Security & data handling

Your congregation's giving is among the most sensitive data a church holds. Our answer is architectural, not just contractual: GivingBooks Sync is designed so the most sensitive data never enters our systems in the first place.

Donor privacy by construction

Donor names, emails, addresses and payment details are never stored and never posted. The engine matches deposits using Planning Center donation IDs, dates, amounts, fees and fund designations — that is all it keeps and all it writes to QuickBooks. Entries and audit records reference IDs like "donation 48291103," never who gave. This isn't a privacy setting that could be misconfigured; the product has no tables to store donor identities in. Our privacy policy spells out exactly which gift-level fields each posting mode keeps.

OAuth only — no passwords stored

You connect Planning Center and QuickBooks through their official OAuth flows. We never see, ask for, or store your password for either system. Access is scoped: read-only giving data from Planning Center, accounting writes to QuickBooks — nothing more.

Encryption at rest and in transit

All traffic uses TLS. OAuth tokens and credentials are encrypted at rest with versioned, rotatable keys, separate from the application database credentials.

Full audit trail

Every entry we post is recorded in an append-only event log: what posted, when, from which source period, and what happened afterward (retries, adjustments, mapping changes). Your auditor can trace every number in QuickBooks back to its source.

Revoke anytime

Inside the app, Organization settings → Connected apps → Disconnect deletes the stored Planning Center or QuickBooks authorization immediately and stops the sync — no email, no waiting on us. You can also revoke us from Planning Center's or Intuit's own app screens; the app notices and asks you to reconnect rather than failing silently. Entries already posted remain in your QuickBooks, because they're your books, and your history stays available to you until you ask us to delete it.

Wrong-church-file guard

When a payout file carries Planning Center's organization identifier, we check it against the connected church and refuse a mismatch outright — the file is rejected, not "handled." Some export formats carry no organization id at all; those are flagged as unverifiable in the preview, before you commit anything, rather than passed off as checked. A bookkeeper managing many churches always knows which of the two they are looking at.

Approval queue: nothing posts on a guess

Entries post automatically unless you say otherwise — Review first, where every entry waits in an approval queue until a human accepts it, is one radio button on the setup screen and switchable per church at any time. Either way, anything the matcher can't prove to the penny is flagged and held, never posted on a guess.

Payout files: parsed, then discarded

If you upload a payout CSV, we parse it, keep only the donation IDs, dates, amounts, fees and fund designations the matcher needs, and discard the raw file. Row-level donor names and emails are never retained.

Backups and recovery

The database (fund totals, donation IDs with their dates, amounts and fees, mappings, audit log — no donor identities) runs on managed Postgres with daily provider snapshots, and we keep a written, step-by-step restore procedure rather than an assumption. Scheduled off-platform dumps to independent storage are documented in our runbook and are being wired now — we would rather tell you exactly where that stands than claim it early.

Questions we welcome

If your finance committee, auditor, or denomination has a security questionnaire, send it over — we'd rather answer hard questions before you connect than after. Send it through our contact form or write to hello@givingbookssync.com — a questionnaire attachment is welcome by email.

See also: Privacy policy · Terms of service