This page is a practical overview of BaptistFinder's current data and security practices. It helps visitors and church representatives understand the system; it is not a claim of certification or a substitute for the Privacy Policy.
Data map
| Information | Visibility | Main purpose |
|---|---|---|
| Approved church details and source links | Public | Operate the searchable directory |
| Pending church submissions | Authorized administrators | Review before publication |
| Contact and update requests | Authorized reviewers and relevant providers | Respond, correct, or remove information |
| Featured Supporter applications | Authorized administrators | Review eligibility and arrange activation |
| Security and delivery logs | Relevant providers and authorized operators | Deliver the site, diagnose faults, and prevent abuse |
| Google Analytics data | Google and authorized operators | Measure and improve the site only after opt-in |
Current service providers
- Cloudflare: hosting, HTTPS delivery, security controls, and Turnstile.
- Supabase: database, row-level access policies, and administrator authentication.
- Google: optional Analytics. Historical listing-update responses may remain in Google Forms; new requests use Supabase.
- jsDelivr: delivery of a pinned Supabase browser library.
Technical safeguards in this site
- HTTPS-only delivery and browser security headers.
- A restrictive Content Security Policy limiting scripts and embedded frames to named services.
- Database Row Level Security: public visitors can read only published listings, while private records require an allowlisted administrator account.
- Administrator password authentication plus Cloudflare Turnstile, with server-side validation handled by Supabase Auth.
- Escaped text and validated links when database content is displayed.
- Limited database grants so public forms cannot publish, verify, or promote their own submissions.
- Honeypot and timing checks to reduce basic automated form spam.
- Optional analytics that stays off until a visitor accepts it and is disabled on the admin page.
- No direct file-upload feature and no collection of payment-card details.
Organizational safeguards
- Only explicitly allowlisted accounts may access administration records.
- Submissions are reviewed before publication or paid-feature activation.
- Verification and paid placement are separate statuses.
- Correction, removal, privacy, and IP concern channels are published.
- Private records should be deleted or anonymized when no longer reasonably needed.
Important limits
No website is perfectly secure. Client-side spam controls do not replace provider-level rate limiting, security monitoring, account protection, backups, and regular review of Supabase and Cloudflare settings. BaptistFinder does not claim ISO, SOC, PCI, or government certification. Payment providers, Google, Cloudflare, Supabase, and linked church sites operate under their own terms.
Data requests and incidents
To request access, correction, removal, or another privacy action, contact baptistfinderteam@gmail.com or use the Contact page. Include the relevant church or page and enough information to identify the record. If BaptistFinder becomes aware of a material incident, it will investigate, contain the issue where possible, preserve necessary records, and make notifications required by applicable law.
Legal framework
BaptistFinder's privacy program is designed with the Philippine Data Privacy Act of 2012 and the principles of transparency, legitimate purpose, and proportionality in mind. See the National Privacy Commission's official Data Privacy Act page. Questions about how a rule applies to a particular situation should be taken to a qualified Philippine professional.