Back to home

Privacy Policy

StewardDesk ("we," "our," or "us") is a free tool built to help volunteer church treasurers and assistants manage their church's finances. This Privacy Policy explains what information we collect, how we use it, and how we protect it. We will never sell your data.

1. Information We Collect

We collect only what we need to provide the service:

2. How We Use Your Information

We use the information we collect to:

We do not use your data for advertising, profiling, or any purpose unrelated to operating the service.

3. Role-Based Access Within Your Organization

StewardDesk uses role-based access control. Within each organization, an OrgAdmin can manage users, configure integrations, and access all records. OrgUsers have access to contribution and operational data but cannot manage other users or integration settings. Only users belonging to your organization can access your organization's data.

4. Bank Connectivity via Plaid

StewardDesk uses Plaid to connect to financial institutions. When an organization administrator initiates a bank connection, they interact directly with Plaid's secure interface. Plaid's handling of your financial data is governed by the Plaid End User Privacy Policy. We encourage you to review it before connecting a bank account.

What we import. The bank connection is read-only — StewardDesk can never initiate transfers or move money. We import only inbound transactions (deposits and credits) from the following categories: peer-to-peer transfers (Zelle, Venmo, Cash App), cash and check deposits, ACH and direct deposits, and certain income credits. Outgoing payments, bills, purchases, and transactions in unrelated categories are automatically filtered out and never stored.

Purpose. Imported deposits are held in a staging area for review by your team. Users can then match each deposit to a member and giving category to create a contribution record. Your bank login credentials are never stored by StewardDesk.

Bank connections in StewardDesk are organization-level — one connection serves all users within your organization. The connection persists until an administrator explicitly disconnects it through the Integrations settings page. You may also manage your Plaid data directly at my.plaid.com.

5. Giving Platform Integrations (Zeffy)

StewardDesk supports importing giving records from Zeffy. When this integration is enabled by your organization's administrator and an import is performed, donor information (name, email address), giving amounts, payment method types, and campaign details are fetched via the Zeffy API and stored within your organization's account. This data is governed by this Privacy Policy. The data practices of Zeffy are governed by Zeffy's own privacy policy.

6. Cookies and Sessions

StewardDesk uses a single authentication cookie to maintain your login session. Sessions expire 12 hours after you sign in and do not use sliding expiration — you will be required to sign in again after that period. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

7. Data Storage and Security

Your data is stored in Microsoft Azure (Azure SQL Database and Azure App Service) in the United States. We use industry-standard security practices including:

No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we take your data seriously and maintain appropriate safeguards.

8. Data Sharing

We do not sell, rent, or trade your personal information. We may share data only in the following limited circumstances:

9. Multi-Organization Isolation

StewardDesk is a multi-tenant platform. Each organization's data is stored with a unique site identifier and is accessible only to users within that organization. Database-level query filters enforce this separation — users from one organization cannot access another organization's data.

10. Data Retention

We retain your account and organization data for as long as your account is active. If you request account deletion, we will remove your personal information and organization data within a reasonable timeframe, except where retention is required by law or to resolve pending disputes.

Congregation member records entered by your team are retained as long as your organization's account remains active. Your organization's administrator may delete individual member records at any time from within the application.

11. Your Rights

You have the right to:

To exercise any of these rights, contact us at hello@stewarddesk.com.

12. Children's Privacy

StewardDesk is not directed at children under the age of 13 and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for significant changes, notify users by email. Continued use of StewardDesk after changes take effect constitutes acceptance of the updated policy.

14. Contact

Questions about this Privacy Policy? Reach us at hello@stewarddesk.com or through the contact form.