Privacy Policy
Version 1 · Updated on 13 de August de 2026
- Data Controller
- Zion Global
- Privacy Contact
- privacy@zionchurch.org.br
- Supervisory Authority
- Your local data protection authority
- Data Retention
- Account data: until you delete it or 3 years after your last access.
Zion Global — Privacy Policy Addendum (EU/UK)
Aligned with the GDPR (EU) 2016/679 and UK GDPR baseline. This addendum supplements the main Privacy Policy for users located in the European Economic Area and the United Kingdom; where a term is not defined here, the definitions and general provisions of the main Privacy Policy apply, including its Regional Jurisdiction Table and Annex I (Consent Term for Personal Data Processing and Authorization to Use Image, Voice, and Name).
Controller: Zion Church Global DPO: Victor Matheus Jesus Caetano — dev@zionchurch.org.br Privacy contact: privacy@zionchurch.org.br
1. Data We Collect and Why
We collect data to manage your account, enable community participation, and meet legal obligations. This includes:
- Registration data: name, email, phone number, date of birth, profile photo, and related profile information.
- Church/community data (special category): membership status, water baptism and Holy Spirit baptism records — treated as data revealing religious belief.
- Activity data on the platform: profile, campus, and community IDs; session and refresh tokens.
- Usage, performance, and error telemetry: screens opened, actions taken, app open/load times, crash and error logs, device model and OS version. Telemetry is identified only by an internal, non-identifying profile ID — never by your name, document number, password, or contact details. We do not use advertising identifiers (IDFA/AAID), do not track you across other apps or sites, and do not use telemetry for advertising or automated decisions about you.
2. Legal Basis
As a religious non-profit, we process our members' religious data under the religious- organization basis (Art. 9(2)(d) GDPR), complemented by performance of the service (Art. 6(1)(b)) and compliance with legal obligations (Art. 6(1)(c)) for registration and account data.
Usage, performance, and error telemetry is processed under legitimate interest (Art. 6(1)(f) GDPR), to keep the app functional, secure, and usable. This relies on three safeguards: the data is pseudonymized (identified by profile ID only), used exclusively to operate and improve the app, and never used for advertising, behavioral profiling, or automated decisions affecting you. You may object to this processing using the contact details above.
Where image, voice, or name are used individually (rather than incidental appearance at an event or broadcast), the applicable basis is consent, as set out in Annex I.
3. Data Processors
The following processors act on our instructions; none of them receives your document number, password, or authentication tokens:
| Processor | What it processes | Location | GDPR transfer safeguard |
|---|---|---|---|
| Supabase | Platform database: profile, campus, groups, events, contributions | United States | Standard Contractual Clauses |
| Amazon Web Services (AWS) | Identity and authentication (Amazon Cognito), image storage | United States | Standard Contractual Clauses |
| Google LLC | Address autocomplete via Google Places API | United States | Standard Contractual Clauses / adequacy mechanisms |
| PostHog | Usage events and screens (Section 1), identified by profile ID | European Union | N/A — processed within the EU |
| Datadog | Technical logs, errors, and crashes | United States | Standard Contractual Clauses |
| Expo (Expo Application Services) | Performance metrics and app update distribution | United States | Standard Contractual Clauses |
4. Data Retention
- Account data is retained until deletion by the user or for up to 3 years after your last access, whichever comes first.
- Session data is stored locally on your device and removed on logout.
- Telemetry (Section 1): technical/error logs are kept for up to 90 days; usage events for up to 12 months. After that, they are discarded or kept only in aggregated, non-identifiable form.
- Following a deletion request, data is removed within 30 calendar days, except where retention is required by law.
5. Cookies and Tracking Technologies
The platform uses cookies and similar technologies strictly necessary for its operation and for authentication. We do not use advertising cookies or cross-site/cross-app tracking technologies.
6. Children and Minors
Minors may not use the app or have their data entered into the system unless a parent or legal guardian has given specific and unambiguous consent. Under the GDPR, the applicable age threshold for a minor's own consent ranges from 13 to 16, depending on the EU member state; below that threshold, parental consent is required. The use of a minor's image, voice, or name additionally requires the specific, highlighted parental authorization described in Annex I, Clause 15.
7. Security and Incidents
We maintain technical and organizational measures including TLS/HTTPS encryption in transit, token-based authentication, access controls, and pseudonymization. In the event of a personal data breach posing a risk to data subjects, we will notify the competent supervisory authority and, where required, affected data subjects, within the timeframes required under the GDPR (Arts. 33–34).
8. Your Rights
You have the right to access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw consent at any time where processing is based on consent (without affecting the lawfulness of processing carried out before withdrawal, per Art. 7(3) GDPR). To exercise them, contact the DPO or privacy email shown in the header.
9. Image, Voice, and Name Use
Where you appear individually (rather than incidentally, as part of a crowd or general venue shot) in photos, video, or livestreams of church events, the use of your image, voice, and name is governed by the consent-based terms of Annex I to the main Privacy Policy, including the right to request removal or non-future use.
10. Complaints
You may lodge a complaint with your local supervisory authority (in the EU, the authority of your member state; in the UK, the ICO), or contact us first at the privacy email shown above so we can investigate and try to resolve the matter directly.