Effective Date: December 01, 2024
Privacy policies may not top the list of the most entertaining reads on the internet, but they are undeniably important—especially in today's data-driven world. At Stablish, we enjoy keeping things engaging, but when it comes to your privacy, we're all business. We deeply value the trust you place in us when you share your personal information, and we take that responsibility very seriously.
Just as feeling in control of your finances brings peace of mind, the same principle applies to your personal information. That's why we've crafted Stablish's Privacy Policy to be as transparent and straightforward as possible. While we encourage you to read the full Privacy Policy, here are the highlights:
The remainder of this document delves into the legal details, just as our lawyers recommend. To make it easier to navigate, we've included a table of contents and section summaries. While we've worked to simplify the language, it's crucial to review the entire Privacy Policy for complete understanding.
At Stablish Solutions Inc., a Delaware Corporation ("Stablish," "we," "us," or "our"), we are committed to protecting your privacy. This Privacy Policy outlines the information we collect, how we use and safeguard it, and your rights regarding our handling of your data.
This Policy applies to our websites and web applications accessed via stablish.church, www.stablish.io, www.stablish.ai, and all related domains and subdomains. These websites are operated by Stablish Solutions Inc. and provide information about our company and access to our online platforms, which support churches and non-profit organizations. Our Services include tools for web building, form building, content management, donation platforms, communications, and other related functionalities (collectively, the "Services").
By using any part of our Services, you consent to the collection, use, and disclosure of your information as described in this Policy.
Under the EU General Data Protection Regulation 2016/679 ("GDPR"), the data controller of personal data you provide or we collect is Stablish Solutions Inc. You can contact us using the details in the "How to Contact Us" section below.
"Personal data" refers to information that identifies you directly or indirectly, either alone or in combination with other data.
Please note that Stablish Solutions Inc. acts solely as a data processor for third-party data you submit through our Services (e.g., personal data processed within your church, CRM systems, email communications, etc.). You, as the user, may be the data controller for such information. The processing of third-party data is subject to our Terms of Service.
We may revise this Privacy Policy periodically. Any updates will be made available through the Services, and you can check the "Last Modified" date at the top of this document to track changes. If significant updates are made, we will notify you as required by law. By continuing to use our Services after any updates, you confirm your understanding and acceptance of the revised Policy.
If you have questions or concerns regarding this Privacy Policy, please contact us at support@stablish.io.
Summary: We collect information as you interact with us or use the Services. This information is used to contact you, fulfill our agreements, and support routine business operations, including marketing. Below, we detail the types of information collected, how and why we collect it, how we protect it, and, for users in the UK and European Economic Area, the legal bases for processing it.
We gather information that directly or indirectly identifies you through your use of Stablish. This information is collected in the following ways:
This includes:
Details submitted through forms on the Services, such as during registration, subscription, service requests, promotions, surveys, or general inquiries. For instance, if you log in using a third-party identity provider like Google, we receive your associated email address. Additionally, if you use the Services through a plan (e.g., workplace-provided), we collect related information, such as your work email and date of joining.
Collected when you interact with the Services.
Including your postal code, for billing purposes.
When linking financial accounts, we may collect data such as account balances, transactions, and holdings.
If enabled, precise or general location information is collected when recording transactions. Precise location helps suggest payees for future transactions near the same location. General location identifies your city and state based on your IP address. Stablish does not use location data for targeted advertising. Note: Precise location information is considered "sensitive personal information" under certain privacy laws and is handled accordingly. You may disable precise location tracking on your device.
Emails and messages sent to our support team, including those sent from email addresses different from your account email.
Information about purchases made through the Services, such as subscription records. Billing information may be required for these transactions.
When you contact support, we may review a limited amount of data (e.g., account names, recent transactions) to facilitate technical support and resolve issues with financial account integrations, but only with your explicit consent.
Information about how you use the Services, including IP address, device location, browser type and language, visit times, error logs, browsing behavior, and other data that helps analyze usage and improve the Services.
In some cases, we will inform you when specific information is required to provide certain Services (e.g., troubleshooting an issue with your budget). If you choose not to provide the required information, we may be unable to fulfill your request.
We primarily collect information directly from you. However, we may also gather information about you from the following third-party sources:
We use third-party analytics services (such as Posthog, Amplitude, fullstory, and Google Analytics) and self-hosted data collection tools on our Services to gather and analyze usage data. This includes information such as the most-read pages, time spent on the site, search terms, and other engagement metrics. These tools assist with auditing, research, fraud prevention, reporting, and delivering specific features. To prevent Google Analytics from collecting your data, you can install the Google Analytics Opt-out Browser Add-on.
