Privacy Policy

Last updated: September 12, 2026

Plan2Serve is an app churches use to organize their serving teams: who serves, when, and in what role. This page explains in plain terms what personal data passes through the app, why, where it is kept, and what you can ask us about it.

Who is responsible for your data

Each church decides on its own whom it adds to the app and what data it enters about that person. The church is, in legal terms, the controller of that data. Plan2Serve provides the software that stores and displays it, which makes us a processoracting on the church's behalf.

If you want to know what data exists about you, or want it deleted, the fastest way is to talk to your church's administrator. You can also write to us directly at emanuel.miron6@gmail.com.

What data we collect

Name and initialsSo others can recognize you in the serving lists.
Phone numberIt is both how you sign in (you receive a code by SMS) and where you receive the notice when you have a new assignment.
Email addressOnly for accounts created with email and password. Most members don't have one.
Role and churchMember, leader or administrator, plus the ministries you belong to. This determines what you can see and change.
Your assignmentsYour assignments to services and your response: confirmation or decline, together with the reason, if you choose to write one.
UnavailabilityThe days you said you cannot serve, plus an optional note. Your church's leaders see them so they don't schedule you then.
SMS messagesWe keep the number, the text sent and whether it arrived, so we can explain a message that was not delivered.

Usage statistics

We use PostHog (hosted in the European Union) to see whether the app is being used: how many services are planned, where things get stuck. The data is anonymous: we don't build profiles, we don't use cookies and we don't identify you. We never send names, phone numbers, the content of SMS messages or service notes. You can turn statistics off at any time from Settings β†’ Privacy.

We also use Vercel Web Analytics, the statistics of the provider hosting the site, to see how many visits the app gets. It records only the page address, where you came from, your approximate country and region, the device type and the browser. It uses no cookies: visitors are counted with a code computed on the server from the incoming request, which is deleted after 24 hours. The same setting in Settings β†’ Privacy turns it off too.

Concretely: we don't record the screen, we don't automatically capture what you type or where you click, and from each page address we cut everything after β€œ?” and β€œ#”, at both services, so the access link you receive by SMS never leaves your device. PostHog keeps a single random identifier, stored in your browser, so we can count repeat visits; it is not tied to your account. Statistics currently exist only in the web version, not in the phone app.

Contacts access (phone app only)

If you are an administrator, the Android and iOS app can offer to add people directly from your phone's contacts, so you don't type the numbers by hand. We ask for permission explicitly, you can refuse it, and the rest of the app works the same without it. We read only names and phone numbers (never email addresses, postal addresses, birthdays or photos), and only the people you tick reach the server, never your whole address book.

Push notifications

If you allow notifications in the Android or iOS app, your phone receives a code from Apple or Google called a token, which we store so we know where to send a notification. The token identifies one installation of the app on one phone, not a person, and it does not contain your name or your number. We delete it when you turn notifications off, when you uninstall the app, and when you delete your account.

Notifications travel through the Exposervice and then through Apple (APNs) or Google (FCM), which deliver them to the phone. The text of a notification contains only what you would see in the app anyway β€” for example the name of the ministry and its date. You can turn notifications off at any time, from your phone's settings or from the app.

What we do NOT do

Where the data goes

To work, the app relies on a few providers. Each sees only what it strictly needs:

How long we keep the data

How it is protected

Your rights

Under the GDPR, you have the right to find out what data exists about you, to correct it, to request its deletion or a copy of it, and to object to its processing. Your name and phone number you can correct yourself, from Settings, and you can delete your account from there too, without asking anyone. For everything else, write to your church's administrator or to us at emanuel.miron6@gmail.com. We reply within 30 days at most.

If you are not satisfied with the answer, you can contact the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).

Children

The app is designed for volunteers serving in a church and is not directed at children under 16. If a church adds a minor, the responsibility for having parental consent lies with the church.

Changes

If we change this policy, we update the date at the top of the page. When the change is significant, we announce it in the app.

Contact

emanuel.miron6@gmail.com