OPTIONAL CONNECTION DATA

Useful product insight, with ministry records left at church.

Connected installations can separately choose technical health, customer-linked aggregate usage totals, and sanitized error diagnostics. Turning any category off does not disable the self-hosted suite.

MAY BE SENT

  • Installation and request identifiers
  • Approved software and server versions
  • Enabled tool names
  • Allowlisted non-financial counts
  • Explicit 7-day or 30-day activity totals
  • Consent state and timestamp

NEVER ACCEPTED

  • Student, parent, or volunteer names
  • Individual attendance or check-in records
  • Care notes, medical information, or comments
  • Budgets, receipt amounts, or financial records
  • Passwords, tokens, cookies, or database credentials
  • Raw SQL, request bodies, uploads, or arbitrary metadata
01Church administrator chooses

Each reporting category is visible during setup and remains independently adjustable inside Suite Core.

02Revocable token authenticates

Aggregate metrics require a connected installation token. The central website stores only its one-way hash.

03Positive allowlist filters

Unknown metric keys, oversized payloads, reused request IDs, stale timestamps, and values outside defined bounds are rejected.

CONTROL STAYS VISIBLE

Disconnect or withdraw consent without disabling the suite.

A church can turn off a reporting category locally or unlink the installation entirely. Those actions affect only central sync. Youth Ministry Tools continues operating on the church’s own server.

Read the privacy policy