Privacy Policy

Effective July 16, 2026

Vestry keeps the books for churches, which means we hold financial records and donor information on your behalf. This policy explains what we collect, where it lives, and the rules we hold ourselves to. It's written to comply with PIPEDA, Canada's federal privacy law, and to be readable by an actual treasurer. Questions: hello@vestryaccounting.com.

1. Two kinds of information

Account information is what we collect about you directly: your name, email address, and sign-in activity when you create or join a workspace, and your contact details if you write to us or request a demo.

Workspace records are your organization's books: donors and their contact details, gifts, donation receipts, transactions, payroll records, and everything else entered by your team or imported from systems you connect. For these records your church is the data controller — it decides what goes in — and Vestry is the processor, handling the data only to provide the service. Donors with questions about their information should contact their church; we help churches answer.

2. Where your data lives

Your workspace database is hosted in Canada (Vancouver, British Columbia). The application itself is served through infrastructure in the United States, so requests transit US systems while the stored books remain in Canada. Encrypted backups follow the same arrangement.

3. Who processes it for us

We use a small number of subprocessors, each bound by their own data-protection commitments:

  • Supabase — database and authentication (Canada)
  • Vercel — application hosting and delivery (United States)

If you connect an integration — QuickBooks Online (Intuit), Planning Center, a giving platform — data flows between Vestry and that provider only when you authorize the connection and only to perform the imports you initiate. The access tokens for those connections are stored server-side, never exposed to the browser, and are revoked when you disconnect. Each provider's own privacy policy governs their side.

4. What we don't do

We don't sell personal information, we don't use your books or your donors' data for advertising, and we don't train machine learning models on your records. Our cookies are session cookies that keep you signed in — there is no third-party ad tracking on the application.

5. Retention

We keep workspace records for as long as your workspace is active. Charities are required by the CRA to retain donation records and issued receipts for prescribed periods, so Vestry is deliberately conservative about deletion inside active books — voided receipts, for example, are retained and marked rather than erased. If you close your workspace, your data stays exportable for at least ninety days and is then deleted from production systems.

6. Security

Data is encrypted in transit and at rest. Access inside a workspace is role-based; every workspace's records are isolated from every other's at the database layer, and posted accounting records are immutable by design — corrections leave a trail. No system is perfect: if we ever discover a breach affecting your information, we will notify affected workspace administrators and the Privacy Commissioner as PIPEDA requires.

7. Your rights

You can access, correct, or export your account information and your organization's records at any time — most of it directly in the app. For anything else, email us and we'll respond within thirty days. If you're not satisfied with how we've handled a privacy concern, you may complain to the Office of the Privacy Commissioner of Canada.

8. Changes

If this policy changes in a way that matters, we'll notify workspace administrators before the change takes effect and update the date at the top.

9. Contact

Vestry Accounting · hello@vestryaccounting.com