Privacy Policy

Last updated: July 28, 2026

Next Steps (“Next Steps,” “we,” “us”) provides engagement analytics and follow-up tooling for churches that use Planning Center. This policy explains what we collect, why, and the choices you have. We built this product to help churches care for their people, and we treat the data that makes that possible with the same seriousness.

Who controls the data

Your church is the data controller of the member information in your account. Next Steps is a data processor: we process that information on your behalf and under your instructions to provide the service. We do not sell member data, and we do not use it to train third-party advertising models.

What we collect

  • Account data. Your name, email, church name, role, and authentication identifiers, handled through our auth provider (Clerk).
  • Planning Center data you connect. When you connect Planning Center, we ask for permission to read your people, check-ins, forms, workflows, groups, sign-ups, and team schedules. That is what powers your dashboards and follow-up. You pick which Planning Center account to connect, and you can disconnect at any time.
    We do not ask for your giving data. Giving is a separate permission in Planning Center and we never request it, so we cannot see it. We also only ever read — the one thing we write back is a follow-up card, and only when you tell us to.
  • Google data you connect (optional). If you connect Google, we read only the spreadsheets you point us to, plus enough file information to show you a list to pick from.
  • Messaging data (optional). If you connect Clearstream, we record outbound message metadata and inbound replies/opt-outs to attribute follow-up outcomes. We do not store SMS content beyond what is needed for that audit.
  • Billing data. Subscription status and customer identifiers from our payment processor (Stripe). We never receive or store full card numbers — Stripe handles payment details directly.
  • Usage data. Standard logs (timestamps, request paths, error diagnostics) used to operate, secure, and debug the service.

How we use it

  • To provide the dashboards, follow-up queues, and reports you configure.
  • To write plain-English summaries of your numbers. For those we send the least amount of data we can to our AI provider (Anthropic) to get the answer back. It is not used to train their models.
  • To send transactional and product email you would expect as an account holder.
  • To secure the service, prevent abuse, and meet legal obligations.

How we protect it

  • One church can never see another. Every church’s data is walled off inside the database itself, and that wall is checked on every single request — not just in the app screens.
  • Encryption. Connection tokens are encrypted at rest (AES-256-GCM). Traffic is encrypted in transit (TLS).
  • Access control. Each person on your team has a role (admin or editor) that decides what they can see and do. Group and team leaders can be given a private link to only their own people.
  • Signed integrations. Incoming webhooks are verified by cryptographic signature before we act on them.
  • Our team’s access. Our team can access your account and data to set up, support, troubleshoot, and operate the service — for example during concierge onboarding or when you ask us for help. This access is read-only, purpose-bound, and every access is logged. We never use one church’s individual member data in conversations with another church, and we never use member information for marketing.

Sharing

We share data only with the sub-processors required to run the service — currently our hosting/database provider, authentication provider, payment processor, email provider, and the integrations you choose to connect (Planning Center, Google, Clearstream) and our AI provider for the AI features. We do not sell personal data.

Retention & deletion

We retain your data for as long as your account is active. You can disconnect an integration at any time, and you can request export or deletion of your church’s data by emailing us. When you delete your account we remove or anonymize personal data within a reasonable period, except where we must retain it to meet legal or accounting obligations.

Your choices

  • Disconnect any integration from settings at any time.
  • Request a copy of, or deletion of, your data.
  • Manage who in your church can access the account via roles.

Children

Churches may track check-in data for minors as part of normal ministry operations. That data is provided and controlled by your church. Next Steps is not directed to children and does not knowingly create accounts for them.

Changes

We’ll update this policy as the product evolves and revise the “Last updated” date. Material changes will be communicated to account admins.

Contact

Questions about privacy? Email bradg@nextstepstaken.com.

Privacy Policy · Next Steps