Privacy Policy
Last Updated: August 4, 2026 · Version 2.1
Blitzbit Limited (“we”, “us”, or “our”), the developer and operator of the Mychurchbase application, is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, share, and protect personal information in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Nigeria Data Protection Act (NDPA) 2023, and the Nigeria Data Protection Regulation (NDPR).
This policy applies to all users of Mychurchbase worldwide, regardless of location. Where specific regulations grant additional rights to individuals in certain jurisdictions, those rights are noted in the relevant sections.
1. Identity of the Data Controller
Blitzbit Limited
House 15 Legend Estate, Abuja, Nigeria
Email: support@blitzbitai.com
Data Protection Officer (DPO): Emeka Madubuko
Email: support@blitzbitai.com · Phone: 08037716406
✓ Registered Data Controller/Processor — Nigeria Data Protection Commission (NDPC)
Blitzbit Limited is the data controller for all personal data processed through Mychurchbase. If you are a church member whose data is managed by a church using our platform, the church is a joint data controller with us for data they input and manage.
2. Information We Collect
We collect the following categories of personal data:
| Category | Data Collected | Purpose |
|---|---|---|
| Identity Data | Full name, gender, date of birth, marital status, occupation, profile photo | Member identification and management |
| Contact Data | Email address, phone number, residential address | Communication, follow-up, and pastoral care |
| Spiritual & Membership Data | Church affiliation, department membership, cell group participation, service attendance, baptism status, prayer requests | Church administration, discipleship, and spiritual growth tracking |
| Financial Data | Records of voluntary contributions (tithes, offerings, donations), campaign pledges | Financial stewardship and reporting |
| First-Time Visitor Data | Name, contact details, visit preferences, interests, referral source | Welcoming and follow-up |
| Technical Data | IP address, browser type, device information, pages visited (on marketing pages only, with consent) | Security, analytics, and service improvement |
| Communication Data | SMS, WhatsApp, and email message content and delivery status | Pastoral communication and notifications |
| Account Data | Email, role, authentication credentials (passwords handled by Firebase Auth, never stored by us) | Platform access and authorization |
3. Special Category (Sensitive) Data
As a church management platform, Mychurchbase inherently processes data relating to religious beliefs and affiliation, which constitutes “special category data” under GDPR Article 9 and sensitive personal data under the NDPA.
This includes: church membership records, attendance at religious services, voluntary financial contributions (tithes, offerings), participation in religious training and discipleship programs, prayer requests, and cell group involvement.
We process this data under the following legal bases:
- GDPR Article 9(2)(d) — Religious Body Exemption: Processing is carried out by a not-for-profit body with a religious aim, relates solely to members or former members (or those in regular contact), and data is not disclosed outside the organization without consent.
- Explicit Consent (Article 9(2)(a)): Where required, we obtain your explicit consent before processing sensitive data, particularly for prayer requests and communications.
- NDPA Section 30: Processing of sensitive personal data with the explicit consent of the data subject or where necessary for the legitimate activities of a religious organization.
4. How We Use Your Information
We process your personal data for the following purposes:
- Administration: Managing membership records, church operations, and organizational structure.
- Communication: Sending updates, service reminders, pastoral messages, and notifications via SMS, WhatsApp, or email.
- Reporting: Generating attendance and financial reports for church leadership (anonymized where appropriate).
- Spiritual Growth: Tracking participation in training programs, discipleship, and pastoral follow-up.
- Security: Authenticating users, preventing unauthorized access, and protecting the platform against abuse.
- Payment Processing: Processing subscription payments for churches using the platform.
- Service Improvement: Analyzing usage patterns on our public marketing pages (with consent) to improve the platform.
