Privacy and your church's data
Last updated 2026-08-27.
What OneFlock collects, and why
OneFlock holds the records a church keeps about the people in it: names, contact details, dates of birth, family relationships, group membership, who serves on which Sunday, children's check-in records, and pastoral notes the church chooses to write. Every one of these is collected because a church already keeps it — on paper, in a spreadsheet, or in somebody's phone — and for no other purpose. OneFlock does not collect anything for advertising, does not build a profile of anyone across churches, and does not sell or share church data with anyone.
Who is responsible for what
Your church decides what is recorded about you, who at the church may see it, and how long it is kept. Under the Privacy Act your church is the entity accountable for those decisions. OneFlock stores and processes the data on the church's instructions, and does not decide what goes in. If you want something corrected or removed, ask your church — they can do it themselves, and they do not need us.
Who can see your record
Nobody at your church sees everything by default. Access is granted role by role and permission by permission: a group leader ordinarily sees their own group, contact details are a separate permission from names, and pastoral and medical notes are restricted to the people the church has deliberately given them to. Reads of restricted records are recorded in the church's audit log. Children's records are stricter still: only administrators and the leaders and members of the group that staffs the children's rooms can see them.
The public roster link
A church can publish a Sunday roster to a link anyone can open without signing in. That page shows the date, the serving roles, and the names of the people serving. It carries no phone numbers, no email addresses, no notes, no birthdays, and no links to anyone's profile, and search engines are asked not to index it. If you do not want your name to appear there, tell your church — they can take you off the published roster.
Where the data lives
Church data is stored in Sydney, Australia, and is encrypted in transit and at rest. Nightly backups are encrypted before they leave the application and are kept in Australia for 30 days, after which they are deleted. Backups are the one place where deleted data can persist for up to 30 days after a church removes it.
Your rights
You can ask your church what it holds about you, ask for it to be corrected, and ask for it to be deleted. A church can export everything it holds, and can permanently delete a person's record. Where a church cannot resolve your concern, you may complain to the Office of the Australian Information Commissioner.
If something goes wrong
If church data is exposed in a way likely to cause serious harm, we notify the church, and the church notifies the people affected and the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme. Our own procedure for assessing and reporting a breach is written down and kept with our operational runbook.
Getting in touch
For anything about your own record, speak to your church — they hold it and can change it. For anything about OneFlock itself, your church administrator has our contact details.