Privacy Policy

    Last Updated: August 4, 2026 · Version 2.1

    Blitzbit Limited (“we”, “us”, or “our”), the developer and operator of the Mychurchbase application, is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, share, and protect personal information in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Nigeria Data Protection Act (NDPA) 2023, and the Nigeria Data Protection Regulation (NDPR).

    This policy applies to all users of Mychurchbase worldwide, regardless of location. Where specific regulations grant additional rights to individuals in certain jurisdictions, those rights are noted in the relevant sections.

    1. Identity of the Data Controller

    Blitzbit Limited

    House 15 Legend Estate, Abuja, Nigeria

    Email: support@blitzbitai.com

    Data Protection Officer (DPO): Emeka Madubuko

    Email: support@blitzbitai.com · Phone: 08037716406

    ✓ Registered Data Controller/Processor — Nigeria Data Protection Commission (NDPC)

    Blitzbit Limited is the data controller for all personal data processed through Mychurchbase. If you are a church member whose data is managed by a church using our platform, the church is a joint data controller with us for data they input and manage.

    2. Information We Collect

    We collect the following categories of personal data:

    CategoryData CollectedPurpose
    Identity DataFull name, gender, date of birth, marital status, occupation, profile photoMember identification and management
    Contact DataEmail address, phone number, residential addressCommunication, follow-up, and pastoral care
    Spiritual & Membership DataChurch affiliation, department membership, cell group participation, service attendance, baptism status, prayer requestsChurch administration, discipleship, and spiritual growth tracking
    Financial DataRecords of voluntary contributions (tithes, offerings, donations), campaign pledgesFinancial stewardship and reporting
    First-Time Visitor DataName, contact details, visit preferences, interests, referral sourceWelcoming and follow-up
    Technical DataIP address, browser type, device information, pages visited (on marketing pages only, with consent)Security, analytics, and service improvement
    Communication DataSMS, WhatsApp, and email message content and delivery statusPastoral communication and notifications
    Account DataEmail, role, authentication credentials (passwords handled by Firebase Auth, never stored by us)Platform access and authorization

    3. Special Category (Sensitive) Data

    As a church management platform, Mychurchbase inherently processes data relating to religious beliefs and affiliation, which constitutes “special category data” under GDPR Article 9 and sensitive personal data under the NDPA.

    This includes: church membership records, attendance at religious services, voluntary financial contributions (tithes, offerings), participation in religious training and discipleship programs, prayer requests, and cell group involvement.

    We process this data under the following legal bases:

    • GDPR Article 9(2)(d) — Religious Body Exemption: Processing is carried out by a not-for-profit body with a religious aim, relates solely to members or former members (or those in regular contact), and data is not disclosed outside the organization without consent.
    • Explicit Consent (Article 9(2)(a)): Where required, we obtain your explicit consent before processing sensitive data, particularly for prayer requests and communications.
    • NDPA Section 30: Processing of sensitive personal data with the explicit consent of the data subject or where necessary for the legitimate activities of a religious organization.

    4. How We Use Your Information

    We process your personal data for the following purposes:

    • Administration: Managing membership records, church operations, and organizational structure.
    • Communication: Sending updates, service reminders, pastoral messages, and notifications via SMS, WhatsApp, or email.
    • Reporting: Generating attendance and financial reports for church leadership (anonymized where appropriate).
    • Spiritual Growth: Tracking participation in training programs, discipleship, and pastoral follow-up.
    • Security: Authenticating users, preventing unauthorized access, and protecting the platform against abuse.
    • Payment Processing: Processing subscription payments for churches using the platform.
    • Service Improvement: Analyzing usage patterns on our public marketing pages (with consent) to improve the platform.

