Operator: Triune Softwares Inc.
1. Who We Are
Stewards is a software platform operated by Triune Softwares Inc. that helps churches and parishes manage their membership, donations, charitable tax receipting, finances, and communications.
Stewards is offered to organizations (each, a “parish” or “tenant”) on a multi-tenant basis. In most cases the parish is the data controller of the personal information it enters about its members, families, and donors, and Triune Softwares is the data processor (service provider) acting on the parish's behalf, plus a limited amount of information we control directly (such as administrator login accounts and operational/security logs).
Members, families, and donors with questions about how their own parish uses their information should also contact that parish directly.
2. Information We Collect
We collect and process the following categories of information. Each corresponds to data the application actually stores.
- Member and family records (entered by the parish): names (including local-language names), date of birth, gender, blood group, marital/family status; contact details (address, phone, email) and emergency-contact information; profession, residential status, country of origin; church roles, membership dates and status; sacramental records (such as baptism and chrismation dates); profile photos and uploaded family documents.
- Board directors, trustees, and like officials: for a parish registered as a Canadian charity, the Canada Revenue Agency (CRA) requires Form T1235 to be filed with the annual return for everyone who served on the board during the fiscal period. We collect the name, position, and term start/end dates the CRA publishes on its charity listing, and — in the CRA's confidential column, which it does not publish — the individual's date of birth, residential address, and phone number. The date of birth and residential address are collected for the sole purpose of filing the parish's annual return, and are shown masked in the application. The phone number is treated differently: it is also ordinary board contact information the parish uses to reach its directors, it predates the T1235 requirement, and it is shown to authorized board-of-directors users without a masked reveal. All three are stored with field-level encryption and are disclosed to the CRA as part of the return. The CRA strongly encourages (but does not require) charities to tell their directors that this information was collected and disclosed.
- Donations, pledges, and tax receipts: donor identity, amounts, dates, fund/category and payment method; charitable tax receipts including the donor name and address, receipt number, fiscal year, and total — retained to meet Canada Revenue Agency (CRA) requirements.
- Bank and financial-account data via Plaid: when a parish connects a bank account through Plaid, Plaid returns an access token, item identifier, institution name/logo, account metadata (account name and last four digits), and transactions and balances. The Plaid access token is encrypted at rest (AES-256-GCM). Plaid Link collects the bank credentials and consent; we never see or store online-banking usernames or passwords.
- Payment data via Stripe: online donation and subscription payments are processed by Stripe. We receive payment-method metadata, customer/subscription identifiers, and the donor email; we do not store full card or bank-account numbers for these payments.
- Account, authentication, and security data: administrator/staff login accounts (email, hashed credentials managed by our identity provider, role assignments, MFA enrolment status); audit logs of security- and finance-relevant actions (acting user, action, affected record, timestamp, request IP); and operational/error logs with personal information automatically redacted.
- Documents and communications: documents uploaded to a parish's document vault or family records, digital signatures captured during onboarding, and communication records, preferences, and unsubscribe status.
- Employment and payroll (only where the parish employs you): the employment record — name, contact details, date of birth, home address, hire and termination dates, employment type and pay frequency, salary or hourly rate, tax-credit claim codes, Social Insurance Number, and the banking details used to deposit pay — together with pay stubs, records of employment, and payroll deductions derived from it. This is used only to run payroll and meet Canada Revenue Agency payroll obligations, and is retained for 6 years from the end of the calendar year in which your employment ended, which is how the CRA measures its six-year books-and-records requirement. It cannot be erased on request before that period ends (see Section 8).
- Governance records: where a member holds or has held office, the register of directors — name, contact details, home address, position, appointment and removal dates, and consent/identification-verification status — and general-body meeting voting eligibility, including any override and the reason recorded for it. The register retains a former director's name permanently; contact details are retained for 6 years from the end of the calendar year in which they ceased to hold office.
- Information collected automatically: essential request metadata needed to operate the service securely (a per-request correlation identifier and IP address for rate-limiting and abuse prevention). Stewards uses only essential, first-party storage required for authentication and security — no third-party advertising or cross-site tracking cookies.
3. Why We Use Your Information
- To provide the Stewards service: membership and family records, donations and pledges, CRA charitable tax receipts, and parish finances and accounting.
- To connect and reconcile bank-account activity (via Plaid) and process online payments (via Stripe), where the parish enables those features.
- To send transactional and parish communications and honour communication preferences and unsubscribe requests.
- To authenticate users, enforce role-based permissions, and secure the service (fraud/abuse prevention, audit logging, incident response).
- To meet legal and regulatory obligations, including CRA record-keeping for charitable donations and tax receipts.
- To maintain, troubleshoot, and improve the reliability and security of the platform.
4. Legal Basis and Consent (PIPEDA)
We process personal information in accordance with PIPEDA. Depending on the situation, our basis is one or more of: consent (members and donors consent through the parish's onboarding and communication-preference flows; the platform records consent, including the policy version accepted, and supports withdrawal at any time); performance of the relationship (processing necessary to deliver the service); and legal obligation (retaining donation and tax-receipt records as required by the CRA).
For commercial electronic messages, we follow Canada's Anti-Spam Legislation (CASL): every commercial email includes a working one-click unsubscribe, and unsubscribe requests are honoured.
