1)(b) GDPR).
- Photos and media library: to upload an event image or a profile picture (organisers) and to save your ticket as an image in your gallery. Only the images you select are read (Art. 6(1)(a) and (b) GDPR).
- Calendar: to add an event as an appointment if you ask for it. We do not read your appointments. The app only asks which calendars exist on the device and which of them is your default calendar, and writes exactly there. If that is a calendar your device synchronises with a service such as iCloud or Google, the appointment travels along through that service. After adding it, the app shows you which calendar the appointment went into (Art. 6(1)(a) GDPR).
- Notifications: for four occasions. First, reminders for events you hold a ticket for (24 hours and 3 hours in advance). Second, a single reminder for saved events (24 hours in advance). Third, a one off notice when places are running out for a saved event. Fourth, a notice when an organiser you follow creates a new event. All four can be switched off individually in the app. They are scheduled locally on the device. No push token is created and nothing is transmitted to us or to third parties (Art. 6(1)(a) GDPR).
On Android devices the system permission list may additionally show the microphone permission. It comes from the camera component we use. Churchpoint never records audio and does not request the permission.
6.3 Data that does not leave your device
Stored locally on the device are:
- your tickets (so that they also work offline and without reception),
- your favourites and saved organisers,
- whether you have already seen the onboarding,
- whether you agreed to the ticket email being sent,
- whether you switched off the anonymous usage statistics (section 6.7),
- your language and region setting (taken from the operating system).
This data stays exclusively in the app on your device. If you delete the app, it is gone.
Only on organisers’ devices: whoever scans tickets at the entrance often has a poor connection. So that admission still works, the app downloads the guest list of the event in question onto the device when the scanner is opened. Only what admission needs is stored: ticket number, name, whether it was paid and whether the ticket has already been used. Email address, phone number and comment stay out. The list deletes itself after 3 days, and check-ins not yet transmitted after 7 days. The legal basis is Art. 6(1)(b) GDPR, because admission cannot be carried out without this list. The organiser is responsible for how the list is handled on their device, see section 4.
6.4 Map and address lookup
The map view uses the map service of your operating system: on iPhones Apple Maps (Apple Inc.), on Android devices Google Maps (Google Ireland Ltd. and Google LLC). When you open the map, technically necessary data such as the IP address and the map section displayed is transmitted to the respective provider. The same applies when an event address is converted into coordinates in order to place it on the map, because the address is then passed to the geocoding service of the operating system.
The legal basis is our legitimate interests in a usable map display (Art. 6(1)(f) GDPR). Both providers may also process data in the USA, see section 9. If you want to avoid that, use the list view instead of the map.
6.5 Translation of event texts
The app is available in eleven languages. So that events can be read in other languages too, the event texts entered by the organiser (title, description) are translated automatically, via DeepL SE (Germany) or the Google Cloud Translation API (Google Ireland Ltd.). Only these public event texts are transmitted, no participant data (Art. 6(1)(f) GDPR). Organisers should therefore not include personal details of third parties in event descriptions.
6.6 App stores
The app is downloaded through the App Store (Apple) or Google Play (Google). In doing so, Apple and Google process data such as your store identifier, device data and time of download under their own responsibility. We have no influence on that. The privacy notices of the respective provider apply.
6.7 Anonymous usage statistics
So that we can improve the app, we count how often certain areas are used, for example how often the map is opened, an event is viewed or a registration is completed. All that is stored is a counter per day: which area, which day, how often, plus the operating system (iOS or Android) and the app language set. For counters that relate to a specific event (for example “event viewed”), the identifier of that event is stored as well. It says which event was meant, not who viewed it.
Not stored are: your name, your email address, a device identifier, your IP address, the time of day or any text you entered. No identifier is created that would recognise you across several visits. These figures do not allow any conclusion about who did something. It is not possible to tell whether one person or a hundred people are behind a hundred views. There is therefore no link to a person within the meaning of the GDPR, and no profiling takes place.