The usage information collected from our Services helps us compile statistical data to improve and develop new features, refine marketing efforts, identify popular tools, and deliver content tailored to your interests.
If you receive emails from us, we may use analytics tools, such as tracking pixels, to gather data on when you open messages or click links or banners. This helps us measure the effectiveness of our communications and marketing efforts.
We also collaborate with third-party advertisers, ad server companies, and ad networks to promote Stablish. If you respond to one of our advertisements and access or register for our Services, we or our service providers may share identifiers from your device or computer (e.g., IP address or device ID) with these third-party advertisers to analyze user acquisition and marketing performance.
The cookies or tracking technologies used by non-affiliated third parties on your devices are governed by those third parties' privacy policies. For more information about tailored browser advertising and how to manage cookies on your devices, please refer to our Cookies Policy.
We may combine data collected through cookies with other information gathered about you to enhance our Services and your experience.
The laws of some jurisdictions, including the European Economic Area ("EEA") and the United Kingdom ("UK"), require that companies only process your "Personal Data" (as that term is defined in the applicable law, like the EU General Data Protection Regulation) if they have a "legal basis" (or justifiable need) for processing your Personal Data. To the extent those laws apply, our legal bases for processing Personal Data are as follows:
We disclose data to fulfill the purposes for which you provide it and to enforce or apply our Terms of Service, including billing. We may disclose or transfer information that we collect or you provide with:
These parties help us provide the Services or perform business functions on our behalf. They include:
These parties help us market our service. They include ad networks and other marketing providers.
These parties provide analytics on web traffic or usage of the Services. They include:
which at this time are Stripe, to process and manage your payment for the Services.
but only with your consent. By utilizing these services, you acknowledge that the terms of the respective privacy policies of these providers (MX, Plaid, TrueLayer, etc.) will apply to your use of their services. With respect to aggregating your banking and other financial accounts, you or we (with your consent) will transmit your account credentials to third-party financial data aggregation services, who will use them to link, gather, and maintain your account balances, transactions, and holdings used to provide the Services.
in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us about users of the Services is among the assets transferred.
For example, when you use Stablish Together, you authorize us to share budgets that you own and data encompassed within those budgets with your Group Manager and selected Members of your Stablish Together Group. Members of your Stablish Together Group may view certain information about you, including budgets that you own or have access to, your first name, and email address.
If you elect to participate in the Product through a business or other organization ("Partner") as part of a Partner's plan ("Plan"), for example, when an employer provides Stablish as an employee benefit, we will share certain information—such as your name, email address, and the date you joined the Services—with that Partner. If a Plan has 10 or more users, we may also provide the Partner with aggregated, anonymized data about the number of Plan users who access Stablish each month and how users are interacting with the Services.
We may also disclose your information:
We may de-identify and aggregate information collected in such a way that the information cannot reasonably be linked to you or your device. We may use such de-identified or aggregated data for any purposes (including testing our IT systems, research, data analysis, improving the Services, and developing new products and features) and may disclose it to our service providers. Additionally, when we de-identify and aggregate non-Financial Data, we may disclose such data to third parties, including advertisers, promotional partners, and others.
We retain your information as necessary to provide the Services, fulfill your requested transactions, and for purposes such as complying with legal obligations, resolving disputes, enforcing agreements, and preventing fraud or other security-related issues. When determining how long to keep your data, we consider factors like the sensitivity of the information, the potential risks of unauthorized access or disclosure, the purpose of processing the data, how long an account has been inactive, and any legal requirements.
Specifically:
You can request the deletion of your information at any time by following the steps outlined in the Your Rights and Choices section of this Policy.
If you choose to use third-party apps, or any church management system integrated (OAuth-based applications that integrate with our Services), plugins, or external websites, these third parties may access your data, including personal information, photos, and activity data. The information they collect is governed by their respective terms and privacy policies. Stablish is not responsible for the practices or policies of these third parties, so we encourage you to review their privacy and security policies before using their services.
The Services are not intended for children under 13 years of age, or 16 years of age for those who reside in the European Economic Area or the United Kingdom. Children below these ages may not provide personal data to the Services. We do not knowingly collect personal information from children under 13 or 16. If you are under these ages, please do not use or provide any information on the Services or through any of its features, register for the Services, make purchases, or provide any information about yourself, including your name, address, telephone number, email address, or any username you use.
If we learn that we have collected personal data from a child under 13 or 16, we will delete that information. If you believe we might have received information from or about a child under these ages, please contact us at support@stablish.io.
