Giving

Writing a one-page giving privacy policy your board will approve

Who can see individual giving records, and why, settled in six short sections.

6 min read

Ask AI · in the $19/mo plan

Ask your own records a question. How did giving do this quarter against last year?” — answered from the records you already keep. It reads your church and no other, and it can't invent a number.

10 questions a month included · no AI add-on to buy

Ask five people at your church who can see what a family gave last year, and you will likely get five different answers, most of them a guess. That gap between what people assume and what is actually true is where trust quietly erodes — not because anyone misused the data, but because no one ever said out loud who is allowed to look at it.

A giving privacy policy fixes that gap. It does not need to be long, legal, or intimidating. It needs to be one page, written down, approved by whoever governs your church, and specific enough that a new treasurer or a curious board member can read it and know exactly where the lines are. Here is a template you can adapt in an afternoon.

Why a policy beats an unwritten understanding

Most churches already have an informal sense of who sees giving records. The problem with informal is that it does not survive turnover. A treasurer resigns, a new bookkeeper starts, a well-meaning board member asks for “just a quick look” at who gave what before a capital campaign — and without a written policy, there is nothing to point to except memory and awkwardness. Writing it down does the same job a lock does on a filing cabinet: it does not assume anyone is dishonest, it just makes the boundary visible and enforceable for everyone, including the people who would never think to test it.

A written policy also protects the people entrusted with the data. If a treasurer can point to an approved document that says exactly who has access and why, they are not making a judgment call under pressure when a well-liked staff member asks for a favor. The policy has already made the decision. That is a kindness to the person holding the records as much as it is a protection for the giver.

The template: what one page should cover

A giving privacy policy does not need more than six short sections. Each one answers a single question a board member, a new volunteer, or a concerned giver might actually ask.

1. Purpose

One sentence: this policy states who may view individual giving records at [church name] and under what circumstances, in order to protect the privacy of givers and the integrity of the church's financial records.

2. Roles with access, and why

List roles, not names. For each role, state the specific reason it needs access and the specific scope of what it can see. For example: the treasurer sees all individual giving records for reconciliation and year-end statements; the counting team sees weekly totals by envelope number for deposit purposes only, without names attached; the finance committee sees aggregate totals by category, never individual amounts.

3. The pastor question, answered explicitly

State plainly whether the senior pastor has access to individual giving records, and if so, under what limits — for instance, only for households who have asked for a stewardship conversation, or only in aggregate. If the pastor deliberately does not have access, say that too. This is the section people will actually read, so do not leave it implied.

4. Requests from outside the named roles

State what happens when someone not on the list — a board member, a spouse, a well-meaning volunteer — asks to see giving data. The simplest version: such requests go to the treasurer, who may share aggregate figures but not individual records without board approval.

5. Systems and storage

Name where giving records live — a spreadsheet, a binder, or software — and who holds logins or keys. If access is a shared login, say so and note the plan to move to individual logins if the system supports it.

6. Review date

A single line: this policy will be reviewed annually by [board or committee], next review [date]. That line is what keeps the document alive instead of filed and forgotten.

What to leave out

Resist the urge to make this a comprehensive financial-controls document. A giving privacy policy is not the same thing as your check-signing policy, your budget-approval process, or your audit schedule, even though all of them touch money. Bundling them together produces a document long enough that no one reads it closely, which defeats the purpose. Keep this one page focused on a single question: who can see individual giving records, and why.

It also does not need legal language. A board can approve a policy written in plain sentences just as validly as one full of “whereas” clauses, and plain sentences are more likely to be followed because people actually understand them.

Getting board approval without a long meeting

Bring the one-page draft to a board or elder meeting as a single agenda item, not a discussion starter. Most of the substantive decisions — who has access, what the pastor sees — should already be settled through a quiet conversation with the treasurer and pastor beforehand, so the board meeting is a ratification, not a debate held in front of everyone. If there is real disagreement about the pastor question, have that conversation separately and bring a decided position to the board rather than litigating it live.

