Privacy Policy

Introduction

Your privacy is important to us. Everyone Church is a Christian church and an ACNC-registered charity. We are committed to maintaining an environment and processes that protect the privacy of individuals associated with our church and uphold the trust placed in us.

This Privacy Policy explains how Everyone Church collects, holds, uses, discloses and protects personal information. It is guided by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), other applicable laws, and good governance practices for charities. Where the Privacy Act or APPs apply to Everyone Church, we will comply with those requirements.

More information about Australian privacy law is available from the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au

1. Why we collect your personal information

We provide a range of Christian services and programs including face-to-face and online church services, connect groups, kids' and youth programs, pastoral care, discipleship and leadership training, prayer, community outreach, missions activities and other church programs.

Participation in our programs and activities may require us to collect information from people who want to be involved with our church so that we can communicate effectively, provide requested services, promote safety and wellbeing, administer our ministries, fulfil legal obligations and provide appropriate pastoral support and care.

2. What is personal information?

In general terms, 'personal information' has the meaning given to it in the Privacy Act. It is information or an opinion about an identified individual, or an individual who is reasonably identifiable. It may include your name, address, telephone number, email address, date of birth, profession or occupation.

3. Personal information we collect and hold

The information we collect will vary depending on the nature of your involvement with Everyone Church. We endeavour to request only information that is reasonably necessary for our functions, activities and the services you are seeking to access.

You are not generally required to provide personal or sensitive information that we request. However, if you choose not to provide certain information, it may limit our ability to include you in particular activities or communications, meet safety or legal requirements, or provide appropriate pastoral support.

The information we may collect includes:

  • Personal details such as your name, title, date of birth, marital status and gender.

  • Contact details such as your mailing or street address, email address and telephone number.

  • Family details such as spouse, parent or guardian, and children.

  • Profession, occupation or job title.

  • Details of services, ministries, events or activities in which you participate or about which you enquire.

  • Volunteer, leadership, employment or ministry-related information where relevant.

  • Donation, payment or transaction information, noting that payment card details may be processed by third-party payment providers rather than stored by Everyone Church.

  • Information you provide directly through our website, forms, church management systems, email, social media, correspondence or interactions with our representatives.

  • Information you provide through surveys, registrations, check-in processes, applications, pastoral interactions or prayer requests.

  • Photographs, video or audio recordings created in connection with church services, events or activities.

3.1 Sensitive information

Some personal information is considered sensitive information under privacy law. Because of the nature of a Christian church, Everyone Church may at times need to collect sensitive information that is reasonably necessary for our functions or activities and where consent or another lawful basis applies.

This may include:

  • Religious beliefs, denominational background, spiritual milestones, church involvement or attendance.

  • Prayer requests and information shared for pastoral care.

  • Health or medical information where relevant to pastoral care, participation, safety or an activity.

  • Racial or ethnic origin where relevant and appropriately collected.

  • Criminal history information or Working with Children Check information where required for safeguarding, employment or volunteer screening.

  • Passport, travel or vaccination information where required for missions or other travel.

We take particular care when collecting, using, disclosing and storing sensitive information and seek to limit access to people who reasonably need that information for their role.

3.2 Anonymity and use of a pseudonym

Where it is lawful and practicable, you may choose not to identify yourself or may use a pseudonym when dealing with Everyone Church. In some circumstances we may be unable to provide a service, meet safeguarding or legal obligations, process a registration or provide effective pastoral support without identifying information.

3.3 Photography, video and live streaming

Everyone Church may photograph, film, livestream or otherwise record church services, events and activities for ministry, communication, historical, promotional or social media purposes.

For children participating in our regular church programs, identifiable photographs or video used on Everyone Church social media or promotional channels will only be used where parent or guardian consent has been obtained.

At community outreach events, photography or video may occur where attendees have been clearly notified in advance, including through registration forms, event websites, event information or signage. Where practicable, people who do not wish to be photographed or filmed may advise an event or church team member.

People attending a service or event may also appear incidentally in livestreams, wide shots, crowd photographs or recordings of public areas. We will take reasonable steps to use images respectfully and appropriately.

Security or safety camera footage, where used, is handled separately from promotional photography and is collected for safety, security and related purposes.

4. How is your personal information collected?

Where practicable, personal information is collected directly from you. Personal information may be collected in a number of ways, including:

  • Church Connect Cards, digital forms, Church Center or other church management systems, children's and youth registration forms, check-in procedures and ministry paperwork.

  • Telephone calls, email, text messages and other correspondence.

  • Our website, online forms and social media platforms.

  • Event, conference, course or activity registrations, including registrations processed by third-party service providers.

  • Volunteer, employment, leadership or ministry applications.

  • Surveys, donations, payments and other transactions.