5. Legal Basis for Processing
We process your personal data based on the following lawful bases under GDPR Article 6 and NDPA Section 25:
| Processing Activity | Lawful Basis | Details |
|---|---|---|
| Member data management | Legitimate Interest (Art. 6(1)(f)) | Necessary for effective church administration |
| Religious/spiritual data | Art. 9(2)(d) + Consent | Religious body exemption with explicit consent |
| SMS/WhatsApp/Email communications | Consent (Art. 6(1)(a)) | You may opt out at any time |
| Financial donations | Legal Obligation (Art. 6(1)(c)) | Tax and financial reporting requirements |
| Subscription payments | Contract (Art. 6(1)(b)) | Necessary to provide the service |
| Analytics (marketing pages) | Consent (Art. 6(1)(a)) | Only activated with explicit cookie consent |
| Security & bot protection | Legitimate Interest (Art. 6(1)(f)) | Platform security and fraud prevention |
6. Data Sharing and Third-Party Processors
We do not sell your personal data. We share information with the following categories of recipients:
Service Providers (Data Processors)
We use the following third-party service providers who process personal data on our behalf under Data Processing Agreements:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Google Cloud / Firebase | Database, authentication, storage, hosting, push notifications, AI processing | All application data | United States |
| Flutterwave | Payment processing | Email, name, payment amounts | Nigeria / United States |
| Termii | SMS and WhatsApp messaging | Phone numbers, message content | Nigeria |
| Resend | Transactional email delivery | Email addresses, email content | United States |
| PostHog | Product analytics (marketing pages only) | IP address, browser data, page views (only with consent) | United States |
| Cloudflare | Bot protection (CAPTCHA) | IP address, browser fingerprint | United States |
Other Recipients
- Church Leadership: Authorized leaders within your specific church, department, or cell group, as necessary for pastoral care and administration.
- Legal Authorities: If required by applicable law (Nigerian law, EU law, or court order).
7. International Data Transfers
All personal data processed through Mychurchbase, regardless of the user's location, is currently stored and processed in the United States via Google Cloud / Firebase infrastructure.
For users in the European Economic Area (EEA) or United Kingdom, this transfer is governed by Standard Contractual Clauses (SCCs) approved by the European Commission, entered into between Blitzbit Limited and Google LLC.
We are actively monitoring Firebase's EU regionalisation roadmap and intend to offer EU data residency options to EEA-based churches in a future platform update.
EEA-based churches with strict data residency requirements should contact our DPO at support@blitzbitai.com before registering.
When we transfer personal data internationally, we ensure appropriate safeguards are in place:
- EU Standard Contractual Clauses (SCCs): We rely on SCCs approved by the European Commission for transfers to the United States (Google, Resend, PostHog, Cloudflare).
- Data Processing Agreements: All processors are bound by contractual obligations to protect personal data to a standard equivalent to GDPR.
- Encryption: All data is encrypted in transit (TLS/HTTPS) and at rest (AES-256 via Google Cloud).
- NDPA Compliance: International transfers comply with NDPA Section 43 requirements, including adequacy assessments and appropriate safeguards.
You may request a copy of the safeguards we have in place by contacting our DPO.
8. Cookies and Analytics
We use the following types of cookies and tracking technologies:
| Type | Provider | Purpose | Consent Required |
|---|---|---|---|
| Essential | Firebase Auth | User authentication and session management | No (strictly necessary) |
| Essential | Cloudflare Turnstile | Bot protection on registration forms | No (strictly necessary) |
| Analytics | PostHog | Page views, user interactions on marketing pages | Yes — opt-in only |
Analytics tracking is only active on our public marketing pages and is never used within the authenticated church management application. Analytics data is only collected after you provide explicit consent via our cookie banner. You may withdraw consent at any time by clicking “Manage Preferences” in the cookie banner.
9. Data Security
We have implemented appropriate technical and organizational measures to protect your personal data, including:
- Encryption: All data is encrypted in transit (TLS/HTTPS) and at rest (AES-256 via Google Cloud).
- Access Controls: Role-based access control (RBAC) with six defined roles limits data access to authorized personnel only.
- Authentication: Secure password handling via Firebase Auth (bcrypt/scrypt hashing). Passwords are never stored in our database.
- Audit Logging: All significant data operations (creation, modification, deletion) are logged with actor identity, timestamp, and action details.
- Input Validation: Server-side validation on all data inputs to prevent injection and data integrity issues.
- Rate Limiting: Protection against brute-force attacks and abuse.
