Skip to content

Privacy policy

How ProWeave processes personal data for proweave.app and ProWeave hosted products.

Last updated: 19 September 2026

Introduction

This privacy policy describes how ProWeave ("we", "us") processes personal data when you use proweave.app, hosted applications such as ProWeave Hub, and related services (together, the "Services").

Effective date: 30 August 2026. Read this policy together with our Terms of service.

1. Data controller and contact

The controller responsible for personal data we process as a controller is ProWeave, KvK 71817042, VAT NL025074519B01.

Registered address: Varenstraat 19, 2681 GN Monster, The Netherlands.

Contact (privacy, general and product enquiries): [email protected] or our contact page.

Data Protection Officer: We do not currently appoint a Data Protection Officer under Article 37 GDPR. For data-protection questions, use [email protected].

2. When we are controller and when we are processor

We act as controller, among other things, for: visitors to our marketing sites; messages you send via contact forms; account and billing data for our customer relationship; our own security, abuse prevention, and service analytics consistent with this policy; and transactional emails we send as part of operating the Services.

We act as processor on behalf of subscribing organisations for much of the content in organisation workspaces (for example roster, scheduling, and volunteer communications entered by the organisation). The organisation is typically the controller for that data; we process it on its instructions via use of the product and, where applicable, a Data Processing Agreement (Article 28 GDPR) available on request at [email protected]. Individuals should contact their organisation first for access or deletion of workspace data where appropriate; we assist organisations as required by law.

3. Personal data we process

Depending on your role, we may process:

  • Account and authentication: email address, name, profile fields from your identity provider where used, session and security-related data.
  • Organisation / roster data: names, contact details, notes, assignments, availability, identifiers your organisation configures, and similar planning data.
  • Files: attachments and profile images (avatars) uploaded to the service.
  • Billing: billing contact details and payment-related metadata. Card payments are handled by Stripe; we do not store full card numbers.
  • Presenter licence activation: account and entitlement identifiers, a random installation identifier, product version, activation and last successful licence-check times, and the signed offline licence issued to that installation. We do not use a network MAC address as the installation identifier.
  • Email and messaging: addresses and content needed to send operational or organisation-triggered messages, such as roster summaries or invitations; organisation email-policy settings and evidence references; invitation acceptance, delivery-attempt records, and organisation-specific unsubscribe preferences.
  • Optional calendar integration: if enabled, OAuth tokens and calendar metadata needed to connect Google Calendar or similar providers.
  • Optional Canva integration: if enabled, encrypted OAuth tokens and transient authorization state, Canva user/team and display-name metadata, presentation metadata, and user-requested PDF or MP4 export jobs. Presenter saves exports in the local collection. Imports requested in Hub are stored as private organisation media and follow the media retention choices below.
  • Optional periodic Presenter diagnostics: when you enable this setting, Presenter sends limited operational information: app version, platform, architecture, distribution channel, interface language, time running while opted in, startup/recovery indicators, selected feature categories, and temporary random report and session identifiers. At most one report is successfully sent per 24 hours. Reports contain no account or organisation identifiers, names, contact details, presentation content, audio, file paths or free-text logs. They are not linked to website visits or customer accounts.
  • Technical and security: IP address, browser and device information, logs, audit records, diagnostics, and abuse-prevention data.
  • Realtime presence (when in use): display name, avatar reference, and session-related metadata to show who is active in the product.
  • Website contact form: name, email, message text, and similar fields you submit. Forms are submitted securely to our backend for delivery by email.
  • Website and product usage analytics (with consent): when you accept analytics cookies on our marketing sites, we record pseudonymous events such as page views, button clicks, demo plays, download attempts, homepage experiment version, and a choice from the fixed Pastor, Worship leader, Planner, Tech team, or Volunteer role buttons. The role choice adapts product information and is not linked to an account or accepted as free text. For installable web apps we may also record fixed product, offer/action/result, and browser-method values; QR contents, setup codes, session identifiers, and participant names are never included in those events. We store a salted daily hash derived from your IP address and browser user agent; we do not store the raw IP address in this analytics table. We use a country routing header where available. If it is unavailable, our server may send the request IP to IPinfo solely to resolve a two-letter country code; we store only that country result. We also store browser locale and time zone, page path, event name, and referring hostname without its path, query, or fragment. These coarse signals are not treated as precise location. We do not use cross-site tracking or sell this data.
  • Optional Presenter online backup: automatic backup starts off. After you review the size and confirm, selected decks, portable Presenter preferences, library content and linked media can be uploaded as private backups scoped to your account and organisation. Backup metadata includes a random computer identifier, computer label, timestamps, sizes and file checksums. Credentials, sign-in tokens and device-pairing state are excluded.