  • Face-to-face conversations with pastors, staff, volunteers or ministry leaders.

  • Photographs, video, audio or livestream recordings.

4.1 Collection of information from third parties

We may collect personal information from third parties where it is lawful and reasonable to do so. This may include information from parents or guardians, referees, screening or verification providers, government agencies, law enforcement agencies or other organisations.

For example, this may occur when a parent registers a child or their child's friend for an activity, when we verify a Working with Children Check, or during recruitment or volunteer screening.

4.2 Unsolicited personal or sensitive information

At times we may receive personal or sensitive information that we did not request. Where the information is not reasonably necessary for our functions or activities and we are not required to retain it by law, we will take reasonable steps to securely destroy or de-identify it.

4.3 Cookies and website information

Access to our public website is generally anonymous except where you log in, submit a form, register for an activity or otherwise provide personal information.

Our website and related digital services may use cookies or similar technologies to provide functionality and analytical information about website use. Information may include the date and time of your visit, IP address, device or browser information and pages or resources accessed.

Our website may contain links to third-party websites. This Privacy Policy does not apply to those external websites and we encourage you to review their privacy policies.

4.4 Government-related identifiers

Everyone Church may collect or record government-related identifiers where this is reasonably necessary and lawful, such as Working with Children Check details or passport information required for travel. We do not use government-related identifiers as our own identifier of an individual unless permitted by law.

5. Security and holding of your information

We take reasonable steps to protect the personal and sensitive information we hold from misuse, interference, loss, unauthorised access, modification or disclosure.

Depending on the type of information, safeguards may include password protection, account access controls, secure cloud services, physical security, limiting access to authorised staff or volunteers and using reputable third-party providers.

Everyone Church uses third-party technology and service providers to support church administration and ministry. These may include church management systems, online forms, website hosting, email and text-message services, event registration, payment processing, accounting systems, cloud storage and other digital tools. We take reasonable steps to select and use providers in a way that is consistent with our legal obligations and reasonable community expectations.

Personal information may be stored in Australia or overseas depending on the systems and service providers we use. Where overseas disclosure or storage is relevant, we take reasonable steps appropriate to the circumstances to protect personal information.

We take reasonable steps to ensure information we hold is accurate, complete, relevant and up to date. We also review whether information remains necessary to retain and will securely destroy or de-identify personal information when there is no longer a legal, ministry, safeguarding, administrative or other legitimate need to retain it.

Pastoral records and notes will be handled with particular care. Personal opinions should not be represented as facts, and access should be limited to authorised persons who reasonably need the information.

6. How we use your information

We generally use personal information for the primary purpose for which it was collected, or for another purpose where you have consented, would reasonably expect the use, or the use is otherwise permitted or required by law.

In most cases, our purposes relate to the spiritual, pastoral, social, educational, charitable and administrative functions of Everyone Church. These include:

  • Providing church services, ministries, programs, pastoral care and community activities.

  • Communicating with you about services, ministries, events, courses or activities.

  • Responding to enquiries and providing information or advice.

  • Maintaining and updating church, volunteer, attendee and contact records.

  • Providing pastoral support, prayer and follow-up.

  • Administering children's and youth programs, including safety and check-in processes.

  • Coordinating volunteers, leaders, staff and ministry teams.

  • Processing registrations, donations, payments, reimbursements or travel documentation.

  • Meeting safeguarding, governance, insurance, financial, employment, charity and legal obligations.

  • Improving our ministries, communications and services.

6.1 Direct communication and marketing

At times we may use your personal information to communicate with you about church events, courses, ministries, appeals or other matters that we reasonably believe may be relevant to your involvement with Everyone Church.

These communications may be by email, text message, telephone, mail or digital platform. Where required, we will provide a practical way to opt out of direct marketing communications. Operational communications that are reasonably necessary for an event, ministry, team or service in which you have chosen to participate may still be sent.

6.2 Automated decision-making

Everyone Church does not currently arrange for computer programs to use personal information to make decisions that could reasonably be expected to significantly affect an individual's rights or interests. If our practices change in this area, we will review and update this Privacy Policy as required.

7. Disclosure of your information

At times Everyone Church may need to disclose personal or sensitive information in order to provide pastoral services, administer ministries and programs, use service providers, meet safeguarding obligations or comply with the law.

Disclosure may include:

  • Providing relevant information to authorised pastors, staff, volunteers or ministry leaders where reasonably necessary for pastoral care, ministry administration, safety or support.

  • Providing information to service providers that support our church operations, such as technology, payment, registration, accounting, communications, storage or professional service providers.

  • Providing information to government agencies, law enforcement, courts or other bodies where required or authorised by law.

  • Providing information to insurers, legal advisers, accountants or other professional advisers where reasonably necessary.

