Institutional Terms of Service & Data Governance Covenant
Effective Date: June 6, 2026
This Institutional Terms of Service and Data Governance Covenant (“Agreement”) is entered into by and between Epworth Software Solutions, LLC, a Texas limited liability company (“Epworth,” “we,” “us,” or “our”), and the subscribing local church, district, or annual conference (“Institution,” “you,” or “your”). This document establishes the legal boundaries, operational requirements, and mutual commitments governing your use of the Epworth Church Management Software platform (the “Software”).
1. Core Data Covenant & Absolute Ownership
We operate on a foundational premise: Your data belongs to you.
- Retained Ownership: The Institution retains exclusive, absolute ownership of all text, rosters, profiles, images, giving histories, payroll records, sacramental markers, or spiritual care notes inputted into the Software by your staff, volunteers, or constituents (“Institutional Data”). Epworth claims zero intellectual property rights over your data.
- No Commercial Exploitation: Epworth solemnly covenants never to sell, rent, lease, or commercially exploit Institutional Data. Your records will never be mined for advertising or shared with third-party marketing entities.
2. Legal Roles: Data Controller vs. Data Processor
To ensure alignment with modern privacy standards, including the Texas Data Privacy and Security Act (TDPSA), the parties define their legal capacities as follows:
- The Institution as Data Controller: You acknowledge that you act as the sole Data Controller. You determine which individuals are entered into the database, how long their active profiles are maintained, and what administrative or pastoral notes are taken. You are responsible for ensuring that your collection of constituent data complies with applicable local, state, and denominational guidelines.
- Epworth as Data Processor: Epworth acts strictly as a Data Processor. We host, secure, and maintain the Software infrastructure to execute your data storage instructions. We do not manipulate, access, or utilize your data except as explicitly required to maintain service continuity or perform requested database maintenance.
3. Technical Security & Infrastructure Commitments
Epworth recognizes that Institutional Data contains sensitive personal, financial, and spiritual records. We implement rigorous technical and organizational controls to protect your environment:
- Data Encryption: All Institutional Data is encrypted using industry-standard protocols in transit (via secure TLS connections) and at rest within the production databases (via filesystem-level encryption).
- Financial Safeguards:
- Credit & Debit Cards: All constituent electronic giving and card transactions are processed securely through a direct integration with Stripe. Credit card numbers are vaulted directly by Stripe; Epworth never views, processes, or stores any credit card information.
- ACH & Routing Numbers: Epworth securely stores and encrypts institutional Automated Clearing House (ACH) bank routing numbers solely for the purpose of transferring processed ministry tithes and offerings directly from Stripe to your verified financial accounts.
- Future Payroll Features: If the Institution opts to utilize Epworth’s forthcoming payroll administration modules, employee Social Security Numbers (SSNs) will be subject to heightened regulatory isolation and distinct security access controls entirely separate from the standard congregational directory.
4. Shared Directories & Connectional Etiquette
The Software includes connectional data logic designed to facilitate fellowship and coordination across churches, districts, and annual conferences. This feature is subject to the following strict boundaries:
- Constituent Autonomy: Individuals retain control over their profile visibility. By default, a person’s records are restricted to their home Institution. Cross-church or district directory sharing is strictly opt-in.
- Fallback Visibility Limits: If a person has not opted into a shared directory, persons affiliated with other congregations can only access limited public placeholder indicators (Name, Home Church affiliation, Photo, and any contact options the user voluntarily flags as public). Full profiles remain locked.
- Prohibition on Data Harvesting: The Institution explicitly agrees that any access to shared connectional data must be used solely for connectional ministries. Extracting, scraping, copying, or utilizing shared data from neighboring churches for unauthorized localized campaigns, fundraising solicitation, or external distribution is strictly forbidden and constitutes cause for immediate account termination.
5. Membership Transfers and Sacramental Ledger Integrity
The Software provides automated workflows to manage the traditional transfer of church membership between Epworth-supported charges.
- Roster Migration: Upon a constituent’s formal request to transfer, non-confidential biographical and communication details will migrate to the receiving Institution. Historical local giving reports will remain available at the originating institution for permanent tax-compliance archiving.
- The Pastoral Care details: To respect the sanctity of pastoral guidance and protect clergy-cognizant privilege, confidential care notes or private counseling logs taken by your leadership do not migrate during a transfer. They remain permanently tied to the originating clergy-person.
- Handling “Right to be Forgotten” Requests: When a constituent requests that your Institution delete their record, the Software will purge active contact records (phone numbers, email addresses, physical addresses). However, to fulfill connectional tracking requirements, the system will permanently maintain an historical entry containing only the individual’s Name, Birthdate, Baptism history (Date/Location/Method), and Death timeline. The Institution agrees to hold Epworth harmless against constituent disputes regarding the preservation of these canonical records.
6. Data Portability & Account Termination
You are never locked into the Epworth network. We respect your administrative flexibility:
- Data Export: Upon formal termination of your service, Epworth will, upon request, export your full Institutional Data into a standard comma-separated values (.csv) layout at no additional charge.
- Permanent Purging: Following written verification that the Institution has successfully downloaded and confirmed receipt of its exported records, Epworth will delete all Institutional Data from its active production databases within thirty (30) days for persons with no other active memberships.
7. Limitation of Liability & Corporate Shield
To the maximum extent permitted under Texas business and commerce provisions, the Institution explicitly acknowledges and agrees to the following liability framework:
- Software Status: During any designated testing or beta operational windows, the Software is delivered “AS IS” and “WITH ALL FAULTS,” without explicit or implied guarantees regarding uptime, error-free processing, or continuous data synchronizations.
- Manager Protection: In no event shall Epworth Software Solutions, LLC, its corporate managers, founders, or individual officers be held personally liable by the Institution, its administrative Church Board/Council, or its broad membership for any operational delays, technical disruptions, or direct/indirect data gaps arising from system use. Any legal remedies are strictly limited to the corporate assets of the LLC itself.
8. Amendments and Governing Law
This Governance Covenant is interpreted and governed under the laws of the State of Texas. Any updates to these infrastructure guidelines will be distributed transparently to your administrative console, ensuring your team is continually aware of how your church resources are shielded.