Privacy Policy.
Symphonia keeps some of the most sensitive records a community has. This is a plain account of how we handle them, written for a parish rather than a boardroom.
Overview
Symphonia is the parish operating system operated by Ancient Designs LLC (in this policy, "we", "us", or "Symphonia"). This policy explains what personal information we handle, why, and the choices you have. It covers both the people who use our marketing site and sign up for Symphonia, and the parishioners whose records a parish keeps inside Symphonia.
1. Who is responsible for your data
There are two relationships to keep clear, because they carry different legal duties.
Parishioner records inside Symphonia. When a parish enters its members, households, giving history and sacramental records, the parish is the data controller: it decides what is collected and why. Symphonia acts as the data processor, handling that information strictly on the parish's instructions. The full terms of that relationship are set out in our Data Processing Agreement.
Your own account and our website. When you visit symphonia.church, request a demo, or administer a Symphonia account, we are the controller of that information and this policy governs it directly.
2. What we collect
From parishes and their parishioners
On a parish's behalf, Symphonia stores the records the parish chooses to keep, which can include:
- Identity: name, saint name, baptismal name.
- Contact details: email, phone, and mailing address.
- Household structure and family relationships.
- Sacramental records (a special category of data under privacy law, as it reflects religious life).
- Giving and pledge history.
- Pastoral notes, which are sealed to the clergy and encrypted at rest.
- Communication history and delivery state.
- Sign-in credentials (stored only as password hashes and second-factor tokens, never as readable passwords).
From visitors and prospective parishes
- What you send us: your name, email, parish, role, and anything you write when you request a demo or contact us.
- Basic usage data needed to run the site securely: IP address, browser type, and pages viewed, kept for a short window.
3. How we use information
We use information only to run Symphonia and support the parishes on it:
- To provide the service a parish has signed up for, and to keep its records available and accurate.
- To send transactional messages a parish has configured (statements, reminders, announcements) on its behalf.
- To answer your questions and follow up on a demo request.
- To keep the service secure: detecting abuse, preventing fraud, and maintaining an audit trail.
- To meet legal, tax, and accounting obligations.
- To improve reliability and performance, using aggregated, non-identifying signals.
4. What we never do
- We never sell personal information, to anyone, for any purpose.
- We never rent your parish list or share it for another party's marketing.
- We never place third-party advertising trackers inside the parish product.
- We never use parish records to train machine-learning or AI models.
- We never read pastoral notes: confession queues and the sealed pastoral record are encrypted so that not even our own staff can open them.
5. Giving and payments
Online giving is processed by Stripe, and gifts settle directly to the parish's own account. Symphonia never receives or stores full card numbers or bank credentials: those are handled inside Stripe's PCI-compliant systems. We keep the giving record (amount, date, fund, and donor, as the parish requires for statements and tax receipts), but not the payment instrument itself. Stripe's own handling of payment data is governed by its privacy policy.
8. How long we keep information
A parish's records are kept for as long as the parish uses Symphonia. When a parish leaves, we return or delete its data within thirty days, at the parish's choice, except where a specific record must be retained by law.
Two categories are treated with care by design: sacramental records, which are a canonical history the parish is responsible for keeping, and giving records, which carry tax-retention obligations. Deletion flows explain both to the person at the moment they act. Website and demo enquiries are kept only as long as needed to follow up, and then removed.
9. How we protect it
Every parish lives in its own isolated database, never commingled in a shared table. Sensitive fields are encrypted at rest with managed keys, pastoral notes are sealed so only the clergy can read them, all traffic is encrypted in transit, and every sensitive action is written to a tamper-evident audit log. Backups are encrypted and kept off-site. The full picture is on our security page.
10. Your rights and choices
Depending on where you live, you have rights to access, correct, export, restrict, object to, or delete your personal information. Symphonia is built so parishioners can exercise most of these themselves, from inside the member app:
- Access and export a full copy of your record (in a portable format).
- Correct your own contact details and family information.
- Set your communication preferences, per channel.
- Request deletion of your record, subject to the sacramental and tax carveouts above.
Because a parish is the controller of parishioner data, a request made directly to us is passed to the parish without delay rather than acted on unilaterally. For your own account or a website enquiry, simply write to us and we will help. We do not charge for rights requests and we do not retaliate for making one.
11. Children
Symphonia is not directed at children and we do not knowingly collect information from children through our website. A parish may keep records for the young people in its community (for example a baptism record or a church-school roster) as part of its own pastoral responsibility; that information is handled under the parish's instruction and is never used for marketing.
12. Where your data lives
Parish data is primarily processed on servers in the European Union. Where a provider processes data in the United States (for example payment or transactional email), those transfers are made under Standard Contractual Clauses or the EU-US Data Privacy Framework, with the safeguards recorded in our Data Processing Agreement. Ancient Designs LLC is a company organised in the United States.
13. Changes to this policy
When we make a material change, we update the date at the top of this page and, for anything significant, we notify parish administrators directly. Continuing to use Symphonia after a change means the updated policy applies. Older versions are available on request.
14. Contact us
Privacy questions from a parish are answered within one business day. The quickest way to reach a real person is to write to us here. For formal notices, the responsible legal entity is Ancient Designs LLC, the operator of Symphonia.
This policy is written to be read, not to be survived. If a passage is unclear, tell us and we will make it plainer.