For the counting itself nothing is stored on your device and nothing is read from it, a counter on our own server is simply increased. The only thing kept locally is your own decision: if you switch the counting off, the app remembers exactly that switch on the device. Consent under Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act) is not required for this. The data is stored in our own database in the EU (Ireland, see section 8) and is not passed on to third parties. The legal basis is our legitimate interests in a working, understandable app (Art. 6(1)(f) GDPR), to the extent that the figures can be regarded as personal data at all.
Switching it off: you can switch the counting off in the app at any time under “More” to “Legal” to “Anonymous usage statistics”. After that nothing is counted any more. Counters that already exist cannot be attributed individually and can therefore not be assigned to a person afterwards or deleted for them.
7. Organiser accounts
Organisers need an account. Registration is only possible with a valid invitation code.
- Account: email address and password (stored only as a cryptographic hash, never in plain text), authentication via Supabase Auth (Art. 6(1)(b) GDPR).
- Public profile: name of the congregation or organisation, description, website, social links, profile picture, a public contact email address and up to three freely labelled links of their own. The organiser provides these details themselves and they are deliberately publicly visible.
- Payouts for paid tickets: processing runs through Stripe Connect. For this, Stripe collects the legally required identity, bank and tax data directly from the organiser (anti money laundering). Of that we only receive the status (“payouts active”) and the revenue totals, not the identity documents or bank details themselves.
- Messages to participants: organisers can send up to three bulk emails per event to their participants. Sending runs through our email service provider. We also store the subject and the text in our database, so that it can be traced who sent what and when, and so that the limit of three messages takes effect. The organiser is responsible for the content. For the retention period see section 10.
An organiser account can be deleted directly in the app (“More”, then account). This deletes the profile, the login, all events created by the organiser together with the associated registrations and tickets, and the uploaded images. The connection to the payment service provider is severed.
Two things come with this that you should know beforehand. First, deletion is blocked as long as bookable events still lie in the future or refunds are still open. Otherwise guests would be left with a ticket and nobody behind it. Cancel the events first, then the deletion goes through. Second, a deletion record remains: the former account identifier, the identifier of the payment account and the time. It contains neither a name nor an email address and serves solely as proof that we deleted correctly (Art. 5(2) GDPR). For the retention period see section 10.
The page Delete account and data describes the whole route, including for guests without an account.
8. Recipients and processors
We only pass data on where it is necessary for operation. Data processing agreements under Art. 28 GDPR are in place with all service providers.
- Functional Software, Inc. (Sentry, USA), error reporting for the app. The data is stored in the EU region. Transmitted are the error text, the error code and the place in the program, without personal details. See section 6.1.
- Expo (650 Industries, Inc., USA), delivery of app updates. With every update check a persistent device identifier and the IP address are transmitted. See section 6.1.
- Supabase, Inc. (USA), database, accounts and image storage. The data is stored in the Ireland (EU) region. Provider access from the USA is based on standard contractual clauses.
- Vercel, Inc. (USA), hosting of the website. Delivery and form processing are pinned to the Frankfurt am Main (fra1) region. Vercel is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition.
- Resend (Plus Five Five, Inc., USA), email delivery for tickets, reminders, organiser bulk emails and contact enquiries. Sending runs through the Ireland (eu-west-1) region; metadata and delivery logs are, however, stored in the USA. Resend is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition.
- Stripe Payments Europe, Ltd. (Ireland), payment processing and payouts to organisers. Stripe processes payment data as its own controller.
- Apple Inc. and Google Ireland Ltd., map display in the app and provision of the app through the stores (see sections 6.4 and 6.6).
- DeepL SE (Germany) and Google Ireland Ltd., translation of public event texts (see section 6.5).
Beyond that we pass data on where we are legally obliged to do so, for example to the tax authorities in the case of paid tickets.
