Back to Home

Privacy Policy

Last Updated: July 14, 2026

This Privacy Policy explains how Node78 LLC ("Node78," "we," "our," or "us"), the company that provides the Ministry Order software and applications ("Ministry Order"), collects, uses, and shares personal information through www.ministryorder.com, our web application, and our mobile apps (together, the "Service"). Capitalized terms not defined here have the meaning given in our Terms of Service.

Two kinds of data, two roles

Information we collect for ourselves. Account, billing, and usage information we collect directly from you to run our business. For this data, we are the data controller (GDPR) or business (US state privacy laws).

Information organizations collect. Rosters, schedules, and volunteer details that a church or ministry (an "Organization") enters into the Service. For this data, the Organization is the controller and we are its processor (GDPR) or service provider (CCPA/CPRA), acting only on the Organization's instructions. If your information appears in an Organization's account, please contact that Organization first and review its own privacy notice — this Policy covers what we do, not how the Organization uses the data it collects.

Contents
  1. Information We Collect
  2. How We Use Information
  3. Legal Bases (EEA & UK)
  4. How We Share Information
  5. Cookies & Similar Technologies
  6. Data Retention
  7. Security & Breach Notification
  8. International Data Transfers
  9. Your Privacy Rights
  10. Rights for EEA & UK Residents
  11. Rights for US State Residents
  12. Do Not Track & Global Privacy Control
  13. Children's Privacy
  14. Links to Other Sites
  15. Changes to This Policy
  16. Contact & Complaints

1. Information We Collect

Account information

Your name, email address, password credentials, and organization details provided during registration. Authentication is handled through Google Firebase.

Roster & schedule data

Information Organizations enter about their teams and volunteers — names, contact details, roles, availability, and brief emergency notes. This may include information about minors, entered under the Organization's responsibility (see Children's Privacy).

Payment information

Payments are processed by Stripe. We receive transaction status and limited card details (such as brand and last four digits) but never store full card numbers on our servers.

Usage & device data

When you use the Service, we automatically collect data such as your IP address, browser and device type, pages viewed, actions taken, timestamps, and diagnostic logs. We use this data for security, debugging, and improving the Service.

Support communications

If you contact us, we keep the correspondence so we can help you and improve our support.

2. How We Use Information

We use personal information to: provide, operate, and maintain the Service; create and authenticate accounts; process subscription payments and keep tax records; respond to support requests; send service notices such as billing or security alerts and changes to the Service or these policies; monitor performance, fix bugs, and improve features; detect and prevent fraud, abuse, and security incidents; and comply with legal obligations. If we send marketing emails, they will include an unsubscribe link and you can opt out at any time.

Where the GDPR or UK GDPR applies, we process personal information: to perform our contract with you (providing the Service, billing, and support); for our legitimate interests in securing and improving the Service and preventing abuse, where those interests are not overridden by your rights; with your consent, for things like non-essential cookies, which you can withdraw at any time; and to comply with legal obligations, such as tax record-keeping.

4. How We Share Information

We do not sell personal information, and we do not share it for cross-context behavioral or targeted advertising. We share personal information only:

A current list of our subprocessors is available on request.

5. Cookies & Similar Technologies

We use essential cookies that are strictly necessary to sign you in and keep your session secure; these do not require consent. Where we use non-essential cookies, such as analytics, we ask for your consent first in regions where consent is required (including the EEA and UK), and you can accept, decline, or change your choices at any time through the cookie banner. We honor Global Privacy Control signals as an opt-out where the law requires. For a full list of the cookies we use and how to manage them, see our Cookie Notice.

6. Data Retention

We keep account information for as long as your account is active. When an Organization cancels or deletes its account, we delete Customer Data, including roster information, within 90 days, and residual copies leave our encrypted backups within 180 days. We retain billing and tax records for as long as the law requires (typically seven years), and server logs for up to 24 months for security purposes. We may retain information longer where necessary to resolve disputes or enforce our agreements.

