Privacy

Privacy Policy

Version 1 · Updated on 13 de August de 2026

Data Controller
Zion Global
Privacy Contact
privacy@zionchurch.org.br
Supervisory Authority
Your local data protection authority
Data Retention
Account data: until you delete it or 3 years after your last access.

Zion Global — Privacy Policy Addendum (EU/UK)

Aligned with the GDPR (EU) 2016/679 and UK GDPR baseline. This addendum supplements the main Privacy Policy for users located in the European Economic Area and the United Kingdom; where a term is not defined here, the definitions and general provisions of the main Privacy Policy apply, including its Regional Jurisdiction Table and Annex I (Consent Term for Personal Data Processing and Authorization to Use Image, Voice, and Name).

Controller: Zion Church Global DPO: Victor Matheus Jesus Caetano — dev@zionchurch.org.br Privacy contact: privacy@zionchurch.org.br


1. Data We Collect and Why

We collect data to manage your account, enable community participation, and meet legal obligations. This includes:

  • Registration data: name, email, phone number, date of birth, profile photo, and related profile information.
  • Church/community data (special category): membership status, water baptism and Holy Spirit baptism records — treated as data revealing religious belief.
  • Activity data on the platform: profile, campus, and community IDs; session and refresh tokens.
  • Usage, performance, and error telemetry: screens opened, actions taken, app open/load times, crash and error logs, device model and OS version. Telemetry is identified only by an internal, non-identifying profile ID — never by your name, document number, password, or contact details. We do not use advertising identifiers (IDFA/AAID), do not track you across other apps or sites, and do not use telemetry for advertising or automated decisions about you.

2. Legal Basis

As a religious non-profit, we process our members' religious data under the religious- organization basis (Art. 9(2)(d) GDPR), complemented by performance of the service (Art. 6(1)(b)) and compliance with legal obligations (Art. 6(1)(c)) for registration and account data.

Usage, performance, and error telemetry is processed under legitimate interest (Art. 6(1)(f) GDPR), to keep the app functional, secure, and usable. This relies on three safeguards: the data is pseudonymized (identified by profile ID only), used exclusively to operate and improve the app, and never used for advertising, behavioral profiling, or automated decisions affecting you. You may object to this processing using the contact details above.

Where image, voice, or name are used individually (rather than incidental appearance at an event or broadcast), the applicable basis is consent, as set out in Annex I.

3. Data Processors

The following processors act on our instructions; none of them receives your document number, password, or authentication tokens:

ProcessorWhat it processesLocationGDPR transfer safeguard
SupabasePlatform database: profile, campus, groups, events, contributionsUnited StatesStandard Contractual Clauses
Amazon Web Services (AWS)Identity and authentication (Amazon Cognito), image storageUnited StatesStandard Contractual Clauses
Google LLCAddress autocomplete via Google Places APIUnited StatesStandard Contractual Clauses / adequacy mechanisms
PostHogUsage events and screens (Section 1), identified by profile IDEuropean UnionN/A — processed within the EU
DatadogTechnical logs, errors, and crashesUnited StatesStandard Contractual Clauses
Expo (Expo Application Services)Performance metrics and app update distributionUnited StatesStandard Contractual Clauses

4. Data Retention

  • Account data is retained until deletion by the user or for up to 3 years after your last access, whichever comes first.
  • Session data is stored locally on your device and removed on logout.
  • Telemetry (Section 1): technical/error logs are kept for up to 90 days; usage events for up to 12 months. After that, they are discarded or kept only in aggregated, non-identifiable form.
  • Following a deletion request, data is removed within 30 calendar days, except where retention is required by law.

5. Cookies and Tracking Technologies

The platform uses cookies and similar technologies strictly necessary for its operation and for authentication. We do not use advertising cookies or cross-site/cross-app tracking technologies.

6. Children and Minors

Minors may not use the app or have their data entered into the system unless a parent or legal guardian has given specific and unambiguous consent. Under the GDPR, the applicable age threshold for a minor's own consent ranges from 13 to 16, depending on the EU member state; below that threshold, parental consent is required. The use of a minor's image, voice, or name additionally requires the specific, highlighted parental authorization described in Annex I, Clause 15.

7. Security and Incidents

We maintain technical and organizational measures including TLS/HTTPS encryption in transit, token-based authentication, access controls, and pseudonymization. In the event of a personal data breach posing a risk to data subjects, we will notify the competent supervisory authority and, where required, affected data subjects, within the timeframes required under the GDPR (Arts. 33–34).

8. Your Rights

You have the right to access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw consent at any time where processing is based on consent (without affecting the lawfulness of processing carried out before withdrawal, per Art. 7(3) GDPR). To exercise them, contact the DPO or privacy email shown in the header.

9. Image, Voice, and Name Use

Where you appear individually (rather than incidentally, as part of a crowd or general venue shot) in photos, video, or livestreams of church events, the use of your image, voice, and name is governed by the consent-based terms of Annex I to the main Privacy Policy, including the right to request removal or non-future use.

10. Complaints

You may lodge a complaint with your local supervisory authority (in the EU, the authority of your member state; in the UK, the ICO), or contact us first at the privacy email shown above so we can investigate and try to resolve the matter directly.