5. How We Share Information
We do not sell, rent, or trade personal information. We share it only as needed to operate the service: within the parish (accessible to authorized users of the same parish per their role-based permissions, with tenant isolation preventing cross-parish access), and with carefully selected service providers (sub-processors) that help us deliver hosting, storage, authentication, bank connectivity, payments, email, monitoring, and related infrastructure — each processing information only as needed and under contractual confidentiality and data-protection obligations.
We do not publish a public inventory of those providers. Parishes may request our current sub-processor list by contacting the Privacy Contact below.
We may also disclose information if required by law, regulation, or legal process, or to protect the rights, safety, or security of users, the public, or our service.
6. How We Protect Your Information
We apply layered, industry-standard safeguards (described in full in our Information Security Policy):
- Encryption in transit: all connections use TLS 1.2 or higher, enforced by HTTP Strict Transport Security.
- Encryption at rest: tenant data is stored in an encrypted-at-rest managed database, and especially sensitive fields receive additional field-level AES-256-GCM encryption — including Plaid access tokens, employee bank/identifier fields, the date of birth, residential address, and phone number of board directors collected for CRA Form T1235, and the phone numbers and preparer address given in the confidential section of the CRA T3010 annual return.
- Access control: role-based access control with least-privilege permissions; multi-tenant isolation enforced at the application layer (fail-closed), with database row-level security provisioned as defense-in-depth.
- Strong authentication: multi-factor authentication is required for users, with additional step-up verification for privileged and financial actions.
- Integrity verification: inbound webhooks are cryptographically verified (Plaid via signed ES256 tokens with replay protection; Stripe via signature verification), and file uploads are validated by content signature, not just file extension.
- Logging and monitoring: security- and finance-relevant actions are recorded in an audit log; errors are monitored; and personal information and credentials are automatically redacted from logs.
- Secure development: automated dependency monitoring, code scanning, secret scanning, and dependency-audit checks run in our continuous-integration pipeline.
No method of transmission or storage is perfectly secure, but we work to protect personal information using the measures above and to respond promptly to any incident.
7. How Long We Keep Information
We retain personal information only as long as needed for the purposes above or as required by law (full schedule in our Data Retention and Deletion Policy):
- Charitable donation records and issued tax receipts: retained per CRA requirements — generally seven (7) years from the end of the relevant fiscal year.
- Board director information filed on CRA Form T1235: the CRA requires a charity to keep the books and records supporting a filed annual return — including that worksheet — for six (6) years from the end of the fiscal period the return covers, and for two (2) years after the date registration is revoked if that happens. Inside that period a director's date of birth and residential address cannot be erased on request. Afterwards the parish can destroy its copy of them; the director's name, position and term dates are kept as governance history and are in any case published by the CRA. The director's phone number is also kept — unlike the name, position and term dates it is not published by the CRA. Stewards keeps it as ordinary board contact information under the register-of-directors rule in Section 2. It is removed when a parish administrator clears it, or when an erasure request is processed once that record's retention window has passed.
- Bank-connection data (Plaid): minimized to what the feature needs and deletable when the parish disconnects the account.
- Audit logs: retained for a limited period (a minimum of two years) for security and accountability.
- Application/session and error logs: short retention (on the order of 90 days), with personal information redacted.
- Inactive member records: anonymized after a defined period of inactivity, retaining only fields the CRA requires us to keep.
When information is no longer required, it is securely deleted or anonymized.
8. Your Rights
Subject to applicable law, you have the right to access the personal information we hold about you (Stewards supports a complete, machine-readable data-subject access export); to correct inaccurate or incomplete information; to request deletion or anonymization, except where we are legally required to retain certain records; to withdraw consent, including unsubscribing from communications at any time; and to complain to us or to the Office of the Privacy Commissioner of Canada (OPC).
Records we cannot erase on request include: CRA-mandated donation and receipt records; sacramental registers (permanent under canon law); proof of consent for commercial electronic messages, as required by Canada's Anti-Spam Legislation; payroll records, for 6 years from the end of the calendar year in which employment ended; and the register of directors, as described in Section 2. When you request erasure, the confirmation you receive states exactly which records were retained and under which legal obligation.
Because parishes control their own member data, please direct access, correction, and deletion requests to your parish administrator in the first instance. You may also contact us at admin@triunesoftwares.com and we will assist or route your request appropriately. We respond to verified requests within 30 days, as required by PIPEDA.
9. Cookies and Essential Storage
Stewards uses only essential, first-party cookies and browser storage required to sign you in and keep your session secure. We do not use third-party advertising or cross-site tracking cookies.
10. International Transfers
Stewards is built to keep tenant data in Canada (our database provider's Canadian region). However, some of our service providers (for example hosting, payment, email, and error-monitoring providers) are based in or may process limited data in the United States. Where information is processed outside Canada, it is subject to the laws of the jurisdiction in which it is held, and we require our providers to protect it under contractual data-protection commitments.
11. Children's Information
Stewards is administrative software used by parishes, and parishes may record information about minors who are members or part of a family (for example, sacramental records). Such information is entered and controlled by the parish under its own authority and consent practices. We do not knowingly use children's information for any purpose other than providing the service to the parish.
12. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify parishes. The current version is always available at /privacy.