Privacy Policy

Version 1.5Effective 2026-07-30

1. Who we are

Minster Scheduling, LLC ("we," "us," "our") operates Minster, a web service for scheduling interviews between congregation leaders and members. We are independent and not affiliated with, endorsed by, or sponsored by The Church of Jesus Christ of Latter-day Saints or any religious organization.

2. Our role

We act as the data controller for the personal information described here: we decide how scheduling information is collected, stored, retained, and secured. A subscribing congregation ("unit") that enters its members' details and conducts interviews is treated as a joint controller for its own members' data.

3. Information we collect

From members booking an interview (no account required):

  • Name (for an interview booked for a minor, this is the youth's name).
  • One contact detail — either a mobile number or an email address — used as the single channel for all messages about the appointment.

For interviews booked on behalf of a minor (Youth Interview only):

  • A guardian's confirmation of consent, stored as a timestamp and a verbatim snapshot of the consent text shown.
  • By default we collect only the guardian's contact information, not the youth's.

From leaders and administrators:

  • Name, contact, and sign-in identity (passwordless email).

For billing:

  • Subscription and payer details. Card payments are processed by Stripe; we do not store card numbers.

Automatically:

  • A security audit log (who did what), and cookieless, aggregated usage analytics.

4. Sensitive-data note

Because a record may indicate that a named person has an interview with a religious organization, this information could reveal religious affiliation in some jurisdictions.

A member or guardian will provide explicit consent to the processing of personal data (through the entry of either a mobile number or email address) for the specific purpose of scheduling interviews between congregation leaders and the member or guardian.

5. Why we use information and our lawful basis

  • To provide scheduling and send appointment confirmations and reminders (performance of a contract / provision of the requested service).
  • To bill subscribers (contract).
  • To secure the service and keep records of consent (legitimate interests; legal obligation).
  • Where this information may reveal religious affiliation (see §4), our processing of that special-category aspect relies on an applicable condition under GDPR Article 9 — for example, that it is necessary to provide a service the member or guardian has actively requested.

-

6. Communications

Appointment messages. If a member or guardian provides a mobile number, we send transactional appointment confirmations and reminders by text; recipients can reply STOP to unsubscribe and HELP for help, and message and data rates may apply. We send the same confirmations and reminders by email when an email address is provided. These messages are part of the Service and are not subject to opt-out, though you may change your contact-channel preference or remove your details.

We do not market to members or guardians. We never use a contact detail that a member or guardian gives us to book an interview for marketing or promotional messages of any kind, and we do not send marketing texts. Any future promotional email — which would go only to leaders or subscribers — will be clearly identified and include an unsubscribe link you can use at any time.

7. How we share information

We share information with service providers ("sub-processors") who help us run the Service:

ProviderPurpose
SupabaseDatabase, authentication, hosting of application data
VercelApplication hosting
TwilioSMS delivery
ResendEmail delivery
StripePayment processing
GoogleCalendar integration (leader-initiated only): reading a connected calendar's free/busy times and writing confirmed interview appointments to it
SentryError monitoring
CronitorUptime/job monitoring
InstatusStatus page
Plausible AnalyticsAggregated, cookieless analytics — EU-hosted
PostHogProduct analytics — anonymized, non-identifying usage events only (no member identifiers); US-hosted
AxiomApplication log storage, retained 30 days, used to operate and secure the Service; US-hosted

We do not sell personal information. We may disclose information if required by law.

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, sale of assets, or wind-down of the Service, personal information may be transferred to the parties involved as part of that transaction, subject to this policy. We will notify affected administrators where required.

8. Where data is stored

Application data is hosted in a single region in the United States. For users in the European Economic Area, the United Kingdom, or Switzerland, this means their personal information is transferred to and processed in the United States; where required, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) as the transfer mechanism, and we make a Data Processing Agreement available to units that require one. Our analytics and log-storage providers also process their limited data in the United States.

9. How long we keep information

  • Completed and missed (no-show) appointments: retained for 1 year, then anonymized — we remove the member's name, phone, email, any notes, and the guardian-consent text, and keep only non-identifying scheduling fields (interview type, unit, timing, status, whether it was a minor booking).
  • Cancelled appointments: deleted after 90 days.
  • Ended subscriptions: when a unit's subscription ends — whether it lapses or is cancelled — member appointment details are permanently anonymized 30 days later. We email the unit's billing contact a reminder 5 days before, and the unit can export its appointment data at any time during that window.
  • Lapsed subscriptions: a 30-day read-only window, then expiry and anonymization of associated personal data.
  • Notification and SMS logs: 30 days.
  • Security audit log: 2 years.
  • Analytics: no raw, personally identifiable analytics events are stored; only aggregate, non-identifying statistics are retained.

