Skip to main content

Sanctuary

Privacy Policy

Effective date: June 2026  ·  Last updated: June 2026

The Hero Church (“we,” “us,” “our”) is a 508(c)(1)(A) faith community. We respect every seeker who steps into our sanctuary. This policy tells you plainly what personal information we collect, why we collect it, who we share it with, how long we keep it, and what rights you have over it.

This policy applies to herochurch.org and any associated sub-pages. It does not apply to third-party sites we link to — those sites have their own privacy practices.

1. Information we collect

We collect information in three ways: information you give us directly, information generated automatically when you visit the site, and information our payment and commerce processors share back with us to fulfill your order.

Information you give us

  • Email address — when you join our mailing list or newsletter.
  • Name, email, and shipping address — when you place an order.
  • Phone number — optional, collected at checkout for delivery coordination.
  • Age confirmation — when you pass through the sanctuary gate (21+) and at checkout.
  • Messages you send — when you contact us via the contact form or chat.

Information collected automatically

  • Page views and navigation — which pages you visit and in what order.
  • Device and browser type — used to improve the experience across devices.
  • Referring source — where you came from (e.g. a search engine or link).
  • Session identifiers — anonymous random IDs that link page views within a visit.
  • Fingerprint ID — a privacy-respecting browser fingerprint used to count unique visitors and power our embedded AI chat assistant (Kit). No persistent device tracking beyond this session.
  • IP address — logged transiently by our hosting infrastructure; not stored in our analytics tables.

Order and payment information

When you place an order, Stripe processes your payment directly. Your card number, CVV, and full card details never touch our servers — they go straight to Stripe and are subject to Stripe's privacy policy. We do receive and store: your order number, the items ordered, shipping address, total amount, and a record of your age and sanctuary acknowledgment, as required for fulfillment and legal compliance.

2. How we use your information

  • To fulfill and ship your order.
  • To send you a transactional confirmation email after your order is placed.
  • To send you sanctuary updates and newsletters — only if you opted in.
  • To respond to your messages and support requests.
  • To improve the site and shopping experience using aggregate analytics.
  • To power the Kit AI chat assistant with session context (no cross-session tracking).
  • To comply with applicable law (accounting, tax, regulatory recordkeeping).

We do not use your information to train AI models, build advertising profiles, or sell your data to brokers or marketers. Ever.

3. Third parties we work with

We share personal information only with the processors listed below, and only to the extent each needs it to do its job. All are under contractual obligations consistent with this policy.

Stripe

Payment processing. Stripe collects and processes card details directly under its own privacy policy (stripe.com/privacy). We receive confirmation of payment and a transaction ID.

Dibs (our commerce backend)

Order management, inventory, and fulfillment records. Dibs is operated by us (Braintied) and stores order and customer data on our behalf in a dedicated database.

Resend

Transactional and newsletter email delivery. Resend receives your email address and the content of emails we send you. We send from mail.herochurch.org.

Shipping carriers

Delivery of physical orders. Carriers receive your name, shipping address, and package details. Your carrier will also send you tracking notifications directly.

Vercel / Cloudflare

Hosting infrastructure and CDN. These providers process request logs and cookies as part of serving the site. They do not receive analytics or order data.

We may also disclose information where required by law, court order, or to protect the rights or safety of our community.

4. Cookies and similar technologies

We use a small set of cookies and local storage values to operate the site. We do not use advertising or cross-site tracking cookies.

  • Cart cookie / localStorage — stores your cart items between sessions so you don’t lose them.
  • Age-gate cookie — records that you confirmed you are 21 or older at the sanctuary gate, so you are not asked again on the same device.
  • Session analytics — an anonymous session ID that lets our analytics count page views within a visit without identifying you personally.
  • Stripe cookies — Stripe sets cookies as part of its fraud-prevention system when the payment form is loaded.

Disabling cookies in your browser settings may prevent the shop from functioning correctly (cart and checkout both rely on browser storage).

5. How long we keep your information

  • Order records — retained for 7 years to satisfy accounting and tax requirements, then deleted.
  • Email marketing lists — retained until you unsubscribe, after which we remove you within 30 days.
  • Analytics data — aggregated and anonymous after 90 days; raw session data deleted at that point.
  • Contact messages — retained for 12 months, then deleted unless we are required to keep them.
  • Age confirmation records — retained alongside the associated order record.

6. Your privacy rights

Depending on where you live, you may have the following rights over your personal information. We honor these requests for everyone, regardless of jurisdiction.

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to correct inaccurate information.
  • Deletion — ask us to delete your personal information. Note: we may need to retain certain order records for legal compliance.
  • Opt-out of marketing — unsubscribe from our newsletter at any time using the link in any email, or by contacting us.
  • Data portability — request your information in a machine-readable format.
  • Non-discrimination — exercising these rights will not affect your access to the sanctuary.

California residents: under the CCPA you have the right to know what personal information we collect, to delete it, and to opt out of the sale of your information. We do not sell personal information.

EEA / UK residents: under the GDPR our lawful basis for processing order and fulfillment data is contract performance. Our lawful basis for analytics is legitimate interest. Our lawful basis for marketing emails is consent. You have the right to lodge a complaint with your supervisory authority.

To exercise any of these rights, email us at heromyco@proton.me. We will respond within 30 days.

7. Children

The Hero Church is a sanctuary for adults 21 years of age or older. We do not knowingly collect personal information from anyone under 21. If you believe a minor has provided us with personal information, please contact us and we will delete it promptly.

8. Security

We take reasonable technical and organizational measures to protect your personal information — including TLS encryption in transit, access controls, and hosting on SOC 2-certified infrastructure. No system is perfectly secure, but we take the stewardship of your information seriously.

9. Changes to this policy

We may update this policy as our practices evolve. When we make material changes we will update the effective date at the top and, where feasible, notify you by email. Your continued use of the site after the updated date constitutes acceptance of the revised policy.

10. Contact

Questions, requests, or concerns about this policy can be sent to:

The Hero Church

heromyco@proton.me

Last updated June 2026. The Hero Church · operated by Braintied Inc.