Who is responsible for your information
The church organization using Flock is responsible for deciding why and how worker information is used. Flock provides the technology used to record attendance, identify care needs, and support authorized follow-up.
Questions or requests should first be directed to your department head or the church administrator responsible for Flock.
Information we handle
- Worker name, phone number, department, service status, and join date.
- Service attendance recorded as Present or Absent.
- Consecutive absence counts, care alerts, and follow-up notes.
- WhatsApp consent preferences and, when messaging is enabled, delivery history.
- User account details for authorized church leaders and administrators.
- First-timer contact details, consent, visits, assignments, journey stage, and coordinator follow-up outcomes.
- Technical and security records needed to operate and protect the service.
Why we use it
- To replace paper-based workforce attendance records.
- To help authorized leaders understand workforce engagement.
- To notice absence patterns and support timely pastoral care.
- To support agreed workforce check-ins if WhatsApp delivery is enabled.
- To maintain accurate records, prevent misuse, and secure the platform.
- To coordinate consent-based welcome and newcomer follow-up.
Automated care alerts
Flock can automatically recognize consecutive missed services and create department, urgent, or pastoral care alerts. WhatsApp delivery is currently paused and requires separate church approval and setup.
These alerts support human care. They do not make disciplinary or other significant decisions about a worker. Authorized leaders remain responsible for the response.
WhatsApp choice
If automated WhatsApp delivery is enabled in the future, messages will be sent only where the worker has opted in. A phone number may still be retained for legitimate church administration or emergencies even when automated messages are off.
A worker can withdraw consent at any time by contacting their department head or asking the church administrator to update their communication preference.
Who may receive information
Access inside the church is role-based. Department heads see their own department, Church Leaders receive a read-only church-wide view, and Super Admins manage the platform and workforce records. First Timers Coordinators can access newcomer records needed for registration and follow-up, but not unrelated administrative records.
Flock relies on service providers such as Supabase for database and authentication services and Vercel for hosting. If messaging is later enabled, approved messaging providers may process only the information needed to provide those services, potentially in other countries.
Retention and security
Information should be kept only for as long as it supports workforce administration, newcomer care, safeguarding, reporting, or applicable legal obligations. Inactive worker records may be retained to preserve historical attendance, then deleted or anonymized under the church’s retention schedule.
Flock uses authenticated access, database row-level security, role-based permissions, encrypted network connections, and activity records. No online system can guarantee absolute security.
Your choices and rights
Subject to applicable law, workers may ask to access, correct, or delete their information; object to or restrict certain processing; withdraw communication consent; or raise a concern with the church. Some information may need to be retained for legitimate or legal reasons.
Individuals in Nigeria may also have the right to complain to the Nigeria Data Protection Commission.
Questions or concerns?
Contact your department head or the church administrator managing Flock. The deploying church should publish its dedicated privacy contact here before production launch.