10. How we protect information

We use a range of measures to protect personal information, including: per-unit access isolation enforced by database row-level security; passwordless sign-in with single-use, time-limited links and mandatory two-factor authentication for operator accounts; encryption of data in transit; secure, HTTP-only session cookies; signature verification on incoming payment and messaging webhooks; and rate limiting and bot protection on public endpoints. [Leader notes, when introduced, will be encrypted and readable only by their author.] No security is perfect, but we take reasonable measures and maintain a breach-response process.

11. Data breach

If a breach affecting personal information occurs, we follow our incident process and notify regulators and affected administrators as required by applicable law.

12. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. To exercise them, contact us at privacy@minster.church. A member may delete their own identifying details from an appointment. A leader's private note about an interview is the leader's own encrypted record and follows a separate lifecycle.

Handling a request. We verify your identity before acting on a request — generally by confirming your control of the phone number or email address on file for the relevant booking or account — and may ask for additional information where needed. Where the law allows, you may use an authorized agent to submit a request on your behalf; we may verify both your identity and the agent's authorization. If we decline a request, you may have the right to appeal — contact us at the same address to do so.

13. Children

Interviews for minors are booked by a parent or legal guardian, who must give explicit consent. We do not knowingly collect a minor's contact information directly and default to collecting only the guardian's contact details.

14. Cookies and analytics

We use privacy-friendly, cookieless analytics that set no cookies, store no IP addresses or other personal data, and do not track you across sites or sessions — only aggregate, non-identifying statistics are collected. The cookies we set ourselves are limited to those strictly necessary to keep you signed in, plus one optional first-party referral cookie: if you open a referral invitation link, we store its 8-character referral code in your browser for up to 30 days so the referring congregation can receive its account credit if you sign up. That code identifies the referring congregation, not you; it is not used for advertising or cross-site tracking, and applying the referral is always confirmed with you during signup. Because we set no analytics or advertising cookies, no cookie-consent banner is required in most jurisdictions.

15. California residents (Notice at Collection)

This section is the notice at collection required of certain businesses under the California Consumer Privacy Act, as amended by the CPRA. It supplements the rest of this policy for California residents.

Categories we collect. In the past 12 months we have collected the categories below. We do not sell or share personal information (as "sell" and "share" are defined under the CCPA), and we do not use it for cross-context behavioral advertising.

Category (CCPA)Examples in our ServicePurposeSold / shared?
IdentifiersName, email, phone, IP address, single-use booking linkScheduling, confirmations and reminders, sign-in, securityNo
Customer recordsSubscriber and payer details (card data is handled by Stripe; we do not store it)Billing and account managementNo
Commercial informationSubscription plan and historyProviding and managing the subscriptionNo
Internet / network activityAggregated, cookieless usage statistics; security audit log; a first-party referral cookie holding an 8-character referral code (no personal information)Operating, securing, and improving the Service; crediting congregation referralsNo
Sensitive personal informationA record may indicate that a named person has an interview with a religious organization, which can reveal religious affiliationUsed only to provide the scheduling service you requested — not to infer characteristics about you, and not for advertisingNo

Sources and disclosures. We collect this information from you (or, for a youth interview, from the booking guardian) and automatically through providing the Service. We disclose it only to the service providers listed in Section 7, for the purposes described there.

Retention. We keep each category only as long as described in Section 9 (How long we keep information).

Your California rights. California residents may request to know, access, correct, or delete personal information; opt out of any sale or sharing (we do none); limit the use of sensitive personal information; and not be discriminated against for exercising these rights. To exercise them, use the contact details at the end of this policy; identity verification and authorized-agent handling are described in Section 12 (Your rights). Where required, we honor opt-out preference signals such as Global Privacy Control (GPC).

16. Google Calendar integration

Leaders may optionally connect a personal Google Calendar so the Service can avoid offering members a time the leader is already busy. This integration is available only to leaders and administrators — members never connect a calendar — and a leader can disconnect it at any time.

What we access. With your permission, we access your Google Calendar to:

  • Read your free/busy times (calendar.readonly) — we retrieve only the start and end times of your existing calendar entries. We store only these opaque busy/free intervals; we never read, store, or receive event titles, descriptions, attendees, locations, or any other event content.
  • Add confirmed interview appointments to your calendar (calendar.events) — when an interview is confirmed in the Service, we create a single calendar event for it so it appears alongside your other commitments. You choose whether the member's name is included or the event is shown generically.

How we handle Google user data. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use this data only to provide the user-facing scheduling features described above; we do not transfer or sell it to others except as needed to provide the Service or as required by law; we do not use it for advertising; and we do not allow humans to read it except with your consent, for security or debugging, or as required by law. OAuth access and refresh tokens are encrypted at rest, and disconnecting your calendar deletes the stored tokens and the cached busy/free data.

17. Changes to this policy

We may update this policy; material changes will be signposted and, for signed-in users, may prompt re-acceptance, keyed to the policy version.

18. Contact

Minster Scheduling, LLC, 5938 N Roper Dr, Mountain Green, UT 84050. Privacy contact: privacy@minster.church.

Version history
VersionEffectiveStatus
1.52026-07-30published
Privacy Policy — Minster