- Security Headers: HTTP security headers including Content Security Policy, HSTS, and X-Frame-Options.
10. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected. Our retention approach distinguishes between data managed by your church organization and data managed by the platform.
Church-Managed Data
Your church organization determines how long to retain member, visitor, contact, attendance, and financial data based on its legitimate pastoral and administrative needs. We provide data hygiene tools within the platform to help churches review and manage their records. The following are recommended retention guidelines:
| Data Type | Recommended Retention | Basis |
|---|---|---|
| Member records | Duration of membership + 2 years | Legitimate interest, legal obligations |
| First-time visitor (MVP) data | As determined by the church | Legitimate interest in pastoral follow-up |
| Financial/donation records | Minimum 6 years | Nigerian tax law (FIRS) and financial reporting obligations |
| Attendance records | Duration of membership + 2 years | Church administration |
| Communication logs | 12 months | Delivery verification, dispute resolution |
Platform-Managed Data
The following data is managed directly by the platform with automated retention schedules:
| Data Type | Retention Period | Basis |
|---|---|---|
| Inactive trial accounts (never activated or abandoned) | 12 months from creation, with 30-day advance email warning | Data minimisation (Art. 5(1)(e)) |
| Audit logs | 24 months | Security and compliance |
| Password reset tokens | 1 hour | Security (time-limited by design) |
| Email verification tokens | 24 hours | Security (time-limited by design) |
| Gateway message cache | 72 hours | Delivery confirmation |
| Analytics data (marketing pages) | 90 days | Governed by PostHog retention policy (consent-gated) |
| User account data | Duration of account + 30 days | Account management |
Before any abandoned account data is permanently deleted, the account owner will receive an automated email notification at least 30 days in advance. When data is no longer required, it is securely deleted or anonymized. You may request earlier deletion by contacting our DPO (subject to legal retention obligations).
11. Your Legal Rights
Under the GDPR, UK GDPR, and NDPA/NDPR, you have the following rights regarding your personal data:
- Right to Access (Art. 15 / NDPA s.34): Request a copy of the personal data we hold about you. We will respond within 30 days.
- Right to Rectification (Art. 16 / NDPA s.35): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17 / NDPA s.36): Request deletion of your personal data where there is no compelling reason for continued processing.
- Right to Restrict Processing (Art. 18 / NDPA s.37): Request that we temporarily halt processing of your data in certain circumstances.
- Right to Data Portability (Art. 20 / NDPA s.38): Request your data in a structured, commonly used, machine-readable format (CSV or JSON).
- Right to Object (Art. 21 / NDPA s.39): Object to processing based on legitimate interests, including opting out of communications at any time.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
- Right Not to Be Subject to Automated Decision-Making (Art. 22 / NDPA s.40): We do not make automated decisions that produce legal or significant effects based solely on automated processing of your data.
To exercise any of these rights, contact our Data Protection Officer at support@blitzbitai.com. We will respond within 30 days (GDPR) or 30 days (NDPA) of receiving your request.
12. Children's Data
Mychurchbase is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. Aggregate attendance counts (e.g., number of children present) may be recorded by churches for reporting purposes, but no individual child records are created. If you believe we have inadvertently collected data from a child, please contact our DPO immediately for deletion.
13. Third-Party Links
Our application may include links to third-party websites. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or an in-app notification. The “Last Updated” date at the top of this page indicates when this policy was last revised. Continued use of the platform after changes constitutes acceptance of the updated policy.
15. Complaints
If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority:
- Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
- EU/EEA: Your local Data Protection Authority (DPA). A list is available at edpb.europa.eu
- UK: Information Commissioner's Office (ICO) — ico.org.uk
We encourage you to contact our DPO first so we can try to resolve your concern directly.
16. Contact Us
For any questions regarding this Privacy Policy, to exercise your data rights, or to report a data protection concern, please contact our Data Protection Officer:
Name: Emeka Madubuko
Email: support@blitzbitai.com
Phone: 08037716406
Address: Blitzbit Limited, House 15 Legend Estate, Abuja, Nigeria