Legal
Privacy Policy
Last Updated: June 10, 2026
1. Overview
ConnectCapture helps churches capture handwritten connect cards, extract contact information through OCR, store captured card records and images, and coordinate follow-up through authorized team members.
This Privacy Policy describes the types of information ConnectCapture may process, how that information may be used, and the choices and responsibilities associated with the service.
2. Information We May Collect
Account information may include user names, email addresses, church names, roles, authentication details, and subscription or billing status.
Connect card information may include uploaded connect card images and extracted information such as names, phone numbers, email addresses, mailing addresses, visit details, prayer requests, notes, and other information a person writes on a card.
Usage and technical information may include device, browser, log, diagnostic, security, and service activity data needed to operate and protect the product.
3. How Information May Be Used
Information may be used to provide the capture, OCR, review, storage, export, follow-up, account, billing, support, security, and product improvement features of ConnectCapture.
To extract contact information, uploaded connect card images are sent to our OCR provider, OpenAI, which processes the image and returns suggested fields for review by authorized church staff. Card images are transmitted to OpenAI solely to perform this extraction.
4. Sharing and Integrations
Captured information may be visible to authorized church staff within the church account based on the permissions and workflows configured by the church.
If a church enables Planning Center integrations or another third-party system, approved contact information may be sent to that service at the church's direction.
Information may also be processed by service providers (sub-processors) that help operate ConnectCapture. These currently include: OpenAI (OCR text extraction from uploaded card images); Planning Center (only when a church connects it and approves a sync); Stripe (payment and subscription processing); Resend (transactional email delivery); Supabase (database, authentication, and encrypted file storage); and Vercel (application hosting). This list may change as the service evolves; material changes will be reflected here.
5. Church Responsibilities
Each church is responsible for its own notices, permissions, access controls, retention practices, follow-up communications, and compliance obligations for the information it collects and uploads.
Churches should review card content before sharing it internally, exporting it, or sending it to another system.
6. Data Retention
ConnectCapture may retain account data, card images, extracted fields, logs, and related records for as long as needed to provide the service, comply with obligations, resolve disputes, and protect the product.
Churches control retention of their card data and can delete individual cards or all card data at any time from within the product (see Section 8). Once deleted, records are removed from the live system; residual copies in encrypted backups age out on the backup provider's cycle.
Retention periods may otherwise vary based on account settings, legal obligations, operational needs, and church requests.
7. Security
ConnectCapture should use reasonable administrative, technical, and organizational safeguards designed to protect information handled by the service.
No online service can guarantee absolute security. Churches should limit access to authorized team members and use strong account security practices.
8. Choices and Requests
Authorized account users can access, correct, and export card information from within the product. Owners and admins can permanently delete an individual card (and its image) from the card's detail view, and an owner can delete all of the church's connection-card data at once from Settings → Account. Deletion removes the card record, extracted fields, and the stored image.
Requests from individuals whose information appears on a connect card are handled by the church that collected the information, using the deletion tools above; ConnectCapture can also assist on request via the contact below.
9. Children's Information
Churches should avoid uploading information from children unless they have the rights, notices, and permissions required for their ministry context and applicable law.
Churches are responsible for determining whether additional consent, notice, retention, or access controls apply to information involving children or students.
10. Contact
Privacy questions should be sent to the contact address designated by the ConnectCapture operator or the church that collected the relevant connect card information.