Cookie Policy
Last updated:
1. What Cookies Are & What We Use
To make Parish Glow work, we need to store a small amount of information in your browser. We use cookies, local storage, and similar technologies to keep you logged in, secure your parish's data, and help us understand when the application crashes so we can fix it.
Scope of this Policy: This Cookie Policy applies strictly to the Parish Glow software application served at parishglow.com. The separate marketing website used to promote Parish Glow is out of scope for this document and is governed by its own distinct Cookie Policy.
Below is the exact taxonomy of cookies and trackers deployed by the Parish Glow application:
| Name | Set By | Purpose | Type | Duration | Sub-processor |
|---|---|---|---|---|---|
sb-<project-ref>-auth-token | Supabase | Manages OAuth and PKCE JSON Web Token access and refresh tokens to maintain secure user authentication across requests. | Essential | Session | Supabase |
_vercel_jwt | Vercel | Enforces edge-level access control, deployment protection, and internal application routing within the Vercel infrastructure. | Essential | Session | Vercel |
__stripe_mid, __stripe_sid | Stripe | Detects fraudulent transaction patterns, ensures 3D Secure checkout compliance, and prevents financial loss during payment flows. | Essential | 1 Year / Session | Stripe |
| CSRF nonces | Parish Glow | Cryptographic nonces utilized strictly for Cross-Site Request Forgery (CSRF) protection. | Essential | Session | None |
sentryReplaySession | Sentry | Disabled by default unless explicit upfront consent is captured. Replay-capable SDK code is dynamically imported only after consent state is resolved. When enabled, records only masked DOM and interactions needed for debugging and does not capture text input contents, passwords, payment fields, pastoral notes, minor profiles, or other sensitive fields. | Analytics | Up to 60 Mins | Sentry |
sentry-trace, baggage | Sentry | Facilitates distributed tracing to link frontend user actions with backend database latency and server errors. | Analytics | Session | Sentry |
2. Essential Cookies
In plain English: These are the cookies that keep the lights on. Without them, you couldn't log in, pay for your parish subscription, or use the app securely.
Under the ePrivacy Directive, the General Data Protection Regulation (GDPR), and the California Privacy Rights Act (CPRA), cookies categorized as "Strictly Necessary" or "Essential" are exempt from prior consent requirements and cannot be disabled via opt-out mechanisms. Our essential cookies include Supabase tokens for authentication, Vercel tokens for secure infrastructure routing, and Stripe tokens for fraud prevention.
Stripe cookies are treated as essential only to the extent they are used for checkout security, fraud prevention, payment processing, and related compliance. Parish Glow maintains merchant and data-processing terms restricting Stripe from using Parish Glow checkout telemetry for independent advertising, sale, or sharing purposes outside those payment and security functions.
3. Analytics Cookies
We use Sentry to monitor application health. Sentry error monitoring may capture technical diagnostics such as stack traces, browser metadata, and performance traces. Sentry Session Replay remains off by default unless and until the user has given explicit, upfront consent; replay-capable SDK code is dynamically imported only after consent state is resolved; when enabled, text inputs, passwords, payment fields, pastoral notes, minor profiles, and other sensitive fields are masked or blocked so Parish Glow does not intentionally record keystroke contents or sensitive page content.
Because Sentry Session Replay records interaction telemetry that is not strictly necessary to provide the requested Service, Parish Glow does not initialize replay code on page load. Replay-capable SDK code is dynamically imported only after consent state is resolved and the user has affirmatively opted in, and it remains disabled for users who opt out, broadcast GPC, or are identified as minors.
4. Marketing Cookies
We do not use marketing cookies in the Parish Glow application.
You are here to manage your parish's music ministry, not to be tracked across the internet. Unless a third-party integration is misconfigured, the Parish Glow application deploys zero marketing or cross-context behavioral cookies. We do not use Facebook Pixels, Google Ads trackers, or similar advertising technologies within the logged-in application.
5. Server-Side Tracking
To measure aggregate page views (such as how many times a particular song's sheet music is accessed), we use Vercel Web Analytics. This is a server-side tracking methodology that does not place third-party cookies on your device. Instead, it tracks unique visitors by generating a temporary hash of the incoming request, combining your IP address and User-Agent. This hash is automatically discarded after 24 hours.
In plain English: Even though we don't put a cookie on your computer for this, the law still considers it tracking.
We recognize that server-side tracking does not bypass privacy legislation. Under the CCPA and CPRA, IP addresses and persistent device hashes are explicitly defined as Personal Information. Routing telemetry through a first-party server before forwarding it to an analytics endpoint still constitutes the active collection of personal data.
6. Your Choices, GPC, and Do Not Sell or Share
Depending on your jurisdiction, you have specific rights regarding how tracking technologies are deployed on your device.
Global Privacy Control (GPC)
Parish Glow explicitly recognizes and honors the Global Privacy Control (GPC) browser signal. As of January 1, 2026, twelve US states mandate the automated recognition of GPC signals:California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas.
If your browser broadcasts a GPC signal, our application will automatically treat it as a valid request to opt out of data sales and sharing, overriding any default opt-in states without requiring you to interact with a banner.
Do Not Sell or Share My Personal Information
The California Privacy Rights Act (CPRA) broadly defines a "sale" as exchanging personal information for valuable consideration, and "sharing" as transferring personal information for cross-context behavioral advertising.
While we do not sell your data to data brokers, the use of certain analytics tools may be considered a "share" under California law. To exercise your right to opt out of sale or sharing, use the Do Not Sell or Share My Personal Information homepage link, the cookie/account privacy control, or email privacy@parishglow.com. The application presents equally prominent Accept All and Decline All choices, makes declining analytics no more difficult than accepting them, honors GPC as an automatic opt-out signal, and blocks analytics or replay trackers until the relevant consent or opt-out state is resolved.
Cookie Settings
7. Changes to This Policy
As Parish Glow expands its feature set and as privacy regulations evolve, we will dynamically update this cookie inventory. We will notify Parish Administrators of material changes to this policy via email or an in-app announcement. Your continued use of the Service after such updates constitutes acknowledgment of the revised policy.
8. Contact
Parish Glow, operated by Jeff Bonilla as a California sole proprietorship; LLC formation in progress.
Mailing Address:
Parish Glow
1014 Broadway #2014
Santa Monica, CA 90401
Email Channels:
- Privacy & Data Requests: privacy@parishglow.com, the cookie/account privacy control, and the Do Not Sell or Share My Personal Information homepage link. Postal notices may be sent to the mailing address above once mail intake is active, but email and web/account controls are the operative privacy-request channels while mail verification is pending.
- Legal Notices: legal@parishglow.com
- General Support: support@parishglow.com