  • Providing information to missions, travel or government partners where reasonably necessary for a trip and with appropriate notice or consent.

  • Disclosing information in an emergency or serious safety situation where permitted by law.

When personal information is shared internally, access should be limited to what is reasonably necessary for the person's role or the purpose for which the information is being used.

Care will be taken when sending group emails or messages so that recipients' contact details are not unnecessarily disclosed. For example, BCC or suitable group communication tools should be used where appropriate.

We do not sell or rent lists of identifiable personal information to other organisations for their direct marketing.

7.1 Public prayer

Prayer requests can contain sensitive personal information. Everyone Church seeks to protect the privacy and dignity of people while enabling prayer and pastoral support.

A person's name or identifying details should only be used in public prayer, public prayer communications or a prayer group where appropriate consent has been obtained from the person who is the subject of the request, unless there is another lawful and compelling reason to disclose the information.

People submitting prayer requests about another person should be mindful of that person's privacy and should avoid sharing unnecessary sensitive details.

7.2 Cross-border disclosure of personal information

Everyone Church may communicate with missions partners, travel providers and service providers located outside Australia. Personal information may also be processed or stored overseas by technology providers used by the church.

For missions or other travel, information such as passport details, medical information or vaccination information may be provided to relevant missions partners, airlines, travel providers, government agencies or visa authorities where reasonably necessary and with appropriate notice or consent.

Where personal information is disclosed overseas, Everyone Church will take reasonable steps appropriate to the circumstances to ensure that the information is handled consistently with applicable privacy requirements.

7.3 Safeguards

  • Personal information will not be shared, sold, rented or disclosed except as described in this Privacy Policy, with consent, or where otherwise authorised or required by law.

  • We do not provide personal information to other organisations for their direct marketing unless the individual has consented or the disclosure is otherwise permitted by law.

  • Staff, pastors, leaders and volunteers who have access to personal information are expected to respect confidentiality and comply with relevant church policies and procedures.

7.4 Pastoral confidentiality and legal or safety disclosures

Pastoral confidentiality is important to Everyone Church. However, confidentiality is not absolute and information may need to be disclosed where required or authorised by law or where necessary to respond to serious safety concerns.

This may include circumstances involving:

  • Mandatory reporting or child protection obligations.

  • A subpoena, court order or other lawful requirement.

  • Suspected abuse or neglect.

  • A serious threat to a person's life, health or safety, or to public safety.

  • Serious threats of violence or harm to another person.

Where practicable and appropriate, a pastor should consult with a supervisor, senior pastor, professional adviser or legal adviser before disclosing confidential information. Only information reasonably necessary for the relevant purpose should be disclosed.

7.5 Data breaches

A data breach may occur where personal information is lost or is subject to unauthorised access or disclosure. Examples include a compromised account, lost device, cyber incident or information being sent to the wrong recipient.

Everyone Church will take reasonable steps to contain and assess suspected data breaches, reduce the risk of harm and improve systems or practices where appropriate. Where the Notifiable Data Breaches scheme or another legal notification requirement applies, we will notify affected individuals and the OAIC or other relevant authority as required.

8. Access to personal information

You may request access to personal information that Everyone Church holds about you, subject to any exceptions permitted by law.

There may be circumstances where access cannot be provided in full, for example where granting access would have an unreasonable impact on another person's privacy or where another legal exception applies.

For security reasons, we may ask you to make your request in writing and provide enough information to verify your identity and locate the relevant records. 

This may include:

  • Your full name.

  • Your address or other identifying details.

  • A contact telephone number or email address.

  • The relevant ministry, department, service or approximate date range to which your request relates.

8.1 Correction of information

If you believe personal information we hold about you is incorrect, incomplete, out of date, irrelevant or misleading, you may request that we correct it. We will consider the request and take reasonable steps as required in the circumstances.

9. Questions and complaints

If you have questions about this Privacy Policy, wish to request access or correction, or wish to make a complaint about how Everyone Church has handled personal information, please contact our Privacy Officer:

Privacy Officer, Everyone Church
Email: info@everyonechurch.com.au

We will consider privacy enquiries and complaints carefully and respond within a reasonable period. We may seek further information where necessary to properly understand and address your concern.

If the Privacy Act applies to the matter and you are not satisfied with how we have handled a privacy complaint, you may also be able to contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au

10. Policy review

This policy will be reviewed at least every five years, and earlier where reasonably required because of legislative, regulatory, technology, ministry or organisational changes.

Everyone Church will take reasonable steps to ensure that staff, pastors, leaders and volunteers who handle personal information understand their responsibilities and receive appropriate guidance or training.

This policy should be read together with other Everyone Church policies and procedures relating to safeguarding, child safety, information security, pastoral care, records management and governance where applicable.

Last reviewed: September 2026