Back to Knowledge Base
Settings & Admin

Security & Data Privacy

Your church trusts us with attendance, giving, and people data. Here's exactly how we protect it — the infrastructure we run on, how data is encrypted, and what we will never do with it.

Vitals runs on a small set of well-established infrastructure providers rather than custom-built or self-hosted systems. That means your data benefits from security practices maintained by teams whose full-time job is keeping that infrastructure safe — not a homegrown setup we'd have to secure ourselves from scratch.

Who We Run On

Vitals is built on top of trusted, industry-standard providers. Here's the full list of services that touch your church's data:

ProviderPurpose
VercelApplication hosting and deployment
Supabase (Postgres)Primary database
StripeSubscription billing and card processing
Google OAuth (NextAuth)Sign-in and account authentication
SentryError monitoring
Elastic EmailTransactional and scheduled report emails
MapboxCampus map display

Vitals also connects to church tools you choose to integrate — Planning Center, YouTube, Google Analytics, Facebook, and Instagram — but only pulls the data those integrations are scoped to, and only after you explicitly connect them in Settings.

Payment & Card Data

Vitals never stores credit card numbers on our servers. Subscription billing is handled entirely by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of certification in the industry. Your card details go straight to Stripe and never touch our database.

How Your Data Is Protected

  • Encrypted in transit

    All traffic between your browser, our servers, and our database is encrypted with TLS.

  • Encrypted at rest

    Your Postgres database on Supabase is encrypted at rest.

  • Multi-tenant isolation

    Every query is scoped to your organization. One church's data is never visible to another.

  • Role-based access

    Within your own organization, access is limited by the permission level each team member is given — see User Permissions for details.

Our Commitments to You

We will never sell your data.

We will never use your church's data to train AI models.

We will never share data across organizations.

You can export your data or close your account at any time.

We only request the integration scopes we need — nothing more.

Integration Data

When you connect Planning Center, YouTube, Google Analytics, Facebook, or Instagram, Vitals syncs only the metrics needed to power your dashboards — attendance, giving totals, engagement stats, and similar aggregate data. You can disconnect any integration at any time from Settings → Integrations, which immediately stops future syncs.

Questions or Concerns

If you have a security question, want to report a vulnerability, or need documentation for your church's own compliance review, reach out and we'll get back to you promptly.

Email support@vitals.church with any security or privacy question.

Related Articles

Still have questions? Email us at support@vitals.church — we usually reply within a few hours.