Skip to main content
Church Websites

Does My Church Website Need a Privacy Policy? (Yes, and Here's Why)

July 24, 20267 min readBy Crystal Reyes
Hand-drawn line art of a shield with a cross and a padlock, prayer hands, and a document, green and gold pencil hatching

"We're a church, not a business. Do we really need a privacy policy on our website?"

Yes. Absolutely yes.

Your church website collects personal data every single day. And whether you realize it or not, you have legal obligations around how you handle that data. The good news is that creating a privacy policy isn't difficult, and it protects both your church and your congregation.

The Data Your Church Website Collects

You might think your church website is simple. But take a closer look at what's flowing through it.

Contact forms collect names, email addresses, phone numbers, and sometimes home addresses. Prayer request forms collect deeply personal and sensitive information about health, relationships, and struggles. Online giving processes financial data through third-party payment services. Event registration gathers family information, ages of children, dietary restrictions, and emergency contacts. Email signups add people to your newsletter list. Google Analytics tracks every page visit, how long someone stayed, what device they used, and their approximate geographic location.

Prayer requests alone should make the case. Someone submitting a prayer request about a health crisis or a struggling marriage is trusting your church with intensely private information. You owe them a clear explanation of who sees that data and how it's stored.

Legal Requirements That Apply to Churches

Tax-exempt status does not exempt you from data privacy laws. Here's what actually applies to your church.

State Consumer Protection Laws

Most states have consumer protection statutes that require honesty in how organizations represent their data practices. Even if specific privacy statutes exempt nonprofits, making misleading statements (or no statements at all) about data handling can create legal exposure.

CCPA and State Privacy Laws

The California Consumer Privacy Act generally exempts nonprofits. However, if your church operates a for-profit bookstore, coffee shop, or other commercial venture that shares data with the church, the exemption gets complicated. Several other states are passing their own privacy laws with varying provisions for religious organizations.

Even where you're technically exempt, having a clear privacy policy is a best practice that protects you if laws change. And they're changing fast.

GDPR for International Visitors

If your church has any connection to international visitors, missionaries abroad, or supporters in Europe, the General Data Protection Regulation applies. GDPR covers any organization that collects data from EU residents, regardless of where the organization is based or its tax status.

For churches with international mission partnerships, visiting exchange families, or an online sermon audience that includes Europeans, this matters. GDPR requires explicit consent for data collection and gives individuals the right to have their data deleted.

Google Analytics Requires Disclosure

This one catches many churches by surprise. Google's terms of service for Analytics require you to disclose your use of Analytics in a privacy policy. If you run Google Analytics without a privacy policy mentioning it, you're violating Google's terms. This applies to every website that uses the service, churches included.

COPPA and Children's Data

If your church collects any information from children under 13 through your website, the Children's Online Privacy Protection Act (COPPA) applies. This is a federal law with real enforcement from the FTC.

Think about whether your website has any of these: Vacation Bible School registration forms. Kids ministry signup forms. Youth group event registration. Sunday school enrollment.

If any of those forms collect a child's name, email, age, or other personal information, COPPA requires verifiable parental consent before that collection happens. You also need to explain what data you collect from children, how you use it, and your data retention practices.

The safest approach: collect children's information from their parents rather than from the children directly. Structure your forms so a parent fills in their child's details, and make it clear in your privacy policy that you don't knowingly collect information directly from children under 13.

What Your Church Privacy Policy Should Include

Your policy doesn't need to be written in legalese. Plain, clear language is better. Here's what to cover.

Data You Collect

List every type of personal information your website gathers. Names, email addresses, phone numbers, mailing addresses, prayer requests, giving amounts, payment information (processed by your payment provider), IP addresses, and browsing data from analytics.

Purpose of Collection

Explain why you collect each type of data. "We collect email addresses to send our weekly newsletter and event announcements. We collect prayer requests to share with our pastoral care team. We process giving through [payment provider name] to handle your donations."

Third-Party Services

This section is critical. Name every third-party service that receives or processes your congregation's data.

Your online giving platform (Tithe.ly, Pushpay, Subsplash, or whatever you use) processes financial transactions and stores giving history. Your church management system (Planning Center, Breeze, Church Community Builder) stores contact information, group membership, and attendance data. Your email platform (Mailchimp, Constant Contact, or the email tool built into your church management system) stores email addresses and engagement data. Google Analytics tracks browsing behavior on your site.

Each of these services has its own privacy policy. Link to them in yours. For a deeper look at giving platforms, see our guide on online giving for churches.

Cookie Policy

Your website uses cookies if you run Google Analytics, embed YouTube videos, use a chat widget, or have social media share buttons. Explain what cookies are active, what they do, and point visitors to their browser settings for managing cookies.

Data Security

Briefly describe how you protect data. SSL encryption on your website, secure processing through payment providers, and access controls limiting who on staff can see giving records and prayer requests.

How to Opt Out or Request Data Deletion

Give people a clear way to unsubscribe from emails, request removal of their information from your database, or ask questions about their data. An email address for your church office works fine.

Where to Display Your Privacy Policy

Put a link in your website footer on every page. This is the standard location that visitors and regulators expect.

Beyond the footer, add a link (or a checkbox with a link) to your privacy policy on every form that collects data. Your contact form, prayer request form, giving page, event registration, and email signup should all reference the privacy policy before someone hits submit.

If you're building out your church's overall privacy approach, our guide on nonprofit privacy policies covers the broader framework in detail.

How to Create Your Church Privacy Policy

You don't need to hire an attorney to draft your privacy policy from scratch, though legal review is smart if you can afford it.

Start with a Template

Several organizations offer free or low-cost privacy policy templates that work well for churches. Look for templates designed for nonprofits or religious organizations. Customize the template to match your actual data practices. Don't just fill in your church name and call it done.

Customize for Your Specific Tools

The most important customization: listing every third-party service you actually use. A template might mention "payment processors" generically, but your policy should name Tithe.ly, Pushpay, or whichever platform you use.

Get a Review

If your church has an elder, deacon, or board member who's an attorney, ask them to review the draft. They can flag potential issues specific to your state and your church's situation. This doesn't need to be a formal legal engagement. A knowledgeable volunteer spending an hour reviewing the document adds real value.

Keep It Updated

Review your privacy policy at least annually, and update it whenever you add or change a tool that handles personal data. Switched from Tithe.ly to Pushpay? Update the policy. Added a new email marketing tool? Update the policy. Started using a new church management system? Update the policy.

What Happens If You Don't Have One

The risks of operating without a privacy policy are both legal and relational.

On the legal side, violating Google's Analytics terms of service, failing to comply with COPPA if you collect children's data, and misrepresenting your data practices (even through silence) all create potential liability.

On the trust side, donors increasingly ask questions about how organizations handle their data. If a congregation member asks "who can see my giving records?" or "what happens to the prayer requests I submit online?" and you don't have a clear answer, that erodes confidence. A published privacy policy shows your church takes data stewardship as seriously as financial stewardship.

Start Today

Pull up your church website and count every form, every third-party service, and every piece of data you collect. Write down the list. Then draft a privacy policy that honestly describes what you do with that data.

Put it in your footer. Link it from your forms. Set a calendar reminder to review it every January. Your congregation trusts you with their most personal prayers. Show them you take that trust seriously in every dimension.

Enjoying this article?

Get more like it delivered to your inbox. Practical web tips for nonprofits, churches, and community organizations.

Unsubscribe at any time. We value your privacy.

Continue Reading