Special categories: Where organisations use the Services in a religious context, some roster or notes data may reveal religious belief or other special categories under GDPR Article 9. The organisation is responsible for establishing a lawful basis; we process such data only as needed to provide the Services under the organisation's instructions.

4. Purposes and legal bases (GDPR Article 6)

We process personal data for the purposes below, on the following legal bases:

  • Providing and operating the Services — performance of a contract with you or your organisation, or steps prior to entering a contract; including hosting, authentication, delivering features you request, and customer support.
  • Security, integrity, and abuse prevention — legitimate interests in keeping the Services secure and reliable, balanced against your rights.
  • Billing and accounting — performance of a contract and legal obligations (for example tax and invoicing rules).
  • Responding to enquiries — legitimate interests and, where relevant, steps prior to a contract.
  • Compliance with law — legal obligation, including lawful requests from public authorities subject to appropriate review.
  • Optional analytics storage — on proweave.app we record first-party marketing analytics events only when you enable Analytics in our cookie settings. Processing is based on consent (Article 6(1)(a) GDPR). You can withdraw consent at any time through Cookie settings in the footer; events are not collected or replayed after rejection.
  • Optional periodic Presenter diagnostics — with your consent, to assess release quality, platform and language support, and feature use. The setting starts disabled and is separate from website analytics or written feedback. You can withdraw consent in Presenter under Settings → Privacy & Permissions. This stops collection and pending reports; reports already received cannot be recalled through the switch.

Where Article 9 GDPR applies to special categories, organisations using the Services must ensure an appropriate Article 9 basis; we process only as necessary to deliver the product they configure.

4a. Organisation emails and invitations

Before sending organisation emails through Hub, an owner or administrator records the organisation’s legal basis, the source of contact details or existing relationship, an evidence reference, and the organisation’s privacy notice and contact. The organisation must also assess any applicable Article 9 condition for data that reveals religious beliefs. These settings record its assessment; they do not establish a lawful basis or prove the recipient’s consent. The organisation remains responsible for its processing and applicable email rules.

The first invitation and subsequent organisation emails identify the sending organisation and include the source or relationship it has recorded, the stated processing basis, its privacy notice, its privacy contact and an unsubscribe link. This information is included outside editable email templates. The organisation’s own notice must describe its actual processing; this ProWeave policy does not replace that notice.

You can stop invitations, reminders, roster summaries, availability requests and other Hub notifications from an organisation without an account. Open the unsubscribe link and confirm; opening or scanning the link alone does not change your preference. Unsubscribe controls supported by your email application can also submit the request. The preference applies to your email address within that organisation, including duplicate directory or guest records. Editing a profile, resending an invitation or accepting organisation access does not turn these emails back on.

Unsubscribing does not delete your profile, decline an assignment or close an account. Login or recovery emails you request remain available; billing and security messages have separate purposes. Receiving an invitation to join an organisation does not itself grant new membership or access to its data: you must accept it, including when you already have a ProWeave account.

5. Subprocessors

We use service providers who process data on our instructions. The following are key categories (specific vendors may change; we will update this policy or provide notice as appropriate):

ProviderRoleNotes
SupabaseAuthentication, database, file storage, realtime channels, Edge Functions, and consent-gated website analytics eventsHosts application data for our production environment in the London (United Kingdom) region. We use Supabase's data-processing terms and applicable transfer safeguards where relevant.
IPinfoCountry-level IP geolocation for consent-gated website analyticsReceives a request IP only when our hosting path does not provide a country header. We request and retain only the resulting country code in our analytics data. See ipinfo.io/privacy-policy.
StripePayments and customer billing portalProcesses payment data under Stripe's terms — see stripe.com/privacy.
ResendTransactional email and contact-form deliveryWe use resend.com to send email on our behalf; Resend processes message metadata and content as needed to deliver mail. See Resend's privacy policy.
GoogleOptional Calendar OAuth and YouTube embedded mediaCalendar data is processed only if an organisation or user enables the integration. YouTube connects only after a visitor enables External media or opens YouTube directly; Google may act as an independent controller for that visit.
CanvaOptional presentation importCanva account identifiers, design metadata, requested exports, and OAuth credentials are processed only when a user connects Canva. Credentials remain encrypted in our backend; disconnecting or deleting the ProWeave account removes them. Presenter copies remain in the local collection. Hub imports are stored as private organisation media until their retention period ends or they are deleted.

