Last updated 21 August 2026
Bellringer is parish management software. Parishes use it to hold records about their parishioners, so most of the personal data in Bellringer is not about our customers — it is about the people their customers serve. We treat it accordingly.
This page describes what we store, who can see it, and how to get it back or have it deleted.
Your parish is the controller of the parishioner data you enter. Bellringer is the processor: we store and process that data on your instructions and do not decide what goes in it.
If you are a parishioner and want to see, correct, or delete what a parish holds about you, contact the parish directly — they control those records. If they need our help to action your request, we will provide it.
We do not store full payment card numbers. Card details are handled by Stripe and never reach our servers.
Religious education and sacrament records often concern minors. Bellringer is sold to parishes, not to children, and we do not knowingly collect data directly from children. Where a parish records information about a minor, the parish is responsible for having the appropriate consent from a parent or guardian and for following its diocese's safeguarding policies.
We use a small number of third parties to run the service. Each has access only to what its function requires:
Connections are encrypted in transit. Passwords are stored hashed, never in plain text. Two-factor authentication is available on every plan, and organizations can require it. Significant account actions are recorded in an audit log you can read. Every record is scoped to one organization, so one parish cannot see another's data.
No system is perfectly secure. If you believe you have found a vulnerability, email security@bellringerhq.com.
You can export your parishioner records, giving history, and message history to CSV at any time, on every plan including Free. Signed-in users can review the personal data held about them at your data .
When you close your account we delete your organization's data within 30 days. Backups are retained for a further 30 days and then expire. Ask us at any time and we will confirm when deletion is complete.
We set a session cookie to keep you signed in, and an optional "remember me" cookie if you choose it. We do not use advertising or cross-site tracking cookies. Our analytics is cookie-free, which is why you do not see a cookie banner here.
Questions about this policy, or a data request: privacy@bellringerhq.com.