Version: 2026-07-18.1 · Effective and last updated: July 18, 2026
1. Scope and identity
This policy applies to the Stewardex website, application, pilot program, support, and related communications. Stewardex is designed for organizations and authorized adult team members and is not directed to children under 13. Stewardex™ operates from Salem, Oregon. The planned legal entity is Stewardex, LLC, but formation is not represented as complete until accepted by the Oregon Secretary of State. The final responsible legal entity and physical address will be identified before public paid subscriptions are activated.
2. Information we process
- Account and acceptance: name, email, authentication status, organization membership, role, permitted departments, policy versions accepted, acceptance time, and pseudonymous technical evidence used to document acceptance.
- Organization information: name, campuses, addresses, contacts, ministries, rooms, and settings.
- Inventory and operations: assets, identifiers, locations, condition, checkout history, maintenance, reservations, audits, labels, files, and optional value estimates.
- Support and pilot: requests, feedback, communications, diagnostics, and resolution history.
- Technical and security: browser and device type, approximate network information, timestamps, application errors, security events, and service activity.
- Billing: plan, customer and subscription identifiers, payment status, and invoice references. Payment-card details are processed by the payment provider and are not intended to be stored by Stewardex.
3. Sources
Information comes from users, organization administrators, invited teammates, activity within the service, connected providers, optional customer-directed integrations, and communications with Stewardex. An organization may enter information about borrowers, volunteers, vendors, or contacts and is responsible for providing any required notice.
4. Purposes and legal grounds
Stewardex uses information to provide and secure the contracted service, authenticate users, isolate workspaces, enforce permissions, deliver invitations and support, generate labels and exports, process billing, detect abuse, diagnose errors, keep required records, and improve reliability. Depending on location and context, processing is based on providing the service, legitimate operational and security interests, legal obligations, or consent where required.
5. Religious affiliation and sensitive information
Use of a church workspace can reveal or imply religious affiliation, which some privacy laws treat as sensitive. Stewardex uses that context only to provide and protect the customer’s workspace and does not use it for targeted advertising. The service is not presently intended for pastoral counseling notes, medical information, children’s data, confidential donor financial details, government identifiers, or payment-card data.
6. How information is shared
Information may be shared with the customer’s authorized administrators and users according to their roles; with providers listed on the Subprocessor List; with an integration a customer directs Stewardex to use; during a corporate transaction subject to appropriate protection; or when reasonably necessary to comply with law, protect rights and safety, or address abuse. Stewardex does not sell personal information or share it for cross-context behavioral advertising.
7. Retention, export, and deletion
Active workspace data is retained while needed to provide the account. After verified closure, production customer data is scheduled for deletion or de-identification within 30 days; protected backups may take up to 90 days to age out. Security, audit, policy-acceptance, support, billing, tax, fraud-prevention, and dispute records may be retained longer when reasonably necessary, generally up to seven years for legal or financial records. Authorized administrators can use available exports before closure.
8. Cookies and browser storage
Stewardex uses authentication cookies and browser storage necessary to keep users signed in, remember settings, and support active workflows such as audits and printer profiles. Stewardex does not currently use third-party advertising cookies.
9. Security and incident response
Stewardex uses safeguards designed for the service, including authenticated requests, role controls, tenant separation, audit records, and managed infrastructure. No internet service can guarantee absolute security. Stewardex investigates suspected incidents and provides notices as required by applicable law and signed customer agreements. Security reports may be sent to security@getstewardex.com.
10. Choices and privacy requests
Depending on applicable law, including the Oregon Consumer Privacy Act when its coverage thresholds and requirements apply, a person may request access, correction, deletion, portability, restriction, or an explanation of processing, and may appeal a denied request. Send requests to privacy@getstewardex.com. Stewardex may verify identity and organization authority. When Stewardex acts only as a church customer’s processor, the request may be directed to that church as the responsible controller. Authorized administrators can also update many records directly. Stewardex does not use personal data for solely automated decisions that produce legal or similarly significant effects.
11. International processing
Providers may process information in the United States and other locations where they operate. Where law requires a transfer mechanism or additional terms, Stewardex and the customer will put those measures in place before offering the affected service.
12. Changes and contact
Material changes will be posted with a revised version and communicated to subscription owners when appropriate. Users may be asked to acknowledge a new policy version before continuing. Contact privacy@getstewardex.com for privacy questions or requests.