7. Security & Breach Notification

We protect personal information with measures that include encryption in transit and at rest, access controls, and the security infrastructure of Google Cloud and Stripe. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach affects you, we will notify you and any applicable regulator without undue delay, by email or a notice in the Service, as required by law.

8. International Data Transfers

We are based in the United States, and personal information is stored and processed on servers in the US. Where we transfer personal information from the EEA, the UK, or Switzerland, we rely on appropriate safeguards: our providers' certifications under the EU–US Data Privacy Framework (including the UK Extension and the Swiss–US DPF) and, where applicable, the European Commission's Standard Contractual Clauses. You can contact us for more information about these safeguards.

9. Your Privacy Rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To exercise a right, email support@node78.com with the subject "Privacy Request." We may need to verify your identity before responding, and we will reply within the timeframe your local law requires.

If your request concerns roster data controlled by an Organization, we will refer your request to that Organization and support it in responding, since we act only on its instructions for that data.

10. Additional Rights for EEA & UK Residents

If you are in the EEA or the UK, you have the following rights over personal information for which we are the controller:

  1. Access — request a copy of your personal information and details about how we process it.
  2. Rectification — have inaccurate or incomplete information corrected.
  3. Erasure — ask us to delete your personal information in certain circumstances.
  4. Restriction — ask us to limit processing in certain circumstances.
  5. Portability — receive your information in a structured, commonly used, machine-readable format.
  6. Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  7. Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

You also have the right to lodge a complaint with your data protection authority — in the EEA, see the European Data Protection Board's list of members; in the UK, the Information Commissioner's Office (ICO). Organizations that need a Data Processing Addendum can request one at support@node78.com.

11. Additional Rights for US State Residents

Residents of California and a growing number of other states — including Texas, Virginia, Colorado, Connecticut, and Oregon — have specific privacy rights. Where these laws apply to us, you may:

In the preceding 12 months, we have collected the categories described in Section 1 — identifiers (like name and email), commercial information (subscription records), and internet activity (usage data) — from you directly, from your Organization, and automatically from your device, for the business purposes in Section 2, and disclosed them only to the service providers listed in Section 4.

You may use an authorized agent to submit a request with written proof of authorization, and we may verify your identity. If we decline a request, we will explain why, and where your state provides an appeal right, you may appeal by replying to our decision. California's "Shine the Light" law: we do not disclose personal information to third parties for their direct marketing purposes.

12. Do Not Track & Global Privacy Control

There is no settled industry standard for "Do Not Track" browser signals, and the Service does not respond to them. We do treat Global Privacy Control signals as a valid opt-out of sale, sharing, or targeted advertising where the law requires — though, as stated above, we do not sell or share personal information for those purposes.

13. Children's Privacy

You must be at least 13 to create an account, and we do not knowingly collect personal information from children under 13 for our own purposes.

Organizations may enter limited information about minors into their rosters — for example, a youth volunteer's name and a guardian's contact details. For that information, the Organization is the controller: it is responsible for obtaining verifiable parental or guardian consent where required by COPPA, the GDPR, or other applicable law, and we process the information solely on the Organization's instructions and never use it for our own purposes.

If you are a parent or guardian and believe your child's information was entered without proper consent, please contact the Organization first; you can also email support@node78.com and we will work with the Organization to address your concern. If we learn we have collected a child's personal information for our own purposes without required consent, we will delete it promptly.

The Service may contain links to websites we do not operate. We are not responsible for their content or privacy practices, and we encourage you to review the privacy policy of every site you visit.

15. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by email or a prominent notice in the Service before the changes take effect, and we will update the "Last Updated" date above. Your continued use of the Service after changes take effect means the updated Policy applies.

16. Contact & Complaints

For data requests, questions, or privacy concerns, please contact:

Ministry Order Privacy Team
Node78 LLC
3200 Wilcrest Drive, Suite 170
Houston, TX 77042, USA
support@node78.com

EEA residents may contact their local data protection authority (the European Data Protection Board lists its members at edpb.europa.eu), and UK residents may contact the Information Commissioner's Office at ico.org.uk.