9. Transfers to third countries
We have deliberately placed all core systems in the EU. Where access from the USA cannot be avoided (see section 8), we base the transfer on an adequacy decision of the EU Commission (EU-US Data Privacy Framework) or on standard contractual clauses under Art. 46(2)(c) GDPR. Despite these safeguards there remains a residual risk that US authorities access the data without you having effective legal remedies against it.
10. Retention periods
- Contact enquiries: deleted at the latest 6 months after the enquiry has been dealt with, unless a statutory retention obligation applies.
- Event registrations and tickets: name, email address, phone number, comment and the time of consent are deleted automatically 90 days after the end of the event (nightly job). For free tickets, only the number of registrations remains afterwards, with no link to a person. For paid tickets the payment reference number also remains, because we have to keep the receipt for tax purposes. Through that number an assignment would still be possible at the payment service provider for as long as their retention period runs. With us there is no name left at that point.
- Details cached during the payment process (phone number and comment between the click on pay and the creation of the ticket): deleted after 2 days.
- Receipts for paid tickets: kept for the commercial and tax law retention periods (as a rule 10 years); during that time processing is limited to storage.
- Organiser accounts: until deleted by the organiser.
- Server log files: deleted or anonymised after 30 days at the latest.
- Fingerprints for protection against misuse (section 5.5): on the website for at most 10 minutes and only in working memory, in the database deleted after 2 days at the latest.
- Bulk emails from organisers (subject and text): deleted automatically 90 days after the end of the associated event, together with the participant data.
- Deletion record after an account deletion (section 7): deleted automatically after 3 years. For that long a supervisory authority can ask us whether we deleted correctly.
- Anonymous counters of the usage statistics: deleted automatically after 400 days.
- Data on your device: until you delete it in the app or uninstall the app.
11. Your rights
You have the right at any time to:
- access to the data stored about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent you have given, with effect for the future (Art. 7(3) GDPR), for example for location, calendar or notifications, directly in the device settings
- withdraw your consent to messages from the organiser (Art. 7(3) GDPR), through the unsubscribe link in every such message (section 5.3)
An informal message to info@churchpoint.de is enough. Organisers can also delete their account directly in the app. If your request concerns the participant list of a particular event, contact the organiser. We will forward the request on request.
Your right to object under Art. 21 GDPR
Some processing is based on our legitimate interests (Art. 6(1)(f) GDPR): the secure operation of the website, protection against misuse, error reporting, the update check, the map display, the translation of event texts and the anonymous usage statistics. You can object at any time to each of these processing operations, on grounds relating to your particular situation. A message to info@churchpoint.de is enough. We will then stop processing the data, unless we can demonstrate compelling legitimate grounds that override your interests.
No automated decision making. We do not take decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). No profiling takes place.
Do you have to provide your data? You are under no statutory or contractual obligation to do so. Without a name and email address, however, we cannot issue a ticket for you or answer an enquiry, and without an account an organiser cannot create events. Everything else, meaning phone number, comment, location, calendar and notifications, is optional. If you leave it out, only the function in question is unavailable.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59-61, 10555 Berlin
datenschutz-berlin.de
You can also turn instead to the supervisory authority of the federal state in which you live or work, or to that of the place where the suspected infringement took place.
13. Minors
Churchpoint is not specifically aimed at children. You can give consent yourself from the age of 16, for example for location or for sending the ticket email. Below that age the consent of a parent or guardian is required. If parents or guardians contact us, we delete the registrations concerned without delay.
14. Data security
Transmission is encrypted throughout via HTTPS (with HSTS). Access to the database is secured row by row through access rules, so that organisers only see the data of their own events. Passwords are stored only as a hash. Credentials for external services are held on the server side. None of them are held in the app or in the browser, with one technically unavoidable exception: the key for the map display on Android devices has to be shipped inside the app. It serves the map display only and gives no access to user data. Digital tickets also work offline.
15. Changes to this policy
We adjust this privacy policy when the website, the app or the legal situation changes. The version published here applies in each case; the date above shows the current status.