Summary: Users have certain rights concerning marketing communications, mobile interactions, and, depending on their jurisdiction, rights related to accessing, correcting, or deleting personal information. These rights are described below, including instructions for exercising them. If there's a conflict between this section and other parts of this Policy, the section offering the highest level of privacy protection will apply. Residents of California should refer to our California Privacy Policy for additional details.
Depending on your jurisdiction, you may have the right to make specific requests regarding your "personal information" or "personal data" (as defined by applicable laws). These rights may include the ability to:
You also have the right not to be discriminated against for exercising your rights.
Additionally, you may have the right to opt out of the "sale" of your information and "sharing/processing of your information for targeted advertising." If you are a California resident, please refer to our California Privacy Policy for more details.
Certain information may be exempt from such requests under applicable laws. For example, we may need to retain information to provide Services or for legal compliance. We are also required to verify your identity before processing your request, which may involve verifying your name and email address, depending on the nature of your request.
If permitted by law, you may designate an authorized agent to submit requests on your behalf. The agent must have your written, signed permission or a power of attorney, and we may verify your identity before acting on the agent's request. For more details or to exercise your rights, please visit this link or contact us at support@stablish.io.
You may also have the right to appeal a denial of your request. If your request is denied, we will provide instructions on how to appeal, if applicable. Appeals can be submitted via email to support@stablish.io.
You can unsubscribe from marketing emails by clicking the unsubscribe link in those emails. Please note that processing your request may take time as required by law. Even after opting out of marketing emails, you may still receive administrative messages such as order confirmations, policy updates, or other communications related to your account or transactions with us.
We may send push notifications through our applications. You can disable these notifications through your device settings. If you previously granted us access to collect precise GPS location data and wish to revoke this permission, you can disable location features through your device's operating system. Please note that disabling these features may limit access to certain Services, content, or features.
As outlined in our Cookie Policy, we incorporate cookies and similar technologies from third parties into our Services to deliver relevant and tailored ads for our offerings and analyze the performance of our ads and the audiences interacting with them. We may also share certain identifiers, such as a hashed email address, with third-party platforms to display Stablish ads to potentially interested users. These technologies help us and our partners serve targeted Stablish ads on other platforms and reduce ad frequency for existing subscribers.
While these practices are common for companies like Stablish to promote their products and services, certain laws classify these activities as "selling" personal information or "sharing/processing" personal information for targeted advertising—even though we do not exchange your information for money.
We want to emphasize that we do not "sell" the personal information you provide through the Product or "share/process" it for targeted advertising purposes, including Financial Data.
However, under some state privacy laws, our advertising efforts directed toward prospective Stablish users might fall under the definitions of "sale" or "sharing/processing" for targeted advertising. Below, we disclose information about these activities as required.
If you wish to opt out of the online disclosure of your personal information (e.g., via cookies and pixels) for purposes that might be considered "sales" for third parties' commercial use or "sharing" for targeted advertising, please follow this link or select "Your Privacy Choices" in the Services and follow the instructions. Please note that this choice must be made separately for each browser, device, or app you use to access the Services and must be renewed if you clear your cookies or your browser clears them automatically.
You can also request to opt out of the use of your email address and other associated personal information for targeted advertising purposes by visiting this link. Depending on your jurisdiction, you may designate an authorized agent to submit such requests on your behalf. We do not knowingly sell the personal information of minors under 16 years old without legally required affirmative authorization.
If your device browser supports legally recognized opt-out preference signals, we will honor such preferences as required by law.
We may offer programs that provide benefits, such as monetary rewards for completing surveys, signing up for communications, or other similar opportunities (each, an "Incentive Program"). These may require you to provide personal information, such as creating an account, answering surveys, or providing additional feedback. These programs may qualify as financial incentives under applicable law. Participation in any Incentive Program is entirely voluntary. By participating, you agree to the terms of the Incentive Program and may revoke your participation at any time, subject to the specific terms of the program.
California residents may have additional rights regarding their personal information, as detailed in the Your Rights and Choices section of this Policy. Please refer to our California Privacy Policy for more information about these rights and practices specific to California residents.
Summary: We operate from the United States. Information from users in other countries will be transferred, processed, and stored in the United States.
The Services provided by Stablish are based in the United States. If you are located outside of the U.S. and choose to use the Services or share your information with us, you acknowledge and agree that your data will be transferred, processed, and stored in the United States. This transfer is necessary for us to provide the Services and fulfill our Terms of Service.
