Aller au contenu principal

Privacy notice

This notice explains what Cornerstone Gospel Global Christian Centre does with information you give us through this website. It is written to be read, not to be waved at a regulator.

Last reviewed: 18 September 2026

What this covers

This website. It does not cover the church office, our WhatsApp groups, or anything you tell a pastor in person — those are pastoral relationships rather than website services.

Prayer requests

What you give us
Whatever you write in your prayer request, and — only if you choose to fill them in — your name, email address, telephone number and parish. Every one of those is optional. A request with none of them is genuinely anonymous: there is nothing stored that identifies you.
Why we hold it
So that our prayer team can pray for you, and so that someone can contact you if you have asked us to. That is the whole purpose. It is not used for anything else.
Who can read it
A small number of people who have been given that responsibility deliberately, each with their own account and two-step sign-in. Someone who edits the website, or who looks after the church finances, cannot read prayer requests at all.
Confidential requests
If you ask for your request to be treated confidentially, it is kept out of the ordinary prayer list. Someone in pastoral leadership must take personal responsibility for it before the text can be read at all, and the system records who did so and when. They will involve another person only where that is needed to help you.
A record of who has read it
Every time someone opens a prayer request, the system records that they did. This is unusual, and it is deliberate: with something this sensitive, the harm would come from being read, so reading is what we keep account of.
Contact and follow-up
We contact you only if you asked us to. Ticking that box is the only thing that causes anyone to get in touch.
What we do not do
We do not store your IP address or your device details with your request. We do not send what you write to any other organisation. We do not pass it through any automated analysis, scoring or artificial intelligence system. We do not use it for fundraising, and we do not put it in a newsletter.
Keeping the form usable
To stop the prayer form being flooded, we count recent submissions from the same internet connection — at most 3 an hour and 10 a day. We do this without storing your address: it is converted to a scrambled value that cannot be turned back, that value is held only for the length of the window, and it is never attached to your prayer request.

How long we keep it

Once a request is closed, we keep it for a limited period so that pastoral care has some continuity, and then the request itself and any contact details are erased.

  • Ordinary prayer requests: 24 months after the request is closed.
  • Confidential requests: 6 months after the request is closed.

A request that is still open is never erased automatically. When the period is up, the text of the request and any contact details are removed, and only the dates and the record of pastoral activity remain, so the church can see how many people it prayed for without seeing who or what for.

How it is protected

Access is controlled by the database itself rather than only by the website, so a fault in a page cannot expose requests. Belonging to the prayer team is not by itself enough to read a request — someone has to be given that specific request. Access can be withdrawn, and it stops immediately when it is.

Where it is held

The website runs on Vercel. Prayer requests are stored in a Supabase database used only by this church. Both are third-party providers acting on our instructions.

The region the database is hosted in is confirmed when the church’s own Supabase project is created, and this notice will name it then.

Analytics and cookies

This site sets no advertising cookies and no tracking cookies. Nothing you type into the prayer form is ever sent to an analytics service.

Your rights

You can ask us what we hold about you, ask for it to be corrected, or ask us to erase it. If you gave your name or contact details we can find your request from those. If you sent an anonymous request there is, by design, nothing linking it to you — which means we cannot find it either.

To ask about any of this, please contact the church office.

Still to be confirmed

This notice describes what the website actually does today. Some things still need confirming by the church, and a few need a legal review before launch. They are listed openly here rather than being papered over.

Outstanding

  • Legal review of this notice against UK GDPR and Nigeria’s NDPA, including the lawful basis for holding special category data and whether a Data Protection Impact Assessment is required.
  • The hosting region of the church’s Supabase project, to be named here once that project is created.
  • A named contact route for privacy questions, confirmed by the church.
  • Whether the church wishes to appoint a data protection contact, and who that should be.