Privacy Policy
Last Updated: September 4, 2026
At Graphit, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
1.1 Information You Provide
We collect information you provide directly to us, including:
- Account information (name, email address, password)
- Church or organization details
- Metrics and data you enter into the platform
- Communications with our support team
- Payment and billing information (processed through Stripe)
1.2 Automatically Collected Information
When you use our service, we automatically collect:
- Log data (IP address, browser type, pages visited)
- Device information (operating system, device identifiers)
- Usage data (features used, time spent, interactions)
- Cookies and similar tracking technologies
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process your transactions and send related information
- Send you technical notices, updates, and support messages
- Respond to your comments and questions
- Monitor and analyze trends, usage, and activities
- Detect, prevent, and address technical issues and fraud
- Personalize and improve your experience
3. Information Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
3.1 With Your Consent
We may share your information when you give us explicit permission to do so.
3.2 Service Providers
We share information with third-party service providers who perform services on our behalf, such as:
- Payment processing (Stripe)
- Cloud hosting (AWS)
- Email delivery services
- Analytics providers
3.3 Legal Requirements
We may disclose information if required by law or if we believe such action is necessary to:
- Comply with legal obligations
- Protect and defend our rights or property
- Prevent fraud or security issues
- Protect the personal safety of users or the public
3.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
4. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication measures
- Employee training on data protection
However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to:
- Comply with legal obligations
- Resolve disputes
- Enforce our agreements
You may request deletion of your account and data at any time by contacting us at privacy@graphit.io.
6. Your Rights and Choices
6.1 Access and Update
You can access and update your account information at any time through your account settings.
6.2 Data Portability
You have the right to request a copy of your data in a structured, machine-readable format.
6.3 Deletion
You can request deletion of your account and associated data. Some information may be retained as required by law.
6.4 Opt-Out
You can opt out of marketing emails by clicking the unsubscribe link in any email or by contacting us.
6.5 Cookies
Most browsers allow you to control cookies through their settings. Note that disabling cookies may affect functionality.
7. Children's Privacy
Our service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
9. Third-Party Links
Our service may contain links to third-party websites. We are not responsible for the privacy practices of these websites. We encourage you to read their privacy policies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending you an email notification for material changes
Your continued use of our service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us:
12. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to say no to the sale of personal information
- Right to access your personal information
- Right to request deletion of personal information
- Right to non-discrimination for exercising your rights
To exercise these rights, please contact us at privacy@graphit.io.
13. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
You also have the right to lodge a complaint with a supervisory authority.