Privacy Policy

Last updated: July 22, 2026

1. Overview

Mission21 Finance (“we”, “us”, the “Service”) is a web-based accounting and contribution-management application for churches, operated via mission21.com. This Privacy Policy explains what information we collect, how we use it, and how we protect it, including information accessed through your connected QuickBooks Online account.

2. Information We Collect

  • Account & church data you enter into the Service (contributions, expenses, budgets, accounts, member names used for receipts).
  • QuickBooks data (only if you connect QuickBooks Online): read-only access to your accounting data such as chart of accounts, profit & loss, balance sheet, transactions, and customer/donor totals, obtained through Intuit’s OAuth 2.0 API.
  • Authentication tokens issued by Intuit (access token, refresh token, company/realm identifier) required to retrieve your QuickBooks data.

3. How We Use Information

We use your information solely to provide the Service to you — to display, summarize, and report your church’s financial data to authorized users of your church. We do not sell, rent, or share your data with third parties for advertising or marketing.

4. QuickBooks (Intuit) Data

  • Access to your QuickBooks company is read-only; we do not create, modify, or delete data in QuickBooks.
  • Access is granted by you through Intuit’s secure OAuth authorization; we never see or store your Intuit login credentials.
  • Authentication tokens are stored on our servers only and are never exposed to the browser or any third party.
  • You may disconnect QuickBooks at any time from the Service, which deletes the stored tokens and revokes our access.
  • Our use and transfer of information received from Intuit APIs adhere to the applicable Intuit developer terms and policies.

5. AI Features (Optional)

If a church enables optional AI features, limited, relevant data (such as aggregated financial figures or member names for receipt drafts) may be sent to our AI provider (OpenAI) to generate summaries or drafts. These features are off by default and require the church administrator’s explicit consent before use.

6. Data Storage & Security

Data is stored in access-controlled databases. Sessions use signed, httpOnly cookies; all credentials and API keys are kept server-side only. Traffic is served over HTTPS.

7. Data Retention & Deletion

We retain your data for as long as your account is active. You may request deletion of your data, and disconnecting QuickBooks immediately removes the stored Intuit tokens. To request deletion of other data, contact us at the address below.

8. Children’s Privacy

The Service is intended for use by church administrators and is not directed to children under 13.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by the “Last updated” date above.

10. Contact

For any questions about this Privacy Policy or your data, contact us at info@mission21.com.