Security & Data Privacy
Your church trusts us with attendance, giving, and people data. Here's exactly how we protect it — the infrastructure we run on, how data is encrypted, and what we will never do with it.
Vitals runs on a small set of well-established infrastructure providers rather than custom-built or self-hosted systems. That means your data benefits from security practices maintained by teams whose full-time job is keeping that infrastructure safe — not a homegrown setup we'd have to secure ourselves from scratch.
Who We Run On
Vitals is built on top of trusted, industry-standard providers. Here's the full list of services that touch your church's data:
| Provider | Purpose |
|---|---|
| Vercel | Application hosting and deployment |
| Supabase (Postgres) | Primary database |
| Stripe | Subscription billing and card processing |
| Google OAuth (NextAuth) | Sign-in and account authentication |
| Sentry | Error monitoring |
| Elastic Email | Transactional and scheduled report emails |
| Mapbox | Campus map display |
Vitals also connects to church tools you choose to integrate — Planning Center, YouTube, Google Analytics, Facebook, and Instagram — but only pulls the data those integrations are scoped to, and only after you explicitly connect them in Settings.
Payment & Card Data
Vitals never stores credit card numbers on our servers. Subscription billing is handled entirely by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of certification in the industry. Your card details go straight to Stripe and never touch our database.
How Your Data Is Protected
Encrypted in transit
All traffic between your browser, our servers, and our database is encrypted with TLS.
Encrypted at rest
Your Postgres database on Supabase is encrypted at rest.
Multi-tenant isolation
Every query is scoped to your organization. One church's data is never visible to another.
Role-based access
Within your own organization, access is limited by the permission level each team member is given — see User Permissions for details.
Our Commitments to You
We will never sell your data.
We will never use your church's data to train AI models.
We will never share data across organizations.
You can export your data or close your account at any time.
We only request the integration scopes we need — nothing more.
Integration Data
When you connect Planning Center, YouTube, Google Analytics, Facebook, or Instagram, Vitals syncs only the metrics needed to power your dashboards — attendance, giving totals, engagement stats, and similar aggregate data. You can disconnect any integration at any time from Settings → Integrations, which immediately stops future syncs.
Questions or Concerns
If you have a security question, want to report a vulnerability, or need documentation for your church's own compliance review, reach out and we'll get back to you promptly.
Email support@vitals.church with any security or privacy question.
Related Articles
Still have questions? Email us at support@vitals.church — we usually reply within a few hours.