Who we are
This Privacy Policy describes how the Charismatic Episcopal Church – Territory of Asia ("ICCEC Asia", "we", "us") handles personal information when you use iccecasia.org, its diocesan and ministry sub-sites (for example visayas.iccecasia.org or convocation.iccecasia.org), and the ICCEC Asia mobile app for iOS and Android (together, the "Services").
ICCEC Asia is the territorial body of the Charismatic Episcopal Church serving the Dioceses of Metro Manila and Northern Luzon, Southern Luzon, Visayas, and Mindanao in the Philippines. We process personal information in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules.
Information you give us
Most of the Services can be used without creating an account or providing any personal information. We collect personal information only when you choose to give it to us:
•
Convocation registration: full name, email address, phone number (optional), delegate category, diocese, shirt size, meal preference and notes, and a payment reference you supply. This is used to register you as a delegate to the Territorial Convocation and to contact you about the event.
•
Newsletter subscription: your email address. We send a confirmation email and only add you to the list after you confirm (double opt-in). Every newsletter contains an unsubscribe link.
•
Staff and ministry accounts: accounts are created by invitation only for clergy, staff, and ministry leaders. For these accounts we hold your name, email address, assigned role, and the diocese or parish you serve. Passwords are handled by our authentication provider and are never visible to us.
•
Correspondence: if you email us, we keep the message and your contact details for as long as needed to respond.
Information collected automatically
We keep automatic collection to the minimum needed to run the Services safely:
•
Server logs and abuse protection: when you submit a form (registration, newsletter) our servers record the request time and network address to apply rate limits and prevent abuse. These records are not used to build profiles.
•
Article view counts: when an article is opened we increment an anonymous counter for that article. No identifier linking the view to you is stored.
•
Caching on your device or browser: public content (dioceses, parishes, sermons, resources) may be cached locally so pages load quickly and remain readable on a poor connection. Signed-in sessions in the mobile app are stored on your device in encrypted form using the operating system keychain or keystore.
•
Network status: the mobile app checks whether your device is online to show an offline notice. This information does not leave the device.
•
Crash reporting (mobile app only): if the app crashes or hits an unexpected error, a diagnostic report — device model, OS version, app version, and error details — is sent to Sentry so we can find and fix faults. Reports contain no name, email, or message content; for signed-in staff they carry an opaque account identifier only. The website does not send crash reports.
What we do not do
•
We do not sell, rent, or trade personal information.
•
We do not use advertising networks or third-party tracking or marketing analytics SDKs in the website or the mobile app.
•
We do not request access to your contacts, photos, microphone, or precise location. The church locator shows parishes on a map without reading your device location. The mobile app asks for camera access only so authorised check-in staff can scan delegate QR passes at Convocation; the image is processed on the device and no photo or video is captured, stored, or sent to our servers.
•
We do not knowingly collect personal information from children under 18 through online forms. Youth delegate registrations are submitted by, or with the consent of, a parent, guardian, or parish leader.
How we use information
•
To register and communicate with Convocation delegates, including payment confirmation and event logistics.
•
To send newsletters and pastoral communications you have asked for.
•
To let authorised clergy and staff manage territorial, diocesan, and parish content, registrations, and ministry tasks according to their role.
•
To keep the Services secure, prevent abuse, and diagnose problems.
•
To comply with legal obligations and the canons and policies of the Church.
Service providers
We rely on a small number of providers who process information on our behalf under their own security commitments. They only receive the information necessary for their function:
•
Supabase – database, authentication, file storage, and serverless functions that power registrations, content, and accounts.
•
Resend – transactional email delivery for confirmations, invitations, and newsletters.
•
Vercel – hosting for the website.
•
Expo Application Services – building and distributing the mobile app. The app does not send usage data to Expo.
•
Sentry – crash and error reporting for the mobile app, limited to the diagnostic data described above.
•
OpenStreetMap – map tiles for the church locator, loaded directly from openstreetmap.org when you open the locator. Directions links open your device’s maps app – Apple Maps on iOS, your default maps app (typically Google Maps) on Android, or openstreetmap.org on the web.
•
YouTube and Vimeo – sermon videos open in those services or their apps, which have their own privacy policies.
Retention
Convocation registration records are kept for the duration of the event cycle and the related financial reporting period, after which they are archived or deleted. Newsletter addresses are kept until you unsubscribe. Staff account records are kept while the account is active and removed when the account is deleted by a territory administrator. Server logs used for abuse protection are short-lived.
Security
Access to personal information is restricted by role using database-level security rules, so a parish administrator, for example, can only see records for their own parish. Data is encrypted in transit. Sessions on mobile devices are encrypted at rest. No system is perfectly secure; if we become aware of a breach affecting your information we will notify you and the National Privacy Commission as required by law.
Your rights
Under the Data Privacy Act you have the right to be informed, to access and correct your information, to object to processing, to request deletion or blocking, to data portability, and to lodge a complaint with the National Privacy Commission. To exercise any of these rights, or to unsubscribe from communications, email us at the address below. We will respond within the periods required by law.
Deleting your account or data
Newsletter: use the unsubscribe link in any email, or contact us. Convocation registration: contact the Territory office to correct or withdraw a registration. Staff accounts: delete your account yourself in the mobile app (Account → Delete account), ask a territory administrator, or email us; deletion removes your profile and revokes access immediately. You can also remove locally cached data at any time by signing out or uninstalling the mobile app.
Changes to this policy
We may update this policy as the Services evolve. The effective date at the top of the page shows the latest revision. Material changes will be highlighted on this page.
Contact
ICCEC Territory of Asia – Digital Ministry. Email: admin@iccecasia.org. This address is also the point of contact for data privacy requests.