Privacy Policy
Effective date: 21 September 2026
1. Who we are
27 app is a church financial tracking service provided by Fourello Inc., a corporation registered in the Philippines with its principal office in Quezon City.
In this policy, "we", "us" and "our" mean Fourello Inc. "You" means anyone whose personal data we handle, as described in section 2.
If you have any question about this policy or about your personal data, contact us at rep@fourello.com.
2. Who this policy covers
This policy applies to three groups:
- Church staff and volunteers who sign in to 27 app, such as treasurers, finance volunteers, pastors, and leaders given access by their church.
- Givers whose contributions a church records in 27 app, whether or not they use the service themselves.
- Visitors to our website at 27app.co.
3. Your church controls its own records
Each church decides what records it keeps, who may see them, how long they are kept, and when they are deleted. Under the Data Privacy Act of 2012 (Republic Act No. 10173), the church is the personal information controller for the records it enters into 27 app. We are its personal information processor: we hold and process those records on the church's instructions, and we do not decide what goes into them.
What this means for you in practice:
- If you are a giver and you want to see, correct, or remove your records, ask your church first. They control those records, and we will help them act on your request.
- We do not sell, rent, or share church or giver records with anyone, and we never use them to advertise or market anything to you.
- We do not use church or giver records to train machine learning models.
We are the controller for our own records: staff account details we create, billing information, support correspondence, and website visitor data.
4. What we handle, and why
Staff and volunteer accounts. Name, email address, role, and the times you sign in. We need these to give you access and to keep a record of who changed what. We also store which two-factor method you have set up, but never the codes themselves.
Giver records entered by a church. A giver's name, giver number, household, and optionally an email address and mobile number, along with their contributions: amount, date, giving type, and the account it arrived in. Churches enter this to keep accurate financial records.
Financial records. Transactions, expenses, budgets, accounts, funds, and uploaded receipts. This is the church's own bookkeeping.
Activity records. Every change made in 27 app is logged with who made it and when. This protects the church by ensuring financial records cannot be altered without a trace.
Support and enquiries. If you email us or use the contact form on our website, we keep your message and contact details so we can reply.
Website visits. Basic technical information needed to serve the site securely. We do not use advertising cookies or third-party tracking on our website.
5. Giving records are sensitive personal information
A record that a named person gave to a church reveals their religious affiliation. Under the Data Privacy Act, religious affiliation is sensitive personal information, and it is protected more strictly than ordinary personal data.
We treat giving records accordingly:
- Individual giving records are visible only to the people a church has specifically authorised. Most staff roles in 27 app cannot see who gave what.
- Churches record a giver's consent when they first add that person's details.
- Giving records are never included in error reports, analytics, or any email we send.
- A church can record contributions without attaching them to a named person, for givers who wish to remain anonymous.
6. Legal basis
We process personal data on the following bases under the Data Privacy Act:
- Consent, for sensitive personal information including giving records, obtained by the church from the giver.
- Contract, to provide the service to a church that has subscribed to it.
- Legitimate interests, for keeping the service secure, preventing misuse, and maintaining the activity log, balanced against your rights and freedoms.
- Legal obligation, where we are required to keep records or respond to lawful requests.
7. Who can see your data
Within your church: only the people your church has given access to, limited by the role it assigns them. A volunteer who records expenses cannot see anyone's giving history.
Within Fourello: only the small number of staff who need access to operate and support the service, and only when necessary. Access is logged.
Nobody else, except the service providers listed in section 8, or where we are required by law to disclose.
Each church's records are kept in a separate database. No church can see another church's data, and an issue in one church's setup cannot expose another's.
8. Service providers we rely on
We use the following providers to run 27 app. Each is bound to protect the data it handles on our behalf.
| Provider | What it does | Where it processes data |
|---|---|---|
| Supabase | Database, sign-in, and file storage | Singapore |
| Vercel | Application hosting | Singapore |
| Resend | Sending emails such as reminders and sign-in codes | United States |
| Sentry | Error reporting, with personal details removed | United States |
| PayMongo | Online giving payments, only where a church enables it | Philippines |
We will update this list when it changes and give notice of material changes as described in section 14.
9. Where your data is stored
27 app's database and application are hosted in Singapore, the nearest region to the Philippines. Some supporting services, such as email delivery, process limited data in the United States. This means your personal data is transferred outside the Philippines.
We remain accountable for your personal data under the Data Privacy Act wherever it is processed, and we use only providers that are contractually bound to protect it.
10. How long we keep it
- Church financial records are kept for as long as the church subscribes. When a subscription ends, we offer the church a full export and delete its records 90 days later, unless the church asks us to delete them sooner. Each church remains responsible for keeping its own books for as long as the law requires it to.
- Staff accounts are removed when a church removes that person's access.
- Activity logs are kept for as long as the records they describe, because a financial record's history is part of its integrity.
- Support emails are kept for two years.
A church can ask us to delete its data at any time. See section 11.
11. Your rights
Under the Data Privacy Act you have the right to:
- Be informed about how your personal data is used, which this policy is part of
- Access the personal data we hold about you
- Correct anything inaccurate
- Object to processing in certain circumstances
- Erasure or blocking of your data where the law allows
- Data portability, meaning you can receive your data in a usable electronic format
- Damages, if you suffer harm from a violation of your rights
- Complain to the National Privacy Commission
How to exercise them. If you are a giver or member of a church using 27 app, contact your church first, since they control those records and can act immediately. If you would rather come to us, or your church does not respond, email rep@fourello.com and we will help.
We will respond within 15 working days and may need to verify your identity before acting.
12. Keeping data safe
- Every church's data is held in its own separate database.
- Two-factor sign-in is required for staff accounts that can record or approve financial entries.
- Access rules are enforced by the database itself, not only by the app screens.
- Uploaded receipts are stored privately and are not publicly accessible.
- Every change to a financial record is logged, and the log cannot be altered or deleted without detection.
- Personal details are removed from error reports before they reach us.
No system is completely secure. If a breach occurs that is likely to put your rights at risk, we will notify the National Privacy Commission and affected individuals within the period required by law, and we will notify the affected church without undue delay.
13. Minors
27 app is not intended for use by anyone under 18, and church staff accounts should not be created for minors.
A church may record a contribution from a young person. Where it does, the church is responsible for obtaining the consent required by law from that person's parent or guardian. If you believe a minor's data has been recorded without proper consent, contact us at rep@fourello.com.
14. Changes to this policy
We may update this policy. If a change materially affects how we handle your personal data, we will notify subscribing churches by email before the change takes effect and update the effective date at the top of this page.
15. Contact us
Questions, requests, and complaints about privacy or data protection:
Fourello Inc. Quezon City, Philippines