5a. Google Calendar data, sharing and local AI

Connecting Google Calendar is optional. Hub uses Google account identity and email to identify the connected account, calendar names, identifiers, time zones and access roles to let you choose a calendar, and event data to preview and import the events you select. Event data can include titles, descriptions, dates, times and identifiers. Imported Hub events retain the title, dates, times and Google identifiers needed for planning and synchronisation.

Import only reads the selected calendar. If you choose Import + sync, Hub also creates and updates events in your selected writable Google calendar and deletes linked Google events when the corresponding Hub event is unpublished or removed. Hub controls the titles and times it publishes; this is not automatic merging of edits made in Google. Switching the sync calendar can remove linked events from the old calendar and recreate eligible events in the new one.

We share, transfer or disclose Google user data only as needed for the calendar and planning features you enable, with the following recipients:

  • Supabase: processes Google OAuth credentials, connected-account and calendar settings, imported event records and sync jobs on our behalf through its hosted database and Edge Functions. Google credentials are kept in backend storage and are not exposed to other Hub users.
  • Google: receives authorisation and token requests and, when sync is enabled, event titles, dates, times and technical identifiers needed to create, update or delete events. People who can access the destination calendar may see those events according to its Google sharing settings, including public visibility if you chose a public calendar.
  • Your organisation and the people you share with: imported events become organisation planning records. Authorised organisers, invited participants and members can see the relevant event information according to Hub permissions and the invitations or publications your organisation enables. Exports and connected Presenter workflows can also copy event information to devices or recipients your organisation chooses.
  • Resend and email recipients: when your organisation sends invitations, reminders or other operational emails about an imported event, the event information included in those messages, such as its title and time, is processed by Resend for delivery and disclosed to the intended recipients. Google OAuth credentials are not included.
  • Support, security and legal disclosures: access by ProWeave staff or service providers is limited to what is needed for the service. Human access to Google data is permitted only with your explicit agreement for the specific data, for necessary security investigations, or to comply with applicable law. Any disclosure to authorities is limited to applicable legal requirements.

Google data is not sold, shared with advertising platforms or data brokers, used for personalised advertising, or supplied to AI providers for training or secondary purposes. We do not use raw, aggregated, anonymised or derived Google user data to create, train or improve general-purpose AI or machine-learning models.

Local/offline models: ProWeave’s optional speech and music assistance runs local inference on the user’s device. Local models are AI, but they do not send their input to the model provider. The Hub Google Calendar integration does not use AI or send Google Calendar data to these models or to third-party AI services. Calendar connection and sync themselves use our hosted backend; they are not an offline-only service.

Limited Use: ProWeave’s use and transfer of information received from Google APIs, including raw and derived Google Workspace data, will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.

Retention and removal: we retain the connection credentials and settings while the organisation keeps Google Calendar connected. Disconnect in Hub Settings → Integrations → Google Calendar to remove the stored connection, credentials and pending sync jobs and stop future access through that connection; we also request revocation from Google. You can independently revoke access in your Google Account connections settings. Disconnecting does not erase events already imported into Hub or events already written to Google. Remove Hub copies through the event controls or request deletion through your organisation or [email protected]; remove remaining Google copies in Google Calendar. Related audit and delivery records follow the retention periods in section 7.

6. Cookies and local storage

Our settings cover cookies and similar technologies such as localStorage, sessionStorage, web beacons, and embedded third-party content. Optional categories are disabled by default.

Required storage is always active and is limited to operating features you request: storing your consent record, session security, payment checkout, and short-lived release or issue-list caches. The consent record is stored in localStorage and is renewed after approximately twelve months.

Preferences is optional. If enabled, localStorage may remember your selected language and, only if you enter it, your optional download email preference. Disabling Preferences removes those stored values.

Analytics is optional. If enabled, a pseudonymous identifier is stored in sessionStorage under pw_analytics_session_id to group first-party events within one browser session. We do not send or later replay analytics events that occur before consent. Disabling Analytics stops events and removes that session identifier.

External media is optional. YouTube frames are not loaded until you enable this category. We use YouTube's privacy-enhanced embed domain, but loading or opening a video still connects to Google and may allow Google to store or access information under its own policies.

