Privacy Policy
How AsoreOnline collects, uses, protects, and governs personal data.
1. Information We Collect
When a church registers with AsoreOnline, we collect administrator profile details including full name, official email address, telephone number, and payment information. During platform usage, subscriber churches enter data concerning their congregation — including member directories, attendance metrics, contribution logs, cell group assignments, and children check-in records. Subscriber churches act as Data Controllers for congregation records, while AsoreOnline acts as a Data Processor.
2. Purpose & Legal Basis of Processing
We process personal and organization data strictly to operate, maintain, and secure the AsoreOnline platform. This includes account provisioning, identity verification, financial transaction processing, delivering bulk communication services (SMS/Email), preventing unauthorized access, and complying with legal obligations under applicable law.
3. Multi-Tenant Data Isolation & Security
Each church workspace is logically isolated through mandatory tenant header verification (x-church-id) on every server transaction. Database records carry strict church identifiers preventing cross-tenant data leakage. All data transfers across public networks use TLS 1.3 encryption, and passwords are encrypted using industry-standard bcrypt hashing.
4. Third-Party Sub-Processors
We partner with vetted third-party service providers to deliver essential features: Paystack & Mono for payment processing and banking integration, Arkesel & Resend for transactional SMS and email broadcasting, Cloudflare & AWS R2 for content delivery and media storage, and Sentry for error tracking. Sub-processors receive only the minimum necessary data to perform their service.
5. Children Data & Special Category Data
We provide dedicated child check-in and safety modules. Security PINs, guardian contacts, and allergy notes are collected exclusively with parent or guardian authorization and accessible only to designated church child safety officers.
6. Data Retention, Portability & Deletion
Subscriber churches maintain ownership of their records and can export data in standard electronic formats (XLSX, CSV, PDF) at any time. Upon workspace termination, account data is retained for 30 days before permanent deletion from active database clusters, except where financial retention laws require longer archiving.
7. Your Rights & Contacts
Under applicable Data Protection Acts, administrators and church members have rights to access, rectify, or request deletion of their personal data. Church members should submit requests directly to their church administrator. For platform-level privacy inquiries or DPA requests, email privacy@asoreonline.com.
Last updated: August 2026
Questions? Email privacy@asoreonline.com