Privacy policy
What this website collects, why, and how to have it removed.
Last updated: 4 August 2026
This page explains exactly what this website collects, why, and how to have it removed. It describes what the software actually does — not a generic template.
Who is responsible
Rayspring Ministry Digital is a ministry-focused digital service operated by Ray, with technical support from Rayspring Tech. There is no larger organisation behind it. For anything on this page, write to [email protected].
Rayspring Ministry Digital is not a registered company. It is run by one person, and the plan is to register it in its own right under a Christian ministry in the Philippines. Until that happens, the person responsible for the information on this page is Ray, and the way to reach him is the address above. This page will be updated when there is a registered entity to name.
What the contact form collects
When you send a message through the contact page, these fields are stored:
- Your name and email address
- Phone or WhatsApp number, if you give one
- Church or ministry name, country and preferred language, if you give them
- The kind of project, budget range and desired launch date you selected
- How you heard about us, if you tell us
- Your message
Alongside those, the system records the page you submitted from, your browser’s user-agent string, and a one-way hash of your IP address. The hash is used to stop the same person flooding the form and to detect duplicate submissions. Your actual IP address is never stored.
What the supported-ministry application collects
The application form is longer because the decision needs real information. It stores everything you type into it: your name and contact details, your ministry’s name, type, country and city, a description of your ministry, whether you have a website, your social media links, why you need a website, what you want it to do, which languages you need, what you could contribute financially, your preferred plan, and your referee’s name and contact details.
If you attach a supporting document, that file is stored on the server. It is not publicly accessible: it can only be opened by a signed-in administrator, through a link that checks permission first.
As with the contact form, a hashed IP is stored and the raw address is not.
Why it is collected
- To reply to you. That is the whole point of both forms.
- To assess an application. Supported places are limited, so applications are compared against each other.
- To stop abuse. Hashed IPs and submission fingerprints block spam floods and accidental double submissions.
Your details are never sold, rented, or passed to advertisers, and you will not be added to a mailing list because you used a form.
Cookies and local storage
This site sets one cookie, and only when it needs to:
rsmd_session— a session cookie. On the public site it exists to carry the security token that protects the forms; in the admin it keeps an administrator signed in. It contains a random identifier and nothing else, is marked HttpOnly and SameSite, and is deleted when you close your browser.
Your chosen colour theme is remembered in your browser’s local storage under
rsmd-theme. That never leaves your device and is not a cookie.
There are no advertising cookies, no tracking pixels, and no third-party social widgets.
Analytics
This site uses Google Analytics. It records which pages are visited and roughly where visitors come from, so it is possible to tell which parts of the site are useful. Your IP address is anonymised before it is stored, and the data is never used for advertising, never sold, and never linked to anything you type into a form.
Measurement id: G-BV0XT1H639
The paragraph above is written by the site itself from its own settings, not typed by hand. If analytics is ever switched on or off, it changes with it — nobody has to remember to update this page.
When you submit a form, a notification is sent to us and an acknowledgement is sent to you. These go through an authenticated SMTP mail server. The contents of that email — which is to say, what you wrote — pass through that provider in the ordinary course of delivery, exactly as any email does.
How long it is kept
- Enquiries and applications are kept while they are relevant to the conversation or the decision, and reviewed periodically after that.
- Security records — failed sign-in attempts and rate-limit counters — are deleted automatically after 30 days.
- Administrator activity logs are kept for up to a year.
How your information is protected
- The site is served over HTTPS.
- Every database query uses prepared statements, so submitted text cannot alter a query.
- Anything you type that is later displayed is escaped or passed through a strict HTML filter.
- Administrator passwords are stored as bcrypt hashes and are not recoverable, only resettable.
- Uploaded files are re-encoded, renamed, and stored in a directory where the server is configured not to execute anything.
- The folders holding configuration, application code and logs are blocked from the web.
No system is perfect, and this is an honest description of the measures in place rather than a promise that nothing can ever go wrong.
Asking to see or delete your information
Email [email protected] and ask. You can request a copy of what is held about you, a correction, or deletion. Deletion is done unless there is a specific reason to keep something, in which case you will be told what and why.
Links to other sites
Client websites, payment providers, YouTube, Vimeo and Facebook all have their own privacy policies, and this one does not cover them.
Children
This site is aimed at churches, ministries and organisations, not children, and does not knowingly collect information from anyone under 16.
Changes
If this policy changes, the date at the top changes with it.