Security & data handling
Your congregation's giving is among the most sensitive data a church holds. Our answer is
architectural, not just contractual: GivingBooks Sync is designed so the
most sensitive data never enters our systems in the first place.
Donor privacy by construction
Donor names, emails, addresses and payment details are never stored and never
posted. The engine matches deposits using Planning Center donation IDs, dates,
amounts, fees and fund designations — that is all it keeps and all it writes to
QuickBooks. Entries and audit records reference IDs like "donation 48291103," never who
gave. This isn't a privacy setting that could be misconfigured; the product has no tables
to store donor identities in. Our
privacy policy spells out exactly which
gift-level fields each posting mode keeps.
OAuth only — no passwords stored
You connect Planning Center and QuickBooks through their official OAuth flows. We never
see, ask for, or store your password for either system. Access is scoped: read-only
giving data from Planning Center, accounting writes to QuickBooks — nothing more.
Encryption at rest and in transit
All traffic uses TLS. OAuth tokens and credentials are encrypted at rest with versioned,
rotatable keys, separate from the application database credentials.
Full audit trail
Every entry we post is recorded in an append-only event log: what posted, when, from
which source period, and what happened afterward (retries, adjustments, mapping
changes). Your auditor can trace every number in QuickBooks back to its source.
Revoke anytime
Inside the app, Organization settings → Connected apps
→ Disconnect deletes the stored Planning Center or QuickBooks authorization
immediately and stops the sync — no email, no waiting on us. You can also revoke us from
Planning Center's or Intuit's own app screens; the app notices and asks you to reconnect
rather than failing silently. Entries already posted remain in your QuickBooks, because
they're your books, and your history stays available to you until you ask us to delete
it.
Wrong-church-file guard
When a payout file carries Planning Center's organization identifier, we check it against
the connected church and refuse a mismatch outright — the file is rejected, not
"handled." Some export formats carry no organization id at all; those are flagged as
unverifiable in the preview, before you commit anything, rather than passed off as
checked. A bookkeeper managing many churches always knows which of the two they are
looking at.
Approval queue: nothing posts on a guess
Entries post automatically unless you say otherwise — Review first, where every
entry waits in an approval queue until a human accepts it, is one radio button on the
setup screen and switchable per church at any time. Either way, anything the matcher
can't prove to the penny is flagged and held, never posted on a guess.
Payout files: parsed, then discarded
If you upload a payout CSV, we parse it, keep
only the donation IDs, dates, amounts, fees and fund designations the matcher needs, and
discard the raw file. Row-level donor names and emails are never retained.
Backups and recovery
The database (fund totals, donation IDs with their dates, amounts and fees, mappings, audit log — no donor identities)
runs on managed Postgres with daily provider snapshots, and we keep a written,
step-by-step restore procedure rather than an assumption. Scheduled off-platform dumps to
independent storage are documented in our runbook and are being wired now — we would
rather tell you exactly where that stands than claim it early.
Questions we welcome
If your finance committee, auditor, or denomination has a security questionnaire, send it
over — we'd rather answer hard questions before you connect than after.
Send it through our contact form
or write to hello@givingbookssync.com — a questionnaire attachment is welcome by email.
See also: Privacy policy · Terms of service