Who controls church data
The church or organization that creates a SimpleSteward workspace controls the donor, contribution, vendor, financial, user, and organization data entered into that workspace. GoodForge operates SimpleSteward and processes that information to provide, secure, support, and improve the service.
Information we collect
We collect account and identity details supplied through Google sign-in, tenant membership and role information, church settings, bookkeeping records, donor and vendor contact information, uploaded files, support communications, accepted AI Help questions, billing status, and technical activity such as IP address, device or browser details, request identifiers, and audit events.
SimpleSteward does not store Google passwords. Payment card and bank payment details are collected by Stripe when paid billing is enabled; SimpleSteward stores only provider identifiers and subscription status needed to operate the account.
How we use information
- Provide tenant-scoped bookkeeping, reporting, reconciliation, exports, and collaboration.
- Authenticate users and enforce roles and permissions.
- Deliver invitations and service messages.
- Protect accounts, investigate misuse, restore access, and preserve audit evidence.
- Operate subscriptions, support requests, backups, monitoring, and service reliability.
- Meet legal obligations and enforce our terms.
AI Help
Beacon sends a question and limited recent page-only conversation context to OpenAI to generate an answer. SimpleSteward retains each accepted question for 180 days with the customer, authenticated user, time, screen, and outcome so authorized GoodForge Platform Owners can review failures and improve guidance. SimpleSteward does not retain the generated answer or recent chat context. Question content rejected because it may contain private information is not retained. Users should ask with general examples and must not enter donor, vendor, employee, payroll, bank, tax, credential, or other private record details.
Service providers
SimpleSteward is designed to use Google Cloud for application hosting, databases, files, secrets, logging, and monitoring; Google for identity; OpenAI for Beacon answer generation; Resend for transactional email; and Stripe for subscription checkout and billing management. These providers process information under their own security and privacy terms. We do not sell personal information or church financial data.
Tenant isolation and access
Church-owned records are associated with a tenant identifier. Server-side membership and permission checks are used to restrict access to authorized users. Authorized church administrators control invitations and role assignments. GoodForge support access is limited to documented support and recovery workflows and is audited.
Retention and deletion
We retain active workspace data for the period needed to provide the service. Audit, security, billing, backup, and legal records may be retained longer where needed for accountability, fraud prevention, dispute resolution, or legal obligations. A church administrator may request account closure or data export by contacting us. A final retention schedule will be incorporated into the production service before unrestricted public launch.
Security
We use measures intended to protect information, including encrypted network connections, managed cloud secrets, tenant-scoped authorization, append-only audit records, backups, and operational monitoring. No service can guarantee absolute security. Report a suspected security incident promptly through the contact below.
Your choices
Authorized users may update many account and church details inside SimpleSteward. Contact the church administrator for membership or record corrections. Contact GoodForge for privacy, access, export, deletion, or security questions. Recovery for the Google or email account used to sign in remains that identity provider’s responsibility.
Children and donor records
SimpleSteward is a business service for churches and authorized adult users, not a service directed to children. Churches are responsible for deciding what donor information is appropriate to enter and for complying with laws and internal policies that apply to their records.
Changes
We may update this notice as the service evolves. Material changes will be identified by a new effective date and, when appropriate, communicated to tenant administrators.
Contact
GoodForge
Email: support@goodforge.co
Website: goodforge.co