Privacy policy

Last updated: August 16, 2026

WayHouse, Inc. (“WayHouse,” “we,” “us”) provides a church-management workspace at wayhouseonline.com and the WayHouse app for iPhone. This policy explains what both products collect, why, and how it’s handled.

Who controls what

A church using WayHouse is the data controller for its own congregation’s information — members, prayer requests, attendance, giving records, and communications. WayHouse acts as a data processor: we store and process that information on the church’s behalf and under its instructions. If you’re a member of a church wondering what’s held about you, your church is the right first stop — see “If you’re a congregation member” below.

What we collect

Account data — when a church staff member or congregation member activates an account, we collect the name, email, and authentication information needed to sign them in.

Congregation data — whatever a church chooses to enter or upload: member profiles (names, emails, phone numbers, birthdays, household groupings), prayer requests, attendance, sermon content, broadcast history, and — once giving is available — donation records. This data belongs to the church; we don’t use it for our own marketing or resell it.

Usage and log data — standard operational data generated by using the service (IP address, device/browser information, timestamps, error logs), used for security, debugging, and keeping the product reliable.

Cookies — we use cookies required to keep you signed in and to maintain your session (via Supabase Auth). We do not run third-party advertising trackers or analytics scripts on WayHouse today.

What the mobile app collects

The app reads the member and congregation information your church makes available to you, including your profile, household, directory, events, groups, serving schedule, prayer requests, messages, and sermons. Information you submit — such as profile edits, prayer requests and comments, group posts and chat messages, RSVPs, and volunteer availability — is sent to WayHouse and stored for your church.

If you choose a profile or family photo, the app can read the image you select from your photo library. It does not request access to your location, contacts, calendar, camera, microphone, health data, or advertising identifier.

If you enable notifications, we store an Expo push token with your user account and device so the app can receive the categories you choose. The app also keeps your session and limited read-cache data in its local app storage so it can keep you signed in and recover gracefully from a weak connection.

The iPhone app contains no advertising or product-analytics SDKs and does not use data for cross-app tracking. It does not collect payment information.

Video from other services

When a church publishes a sermon hosted by YouTube or Vimeo, the app plays it in an embedded web view. Those services may process playback information or set their own cookies under their privacy policies. WayHouse does not send them your member profile.

How we use it

To operate your workspace, send the transactional and broadcast emails a church authorizes, protect against abuse and spam, and maintain and improve the product. We do not sell personal data, and we do not use congregation data to train AI models.

Sub-processors

We rely on a small set of infrastructure providers to run the service. Each receives only what it needs to do its job:

  • Supabase — database, authentication, and file storage. Congregation data is hosted in Supabase-managed Postgres, isolated per tenant with row-level security.
  • Vercel — application hosting and delivery.
  • Resend — sends transactional email (account, password reset) and email broadcasts a church chooses to send.
  • Expo — delivers app updates and push notifications to the mobile app.
  • Sentry — when error diagnostics are enabled, receives technical crash and error details so we can diagnose reliability problems.
  • Stripe — bills paid subscription plans; will also process giving, as the church’s payment processor, once that feature is live.
  • Cloudflare (Turnstile) — bot protection on public forms, such as our contact form.

Where data is hosted

Congregation and account data is hosted with Supabase, on managed Postgres infrastructure. We don’t publish a specific hosting region here; if your church has a data-residency requirement, contact us and we’ll tell you what we can confirm.

Retention and deletion

Congregation data is retained for as long as a church keeps it in its workspace. When a church deletes a record, or closes its account, we delete the underlying data (subject to what our sub-processors need to briefly retain for backups and operational continuity). Churches can export their data — members, gifts, and history — at any time from their workspace, or by asking us.

A congregation member can permanently delete their WayHouse sign-in account from MoreProfileDelete account in the iPhone app or member website. Deletion permanently removes the member’s WayHouse sign-in account, access across every church, account notification data, member profile photo files, and the prayer, group, and chat content they authored. A thread may retain a content-free placeholder where removing the row would break the conversation.

Deleting a WayHouse account does not delete a church’s separate pastoral or membership record. The account is detached from those records and can no longer use them for app access, while the church continues to control its household, attendance, serving, and other church-managed history. See the account deletion guide for the exact steps and distinction.

If you’re a congregation member

If you attend a church that uses WayHouse and want to know what information is held about you, correct it, or have it removed, please contact your church directly first — they control their own records and can act on your request immediately. We assist churches with these requests whenever they reach out to us.

Security

Data is encrypted in transit. Every church’s data is isolated from every other church’s at the database level, using Postgres row-level security — one tenant cannot read another tenant’s records. Internal access follows the principle of least privilege. We don’t claim a specific compliance certification (such as SOC 2 or HIPAA) at this time.

Children’s information

WayHouse is not directed at children under 13. Congregation records can include minors — for example, a child’s name and birthday in a household — when a church stores that information as part of its own records. We do not market to children. If you believe a child under 13 has activated an account, contact the church and WayHouse so the account can be reviewed.

Changes to this policy

We may update this policy as the product changes. We’ll update the effective date above when we do, and we’ll flag material changes to churches on the platform or by email.

Questions about this policy? hello@wayhouseonline.com.