    5. Legal Basis for Processing

    We process your personal data based on the following lawful bases under GDPR Article 6 and NDPA Section 25:

    Processing ActivityLawful BasisDetails
    Member data managementLegitimate Interest (Art. 6(1)(f))Necessary for effective church administration
    Religious/spiritual dataArt. 9(2)(d) + ConsentReligious body exemption with explicit consent
    SMS/WhatsApp/Email communicationsConsent (Art. 6(1)(a))You may opt out at any time
    Financial donationsLegal Obligation (Art. 6(1)(c))Tax and financial reporting requirements
    Subscription paymentsContract (Art. 6(1)(b))Necessary to provide the service
    Analytics (marketing pages)Consent (Art. 6(1)(a))Only activated with explicit cookie consent
    Security & bot protectionLegitimate Interest (Art. 6(1)(f))Platform security and fraud prevention

    6. Data Sharing and Third-Party Processors

    We do not sell your personal data. We share information with the following categories of recipients:

    Service Providers (Data Processors)

    We use the following third-party service providers who process personal data on our behalf under Data Processing Agreements:

    ProviderPurposeData SharedLocation
    Google Cloud / FirebaseDatabase, authentication, storage, hosting, push notifications, AI processingAll application dataUnited States
    FlutterwavePayment processingEmail, name, payment amountsNigeria / United States
    TermiiSMS and WhatsApp messagingPhone numbers, message contentNigeria
    ResendTransactional email deliveryEmail addresses, email contentUnited States
    PostHogProduct analytics (marketing pages only)IP address, browser data, page views (only with consent)United States
    CloudflareBot protection (CAPTCHA)IP address, browser fingerprintUnited States

    Other Recipients

    • Church Leadership: Authorized leaders within your specific church, department, or cell group, as necessary for pastoral care and administration.
    • Legal Authorities: If required by applicable law (Nigerian law, EU law, or court order).

    7. International Data Transfers

    All personal data processed through Mychurchbase, regardless of the user's location, is currently stored and processed in the United States via Google Cloud / Firebase infrastructure.

    For users in the European Economic Area (EEA) or United Kingdom, this transfer is governed by Standard Contractual Clauses (SCCs) approved by the European Commission, entered into between Blitzbit Limited and Google LLC.

    We are actively monitoring Firebase's EU regionalisation roadmap and intend to offer EU data residency options to EEA-based churches in a future platform update.

    EEA-based churches with strict data residency requirements should contact our DPO at support@blitzbitai.com before registering.

    When we transfer personal data internationally, we ensure appropriate safeguards are in place:

    • EU Standard Contractual Clauses (SCCs): We rely on SCCs approved by the European Commission for transfers to the United States (Google, Resend, PostHog, Cloudflare).
    • Data Processing Agreements: All processors are bound by contractual obligations to protect personal data to a standard equivalent to GDPR.
    • Encryption: All data is encrypted in transit (TLS/HTTPS) and at rest (AES-256 via Google Cloud).
    • NDPA Compliance: International transfers comply with NDPA Section 43 requirements, including adequacy assessments and appropriate safeguards.

    You may request a copy of the safeguards we have in place by contacting our DPO.

    8. Cookies and Analytics

    We use the following types of cookies and tracking technologies:

    TypeProviderPurposeConsent Required
    EssentialFirebase AuthUser authentication and session managementNo (strictly necessary)
    EssentialCloudflare TurnstileBot protection on registration formsNo (strictly necessary)
    AnalyticsPostHogPage views, user interactions on marketing pagesYes — opt-in only

    Analytics tracking is only active on our public marketing pages and is never used within the authenticated church management application. Analytics data is only collected after you provide explicit consent via our cookie banner. You may withdraw consent at any time by clicking “Manage Preferences” in the cookie banner.

    9. Data Security

    We have implemented appropriate technical and organizational measures to protect your personal data, including:

    • Encryption: All data is encrypted in transit (TLS/HTTPS) and at rest (AES-256 via Google Cloud).
    • Access Controls: Role-based access control (RBAC) with six defined roles limits data access to authorized personnel only.
    • Authentication: Secure password handling via Firebase Auth (bcrypt/scrypt hashing). Passwords are never stored in our database.
    • Audit Logging: All significant data operations (creation, modification, deletion) are logged with actor identity, timestamp, and action details.
    • Input Validation: Server-side validation on all data inputs to prevent injection and data integrity issues.
    • Rate Limiting: Protection against brute-force attacks and abuse.
    • Security Headers: HTTP security headers including Content Security Policy, HSTS, and X-Frame-Options.

    10. Data Retention

    We retain personal data only as long as necessary for the purposes for which it was collected. Our retention approach distinguishes between data managed by your church organization and data managed by the platform.

