Tend is software used by congregations. Each congregation that uses Tend keeps its own directory, decides who is contacted, and sends its own email and text messages to its own members and visitors. Still Standing Studios, LLC ("Still Standing Studios," "we," "us") builds and operates the software on that congregation's behalf. When you receive a message sent through Tend, it comes from your congregation — not from us. This policy explains what Tend holds, how permission to contact people is obtained and recorded, and what we do and do not do with any of it.
Tend is available as a web application and on mobile devices. This policy applies to both, and to the public communication card that a congregation may publish for visitors. It also governs the text messages congregations send through Tend; the congregation currently sending is OrangeView Church, and congregations that adopt Tend later send under these same practices.
Your congregation is the one making the decisions. It chooses what to record about its members, who is added to the directory, which people are contacted, and what those messages say. It is responsible for its own members' information and is the right place to start with any question about what it holds about you.
Still Standing Studios provides and operates the software. We store and process information on the congregation's behalf and under its direction. We do not use congregation data for our own purposes. We do not sell it, rent it, or trade it. We do not use it for advertising, and we do not use it to train machine-learning or artificial-intelligence models. Our staff access congregation data only when necessary to keep the service running or to respond to a support request from that congregation.
Tend runs on a small number of established services. Each one handles data only to perform the function described:
We do not share congregation information with anyone else. We do not sell it, and we have no advertising partners, data brokers, or marketing affiliates of any kind. The only other circumstance in which congregation information would leave the arrangement described above is a lawful legal demand that we are obliged to answer, and we would tell the affected congregation about such a demand unless forbidden by law from doing so.
Phone numbers, opt-in records, and consent data used for text messaging are held to a stricter rule than everything else, and that rule admits no exception:
In practice this means opt-in and consent data goes only to Twilio and its carrier aggregators, for the sole purpose of delivering the message. It is never sold, never rented, never shared for marketing, and never passed to any other congregation or organization.
This website — the public pages at stillstandingstudios.com, including this one — uses Cloudflare Web Analytics to count page views. It sets no cookies, uses no fingerprinting, and does not track visitors across sites. It is separate from the Tend application and touches no congregation data.
Tend holds the information a congregation records in the ordinary course of caring for the people in it:
Tend holds no financial information. There is no giving module, no contribution record, no card number, and no bank detail anywhere in the system. This is a deliberate design decision, not an oversight.
This is the part that matters most, so it is set out precisely.
Members. A member is added to the directory by their own congregation, and gives their contact details to that congregation directly — on a membership form, in conversation, or by asking to be added. The relationship is between the person and their congregation.
Visitors and communication cards. A person filling in a communication card sees an explicit checkbox reading "It's okay for the church to contact me." It is a separate, unticked box. When it is ticked, Tend stores the exact wording shown, the version of that wording, and the date and time permission was given, alongside the submission.
Permission is never assumed and never bundled. A card submitted without that box ticked is still stored, so the congregation can read what the person wrote — but that person is not eligible to be messaged. Consent is not a condition of submitting a card, and it is not buried inside agreement to anything else.
Permission is checked twice. Once when the audience for a message is assembled, and again at the moment each message is dispatched. A person who has opted out between those two moments is not sent the message.
No phone number in Tend is ever purchased, scraped, rented, or imported from a third-party list. Every number in the system was given to a congregation by the person it belongs to, or recorded by that congregation from its own direct relationship with that person.
Opting out of messages is not the same as leaving the directory. Replying STOP stops the texts; it does not remove a person from their congregation's records, and it does not end their membership. Those are separate things, and a person who wants to be removed from a congregation's directory entirely should ask that congregation.
Tend separates sensitive submissions by who is permitted to read them, and it does so in storage rather than only in the interface. A prayer request marked for the elders or the ministers is kept where a general volunteer reviewer cannot reach it at all — it is not merely hidden from view on screen. Views of restricted material are logged.
The corresponding disclosure, stated plainly: the elders of a congregation can read communication cards, prayer requests, and comments submitted to that congregation, because they are charged with shepherding it. Tend says so on the card itself, before anyone writes anything.
A congregation's directory ordinarily includes minors, because congregations include families. Tend restricts contact details for minors to congregational leaders rather than exposing them in the general directory. Tend is not directed to children as users, and accounts are for adults acting on behalf of a congregation. A parent or guardian with a question about what a congregation records about their child should ask that congregation, and may also write to us at the address below.
Congregations control retention. Information is kept while it serves the purpose for which the congregation collected it, and a congregation can delete records in Tend at any time. When a congregation ends its use of Tend, it may request export or deletion of its data.
Congregation data is stored with Google Cloud / Firebase, which encrypts data at rest and in transit. All connections between Tend and its services use encrypted (HTTPS) connections. Access within a congregation is governed by roles, so that a volunteer, a minister, and an elder see different things; the storage-level partitioning described above backs those roles up rather than relying on the interface alone. Sign-in is handled by Firebase Authentication.
No system is perfect, and we do not claim otherwise. If a breach affecting congregation data occurs, we will notify the affected congregations promptly and give them the information they need to meet their own obligations.
Start with your congregation. They decide what is recorded about you, and they can view, correct, or delete it directly in Tend. This is almost always the fastest route.
If you cannot reach your congregation, or your request concerns how the software itself operates, write to privacy@stillstandingstudios.com. Where we act as operator on a congregation's behalf, we will work with that congregation to answer the request rather than act unilaterally over their records.
If we change how information is handled, we will post the updated policy at this address and revise the effective date above. Congregations using Tend are notified of material changes.
A person reads this address. privacy@stillstandingstudios.com