Privacy Policy
Last updated: August 23, 2026
Notice at Collection
This short notice summarises our privacy practices. The full details are in the numbered sections below.
- What we collect: Account details from parish staff, the Mass schedule and register your parish records, and the name, contact details and intention text a parishioner submits when asking for a Mass. See Section 3.
- Why we collect it: To run your Mass intention register, publish your bulletin and sacristy sheet, produce diocesan reports, take payment for the subscription, send transactional email, and keep the platform secure. See Section 4.
- Who we share it with: Only with vetted service providers acting on our behalf, such as hosting, database, payments and email. See Section 7.
- We do not sell your personal data: We do not sell personal data, we do not use it for targeted advertising, and we do not use it to train AI models. Memento does not use artificial intelligence to generate any part of your register.
- Sensitive data: A Mass intention is inherently religious, and often names a deceased person or refers to someone's illness. We treat intention text as sensitive personal data and process it only to fulfil the request. See Section 3.4.
- Your rights: Depending on where you live you can request access, correction, deletion or portability. Email privacy@greetyr.com. See Section 10.
1. Introduction and Scope
Greetyr ("Greetyr", "we", "us" or "our") operates Memento, a Mass intention register and scheduling service for Catholic parishes (the "Service"). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. It applies to the Service, the Memento website, the public Mass request form we host for each parish, the calendar feed, and transactional messages we send.
It describes practices for two groups of people:
- Parish staff and account holders, who create accounts, record intentions, and manage the register from the Memento dashboard.
- Parishioners, who request a Mass through a parish's public request page or whose intention is entered by parish staff on their behalf.
For parishioner data recorded through a parish's register, the parish is the controller (or business) of that data and Memento acts as a processor (or service provider) on the parish's behalf. A parishioner with questions about a particular parish's practices should contact that parish. For account, billing and Service level data, Memento is the controller.
2. Who We Are
Memento is a Greetyr product, operated from Austin, Texas. You can reach us at:
- Greetyr
- 5900 Balcones Drive, STE 100
- Austin, TX 78731
- USA
- Email: privacy@greetyr.com
3. Information We Collect
3.1 Parish Staff Account Data
When you create or use a staff account, we collect:
- Email address and name
- Password, stored only as a salted hash by our authentication provider
- Role within the parish account (administrator, staff or celebrant)
- Parish membership and last sign in time
- An audit trail of actions taken in the register, including who made a correction and when
3.2 Parish Configuration and Register Content
To operate your register, your parish provides and we store:
- Parish name, time zone, public address slug and contact preferences
- The Mass schedule as recurring rules, plus one off Masses, holy days and cancellations
- Clergy names and whether each is a priest or a deacon
- Bulletin and sacristy sheet formatting preferences
- The Mass intention register itself, including entry numbers, intention text, dates accepted and celebrated, and the celebrant assigned
3.3 Parishioner Data
When a parishioner requests a Mass, whether through the public form or by telephone at the parish office, we collect on behalf of the parish:
- Name, and an email address or telephone number so the parish can confirm
- The intention itself, as free text, and whether it is for a deceased or a living person or another purpose
- The Mass or date requested, and any note about the preference
- Whether the intention may be printed in the bulletin
- The offering amount, method and status, and whether it has been received or forwarded
- Whether a Mass card was asked for and who it should be addressed to
- A short public reference code issued so the parishioner can ask the office about their request
3.4 Sensitive Personal Data
Several United States state privacy laws, including the Texas Data Privacy and Security Act and the California Consumer Privacy Act, treat information about religious beliefs and health as sensitive personal data. A Mass intention is by its nature religious, and in ordinary parish practice it frequently names a person who has died, refers to someone's illness or recovery, or describes a family relationship such as an anniversary of a death.
We treat intention text as sensitive personal data. We process it only to record and fulfil the request, to print it in the parish's own bulletin and sacristy sheet where the parishioner has permitted that, and to maintain the register the parish is required to keep. We do not sell it, we do not use it for advertising, and we do not use it to build profiles or to train AI models.
3.5 Usage and Technical Data
- Server access logs, including IP address, request path, response code and user agent
- Error logs and performance telemetry
- A short lived count of recent submissions from the public request form, used to limit abuse
We do not load third party advertising or analytics trackers on the Memento website, in the parish dashboard, or on the public request form.
3.6 Payment Data
Subscription payments are processed by Stripe. We do not receive or store full payment card numbers. From Stripe we receive a customer identifier, a subscription identifier, the subscription status and limited metadata such as card brand and last four digits, so that we can show billing information and support the account.
Mass offerings are not our money and never pass through our accounts as revenue. Where a parish enables card offerings, funds settle to the parish's own connected payment account. We take no percentage of any Mass offering, in keeping with canon 947.
4. How We Use Information
- Provide and maintain the Service, the public request form and the calendar feed
- Record, number and preserve the Mass intention register
- Produce the bulletin block, the sacristy sheet, Mass cards, confirmations and diocesan reports
- Track canonical obligations, such as the year within which a Mass must be celebrated
- Process the parish subscription and manage billing through Stripe
- Send transactional email, such as confirmations to a parishioner, account notices and security messages
- Respond to support requests
- Detect and prevent fraud, abuse and security incidents
- Comply with legal obligations and enforce our agreements
5. The Register, and Why Some Data Cannot Simply Be Deleted
Canon 958 of the Code of Canon Law requires a parish to keep a book recording the Masses it has undertaken to celebrate, the intentions, the offerings given and the fact of celebration. Memento keeps that record as an append only, consecutively numbered register. Entries are corrected by recording a correction, never by erasing or renumbering, because a register that can be quietly rewritten is one no diocese can rely on.