We do not use advertising cookies or cross-site tracking on the marketing sites. You can change or withdraw any optional choice at any time through Cookie settings in the footer; withdrawing consent is as easy as granting it.

The ProWeave Hub web interface may store a short-lived functional preference (for example a sidebar_state cookie, on the order of one week) to remember UI layout. This is strictly necessary for the interface and does not track you across unrelated sites.

7. Retention

We retain personal data only as long as necessary for the purposes above and to meet legal, tax, and accounting requirements. Organisations may delete or export data using in-product controls where available.

Configured maintenance removes additional audit-event details and the linked account identifier from entries older than 730 days. Summaries and other actor fields can remain identifiable, so this is not full anonymisation of the audit log. The same maintenance process deletes volunteer access tokens more than 90 days after expiry and directory records archived for more than 395 days. These are configured cleanup thresholds; contact support for information about the maintenance process and any remaining records.

Hub’s delivery-attempt records are scheduled for deletion once they are more than 90 days old. We retain the organisation, email address and registration time needed to honour an unsubscribe preference even if a directory or guest record is deleted. Removing a person therefore does not reset their email preference. Requests concerning these records can be made through the organisation’s privacy contact.

Contact-form and mailbox content is kept for the time needed to handle your request and ordinary business follow-up unless a longer period is required by law.

Raw website analytics events are retained for up to fourteen months, then deleted or aggregated for reporting. Download analytics events follow a similar operational retention window.

A Canva connection is retained until the user disconnects Canva or deletes the ProWeave account. We then remove the stored credentials and attempt to revoke Canva consent. Disconnecting does not delete imported copies. Local copies are controlled by the user. Hub service attachment references expire 30 days after the service ends. Shared files remain while another service reference is valid or Keep in Hub is enabled. Up to 10 GB per organisation can be kept beyond service expiry within its shared 50 GB cloud allowance. Releasing a kept file with no service references queues it for deletion; deleting the organisation removes its retained media too.

Periodic Presenter diagnostic reports are scheduled for deletion after 90 days by an hourly task; deletion can take until the next run. The reporting view covers the latest 30 days and stores no indefinite aggregate history. Separate abuse-prevention records use an hourly rotating hash derived from the request IP, are not attached to reports, and expire after two hours before the next cleanup. Infrastructure access logs are managed separately.

Presenter backups share the organisation’s 50 GB Team allowance with Hub media. We keep the latest two completed backups per computer, for up to five computers per account and organisation. Saved copies remain until replaced or deleted; deleting the account or organisation queues its copies for storage cleanup. Turning off automatic backup does not delete existing copies. While organisation membership remains, the account can restore its saved backups after Team ends.

8. International transfers

Data may be processed in the Netherlands (our company), the United Kingdom (including our primary application hosting in London), elsewhere in the European Economic Area, and in other locations where subprocessors operate. Transfers from the EEA to the UK rely on applicable adequacy decisions or appropriate safeguards. Where personal data is transferred outside the EEA or UK without adequacy, we implement appropriate safeguards such as Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement where relevant), as offered by our vendors.

9. Your rights

Under the GDPR and applicable local law you may have the right to access, rectify, erase, restrict or object to processing, and data portability where applicable, and to withdraw consent where processing is based on consent. You may lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

For workspace data controlled by your organisation, contact the organisation first. The product may offer organisation export, organisation deletion, administrator account deletion, and person-level deletion subject to role rules; see in-app settings or your administrator.

To exercise rights against ProWeave as controller, contact [email protected]. We may need to verify your identity.

10. Children

The Services are not directed at children. Organisations must not use the Services to process children's personal data in violation of applicable child-protection laws.

11. Security

We implement technical and organisational measures appropriate to the risk, including access controls and encryption in transit. No method of transmission or storage is completely secure.

Hub limits event editing to owners, administrators and editors by default. An administrator or editor can enable Collaboration for an individual event so its invitees, including guests, can also edit the service, assignments and files. With Collaboration disabled, invitees can read the event and respond to their own invitation; other people’s invitation statuses and contact details are excluded from the event roster response. Organisation-level permissions remain separate from this event setting.

12. Third-party sites and embedded content

Our sites may link to or embed third-party content. YouTube embeds remain blocked until you enable External media; following an external link takes you to the third party directly. Those parties have their own policies, and we are not responsible for their independent practices.

13. Changes

We may update this policy. We will revise the "Last updated" date and, where required, provide additional notice.