Legal
Privacy Policy
Last updated: 8 September 2026
Christian Foundation (“CF”, “we”) is a home for sound teaching, and a place where teachers can be found, booked, and paid. Handling people's information carefully is part of keeping faith with them. This policy sets out what we collect, why we collect it, who we share it with, and what you can ask us to do about it.
1.Who this covers
It covers everyone who uses CF at thecf.online — people who watch and read, creators who publish and take bookings, and visitors who send a booking request or sign a document without ever making an account. Where a rule applies to only one of those groups, we say so.
By using CF you agree to the handling of information described here. If you disagree with any of it, please don't use the service — and do write to us at support@thecf.online, because we would rather know.
2.Information we collect
- Identity. Your name, channel handle, profile and banner images, biography, and anything else you choose to publish on your channel.
- Contact. Email address, and for creators the business email and address printed on quotes, invoices, and contracts.
- Account and sign-in. Authentication is handled by Clerk. If you sign in with Google, we receive your name, email address, and profile picture from Google — never your password.
- Booking and business. Booking requests (name, email, organisation, dates and times requested, budget, and your message), quotes, invoices, and contracts, together with the line items and details you put in them.
- Signature evidence. When a document is signed on CF we record the signer's name and email, the drawn or typed signature image, the time of signing, the IP address, and the browser user agent. This is what makes a signature stand up later, and it is retained with the executed document.
- Payment. Payments run through Stripe and, for micro-payments, Trickl. They handle card details directly. We never see or store your card number. We keep the record of what was paid, when, and to whom.
- Doctrinal affirmation (creators only). Applying to publish on CF involves affirming a published doctrinal statement, and may involve vouches from existing creators. That record concerns religious belief, so we treat it with particular care — see section 4.
- Usage and technical. Pages visited, what you watch and how far through, IP address, browser and device type, and log data.
CF is not intended for children under 16, and we do not knowingly collect their information. If you believe a child has given us information, write to support@thecf.online and we will delete it.
3.How we use it
- To run the service. Create and hold your account, show your library and channel, track where you are in a pathway, and carry a booking through request, quote, contract, and invoice.
- To reach you. Booking notices, signing links, confirmations, receipts, security alerts, and replies to your support messages. These are sent by email — CF sends no marketing messages and no SMS at all.
- To take payment. Process payments, calculate platform fees, and pay creators through their connected accounts.
- To keep CF safe. Detect and prevent fraud, spam, and abuse, apply rate limits, and enforce our Terms.
- To improve it. Understand which teaching is helping people so we can order and present it better.
We rely, depending on the case, on your consent, on performing our contract with you, on our legitimate interest in operating and securing CF, and on our legal obligations.
4.Doctrinal affirmation and religious belief
CF exists to gather teaching that holds to historic Christian doctrine, so creators applying to publish affirm a published doctrinal statement, and other creators may vouch for them. Under data protection law an affirmation of belief is a special category of personal data, and we handle it accordingly:
- It is given voluntarily and explicitly, by creators only, as part of applying to publish. Watching, reading, and booking require nothing of the kind.
- It is used only to review the application, to show a channel's standing, and to handle any later doctrinal review of that channel.
- It is never sold, never used for advertising, and never shared outside CF except where the law requires it.
Withdrawing that affirmation means withdrawing from publishing on CF. Write to support@thecf.online and we will close the channel and remove the record.
5.Google API Services — limited use
CF uses two Google APIs, both narrowly. This section is the full account of what we do with the access you grant.
Google Calendar (calendar.events)
A creator who offers one-to-one sessions may connect their Google account so that a confirmed session lands on their calendar. With the https://www.googleapis.com/auth/calendar.events scope we do exactly two things:
- Create an event on the creator's primary calendar when a session is confirmed — its time, the two attendees, and a Google Meet link generated for that session.
- Delete that same event if the session is cancelled.
We touch only the events CF itself created from a booking. We do not read, change, share, or delete any other event on your calendar; we do not list your calendars or your existing events; and we do not create or delete calendars. We request no broader scope than the one above. If Google is not connected, booking still works — the confirmation email simply carries an “add to calendar” link instead.
YouTube Data API (youtube.readonly)
CF's library is embedded YouTube video, and a creator must prove they own the channel they are claiming. If they choose to prove it by signing in with Google, we make a single read-only call asking Google which channels that account owns, and compare it with the channel being claimed. We read nothing else from the account, and we never post, edit, or delete anything on YouTube. A creator who prefers not to grant this can verify instead by pasting a one-time token into their channel description, which needs no Google access at all.
Limited Use
CF's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not sell Google user data; we do not use it for advertising; we do not transfer it except as needed to provide these features, for security purposes, or where the law requires; and we do not use it to develop, train, or improve generalised or non-personalised AI or machine learning models.
You can withdraw our access at any time from your Google account permissions or by disconnecting Google in your CF settings. Doing so stops all future calendar events immediately.
6.Who we share it with
We do not sell your personal information, and we do not share it for advertising. We share it only with:
- Service providers acting for us: Clerk (authentication), Stripe and Trickl (payments), Amazon Web Services (email delivery and file storage), Aiven (database hosting), and Vercel (site hosting). Each is bound to protect what we entrust to them.
- The other party to your booking. When you send a booking request, the creator sees your name, email, organisation, and message — that is the point of sending it. When a document is signed, every party to it receives the executed copy.
- Legal authorities, where the law, a regulation, or a court order requires it, or to protect the rights and safety of people using CF.
- A successor, if CF is ever merged with or acquired by another organisation — under the same protections you have here.
Watching an embedded YouTube video also involves YouTube, under Google's own privacy policy. We embed rather than host, so playback is a matter between you and YouTube.
7.Keeping it safe
- Encryption in transit (TLS) and at rest.
- Authentication and access controls on every system that holds personal information.
- Signed, expiring links for document signing, so a signing link cannot be reused or guessed.
- Rate limits on public endpoints, and card details never touching our servers.
No system is perfectly secure. If a breach affects you, we will tell you and the relevant regulator as the law requires.
8.How long we keep it
We keep information for as long as it takes to run the service, meet legal, tax, and accounting obligations, and settle disputes. Executed contracts and their signature evidence are kept for as long as they may be needed as proof of the agreement. When a period ends we delete or anonymise the data.
9.Your rights
Depending on where you live, you may ask us to:
- Give you a copy of what we hold about you.
- Correct anything inaccurate or incomplete.
- Delete it, so far as our legal obligations allow.
- Restrict or object to how we use it.
- Take it with you in a machine-readable form.
- Withdraw consent where we relied on it, without unsettling what was done before.
Write to support@thecf.online and we will act within the time the law allows. We may need to confirm who you are first. If you think we have handled your information badly, you may complain to your data protection authority.
10.Cookies
CF sets cookies to keep you signed in and to remember settings such as light or dark mode; our providers set cookies needed for security and payment. You can refuse cookies in your browser, but signing in will not work without them.
11.Where your information lives
CF is hosted in the United States, so your information may be processed outside your own country. Where we transfer personal data across borders we rely on appropriate safeguards, such as Standard Contractual Clauses.
12.Changes
We may update this policy. If a change is material we will say so by email or on the site before it takes effect, and the date at the top will always show the version you are reading.
13.Contact us
Questions, requests, or concerns: support@thecf.online.
Thank you for trusting Christian Foundation with your information. See also our Terms of Service.
Christian Foundation