Privacy policy
Last updated: July 28, 2026
This Privacy Policy explains how KehillaHQ, LLC, a Washington limited liability company(“KehillaHQ,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information in connection with our congregation-management software and websites (the “Service”). It covers both this website, kehillahq.com, where congregations apply for founding access, and the KehillaHQ product itself, where a congregation keeps its records. Read it together with our Terms of service. You can reach us any time at hello@kehillahq.com.
A note on roles
For the personal information that a congregation’s administrators enter about their members (“Member Data”), the congregation is the controller and KehillaHQ acts as a processor on the congregation’s behalf. For the information we collect directly about account holders and website visitors, KehillaHQ is the controller. If you are a member of a congregation, please direct requests about your data to your congregation first.
Who we are
KehillaHQ provides congregation software for small Jewish communities, built and run by Tova Soroka. KehillaHQ, LLC is the entity responsible for the Service. For anything in this policy, write to hello@kehillahq.com.
What the site collects
When you apply through the form on this site, we collect what you enter: your name, email, congregation or community name, your role, roughly how many Households you serve, where your congregation is in its decision, and any free text you choose to add. To keep out automated spam we use a hidden honeypot field and Vercel BotID, which checks that a submission comes from a real browser.
We use this to reply to you about founding access and to keep you posted about KehillaHQ. Your application is recorded in our Notion CRM, Resend sends your confirmation email and holds our contact list, and the site is hosted on Vercel.
What the product collects
- Account data. Name, email, and role of the administrators and staff who create and use accounts.
- Member Data. Records that congregation administrators enter or upload about their Members and Households, which may include names, contact details, family and household relationships, and membership status. This is sensitive information and we treat it accordingly.
- Yahrzeit and lifecycle data. Memorial dates and related details, which may reference deceased individuals and dates of death.
- Pastoral notes. Where the Service supports them, notes that may be sensitive or confidential to the congregation and its clergy.
- Communication data. The content and metadata of communications sent through or to the Service, for example reminder emails.
- Technical data. IP address, browser and device information, and usage and log data generated when you use the Service.
How we collect it
- Directly from you when you sign up, configure your account, or contact us.
- From administrators who enter or upload Member Data, including by CSV import.
- Automatically through your use of the Service (log and usage data).
- From member interactions with communications the Service sends on a congregation’s behalf.
How we use it
We use personal information to:
- Provide, operate, maintain, and secure the Service;
- Send transactional and lifecycle emails, for example account, onboarding, and reminder messages;
- Diagnose problems, debug, and improve reliability and performance;
- Communicate with you about your account, support requests, and important changes; and
- Comply with legal obligations and enforce our Terms.
We do not sell personal information, and we do not use Member Data for advertising.
Legal bases for processing
Where applicable law such as the GDPR requires a legal basis, we rely on performance of a contract (to provide the Service you or your congregation requested), legitimate interests (to secure, maintain, and improve the Service, balanced against your rights), and consent (where required, for example for certain communications, which you may withdraw at any time).
Who we share it with
We share personal information with service providers who process it on our behalf, under contracts that require appropriate safeguards. Our current subprocessors are:
- Supabase. Database and data hosting (United States, AWS us-east-2 region).
- Vercel. Application and site hosting, plus BotID anti-abuse checks on the site form.
- Resend. Transactional and lifecycle email, and our contact list.
- Stripe. Payment processing for payments made to KehillaHQ. Card details go to Stripe directly and never touch our systems.
- Anthropic. AI features in the product. When you import a spreadsheet of Members, contributions, or Yahrzeits, we send its column headings and some of its rows to Anthropic’s Claude model, which suggests how your columns map to our fields and helps match names to existing records. Anthropic processes this on our behalf and does not use it to train its models.
The site’s application form also flows to our Notion CRM, where we track founding applications. We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets.
Your records belong to you
Your records belong to your congregation, not to us. You can export everything as CSV at any time, no permission needed. If KehillaHQ ever winds down, your congregation gets at least 90 days notice and a full export of its records as clean spreadsheets, so your data is never locked in with us.
How long we keep it
We keep application data while it is relevant to the founding process, and we delete it on request. For congregation accounts, two situations can end the relationship, and we handle each differently:
- If you close your congregation’s account: you have a 30-day window after termination to export your records. After that window we delete them in the ordinary course, subject to any legal retention obligations and routine backup cycles.
- If KehillaHQ winds down as a company: we will give your congregation at least 90 days notice and a full export of its records as clean spreadsheets. This is the pledge shown on our landing page, and it holds here too.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, or object to the processing of your personal information, and to withdraw consent. Account holders and visitors can contact hello@kehillahq.comto exercise these rights. Congregation members should contact their congregation’s administrator first, since your data is controlled by your congregation, and we will support them in responding. We will respond within the timeframe required by applicable law, and in any case within 30 days of a verifiable request. We will not discriminate against you for exercising your rights.
What we don’t do
- We don’t sell your data.
- We don’t share it with advertisers or ad networks.
- We don’t use your records to train AI models, and the AI provider that powers our import tools doesn’t train on them either.
Data security
We use technical and organizational measures designed to protect personal information. Each congregation’s data is kept separate, and that separation is enforced at the application level: every request is scoped to the congregation making it, so one congregation cannot reach another’s records. Access within a congregation is role-based, limited to the people that congregation chooses. Data is encrypted in transit over HTTPS and encrypted at rest using our managed cloud database’s default encryption. No system is perfectly secure, and we cannot guarantee absolute security.
Children’s data
Congregations keep records of whole families, so Member Data often includes basic information about children, such as names, birthdays, and family relationships. That information is entered by a congregation’s adult administrators under the congregation’s own authority and consent practices, and we protect it the same way we protect all Member Data under this policy. The Service itself is built for administrators and staff, and we do not knowingly collect personal information online directly from children under 13. If you are a parent or guardian with a question about a child’s record, contact your congregation first, and we will support them in correcting or deleting it.
International data transfers
The Service is hosted in the United States. If you or your congregation’s members are located outside the United States, your information will be transferred to and processed in the U.S. If we ever transfer personal information subject to laws that require additional safeguards, we will put appropriate measures in place.
Payments
Payments to KehillaHQ, such as your congregation’s founding membership, run through Stripe, our payment processor. Stripe handles and stores card details on its own systems; card numbers never touch ours. When Membership commitments ship inside the product, payments from Members will run through Stripe the same way. If we ever add other payment or integration partners, we will name them in this policy before they handle your data.
If something goes wrong
If a data breach ever affects your congregation, we will tell you promptly and plainly, with what we know and what we are doing about it.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will provide reasonable notice, for example by email or in-product notice, and update the date at the top. Your continued use of the Service after changes take effect means you accept the updated policy.
Contact
Questions or requests about this policy: contact us at hello@kehillahq.com. KehillaHQ, LLC.