← Back to Bellringer

Privacy Policy

Last updated 21 August 2026

Bellringer is parish management software. Parishes use it to hold records about their parishioners, so most of the personal data in Bellringer is not about our customers — it is about the people their customers serve. We treat it accordingly.

This page describes what we store, who can see it, and how to get it back or have it deleted.

Who controls the data

Your parish is the controller of the parishioner data you enter. Bellringer is the processor: we store and process that data on your instructions and do not decide what goes in it.

If you are a parishioner and want to see, correct, or delete what a parish holds about you, contact the parish directly — they control those records. If they need our help to action your request, we will provide it.

What we store

  • Account data for parish staff: email address, hashed password, sign-in history including IP address and browser user agent, and two-factor settings.
  • Parish data you enter: parishioner and household records, contact details, notes, tags, groups and ministries, sacrament records, events and attendance, giving and pledge records, and message history.
  • Operational logs: audit records of significant actions taken in your account, and error reports used to diagnose faults.

We do not store full payment card numbers. Card details are handled by Stripe and never reach our servers.

Data about children

Religious education and sacrament records often concern minors. Bellringer is sold to parishes, not to children, and we do not knowingly collect data directly from children. Where a parish records information about a minor, the parish is responsible for having the appropriate consent from a parent or guardian and for following its diocese's safeguarding policies.

What we never do

  • We do not sell parishioner data.
  • We do not share it with advertisers or data brokers.
  • We do not use it to train machine learning models.
  • We do not read your parish's data except when you ask us to help with a fault.

Subprocessors

We use a small number of third parties to run the service. Each has access only to what its function requires:

  • DigitalOcean — hosting and database storage.
  • Stripe — subscription billing and, where enabled, online giving.
  • Resend — delivery of email you send from Bellringer.
  • Twilio — delivery of SMS you send from Bellringer.
  • Plausible — privacy-preserving website analytics. Cookie-free, and it does not track individuals across sites.
  • Sentry and Honeybadger — error reporting.

Security

Connections are encrypted in transit. Passwords are stored hashed, never in plain text. Two-factor authentication is available on every plan, and organizations can require it. Significant account actions are recorded in an audit log you can read. Every record is scoped to one organization, so one parish cannot see another's data.

No system is perfectly secure. If you believe you have found a vulnerability, email security@bellringerhq.com.

Getting your data out, and deletion

You can export your parishioner records, giving history, and message history to CSV at any time, on every plan including Free. Signed-in users can review the personal data held about them at your data .

When you close your account we delete your organization's data within 30 days. Backups are retained for a further 30 days and then expire. Ask us at any time and we will confirm when deletion is complete.

Cookies

We set a session cookie to keep you signed in, and an optional "remember me" cookie if you choose it. We do not use advertising or cross-site tracking cookies. Our analytics is cookie-free, which is why you do not see a cookie banner here.

Contact

Questions about this policy, or a data request: privacy@bellringerhq.com.