Operate

Privacy

Last updated September 26, 2026.

What we keep today

When you start a shop we keep your name, your email, and a scrambled form of your password that we cannot read back. The shop, its customers, quotes, jobs, and money records live in Postgres. That is the name, kind, and city of the shop; the people you add; a quote on a job or an order a visitor asks for; the site, crew, buy list, and time on a job; and the money you type in and out.

The same database holds the rest of what you type on the desk: stock, sales, orders, deliveries, suppliers, goals, workflows, and the hours, about, and contact on the public shop page. If a visitor sends a note, we keep their name, email, phone, and message for you. If you write to us for help, we keep that note and the address to reply to.

We do not invent rows to make a desk look busy. We do not buy data about you.

What we do with it

Run your desk. That is the whole list. We do not sell it, rent it, or hand it to advertisers. We look at it only to fix a problem you have asked us about or to keep the service working.

Where it lives

The app runs on Vercel. Shop, customer, quote, job, and money records are stored in Postgres. Connections to Operate are encrypted.

Photo files are not stored yet. When they are, they will live in Supabase storage. A portfolio picture today is a link you paste, saved with the shop in Postgres.

Billing

The desk is $49 a month. Stripe handles that subscription. Stripe stores the card. We keep the Stripe customer id, the subscription id, and the billing status on the shop so it can renew and so you can cancel or change the card. We do not keep the card number.

Shop deposits through Stripe Connect are queued. They are not on. When they are, Stripe will handle those charges. That is separate from the $49 subscription, and we still will not keep the card number.

Charity donation charges stay off unless a separate live-payments flag is turned on later. That is not this product.

Facebook and Instagram

A Facebook or Instagram connection is queued. When it is on, it goes through ChurchConnect. Operate stores no Meta tokens. The only Meta-related record we keep is a connection id and a status. ChurchConnect holds the connection itself. How to delete that data is on the data deletion page.

Tools we point you to

Website work happens on Easy Peazy. Printer work happens on the Toner family. Marketing materials go through Laser. Group purchasing uses the shared Group Buy spine. When you use one of those, its own notice applies. Easy Peazy reads the public parts of your shop page — hours, about, contact, and items you mark for the website — and nothing else.

Your copy, and leaving

It is your data. From your account page you can download everything at any time, or just your ledger. You can also delete the shop there. That removes the shop and the login, and frees the email to start again. There is no undo in the app. Data deletion explains that step, and how to ask by email if you cannot sign in.

How long we keep it

As long as your shop exists. Sign-in sessions expire on their own (they last 30 days). Notes from your website visitors stay with your shop until you delete them or the shop.

If something goes wrong

If we learn that your data was exposed, we will tell you at the email on your account, plainly and promptly, with what happened and what we are doing about it.

Questions

Ask through Get help or write to privacy@unitedundergod.org. A person reads it. If we change this notice in a way that matters, we will say so here and update the date at the top. The terms say what the desk is and what it is not.