Once approved, note the approval date on the document itself and store it somewhere every future board member can find it — not just in the minutes of one meeting three years ago.

How this connects to how you actually record giving

A privacy policy is only as good as the habits behind it. If your church is still figuring out how to track giving in a way that respects the giver, write the policy first — it will clarify a lot of the smaller decisions about recordkeeping that come after. SundayBridge records contributions and generates year-end giving statements with one login per church, so any access boundary beyond “anyone with the login can see everything in the system” has to live in your written policy and your team's practice, not in the software itself. That is worth knowing before you write the roles section: the tool will not enforce your policy for you, your people will.

The same is true whether giving lives in a spreadsheet, a paper ledger, or software. A privacy policy is a people decision first. It is worth revisiting once your church has moved past the informal-spreadsheet stage, which is a good moment covered in moving your church off spreadsheets, since that transition is exactly when old assumptions about who sees what tend to get exposed.

A short example, filled in

To make this concrete, here is a filled-in version for a hypothetical church of 140 people with one paid staff member and a five-person board:

Purpose: This policy states who may view individual giving records at Grace Fellowship and under what circumstances, to protect the privacy of givers and the integrity of financial records.
Access: The treasurer has full access for reconciliation and statements. The two-person counting team sees weekly totals without names attached. The finance committee sees quarterly totals by category only.
Pastor: The senior pastor may request a household's giving history only when that household has initiated a stewardship conversation, and only through the treasurer.
Outside requests: Board members may request aggregate totals from the treasurer at any time. Individual records require board approval.
Systems: Giving is recorded in [system name]. The treasurer and financial secretary hold the only logins.
Review: Reviewed annually every January by the finance committee.

Adjust the roles and thresholds to fit your church's actual size and staffing, but keep the shape: a stated purpose, named roles with reasons, an explicit answer on the pastor question, a path for outside requests, a note on systems, and a review date.

What changes once the policy exists

The value of this document shows up less in any single moment and more in the ordinary weeks when nothing goes wrong. A new board member joins and reads it instead of asking around. A volunteer steps into the counting team and knows exactly what they will and will not see. A giver asks, directly or indirectly, whether their gifts are kept confidential, and someone can answer with a document instead of a shrug. None of that requires new software or a committee. It requires one page, a half hour of drafting, and a board willing to say plainly what has probably been true all along — just never written down.

Frequently asked questions

Does a small church really need a written giving privacy policy?
Yes, maybe more than a large one. In a congregation of 80, the treasurer and the pastor and the pastor's spouse can all plausibly know who gives what without anyone deciding it should be that way. A short written policy is what turns an accident of small-town intimacy into a choice the church actually made, and it protects whoever holds the records the next time someone asks to see them.
Who should be named in the policy?
Name roles, not people, so the policy survives a change in staff or volunteers. Typical roles are the treasurer, a financial secretary or counting team, and sometimes the senior pastor for stewardship conversations. Each role should have a stated reason for access and a stated limit — for example, the counting team sees totals per envelope for deposit purposes but never sees the annual giving history tied to a name.
Should the pastor be able to see individual giving amounts?
Churches land on both answers, and either can be right if it is decided on purpose. Some pastors want visibility for stewardship conversations and to notice a family in sudden financial distress. Others deliberately opt out so generosity never colors how someone is welcomed, scheduled to serve, or counseled. The policy should state the church's choice and why, not leave it to whoever happens to be logged in.
What do we do about giving data in software or spreadsheets?
Whatever system holds giving records — a spreadsheet, a binder, or church management software — should be covered by the same policy as the paper offering envelopes were. Say in writing who has a login, whether that login is shared or personal, and what happens to access when someone leaves a role. A policy that only covers paper and ignores the spreadsheet on the treasurer's laptop is not actually a policy.
How often should the policy be reviewed?
Once a year is enough for most churches, timed to whenever you already review other financial policies or prepare year-end giving statements. Reread it, confirm the named roles still match who actually holds those jobs, and note the review date at the bottom of the document. A policy nobody has reopened in three years is a policy nobody is really following.