Legal

Privacy Policy

Last updated: September 8, 2026

This policy describes how Cemstree handles information across its church management, ministry operations, public forms, communications, payment-related workflows, and support surfaces.

1. Scope

This Privacy Policy explains how Mad Tech Solutions LLC, a Michigan limited liability company operating the Cemstree service (“Cemstree,” “we,” “us,” or “our”), collects, uses, stores, discloses, and protects information when people use the Cemstree platform, websites, workspaces, sign-in pages, public ministry pages, communications tools, payment-related workflows, support features, and related services.

Cemstree is primarily a service provider to United States churches, ministries, nonprofits, and similar organizations. Customer organizations decide what information they enter, who may access it, how long they keep it, what communications they send, and what ministry workflows they operate. This policy does not replace a customer’s own privacy policy, consent forms, safeguarding procedures, employment policies, donor policies, or member communications.

2. Policy updates

Cemstree may update this policy as the product, provider stack, legal requirements, security practices, or customer agreements change. The updated policy will be posted here with a new effective date, and continued use after an update means the updated policy applies.

3. Information customers and users provide

Cemstree may process account information such as names, email addresses, authentication identifiers, roles, invitations, organization names, church profiles, workspace settings, staff activity, and support requests.

Churches may enter ministry information such as people and household records, contact details, birth dates, family relationships, group involvement, attendance, serving, volunteer availability, pastoral care notes, check-in records, guardian and child safety details, communication preferences, consent records, public-page content, media metadata, event registrations, giving records, payment references, and other information selected by the church.

Users should not enter unnecessary sensitive information. Churches remain responsible for deciding what information is appropriate to collect and store for their ministry, obtaining required consent, and limiting access to authorized people.

4. Information collected automatically

Cemstree and its hosting, authentication, database, payment, communication, and security providers may collect technical information such as IP address, device and browser information, pages visited, timestamps, session identifiers, authentication events, API calls, error logs, performance data, audit events, and security signals.

Cemstree uses this information to operate, secure, debug, improve, monitor, and support the service.

5. How Cemstree uses information

Cemstree uses information to provide the platform, authenticate users, maintain organization-scoped workspaces, enforce roles and permissions, process customer instructions, support onboarding, operate ministry workflows, generate reports, support public pages, route provider integrations, maintain audit records, detect abuse, troubleshoot issues, respond to support requests, comply with law, and improve the product.

Cemstree does not sell customer ministry data. Cemstree does not use private church records for unrelated advertising.

6. Communications, consent, and messaging data

When churches use SMS, email, push, calling, or campaign tools, Cemstree may process recipient contact information, message content, campaign metadata, consent status, delivery events, replies, opt-outs, bounces, complaints, and provider identifiers.

Churches are responsible for obtaining legally sufficient consent before sending communications, recording consent accurately, honoring opt-outs and unsubscribe requests, avoiding unlawful or deceptive messages, and complying with provider rules and applicable laws. Cemstree may suppress recipients when consent is absent or opted out.

7. Children and guardian information

Cemstree may process children's information when a customer uses check-in, events, households, guardian, safety, or volunteer workflows. Cemstree is not marketed directly to children. A customer organization may authorize a person age 13 through 17 to hold a supervised user account for ministry participation, including volunteering, only when the customer has obtained permission from the person's parent or legal guardian and applies appropriate safeguards and permissions. People under age 13 may not hold a Cemstree login account.

Child-related data should be treated as sensitive. Churches are responsible for staff screening, room procedures, checkout procedures, custody review, incident response, and compliance with local child-protection laws.

8. Pastoral care and sensitive information

Cemstree can store pastoral care notes and ministry records that may be sensitive. Churches should limit these records to appropriate ministry purposes and avoid storing unnecessary medical, counseling, legal, financial, or highly sensitive information unless they have a lawful basis and appropriate safeguards.

