Legal
Privacy Policy
After Service ("we," "us") provides churches with a private space to store and share photos, video, and written posts with their members. This policy explains what personal data we collect, why, and the rights you have over it — in line with the UK GDPR, the EU GDPR, and the UK Data Protection Act 2018.
Who is responsible for your data
Two roles apply here, and it matters which one is relevant to you:
- Your church is the data controller for the content it uploads and the members it invites — it decides what to share and with whom, using After Service as the tool to do it.
- After Service is the data processor for that content, and acts as the data controller for account-level data we collect directly to run the platform — your login credentials, billing information, and the security/audit records described below.
If you have a question about specific content in your church's space, start with your church admin. For questions about your account or this platform, contact us directly — see "Contact us" below.
What we collect
- Account data: name, email address, and password (stored as a salted hash — we never see or store your actual password).
- Church data: church name, location, and the access code or invite links your admin generates.
- Content you or your church upload: photos, videos, and written posts (newsletters, announcements, programmes).
- Billing data:handled entirely by Stripe — we store only your subscription status and Stripe's customer/subscription IDs, never your card details.
- Security & audit records:a log of sensitive actions (role changes, account deletions, payment events) kept for accountability — see "Security" below.
We do not run analytics or advertising trackers on this site. The only cookies we set are strictly necessary ones that keep you signed in — no consent banner is required for these under UK/EU law, and we don't use any others.
Photos of children
Churches often photograph children — Sunday school, youth groups, baptisms. Your church, as the data controller for that content, is responsible for having appropriate parental or guardian consentbefore uploading photos of minors. After Service provides the secure, access-controlled storage; we don't vet individual uploads.
Why we process your data
- Contract: to provide the service you or your church signed up for.
- Legitimate interest: to keep the platform secure — fraud prevention, rate limiting, and the audit log described below.
- Legal obligation: to meet tax and accounting requirements tied to billing.
Tenant isolation
Every church's data is walled off from every other church's, enforced at the database and storage level — not just in the interface. Members of one church can never read another church's albums, posts, member list, or files. This is verified through automated testing against the live production system, not just assumed.
Media access
Photos and videos are never stored in a publicly-readable location. They're served through short-lived, signed links generated only after we confirm you're an approved, active member of the church that owns them.
Security
Access to church data is enforced by row-level security policies in our database, not application code alone. Sensitive actions — role changes, account deletions, and payment events — are recorded in an audit log that only your church's admins and our platform administrators can read. We rate-limit actions like joining a church by access code to make brute-force guessing impractical.
Who else processes your data
We use a small number of specialist providers to run the platform, each acting as a sub-processor under contract:
- Supabase — our database, authentication, and file storage.
- Stripe — payment processing. Stripe handles your card details directly; we never see or store them.
- Vercel — application hosting.
These providers may process data outside your home country (including the United States); each maintains its own GDPR-compliant safeguards, such as Standard Contractual Clauses, for international transfers.
How long we keep your data
We keep your account and church data for as long as your account or church exists. If your church's subscription is canceled, its space is locked (not accessible) but not automatically deleted — an admin can reactivate billing to restore access at any time. Deleting your account removes your profile and memberships everywhere; if you're the only member of a church, that church and its files are deleted too — see "Your rights" below for exactly how this works.
Your rights
Under UK/EU GDPR you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. For this platform, the first two are self-service, right now, without needing to contact anyone:
- Export your data:sign in, go to Account, and click "Download my data" for a full copy of your profile, memberships, and anything you've uploaded or posted.
- Delete your account:sign in, go to Account, and use "Delete my account." This removes your profile and church memberships everywhere. Photos, videos, and posts you contributed stay with your church for other members to keep — unless you were the church's only member, in which case the whole church and its files are deleted with you.
For anything else — correcting inaccurate data, objecting to processing, or a question about content someone else uploaded — contact us (below) or your church admin.
Changes to this policy
If we make a material change to how we handle your data, we'll update the date at the top of this page.
Contact us
Questions about this policy or your data: privacy@afterservice.app — replace this with your real support address before launch.