    Church-Managed Data

    Your church organization determines how long to retain member, visitor, contact, attendance, and financial data based on its legitimate pastoral and administrative needs. We provide data hygiene tools within the platform to help churches review and manage their records. The following are recommended retention guidelines:

    Data TypeRecommended RetentionBasis
    Member recordsDuration of membership + 2 yearsLegitimate interest, legal obligations
    First-time visitor (MVP) dataAs determined by the churchLegitimate interest in pastoral follow-up
    Financial/donation recordsMinimum 6 yearsNigerian tax law (FIRS) and financial reporting obligations
    Attendance recordsDuration of membership + 2 yearsChurch administration
    Communication logs12 monthsDelivery verification, dispute resolution

    Platform-Managed Data

    The following data is managed directly by the platform with automated retention schedules:

    Data TypeRetention PeriodBasis
    Inactive trial accounts (never activated or abandoned)12 months from creation, with 30-day advance email warningData minimisation (Art. 5(1)(e))
    Audit logs24 monthsSecurity and compliance
    Password reset tokens1 hourSecurity (time-limited by design)
    Email verification tokens24 hoursSecurity (time-limited by design)
    Gateway message cache72 hoursDelivery confirmation
    Analytics data (marketing pages)90 daysGoverned by PostHog retention policy (consent-gated)
    User account dataDuration of account + 30 daysAccount management

    Before any abandoned account data is permanently deleted, the account owner will receive an automated email notification at least 30 days in advance. When data is no longer required, it is securely deleted or anonymized. You may request earlier deletion by contacting our DPO (subject to legal retention obligations).

    11. Your Legal Rights

    Under the GDPR, UK GDPR, and NDPA/NDPR, you have the following rights regarding your personal data:

    • Right to Access (Art. 15 / NDPA s.34): Request a copy of the personal data we hold about you. We will respond within 30 days.
    • Right to Rectification (Art. 16 / NDPA s.35): Request correction of inaccurate or incomplete personal data.
    • Right to Erasure (Art. 17 / NDPA s.36): Request deletion of your personal data where there is no compelling reason for continued processing.
    • Right to Restrict Processing (Art. 18 / NDPA s.37): Request that we temporarily halt processing of your data in certain circumstances.
    • Right to Data Portability (Art. 20 / NDPA s.38): Request your data in a structured, commonly used, machine-readable format (CSV or JSON).
    • Right to Object (Art. 21 / NDPA s.39): Object to processing based on legitimate interests, including opting out of communications at any time.
    • Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
    • Right Not to Be Subject to Automated Decision-Making (Art. 22 / NDPA s.40): We do not make automated decisions that produce legal or significant effects based solely on automated processing of your data.

    To exercise any of these rights, contact our Data Protection Officer at support@blitzbitai.com. We will respond within 30 days (GDPR) or 30 days (NDPA) of receiving your request.

    12. Children's Data

    Mychurchbase is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. Aggregate attendance counts (e.g., number of children present) may be recorded by churches for reporting purposes, but no individual child records are created. If you believe we have inadvertently collected data from a child, please contact our DPO immediately for deletion.

    13. Third-Party Links

    Our application may include links to third-party websites. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.

    14. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or an in-app notification. The “Last Updated” date at the top of this page indicates when this policy was last revised. Continued use of the platform after changes constitutes acceptance of the updated policy.

    15. Complaints

    If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority:

    • Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
    • EU/EEA: Your local Data Protection Authority (DPA). A list is available at edpb.europa.eu
    • UK: Information Commissioner's Office (ICO) — ico.org.uk

    We encourage you to contact our DPO first so we can try to resolve your concern directly.

    16. Contact Us

    For any questions regarding this Privacy Policy, to exercise your data rights, or to report a data protection concern, please contact our Data Protection Officer:

    Name: Emeka Madubuko

    Email: support@blitzbitai.com

    Phone: 08037716406

    Address: Blitzbit Limited, House 15 Legend Estate, Abuja, Nigeria

    Privacy Policy•Terms of Use•Support
    My Church Base LogoMy Church Base
    Powered by mychurchbase.com