Cemstree is not designed as a medical record system, therapy record system, legal case-management system, or emergency response system. If a church is a covered entity or business associate under health privacy law, it must not use Cemstree for protected health information unless a separate written agreement specifically authorizes that use.

9. Payments and giving

Cemstree may process payment-related records such as funds, gifts, donation metadata, receipt references, Stripe account identifiers, checkout session identifiers, refund references, reconciliation events, and recurring donation metadata. Payment card numbers and bank details are handled by the payment provider and are not intended to be stored in Cemstree.

Churches and payment providers remain responsible for donor receipts, tax treatment, refund decisions, chargebacks, payment disputes, payment-provider compliance, and financial reporting.

10. Third-party providers

Cemstree may share information with providers that help operate the service, including hosting, database, authentication, payment, email, SMS, push notification, logging, security, and support providers. These providers process information according to their own terms, privacy practices, and customer agreements.

Cemstree publishes a Subprocessor List identifying providers authorized to process customer personal information on Cemstree’s behalf. Providers that are merely planned and not enabled are identified separately and are not represented as active subprocessors.

11. Support and platform administrator access

Cemstree platform administrators may access a customer workspace when reasonably necessary for support, troubleshooting, security, migration, abuse prevention, legal compliance, product operations, or customer-requested help. Support access should require an access reason, legal or operational basis, acknowledgement, and audit record.

Cemstree aims to limit support access to legitimate business purposes and to avoid unnecessary review of private ministry records.

12. Security

Cemstree uses technical and organizational safeguards intended to protect information, including authentication, role-based access, row-level security, tenant boundaries, secure provider configuration, audit records, and least-privilege design where practical.

No internet service, database, provider, or communication network can be guaranteed perfectly secure. Customers are responsible for strong passwords, account security, staff permissions, device security, prompt offboarding, and reporting suspected unauthorized access.

Suspected security vulnerabilities, unauthorized access, or data exposure should be reported to security@cemstree.com. This address is not represented as continuously monitored outside Cemstree’s staffed business days.

13. Data retention and deletion

Cemstree retains information as needed to provide the service, maintain records, support customer instructions, preserve audit trails, comply with law, resolve disputes, enforce agreements, maintain backups, and operate provider integrations.

Churches may delete or export certain records through available product tools. Some records may remain in backups, logs, audit records, payment records, provider systems, or legally required archives for a limited period.

14. Sharing and disclosure

Cemstree may disclose information to provide the service, follow customer instructions, support users, integrate providers, process payments or messages, comply with law or legal process, investigate abuse, protect safety and security, enforce agreements, complete business transactions, or respond to an emergency.

Public ministry pages may display content that a church chooses to publish. Churches are responsible for ensuring public content is lawful and that they have rights and permission to publish it.

15. Privacy rights and requests

Depending on where a person lives, they may have rights to access, correct, delete, restrict, or receive a copy of certain personal information. Because churches control most ministry records in Cemstree, requests about church-entered records should usually be directed to the applicable church first.

Cemstree may verify identity and authority before responding to a request. Cemstree may decline or limit requests where allowed by law, where the request affects another person's rights, where the record belongs to a customer organization, or where retention is required for legal, security, audit, payment, or operational reasons.

16. International and state-specific considerations

Cemstree is currently offered to United States customer organizations unless a signed written agreement says otherwise. Privacy laws vary by state. Customers are responsible for determining whether their use requires additional notices, consent, data processing terms, or jurisdiction-specific rights.

17. Changes to this policy

Cemstree may update this Privacy Policy as the product, providers, laws, or business operations change. The updated policy will be posted here with a new effective date. Continued use after an update means the updated policy applies.

Customer support: support@cemstree.com. Mad Tech Solutions LLC, 2222 W GRAND RIVER AVE SUITE A OKEMOS, MI 48864. Requests about church-entered records should ordinarily be sent to the applicable church first. Supporting policies: DPA, subprocessors, security, acceptable use, subscriptions, and support.