Security & your data
Plain answers about how we protect your church's records and your donors' information — because trust is the whole job.
Last updated: June 25, 2026
We never see your donors' card numbers
Online gifts are processed by Stripe, a certified Level 1 PCI-DSS payment provider. Card details go straight from your donor to Stripe — they never touch our servers, and we never store them. We also never hold your church's money: gifts go directly to your account, and we take $0 of them.
Your data is encrypted
Everything is encrypted in transit (HTTPS/TLS) and at rest (AES-256, through our database provider). Passwords are hashed with bcrypt — we can't see them, and neither could anyone who somehow got the database.
Your data is yours — leave anytime
We will never hold your records hostage. You can request a full export of your data (donors, gifts, and your complete ledger) or ask us to delete it, at any time — just email privacy@vestrybooks.com. (Some financial records may be retained where the law requires it for tax purposes.)
We keep only what we need
We don't collect Social Security numbers, and we don't store your online-banking login. When you connect a bank for reconciliation, it's handled by Stripe and is read-only — we can see transactions to help you match them, but we can never move your money.
Who can see what
Every person gets their own login with a role. Treasurers record money; board members can be given view-only access for oversight; and an unchangeable history records every change to the money — who did what, and when. Posted records can't be quietly edited; corrections are made as visible reversing entries.
Backed up
Your data lives in managed cloud infrastructure with automated backups, so a bad day doesn't mean lost records.
Who we work with (subprocessors)
- Stripe — payments & bank connections (PCI Level 1, SOC 2)
- Neon — database (encrypted, US-hosted)
- Vercel — application hosting
- Resend — sending your statement emails
- Cloudflare — domain & network
If something goes wrong
If a security issue ever affected your data, we would notify you promptly, within the time the law requires. To report a vulnerability or ask a security question, email security@vestrybooks.com.
We're a young product and we're honest about it: we don't yet carry our own SOC 2 certification (we rely on our certified providers above), and we're continuing to add protections like two-factor sign-in. We'd rather tell you plainly where we are than hide behind badges.
Questions? Email hello@vestrybooks.com.