Privacy Policy
Effective October 7, 2026
Vine ChMS is church-management software published by Vine Software LLC ("Vine," "we," "us"). This Privacy Policy explains how information is handled in the Vine ChMS application and on the Vine ChMS website (www.vinechms.com, including the sign-up and support pages). Each church that uses Vine ChMS runs its own church account (for example yourchurch.vinechms.com): the church, not Vine, decides what information to collect and how it is used. In data-protection terms, the church is the controller of the information in its account; Vine is the software provider that hosts the service and processes that information on the church’s behalf.
1. Information stored in Vine ChMS
A church account may store, at the church's discretion:
- People records — names, households, contact details, birthdays and anniversaries, membership status, notes, and any custom fields the church creates.
- Giving and financial records — contributions, funds, accounting ledgers, vendors, bills, payroll journal entries, and benevolence records.
- Attendance and check-in records — including children's check-in details and guardian contacts.
- Worship, group, calendar, and messaging data — service plans, group membership, events, and message history.
- Pastoral care notes — restricted to logins specifically granted access.
- Staff login accounts — username, display name, role, and a securely hashed password.
2. How information is used
Information is used solely to operate the church's own ministry functions within the app — maintaining a directory, recording giving, planning services, tracking attendance, communicating with members, and producing the church's own reports and statements. Vine does not use a church's ministry data for advertising, and Vine ChMS shows no third-party advertising.
3. Where data lives, and security
Vine ChMS is delivered as a hosted service. A church's data is stored in Vine's managed cloud hosting environment, and the platform keeps each church's data separate from every other church's. Vine ChMS is built to support good security practices: passwords are stored only as bcrypt hashes; sensitive integration credentials are held server-side and are never returned to the browser; and all connections are served over HTTPS. Vine is responsible for the security of the hosting environment. The church is responsible for who it gives access to — its staff accounts, roles, and permissions — and for keeping its own login credentials safe.
4. Third-party integrations and service providers
A church may choose to connect optional third-party services. When enabled, the relevant data is exchanged directly between the church's account and that provider under the provider's own terms and privacy policy:
- Stripe — online giving and payment processing.
- Plaid — bank-account connections for reconciliation.
- Checkr — background checks.
- Text In Church — SMS messaging.
- PraiseCharts — worship chart and song licensing.
Vine does not receive the data exchanged with these providers. Each is optional and off until a church configures it. Separately, Vine itself uses a small number of providers to run the service and website: Stripe (to bill the church's subscription), Postmark (to send service emails such as sign-in and support messages), and Cloudflare (DNS, network protection, and CAPTCHA on our forms).
5. Website, sign-up, support, and billing information
Apart from the information a church keeps inside its own account, Vine collects limited information directly from people who use our website:
- Signing up. When a church signs up we collect the church name, the requested subdomain, the contact person’s name and email, and an optional phone number. This is used to create and support the church’s account and to send the sign-in details.
- Payment. Payments are handled by Stripe. Card details are entered directly into Stripe’s secure form and are never stored on Vine’s servers. Vine receives from Stripe a confirmation of payment, the amount, and customer and subscription identifiers.
- Support. If you create a support account or open a ticket, we store your name, email, church name, role, optional phone number, the contents of your tickets and replies, and a securely hashed password. This is used only to answer your request and improve support.
- Security. We use Cloudflare Turnstile (CAPTCHA) on our forms and record limited technical data such as IP address to prevent abuse and rate-limit requests.
We do not sell this information or use it for advertising.
6. Disclosure
Vine does not sell personal information and does not share a church's ministry data with outside parties, except as required to provide a feature the church has enabled (see §4) or as required by law. A church controls all disclosure of its own data to its members and staff through the app's roles and permissions.
7. Children's information
The check-in feature is designed to record minors' information for the church's own child-safety and reunification purposes. This information is available only to authorized staff within the church's account and should be handled in accordance with the church's own child-protection policies and applicable law.
8. Data retention
Records persist until the church deletes them. Certain records are retained deliberately: for example, when a person is deleted, a name-only placeholder may be retained for up to five years so that historical giving statements continue to show a real name. A church can remove its data at any time. Sign-up, billing, and support records are kept for as long as needed to provide the service and support, and to meet legal, tax, and accounting obligations.
9. Individual rights
Requests to access, correct, or delete personal information held in a church's account should be directed to that church, since the church controls the data. The church can fulfill these requests directly within the app. For information Vine collects directly (sign-up, billing, and support records), contact us using the details in §12.
Email preferences. Emails a church sends to the people in its records (such as group messages, visitor reminders and follow-up messages) include an unsubscribe link. Using it adds your address to that church’s opt-out list, and that church’s emails will no longer be sent to you. You can undo it from the same link. Unsubscribing applies only to that church. It does not stop account and service messages, such as a sign-in confirmation, a password reset, or a reply to a support request you opened. A church’s opt-out list is stored with that church’s data and is deleted when that church’s data is deleted.
10. Cookies and local storage
Vine ChMS uses a single session cookie to keep staff signed in and stores limited preferences (such as light/dark mode and dashboard layout) in the browser. Our website and support pages use session cookies only to keep you signed in and to protect forms from forgery. Stripe, which provides the payment form, and Cloudflare, which provides our CAPTCHA, may set their own cookies as described in their policies. Vine does not use third-party tracking or advertising cookies.
11. Changes
We may update this Privacy Policy from time to time; the effective date above will change accordingly. Continued use of the software after an update constitutes acceptance of the revised policy.
12. Contact
Questions about the software or this policy: Vine Software LLC — open a support ticket or email [email protected].
Questions about a specific church's data should be directed to that church.