Privacy Policy
Version: v1.0 Effective date: 2026-05-02 Last updated: 2026-05-02
CrossRoads Missions ("CrossRoads," "we," "us," or "our") operates the CrossRoads Missions mobile application (iOS and Android) and the websites at https://crossroadsmissions.com and https://crossroadsmissions.app (together, the "Services"). This Privacy Policy explains what information we collect from you when you use the Services, how we use that information, and the choices you have.
CrossRoads Missions is a Kentucky-based 501(c)(3) faith-based missions organization. The Services exist to support participants in mission trips and the field super-users who lead them. The Services are NOT a social network, a children's product, or an advertising platform.
If you have questions, contact us at info@crossroadsmissions.app.
1. Quick summary
- We collect the minimum information needed to enroll you in a trip and let you participate.
- We do not sell your data, share it with advertisers, or use it for behavioral targeting.
- The app is intended for users 13 and older. Users under 13 are blocked at signup.
- Users 13–17 require parental or guardian consent before participating.
- You can request access to, correction of, or deletion of your information at any time by emailing info@crossroadsmissions.app.
2. Information we collect
2.1 Information you provide directly
- Account email address (used as your sign-in identity, processed by Supabase Auth).
- Display name (you choose this; you can change it in your profile).
- Birthdate — year and month only. We deliberately do not collect the day of the month, to minimize the personally identifying information we hold. We use the year + month to confirm you are at least 13 and to route you through the appropriate consent flow.
- Parent or guardian email address, if you are 13–17. This is collected only to send the parental-consent email and is deleted on consent expiry (7 days) if no consent is recorded.
- Trip enrollment details you submit when accepting an invite link or QR code (the trip name and field are pre-filled from the invite token; you do not provide them yourself).
- Optional access-request reason if you sign up without an invite link or QR code. You may explain why you are requesting access; that explanation is read by an admin who decides whether to enroll you.
2.2 Information collected automatically
- Device and session metadata: when you sign in, our authentication provider records the time of sign-in, the IP address used to sign in, and the user-agent of your device. This is standard authentication audit data and is retained per Supabase's defaults.
- Approximate location — only when you opt in. When you tap "Join the [field] field" on the home screen, we use your phone's foreground GPS to confirm you are within ~200 meters of a CrossRoads field base. We do not store your coordinates. We use them once, in memory, to confirm proximity, and discard them. We do not run background location tasks. You may decline the location prompt; no feature other than the optional geofence join button is affected.
- Crash and error reports (via Sentry). When the app encounters an error, we collect a stack trace and the device model. IP address scrubbing is enabled in our Sentry project, so we do not associate crash reports with your IP address.
- Product analytics events (via PostHog). We record events like "screen viewed," "trip joined," and "consent recorded" so we can understand how the app is used and fix issues. Autocapture is disabled; we only record events we explicitly send. Person profiles are created only for users we have already identified by their account.
2.3 Parental-consent records (for 13–17 users)
When a 13–17 user provides a parent or guardian email address, we create a parental_consents record that includes:
- The child's account ID.
- The parent or guardian email address.
- A single-use, cryptographically-random consent token (sent to the parent via email).
- The timestamp the parent clicks the consent link, and the IP address and user-agent used at that moment.
The IP and user-agent are recorded as a light audit trail and are not used for marketing.
If consent is not recorded within 7 days, the pending account (and the corresponding parental_consents row) are deleted automatically by a scheduled database job.
3. How we use your information
We use the information we collect to:
- Authenticate you to the app via magic-link sign-in.
- Enroll you in the right trip and field when you redeem an invite link or scan a QR code.
- Confirm you are at a field base when you opt in to the geofence join feature.
- Verify parental consent when you are 13–17.
- Record your acceptance of these documents at first launch (timestamp and version stored).
- Communicate with you about your enrollment, your access request, and your trip.
- Operate, maintain, and improve the Services (debugging, analytics, fixing bugs).
- Comply with legal obligations and respond to lawful requests.
We do not use your information to build advertising profiles. We do not sell your information. We do not share your information with advertisers.
4. Children under 13
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If a user reports a birthdate at signup that places them under 13, we automatically delete the account within seconds. The deletion cascades to the user's profile row and any related records.
If you believe a child under 13 has provided personal information through the Services, please contact us at info@crossroadsmissions.app and we will delete the information immediately.
5. Children 13–17 (parental consent)
If you are 13–17, the app will ask for the email of your parent or guardian. We will send your parent a short email with a one-time link. When your parent taps the link and consents, your account becomes active.
