Back

Privacy Policy

Last updated: March 20, 2026

1. Introduction

Flock ChMS ("Flock", "we", "us", or "our") is a church management platform operated by Gr8QM. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at enterflock.com.

2. Information We Collect

Account Information: When you sign up, we collect your name, email address, and profile photo (if you sign in with Google).

Church Data: Churches using Flock may store member information, attendance records, financial data, event details, and other church-related content.

Usage Data: We automatically collect information about how you interact with the platform, including pages visited, features used, and device information.

Third-Party Integrations: If you connect external services (e.g. YouTube, Google Drive), we store the access tokens necessary to maintain those connections.

3. How We Use Your Information

  • To provide, maintain, and improve the Flock platform
  • To authenticate your identity and manage your account
  • To enable church administrators to manage their church operations
  • To send important service-related notifications
  • To detect, prevent, and address technical issues or abuse

4. Google API Services Usage

Flock integrates with Google APIs to provide enhanced functionality. Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we request access to the following Google OAuth scopes:

  • YouTube Read-Only (https://www.googleapis.com/auth/youtube.readonly): We access this to read your YouTube channel content (e.g., video lists, playlists) to display them within the platform. We do not modify your YouTube content.
  • Google Drive File (https://www.googleapis.com/auth/drive.file): We access this only for the specific files you hand to us: files you pick using Google's own file picker, and files Flock itself creates in your Drive (such as form attachments, which are stored in your Drive rather than ours). We cannot see any other file in your Drive.
  • Gmail Send (https://www.googleapis.com/auth/gmail.send): We request this permission to allow church administrators to send communications (emails) to members directly from the platform on your behalf. We do not read your inbox or manage other emails.

Automatic sermon import. If your church chooses to have Flock watch a folder for new sermons, you share that one folder with a Flock service account address. Flock reads only that folder, using its own credentials rather than access to your Google account, and you can stop it at any time by un-sharing the folder. We do not request the broad Google Drive read permission.

We strictly use this data to provide and improve the aforementioned features within Flock. We do not use this data for serving advertisements, nor do we allow humans to read this data unless required for security purposes, to comply with applicable laws, or with your explicit consent.

Sending email through your own Google account

If your church connects its Gmail account, Flock sends the emails your church chooses to send, from your church's own address. Your church remains responsible for who it emails. Specifically:

  • You must not email anyone who has not consented to hear from you. You are prohibited from using Flock, or a connected Google account, to send sales or marketing communications to any contact who has not agreed to receive them. This applies however the address reached you, including addresses typed in by your staff or imported from another system.
  • Consent is recorded where we can capture it. When someone gives their own email address on one of your public pages, Flock asks them to agree to be contacted by email and stores when they agreed and the exact wording they were shown. Where an address is entered by your staff instead, Flock cannot observe that consent, and you are confirming that you hold it.
  • Every recipient can opt out, and we enforce it. Bulk and campaign email carries a one-click unsubscribe header and a visible unsubscribe link. Unsubscribing is recorded against that person and Flock then excludes them from further bulk email from your church. Neither you nor we can override it.
  • Transactional email is different. A giving receipt, an event ticket, a password reset or an invitation you asked us to send goes to the person who asked for it. These are not marketing and are not subject to the opt-in above, but they are still subject to the unsubscribe rules where they are sent in bulk.

We may suspend a church's email sending, including a connected Google account, if we have reasonable grounds to believe it is being used to send unsolicited mail.

5. Information Submitted Through a Church's Public Pages

Churches using Flock can publish public pages, for example a prayer request page, an event registration form or a giving page. If you submit something through one of those pages, this section explains what happens to it.

The church is responsible for that information, not Flock. The church decides what it collects, who on its team can see it and how long it keeps it. Flock stores and displays it on the church's instruction, as its service provider. If you want your information corrected or deleted, contact the church directly and they can act on it. You are welcome to contact us at the address below and we will help them do so, but the decision is theirs.

What is collected depends on the form, and typically includes:

  • What you type: for example your name and the request, message or details you choose to share.
  • A contact email, where the form offers one: it is optional. On a prayer request it is shown only to the members of that church's team who handle pastoral care, so they can reach you. Flock does not send anything to it, and does not use it for marketing.
  • Technical information: the usual server records that come with any web request, kept briefly for security and abuse prevention.

Some of this is sensitive by its nature. A prayer request can say something about your religious beliefs, your health or your family, so it is treated as confidential pastoral information: it is visible to the church's pastoral team rather than its wider membership, and it is never used to train machine learning models, sold, or shared with advertisers. If a form offers to keep your name private from the wider team, that choice is respected.

It is kept for as long as the church keeps it, and is deleted when the church deletes it or closes its account. Because the church controls that, ask them if you need it removed sooner.

6. Data Sharing

We do not sell your personal information. We may share data only in these cases:

  • With your church: Church administrators can view member data within their church account
  • Service providers: We use Supabase for database and authentication, and Vercel for hosting
  • Legal requirements: If required by law or to protect our rights

7. Data Security

We implement industry-standard security measures including encryption in transit (TLS), encrypted data at rest, row-level security policies, and role-based access controls. However, no method of electronic storage is 100% secure.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide services. Church data is retained for the duration of the church's subscription. You may request deletion of your account and associated data by contacting us.

9. Your Rights

You have the right to:

  • Access and receive a copy of your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Withdraw consent for data processing

10. Cookies

We use essential cookies and local storage for authentication and session management. We do not use third-party advertising or tracking cookies.

11. Changes to This Policy

We may update this policy from time to time. We will notify users of significant changes via email or an in-app notice. Continued use of the platform after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy, contact us at hello@gr8qm.com.

© 2026 Gr8QM. All rights reserved.