This Privacy Policy explains how KingdomERP ("the Platform"), operated by Tiidon Innovations Limited, collects, uses, and protects information when a church ("Tenant Church") and its members, visitors, and staff use the Platform.
Each Tenant Church controls the member, visitor, and ministry data it enters into the Platform — it decides who can access it (via roles and permissions) and how long to keep it. Tiidon Innovations Limited acts as the technical operator and processor of that data on the church's behalf, and as the data controller for platform-level account and billing information.
Some churches use the Platform's children's ministry features, which may include information about minors. This information should only be entered with appropriate parental or guardian consent obtained by the church, and access to it is limited to authorized church leaders.
We do not sell member or visitor data to third parties.
Access within a church is restricted by role: for example, only finance-related roles can see individual giving records, and department leaders can generally only see members in their own department, unless a church admin grants broader access. Basic members do not have access to other members' contact details through the Platform.
If a church account is deleted, its data is moved to a recoverable state for a limited period (currently 30 days) before being permanently removed, to protect against accidental deletion. Members and visitors who want their personal information corrected or removed should contact their church directly, as the church controls its own member records.
We use third-party services to operate the Platform, which may include email delivery providers, SMS and WhatsApp providers, and mobile money or payment gateways. These providers process data only as needed to deliver their service (e.g. sending an email, processing a payment) and are not permitted to use the data for their own purposes.
We use measures such as password hashing, role-based access control, session security, and audit logging to protect data. No system is completely secure, and we encourage churches to use strong passwords and limit leadership access to only what each role actually needs.
Depending on your location and applicable law, you may have rights to access, correct, or request deletion of your personal information. Requests about a specific church's records should go to that church directly. Requests about platform-level account data can be submitted to us using the contact details below.
We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or by email to Church Admins.
For questions, concerns, or data rights requests relating to this Privacy Policy, please contact us: