Effective: 31 August 2026 Publisher: The Trustee for Carpenter Family Trust, ABN 82 782 069 476, publishing Church Grants Australia as an unregistered project name. Main business location: SA 5251, Australia. Privacy contact: use the monitored Corrections and contact form at /corrections and select Privacy question, access or deletion request.
The publisher has chosen to operate Church Grants Australia as though the Privacy Act 1988 (Cth) and Australian Privacy Principles apply. This policy explains how the current free service handles personal information.
What the current service collects
Church Grants Australia has no user accounts, paid subscriptions, alert sign-ups or uploaded-document service. The readiness check runs in the browser and does not send individual answers to us.
The corrections and contact form may collect:
- the grant or page involved;
- an issue or request category;
- an official source link;
- the details a person chooses to submit; and
- a reply email, if supplied or required for a privacy or service request.
Do not submit beneficiary names, pastoral details, religious beliefs, health information or other sensitive personal information. We do not ask individuals to state their religion and do not use activity to build individual religious profiles.
Website and analytics information
Our hosting, security and network providers may process an IP address, request time, requested page, browser or device details, referring page and security events when delivering the site.
Google Analytics is configured for service improvement and organic-search validation. It may process a shortened page address without its query string, page title, broad referrer class, device and browser information, and allowlisted events such as viewing a grant, using broad filters, opening an official source or completing the readiness tool. We do not deliberately send search text, names, email addresses, individual religion, beneficiary information or full readiness answers to Analytics.
The site may store one first-touch organic-attribution record in browser local storage. Google Analytics may use first-party analytics cookies; our implementation denies advertising storage, advertising user data and advertising personalisation, disables Google signals and limits its own cookie expiry to 90 days. The Analytics property is configured for the shortest available user-level event-data retention period. Aggregated reporting may be retained longer by Google.
Search filters appear in the page URL so a view can be shared. They may appear in browser history, hosting logs or a recipient's logs. Do not put sensitive or identifying information into search.
How information is used
We use information supplied to us to:
- deliver, secure and troubleshoot the service;
- investigate and correct grant information;
- respond to privacy and service requests;
- understand aggregate use and organic-search performance; and
- improve coverage, navigation, guidance and reliability.
We do not sell personal information, correction reports, individual grant searches or religious profiles. Correction contact details are not used for promotion.
Service providers and disclosure
The current service uses:
- Vercel for hosting, functions, content delivery and technical logs;
- Google Analytics for limited website measurement;
- Resend to transmit correction and contact messages; and
- Migadu to receive and store those messages in a monitored mailbox.
These providers may use their own subprocessors. We may also disclose information where required by law, to address misuse or security incidents, or with the person's consent. We do not disclose information to a related business for marketing or favourable grant treatment.
Overseas processing
Vercel, Google, Resend, Migadu and their subprocessors may process information outside Australia, including in the United States, European locations and other regions in which they operate. Provider locations can change. We minimise the information sent and use provider security and contractual controls available to the service.
Storage, security and retention
The application has no customer database. Correction and contact messages are kept in the restricted mailbox while investigated and for up to 12 months after resolution, then deleted unless an active dispute or legal requirement needs longer retention. Google Analytics user-level event data uses the shortest available retention setting. Infrastructure and aggregate records follow the relevant provider's controls and retention practices.
We use restricted administration access, environment-protected API credentials, input validation, submission throttling, software updates and deletion procedures. No internet service can guarantee absolute security.
Access, correction, deletion and complaints
Use /corrections and select Privacy question, access or deletion request to ask what personal information we hold, request access or correction, seek deletion where applicable, or make a privacy complaint. Provide a reply email so we can respond. We may need to verify identity and may retain records where law requires.
We aim to acknowledge a material request within two business days and investigate it fairly. If a complaint is not resolved, a person may contact the Office of the Australian Information Commissioner at oaic.gov.au.
Data breaches
The publisher is responsible for privacy complaints and suspected data breaches. We will contain and assess a suspected breach and, where required, follow the Notifiable Data Breaches scheme.
Future features and changes
This policy does not authorise alerts, accounts, payments or promotional messaging. Before any such feature launches, we will add an appropriate collection notice, consent and deletion controls, document the provider and retention arrangements, and update this policy.
We may update this policy when the service or providers change. The current effective date will remain visible.