Privacy Policy

Last updated July 10, 2026

This policy explains how Sunday Slip, a service of Roscommon Group LLC ("we", "us"), handles information. We designed the product to collect as little as possible, especially from the people who scan a bulletin. It applies to our website and service, and should be read with our Terms, Data Processing Addendum, and sub-processor list.

Our role

For account and billing information about church staff, we act as a controller. For the content a church publishes in its bulletins (including any personal data the church chooses to include), the church is the controller and we are a processor acting on its instructions.

Two kinds of people

Church staff sign in and manage bulletins. Congregants and guests scan a QR code or open a link to read a bulletin. Their footprints are very different.

Guests who scan a bulletin

Public bulletin pages are view-only. We set no cookies on them, run no analytics, load no third-party trackers, and collect no personal information from people who read a bulletin. We keep a simple per-day view counter per bulletin that is not tied to any individual. Bulletin pages are set to discourage search-engine indexing, but anyone with the link can reach them.

Church staff

When staff sign in with Google we receive their email address and a user ID from Supabase Auth. We store the bulletin content they create, their church profile, a record of publish attestations, and (if they upgrade) a Stripe customer ID. We use strictly necessary cookies to keep them signed in and remember dashboard preferences.

How we use information & legal bases

We use information to provide, secure, and improve the service, to process payments, to communicate about the service, and to comply with law. Where the GDPR or similar laws apply, our legal bases are: performance of a contract (operating your account); legitimate interests (securing and improving the service); consent (where required); and legal obligation. The church is responsible for the legal basis for any personal data it includes in a bulletin.

Cookies

We use two kinds of first-party cookies and no others: a strictly necessary authentication/session cookie that keeps church staff signed in, and functional preference cookies (display currency and the active church) that are only set after you sign in. We honor the Global Privacy Control (Sec-GPC) signal for the preference cookies, and we set no cookies at all on public bulletin pages. We do not use advertising or analytics cookies.

AI features

AI drafting and photo import are optional and powered by Google Cloud Vertex AI (Gemini). When you use them, only the text or photo you submit for that feature is sent to be processed and returned to you. Vertex AI does not use this input to train Google's models. Photos submitted for import are processed to produce a draft and are not stored by Sunday Slip.

Payments & giving

Subscription billing runs through Stripe. Card details go directly to Stripe; we never see or store them. Optional online giving is simply an outbound link to a church's own giving page; we do not process those gifts.

Sub-processors

We use a small number of trusted providers (Supabase, Vercel, Stripe, Google Cloud, Cloudflare) to run the service. Each is listed, with its purpose and location, on our sub-processors page.

International transfers

Some of our providers are based in or operate from the United States, so your data may be processed outside your country. Where required, transfers rely on appropriate safeguards such as the Standard Contractual Clauses.

Data retention & deletion

Bulletin content lives until you delete it or close your account. Deleting a bulletin or a church removes it along with its sections, items, view counts, and uploaded images. We retain records of terms acceptance, publish attestations (including the accepting user's email address), and minimal billing records after deletion, only as long as needed to establish, exercise, or defend legal claims and to meet legal and accounting obligations. To delete your account and data, delete your church in Settings or contact us; we action verified deletion requests within 30 days.

Content you publish about others

Bulletins are public pages, and our Terms do not allow personally identifiable information about any person, living or deceased, in them (other than church staff or clergy named in their official role) — keep prayer requests and similar entries general and anonymous. If a church nonetheless publishes personal information about someone, the church is the controller of that content and is responsible for having permission to publish it and for removing it on request. See our Data Processing Addendum.

Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, LGPD, and similar) you may have rights to access, correct, delete, or port your data, to object to or restrict certain processing, and to withdraw consent. To exercise them, contact us. If a request concerns personal data inside a church's bulletin, we may direct it to that church as the controller, and assist them.

Security

We apply appropriate technical and organizational measures, including encryption in transit, row-level security that isolates each church's data, least-privilege access, and no public exposure of secret keys. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

Children

The service is intended for church staff and is not directed to children. We do not knowingly collect personal information from children through staff accounts. Where a church chooses to include a child's name in a bulletin, the church is responsible for any required consent.

Disputes

This policy is incorporated into our Terms of Service. Any dispute relating to it is subject to the Terms, including the arbitration agreement and class action waiver in Section 18, except where applicable law provides otherwise.

Changes

We may update this policy. We will change the date above and, for material changes, take reasonable steps to notify you.

Contact

Questions or requests about this policy: Roscommon Group LLC, Bellevue, Washington, USA, at matt@roscommon-group.com.