Your church has chosen to use our Website and Services to facilitate the operation of its website, web-based software, and/or fundraising platform. This privacy policy explains how we protect the security and privacy of your information. Please note that both we and your church collect personal information about you. The specifics of what we collect and how we use it are detailed in this Privacy Policy. However, your church owns the data collected about you, not us, and our role concerning such data is limited.
Our customers, such as your church, retain all rights to the data they store in our Services. We act as a "Service Provider" as defined by the California Consumer Privacy Act (CCPA) or a "Subprocessor" as defined by the General Data Protection Regulation (GDPR).
The data stored in our databases by users of our Services is entrusted to us for safekeeping but is not our data. We are legally and contractually obligated to uphold certain standards regarding the data we process, including:
You may have legal rights regarding how your church uses your personal information. These rights vary depending on where you live but generally include the right to:
To exercise these rights, contact your church. We will take all necessary steps to assist your church in satisfying your requests.
At Stablish Solutions Inc., our Services and business may evolve over time. Consequently, we may need to update this Privacy Policy periodically. Stablish Solutions Inc. reserves the right to modify or update this Privacy Policy at any time. If you disagree with any changes, you may deactivate your account or discontinue using our Services. Please review this policy periodically, especially before providing us with any information through the Services. This Privacy Policy was last updated on the date indicated above. Continued use of the Services after any changes indicates your acceptance of the revised Privacy Policy.
We collect information that you voluntarily provide via email, web forms, our products, or other direct interactions. This information helps us respond to your inquiries and assist you in using our products and services. We do not sell your information to third parties.
We avoid disclosing or sharing your information with affiliates or third parties. However, in rare cases, some basic information about you or your church (e.g., email, name, or other identifying information) may be used in third-party tools to help us recognize you or your account for customer service purposes. Unless you request otherwise, we may contact you via email to inform you about our services, new products, changes to this Privacy Policy, or to provide informational or educational newsletters.
You may provide us with sensitive data under the GDPR (e.g., health information). Such information will never be shared unless explicitly requested or authorized by you.
Our Services allow you to invite others to manage your account or provide information. Do not provide personal information about others unless authorized or required by applicable law or contract. Before supplying personal information about others, ensure you and the person consent to our Terms of Use and Privacy Policy. By submitting such information, you warrant that you have obtained the person's consent and agree to indemnify Stablish Solutions Inc. and its affiliates for any failure to comply with this requirement.
When you interact with our Services, we may automatically collect certain information from your devices, such as browser type, operating system, IP address, and location data. This information helps us improve our Services and provide a better user experience.
Unlike many service providers, we do not conduct detailed research or analytics on our customer demographics, interests, or behavior. We also do not aggregate data for the purpose of selling or sharing it with third parties. Any information you provide is used solely by our team to serve our customers' needs directly.
To access certain Services, you may need to register with Stablish Solutions Inc. During registration, you will be required to provide information such as your name and email address. This information is used to contact you about the Services you have expressed interest in and to provide access to protected areas of our Services.
We use cookies and similar technologies to enhance your experience with our Services. Cookies are small pieces of information stored on your device that help us remember your preferences and understand how you use our Services. You can manage your cookie preferences through your browser settings. Please note that blocking cookies may affect your access to certain features of our Services.
If you interact with us on social media platforms (e.g., Facebook, Twitter, Instagram, LinkedIn), we may receive additional information about you, such as profile details, contact lists, and communications. This information is not actively aggregated or appended to your customer profile. Please refer to the privacy policies of the respective social media platforms for more details.
We do not use third-party analytics or behavior-tracking tools in our Services to collect data on our customers, ensuring the privacy and security of your church and congregation's information.
Stablish Solutions Inc. uses the information collected through our Services in accordance with this Privacy Policy. If you provide information for a specific reason, we use it for that reason. For example, if you contact us via email, we will use your information to respond to your query or resolve your issue. If you provide information about yourself or third parties, we will use it to offer and monitor the services you access. Under the GDPR, we may use your information as necessary to fulfill our contractual obligations or to take steps at your request before entering into a contract.
Each marketing or promotional email will include instructions on how to unsubscribe. If you opt-out of promotional emails, we may still communicate with you via mail, phone, or social media. It may take up to 10 business days to be removed from our promotional email list.
We send notification and transactional emails about the Website and Services periodically. Generally, you cannot opt-out of these non-promotional communications, though you can manage some notification preferences in your account settings or by deactivating your account.
