Admin

Writing a privacy policy for who can see what in your database

A one-page written policy for who can see giving and care records, no matter what software you use.

7 min read

Ask AI · in the $19/mo plan

Ask your own records a question. What follow-up has nobody picked up yet?” — answered from the records you already keep. It reads your church and no other, and it can't invent a number.

10 questions a month included · no AI add-on to buy

Somebody at your church has access to who gave what. Somebody else knows why a family stopped coming to the men’s group. Neither of those facts is written down anywhere except in a person’s head, and that person is doing their best, but they are guessing at what they are allowed to say out loud. A privacy policy fixes the guessing.

This is not a legal document, and it does not need a lawyer. It is a one-page decision, made once by your board or elders, about who can see giving records, who can see care notes, and what happens when someone asks. Most churches never write this down because nothing has gone wrong yet. The problem is that the first time something does go wrong — a volunteer mentions a giving amount at coffee hour, a departing staff member takes a printout home — there is no agreement to point back to. Only a memory of what everyone assumed.

Why a written policy beats a settings screen

It is tempting to think this problem is solved by finding software with the right permission checkboxes. Turn on a setting, restrict a role, done. In practice, most small-church software either does not have granular permissions at all, or has so many that nobody configures them correctly and everyone ends up with access to everything anyway. A checkbox you never look at again is not a policy. It is a false sense of one.

A written policy works regardless of what the software can or cannot do. It survives a software switch. It survives a volunteer turnover. It tells a new treasurer, on day one, exactly what she can look at and what she should not go looking for, before she has even logged in anywhere. That is worth more than a settings menu, because it is the thing people actually read and sign, not the thing they click past during setup.

Decide who counts as staff, for records purposes

Start by listing every person who touches a computer with church records on it: the pastor, the church secretary, the treasurer, a second counter or signer, a database volunteer, a small group leader who keeps her own notes. For each name, write down two things — what they need to see to do their job, and what they should never need to see at all.

Most churches find the list is shorter than they feared. A treasurer needs individual giving records to reconcile deposits and prepare year-end statements. A pastor needs pastoral care history and enough giving context to notice a sudden drop, not a running ledger of amounts. A small group leader needs her own group’s roster and attendance, not the whole church directory. Writing this out as a simple table, name by name, is the entire exercise. It does not need to be more complicated than that.

Draw a clear line on giving records

Giving is the record people care most about, and for good reason. Decide, in writing, who can see a specific person’s specific gift amounts. In practice this is usually one or two people: whoever enters the deposit, and whoever double-checks it. Everyone else, including most of the board, should see totals, trends and goals, not a name-by-name ledger.

  • Who enters gifts — the treasurer or a counting team member, named by name, not by role.
  • Who can pull a giving history — for a year-end statement, a tax question, or a pastoral conversation the giver has initiated themselves.
  • Who sees only totals — the board, most staff, and anyone reviewing a giving trend or goal, without individual names attached.

If your church already tracks giving in a way that respects the giver, this policy is the other half of that promise: it says out loud who is trusted with the number, not just how carefully the number is recorded.

Draw a clear line on pastoral care notes

Care notes are more sensitive than giving records, and the circle around them should be smaller, not larger. A hospital visit, a marriage struggle, a note about a teenager’s home situation — these belong to the pastor and, at most, one or two people directly involved in following up. They do not belong to the whole staff, and they certainly do not belong to a volunteer who happens to have a login.

Write down which roles can open a care case at all, and separately, which roles can add a comment to one already open. A small group leader might legitimately need to know a family is going through a hard season, without needing the specific counseling notes behind it. That distinction — the fact of care versus the content of care — is worth spelling out explicitly, because it is the line most churches blur by accident.

Write the one page, then have people sign it

The policy itself can fit on a single page. A workable outline:

  • Who can see individual giving amounts, and who sees totals only.
  • Who can open pastoral care cases, and who can add comments to one.
  • Who can export the directory, and what it may be used for.
  • What happens when someone leaves a staff or volunteer role — access removed, by when, by whom.
  • Who a member can ask if they want to know what is recorded about them.

Have your board approve it, and have everyone with access to records sign it — not as a legal formality, but so the expectation is explicit rather than assumed. A church transitioning off scattered spreadsheets is a natural moment to do this, since moving off spreadsheets already forces a conversation about who has been holding copies of what.

What to do when the software cannot enforce it

Be honest about your tools. Many small-church systems, SundayBridge included, run on one login per church rather than separate staff roles and permissions — whoever has the login can see whatever screen they open. That is not a flaw to work around with a clever setting; it is a reason the written policy matters more, not less. The policy is the control. The software is just where the records live.

In practice this means treating the login itself as something to protect — not shared beyond the people named in your policy, changed when someone with access leaves, and paired with a plain conversation about what “you can see this screen” does and does not mean. A volunteer with access to the giving screen because she also manages the directory is not thereby free to mention what she sees there. The policy says so, out loud, before it is ever tested.

Review it once a year, not once

A policy written once and never revisited quietly stops matching reality. The treasurer changes. A new pastor joins. Someone builds a directory the team actually trusts and suddenly three more people have logins. Put a fifteen-minute review on the calendar alongside your annual board meeting: read the page out loud, ask if the names still match the roles, and update it. That habit fits naturally alongside a broader weekly admin rhythm, where small, regular checks replace one overwhelming annual audit.

None of this requires new software, a lawyer, or a committee. It requires one page, a handful of honest decisions about who sees what, and the discipline to write them down before you need them.

Frequently asked questions

Does a small church legally need a privacy policy for its records?
Probably not a formal legal document, unless your state or denomination requires one. What you do need is an internal decision, written down, about who can see giving amounts and care notes. That protects the treasurer and the pastor as much as it protects the giver, because nobody has to guess what they are allowed to share.
Who should be able to see individual giving amounts?
In most small churches, that is one or two people: the person who records it and one person who reconciles it against the bank deposit, often the treasurer and a second signer. The pastor typically sees totals and trends, not a running list of who gave what, unless the giver has asked for pastoral follow-up tied to a gift.
Should volunteers see pastoral care notes at all?
Only the ones directly involved in that person’s care, and only what they need to act. A small group leader following up on a hospital stay does not need the counseling history from three years ago. Write down which roles can see care notes, and keep the circle as small as the care itself requires.
What if our software lets everyone with a login see everything?
Then the policy is the control, not the software. Write down who is allowed to open which screens, have everyone with a login agree to it in writing, and treat any login shared beyond that agreement as a policy violation, not a technical problem to solve later.
How often should we revisit the policy?
Once a year is enough for most churches, usually alongside a board or elder meeting. Revisit sooner if someone new takes over giving records or pastoral care, or if a volunteer raises a concern about what they can see. A policy nobody has looked at in three years is a policy nobody remembers agreeing to.