We do not currently use the FTC's verifiable-parental-consent methods (such as government ID, payment-card verification, or knowledge-based questions). The Services are categorized in Apple's App Store as "Lifestyle / Religion & Spirituality," not "Made for Kids," and our parental-consent design follows the "light-path" pattern documented in the COPPA FAQ for general-audience apps with 13–17 users.
If consent is not recorded within 7 days, your pending account is automatically deleted.
6. Third parties we use
We use a small number of vendors to operate the Services. Each is named below, with a description of the data they receive and a link to their own privacy policy.
| Vendor | Purpose | Data shared | Their privacy policy |
|---|---|---|---|
| Supabase | Database, authentication, storage, realtime, Edge Functions | Account email, profile fields, trip enrollment data, parental-consent records | https://supabase.com/privacy |
| Sentry | Crash and error reporting | Stack traces, device model. IP scrubbing on. | https://sentry.io/privacy/ |
| PostHog | Product analytics | Event names, screen names, user account ID. Autocapture off. | https://posthog.com/privacy |
| Resend | Transactional email delivery (magic-link sign-in, parental-consent emails, access-request decisions) | Account email, parent or guardian email | https://resend.com/legal/privacy-policy |
| Cloudflare | DNS for our domains | Standard DNS query metadata | https://www.cloudflare.com/privacypolicy/ |
| Vercel | Hosting for the admin web portal | Standard request metadata (IP, user-agent) for admin users | https://vercel.com/legal/privacy-policy |
| Vimeo | HQ video embeds (Crossroads-produced devotional content) | Standard Vimeo embed metadata | https://vimeo.com/privacy |
| YouTube (Google) | Per-field video embeds (unlisted) | Standard YouTube embed metadata | https://policies.google.com/privacy |
| Apple / Google Play | App distribution and Universal Links / App Links | Standard store-attributed data | Apple: https://www.apple.com/legal/privacy/ · Google: https://policies.google.com/privacy |
We do not use third-party advertising networks. No ad SDKs are integrated into the Services. No behavioral-advertising profiles are created.
A future release will add features for user-submitted photos, videos, and donation processing. When those features ship, this Privacy Policy will be updated and you will be notified the next time you open the app.
7. Storage and retention
Data is stored on Supabase's managed cloud infrastructure (US region by default). We retain your account information for as long as you have an account. If you delete your account, we delete your profile, trip-participation rows, and any parental-consent records. Backup snapshots may persist for up to 30 days before they are overwritten.
Crash logs in Sentry are retained for 90 days by default. Analytics events in PostHog are retained per the PostHog free-tier defaults (currently 1 year).
Pending accounts (13–17 users awaiting parental consent) are deleted automatically 7 days after creation if consent has not been recorded.
Under-13 accounts are deleted within seconds of detection; no retention applies.
8. Your choices and rights
- Access: You may request a copy of the personal information we hold about you.
- Correction: You may request that we correct any inaccurate information.
- Deletion: You may request that we delete your account and associated data.
- Withdraw consent (13–17 users): A parent or guardian may revoke consent at any time, which will result in account deletion.
To exercise any of these rights, email info@crossroadsmissions.app. We will respond within 30 days.
If you are in the United States, you may have additional state-specific rights (such as those provided by the California Consumer Privacy Act). We honor those rights as required by law.
9. Security
We use industry-standard technical and organizational measures to protect your information, including:
- TLS encryption for all client–server traffic.
- Row-level security policies in our database that scope every read and write to the appropriate user.
- Cryptographically-random tokens (32 bytes) for invite links, QR codes, and parental-consent links.
- Single-use enforcement on parental-consent links (a consumed link cannot be replayed).
- Audit logs for sensitive operations (sign-in, account deletion, consent recording).
No system is perfectly secure. If you become aware of a vulnerability or a potential incident, please email info@crossroadsmissions.app.
10. International users
CrossRoads Missions is a Kentucky-based organization and operates the Services from the United States. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of the document and post the new version at https://crossroadsmissions.com/privacy. If the change is material, we will notify you in the app the next time you open it.
12. Contact us
CrossRoads Missions Louisville, Kentucky, USA Email: info@crossroadsmissions.app
Privacy Policy generated by Termly. Adapted to CrossRoads Missions' actual data practices in accordance with the Termly free-tier license. The Termly attribution is preserved here per the free-tier license terms.