We use the information collected through our Services to provide and support our Services, process transactions, fulfill information requests, send and receive communications, update email lists, comply with laws, and enforce our Terms of Service and this Privacy Policy. Under the GDPR, this use is necessary to fulfill our contractual obligations, protect against fraud, or comply with legal requirements.
We may send communications related to the Services, such as updates about donations, completing forms, or providing churches with updated information. If you use features that allow communication with third parties, such as referrals, you confirm that you have the authority to provide their information and have informed them of our Privacy Policy. We reserve the right to identify you as the referrer in any communications sent to them. These third parties can opt-out of receiving further communications.
Without your permission, we do not share data we collect from you with third parties, except as described below:
We may share data with limited third-party service providers to communicate with you about your account. These providers are restricted to using your data only to provide their services and must ensure they safeguard your data appropriately.
We may disclose your data to third parties if we believe it's necessary to comply with laws, regulations, legal processes, or government requests; to enforce our agreements and policies; to protect the security or integrity of our site or services; or to protect ourselves, our customers, or the public from harm or illegal activities.
We may share data collected through our Services with our affiliates, who will use the data as described in this policy.
In the event of a corporate sale, merger, reorganization, dissolution, or similar event, or during steps taken in anticipation of such events, user information may be part of the transferred assets.
If you donate to a church's fundraising campaign or submit information to a church through our Services, we may share your name, email address, and other provided information with the church, which may contact you. By participating in these activities, you consent to our sharing your information and to the church contacting you.
We may aggregate or de-identify your information so that it no longer relates to you individually. Our use and disclosure of such aggregated or de-identified information is not subject to this Privacy Policy and may be shared with others without limitation. We do not share your data (including the personal data of your end users or congregants) with third parties for their direct marketing purposes.
Certain information you provide may be publicly accessible, such as posts in forums or comment sections. We may also collect information through customer support communications, suggestions for new products or modifications, and other unsolicited submissions (collectively referred to as "Unsolicited Information"). By providing Unsolicited Information, you agree that:
This section remains effective even after the termination of your account or use of our Services. This Privacy Policy does not apply to information collected by Stablish Solutions Inc. outside of the Services.
Our Services are not intended for individuals under the age of 16. If you are under 16, do not use the Services or provide any information through them. If you believe a child under 16 has provided personal information to Stablish Solutions Inc. through the Services, please contact us at support@stablish.io and we will take steps to delete such information as required by law.
This Privacy Policy applies solely to our Services. The Services may contain links to other websites not operated or controlled by Stablish Solutions Inc. ("Third-Party Sites"). This Privacy Policy does not govern Third-Party Sites. We suggest reviewing the privacy policies of those sites directly for information on their practices.
We retain your information for a period consistent with the original purpose of collection. For example, we may retain your information while your account is active and for a reasonable period afterward. We may also retain your information as necessary to pursue legitimate business interests, conduct audits, comply with legal obligations, resolve disputes, and enforce agreements.
You may opt out of future communications from us at any time. If your personal data collection was based on consent, you have the right to revoke that consent at any time, which may affect your access to the Services.
You can request to review, correct, delete, or otherwise modify any personal information you have provided to us through the Website or Services. You can access and update certain information via the "Control Center" or "Dashboard" on our Services.
Under Section 1798.83 of the California Civil Code, California residents can request information about personal data shared with third parties for direct marketing purposes during the previous calendar year. To request this information, contact us as described in the "How to Contact Us" section, and we will respond within 30 days as required by law.
To exercise any of these rights, send a request to the email or mailing address in the "How to Contact Us" section. For privacy and security reasons, we may require you to verify your identity before fulfilling the request. Stablish Solutions Inc. may take up to 30 days to fulfill such requests.
You can lodge a complaint with the local data protection authority if you believe we have not complied with applicable data protection laws. A list of local data protection authorities in European countries is available here.
If you have any questions or concerns regarding this Privacy Policy or our data handling practices, please contact us at:
Stablish Solutions Inc.
email: support@stablish.io.
Stablish Solutions Inc. is committed to addressing any concerns regarding the collection or use of your personal information. We take your privacy seriously and are dedicated to limiting access to your personal or account information and safeguarding your data. If you believe that Stablish Solutions Inc. has not adhered to this Privacy Policy with respect to your personal information, please contact us first by emailing us at support@stablish.io.
Please note that Stablish Solutions Inc. is not responsible for the content or privacy practices of websites not operated by us, even if our Website or other Stablish Solutions Inc. services link to them. Additionally, we are not responsible for the privacy practices of our customers or users of our customers' websites. You should review the privacy policies of any customer site before using it.