Security Policy

Church finances, protected by Stripe.

TithePay is built so sensitive card data and donor records stay encrypted, separated, and out of our hands.

Every gift travels a secure path.

Step 1

Donor gives

Payment details are entered directly on Stripe's secure checkout — never on TithePay's servers.

Step 2

Stripe processes

Stripe handles card verification, fraud screening, and authorization under PCI DSS Level 1.

Step 3

Funds settle to you

The net gift is deposited straight into your church's bank account on your payout schedule.

Step 4

Records stay yours

Giving reports live in your dashboard, visible only to your church's accounts.

How we protect you

Eight commitments to your church's security.

Card data never touches our servers

When a donor gives, the payment is entered on a Stripe-hosted checkout page. TithePay never sees, stores, or transmits raw card numbers, CVVs, or bank login details.

PCI DSS Level 1 infrastructure

Donations are processed by Stripe, a PCI Service Provider Level 1 — the highest certification in the payments industry. Your church inherits that protection automatically.

Encryption in transit

Every page, form, and API call on TithePay runs over TLS (HTTPS). Data moving between your church, your donors, and the platform is encrypted end to end.

Your church's money goes to your bank

Donations settle directly into your church's own Stripe-connected bank account via Stripe Connect. TithePay never holds, pools, or touches church funds.

Least-privilege data access

Each church sees only its own donors, gifts, and reports. Access is enforced in the database itself — not just in the interface.

Donor privacy

Donor contact details and giving records are private to your church. We don't sell, share, or advertise against your congregation's data.

Verified internal operations

Administrative and automation actions (like follow-up tasks and payout tracking) require server-side verification keys — they can't be triggered from the outside.

Transparent fee handling

The 1.1% platform fee is applied at the payment level, visible in your dashboard, and routed only to the destination you chose — never skimmed silently.

Stripe is certified to PCI Service Provider Level 1, the most stringent level of certification in the payments industry. Because all card data is handled on Stripe-hosted pages, your church stays out of PCI scope entirely. Questions about this policy? Reach us through the Contact page.

Calm horizon at dawn

Simple Giving. Real Security.

Launch your giving page in minutes — with Stripe-grade protection built in.