Privacy Policy
Conference and privacy enquiries: tfcconference@gmail.com
Effective 24 September 2026 · Version TV20-2026-09-24
1. Who Is Responsible for Your Information?
Truevine Community Church ("Truevine", "we", "us"), organises the Truevine@20 Homecoming Emerge Conference 2026 and determines how conference registration information is used.
- Website: https://truevine20.co.za
- Church address: 21 Holder Rd, Westgate, Pietermaritzburg
- Privacy requests: address to the Information Officer at tfcconference@gmail.com
- Privacy email: tfcconference@gmail.com
- Effective date: 24 September 2026
This policy covers the conference website, registration, payment verification, attendance and related enquiries. Separate notices will explain any additional services when introduced.
2. What We Collect and Why
We collect information directly from you, from someone authorised to register you, and from your use of the system.
| Information | Conference purpose |
|---|---|
| Names, ministry/age group, branch or visitor status | Identify attendees and organise attendance |
| Lead contact mobile number and optional email | Registration updates, support and access to passes |
| Pastor status, church/organisation name and accompanying headcount | Organise visiting groups and calculate the relevant registration charge |
| Selected sessions, household links and guardian details | Session planning, capacity management and safe administration of family attendance |
| Optional accessibility requests and transport interest | Arrange appropriate support and assess transport demand |
| Ticket pricing, payment references and PDF payment proofs | Match bank transfers, review payment and handle related queries |
| Consent choices, QR pass identifiers and check-in records | Record preferences, issue passes and manage entry |
| Relevant technical, security, communication and administrative logs | Maintain the service, investigate errors and prevent misuse |
Required fields are identified on the form. Without essential booking details, we may be unable to register you. Payment proof is required where a payment is due; exempt bookings do not require it. Declining marketing or leaving optional accessibility information blank does not prevent registration. Support arrangements may require a confidential follow-up.
Please do not upload full bank statements, passwords, PINs, card security codes or identity documents. A payment proof should show only what is needed to match the transfer, such as payer/reference, date, amount and recipient. Redact unrelated balances, transactions and unnecessary account details.
3. How We Use Your Information
We use the information for the purposes described above, including corrections, cancellations, payment queries and necessary event communications. We do not sell attendee details, publish registration lists or use a registration to enrol you automatically in church membership or marketing.
Our legal grounds depend on the activity and may include consent, arranging the requested service, legal duties and legitimate interests in secure event administration. Special information and children’s information require additional lawful grounds. Acknowledging this policy does not waive your rights.
4. Church Affiliation and Accessibility Information
Branch, congregation and ministry information may reveal religious beliefs. Accessibility information may reveal health information. We request only what is needed for the stated conference purpose and limit access to people who need it.
Where we rely on consent for this information, we ask for a specific choice explaining the use. Do not provide medical histories or diagnoses when a practical request will suffice, for example, "step-free access required". Contact our privacy contact if you prefer to discuss a sensitive request privately. Information is not shared with unrelated churches, sponsors or the public for their own purposes.
5. Registering Children or Other People
For this policy, a child is a person under 18. The church’s ministry groups are not legal age classifications. An adult group containing 18–19-year-olds and under-18s does not remove the need to distinguish their consent requirements.
A parent, legal guardian or another person legally competent to consent must authorise a child’s information being provided. We may ask for proportionate evidence of that authority. Registering another adult requires their permission and giving them access to this policy. An organiser’s or pastor’s role alone does not authorise disclosure of every group member’s sensitive information.
We do not use children’s registration details for direct marketing. Child photographs and testimonials require a separate appropriate permission process.
6. Who Can Receive Information?
Authorised registration, finance, support and check-in personnel receive access appropriate to their duties. For example, personnel reviewing payment proofs need different access from a person checking a pass. Where transport or venue support is arranged, we share only the details necessary for that arrangement and explain any additional disclosure.
The website uses Vercel for hosting and Supabase for database, authentication and file storage. If a messaging provider is enabled, it receives the contact details and message content necessary for delivery. The intended confirmation channels are WhatsApp, SMS and email. Twilio is the selected provider for WhatsApp and SMS; sender setup and testing are pending. The email-sending service is still to be confirmed.
Service providers must be subject to appropriate confidentiality, security and processing arrangements. Information may also be disclosed where legally required or necessary to handle a dispute or protect people’s safety, within applicable law.
7. International Processing
Some hosting, storage, support or messaging processing may occur outside South Africa. We will verify a permitted cross-border transfer basis and appropriate safeguards before such processing. Transfers involving children’s or special information may need additional assessment or prior authorisation. Use of the website is not blanket consent to unrestricted international transfers.
8. Messages and Marketing Choices
Booking confirmations, pass access, payment queries and material event updates are service communications. Optional promotional messages require a separate choice and are not a condition of attendance. We will identify the sender and provide a way to withdraw marketing consent without charge. Withdrawing marketing consent will not cancel your booking. Necessary service messages may still be sent.
New registrations receive a private registration link on-screen. Save that link to view and print your passes. Automated WhatsApp, SMS and email confirmations are not currently active. Contact tfcconference@gmail.com for registration support.
9. Security and Private Passes
The application uses restricted staff access, private payment-proof storage and opaque QR identifiers. QR payloads do not contain attendee names or phone numbers. A private management link can grant access to a booking, so keep it and your passes confidential. Contact us promptly if they are shared or compromised.
We use reasonable organisational and technical safeguards, but no service can promise absolute security. We will investigate suspected unauthorised access and notify the Information Regulator and affected people where required, as soon as reasonably possible, subject to lawful delays.
10. Retention and Deletion
We keep identifiable information only as long as necessary for its purpose or a justified legal requirement. Different periods apply to event administration, support requests, financial evidence and security records. When retention ends, information is securely deleted or irreversibly de-identified. Restricted backups expire through their documented lifecycle; legal holds may delay deletion of relevant records.
11. Cookies and Browser Storage
Staff authentication uses session-related cookies. The registration invitation can remember that you have registered or dismissed it using browser storage and a preference cookie. This preference contains a yes/no marker, not your registration details. The current cookie requests up to ten years; browser storage persists until cleared. Closing a session or clearing site data may reset some preferences.
We do not currently include advertising trackers in the registration application. Hosting security logs are separate from browser tracking. We will review any new analytics or third-party embeds and obtain consent where required before enabling non-essential tracking. Browser settings let you clear stored site data; doing so may sign you out or restore dismissed prompts.
12. Your Rights and Complaints
Contact our Information Officer to request access, correction or deletion, object to processing where applicable, or withdraw consent. Withdrawal does not retrospectively invalidate lawful processing. We may verify identity and explain any lawful limits or required retention. A booking cancellation does not automatically erase associated financial or audit records.
You may complain directly to the South African Information Regulator without first complaining to us. Its website and eServices portal provide current channels; its POPIA forms include objection, correction/deletion and complaint forms.
13. Photography and Policy Changes
Registration and marketing choices do not provide blanket permission to use your portrait, interview or testimonial. Any event photography, filming or livestream arrangements will have a separate notice and appropriate permission process, particularly for children.
We will update the date and version when this policy changes. A materially new use will be explained, with further consent where required. This policy does not replace booking, refund or safeguarding terms.
Return to Registration