This has a practical consequence for deletion requests. Where a parishioner asks us to delete information that forms part of a parish's canonical register, we will forward the request to the parish, which is the controller of that record. The parish may be required by canon law or by its diocese to retain the entry. Where retention is required, we may restrict processing and remove the entry from bulletins, cards and other publications rather than delete the register line itself, and we will tell you when we do that and why.
Requests that do not touch the canonical register, such as removing a telephone number or a contact record, are handled in the ordinary way described in Section 10.
6. The Calendar Feed
Each parish can publish its Mass schedule as a read only calendar feed, so that staff can subscribe to it in Google Calendar, Outlook or Apple Calendar. The feed is served at an unguessable address because calendar applications cannot sign in.
The feed publishes only what the parish bulletin would publish. An intention the parishioner asked not to be announced shows the Mass as taken, without a name. The feed is one directional: nothing done in a calendar application can alter the register.
Anyone holding the address can read the feed, so a parish should treat it as it would treat its printed bulletin. The address can be rotated at any time from Settings, which immediately stops the old one from working.
8. Data Retention
- Account data
- retained while the parish account is active, and deleted within 30 days after the account owner confirms deletion
- Register entries
- retained while the account is active. Because the register is a canonical record, it is exported to the parish rather than silently discarded. See Section 5
- Parishioner contact records
- retained while the account is active, and deleted on request where they are not part of a register entry
- Server logs and security telemetry
- retained for a limited period needed for security, debugging and abuse prevention
- Payment and tax records
- retained for up to 7 years as required by financial and tax law
After termination, a parish may export its full register for 30 days. We then delete parish content, subject to the limited retention described above.
9. Security
- HTTPS and TLS encryption in transit
- Encryption at rest for the database
- Salted, hashed password storage through our authentication provider
- Row level security on every table, so one parish cannot read another parish's register
- Deny by default database permissions, meaning a table with a missing grant fails closed rather than leaking
- Rate limiting and request validation at the public boundary
- Least privilege and audit logging for our own staff
No method of transmission or storage is perfectly secure and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information we will notify you as required by applicable law.
10. Your Privacy Rights
The rights below come from applicable United States state privacy laws. We extend the substantive rights of access, correction, deletion and portability to everyone on a good faith basis, regardless of where they live.
10.1 Texas Residents
Under the Texas Data Privacy and Security Act, Texas residents may confirm whether we process their personal data and access it, correct inaccuracies, request deletion, obtain a portable copy, opt out of sale, targeted advertising and certain profiling, and appeal a decision we make on a request. We do not sell personal data, serve targeted advertising or carry out profiling with legal effects, so there is currently nothing in those categories to opt out of.
We respond to verified requests within 45 days and may extend once by a further 45 days where reasonably necessary, telling you if we do. If we decline a request you may appeal by replying to our response or writing to privacy@greetyr.com. We respond to appeals within 60 days and, if we deny one, we will explain how to complain to the Texas Attorney General.
10.2 California Residents
California residents may know what categories of personal information we collect and why, access the specific pieces we hold, correct inaccuracies, request deletion, opt out of sale or sharing, limit the use of sensitive personal information, and not be treated differently for exercising these rights. We do not sell or share personal information for cross context behavioural advertising and have not done so. We have not knowingly sold or shared the personal information of anyone under 16.
10.3 Virginia, Colorado, Connecticut, Utah and Florida Residents
Residents of those states may access, correct where their law provides it, delete and obtain a portable copy of their personal data, and opt out of sale, targeted advertising and certain profiling. Residents of Virginia, Colorado, Connecticut and Florida may appeal using the process in Section 10.1. We honour opt out preference signals such as Global Privacy Control where technically feasible, although our Service does not carry out the practices they would opt out of.
10.4 How to Exercise Your Rights
Email privacy@greetyr.com with the subject line "Privacy Request". To protect your information we will verify your identity, generally by confirming control of the email address on the account or, for a parishioner, by matching details previously given to the parish. We do not charge a fee for verified requests except where the law permits it for repeated or manifestly unfounded requests. We accept requests from authorised agents who provide written authorisation.
If your request relates to a Mass intention recorded by a parish, that parish is the controller of the record. We will forward your request to the parish and coordinate with them, subject to Section 5.
12. Marketing Communications
Transactional messages, such as a confirmation that a Mass has been booked, a billing receipt or a security alert, are part of the Service and are not subject to marketing opt out.
If we send marketing email, every message will identify Greetyr as the sender, carry a truthful subject line, include a one click unsubscribe link and show our postal address, in line with the CAN-SPAM Act.
13. Children's Privacy
The Service is intended for adults working in a parish office. In compliance with the Children's Online Privacy Protection Act we do not knowingly collect personal information directly from children under 13, and we do not create accounts for anyone under 18.
A Mass intention may name a child, for example a Mass offered for a sick child or for a family. That information is provided by the adult making the request, not collected from the child, and it is treated as sensitive personal data under Section 3.4.
If you are a parent or guardian and believe a child has provided personal information through the Service, contact privacy@greetyr.com and we will delete it.
14. International Data Transfers
The Service is hosted in the United States and the providers in Section 7 process personal information there. If you use the Service from outside the United States, your information will be transferred to and processed in the United States. Where required we rely on appropriate safeguards, such as standard contractual clauses.
15. Third Party Links
The Service may link to sites we do not operate, which have their own privacy practices. We are not responsible for those practices and we encourage you to read their policies.
16. Changes to This Policy
We may update this Privacy Policy. When we make material changes we will update the date at the top of this page and, where feasible, notify account owners by email or by a notice in the dashboard at least 30 days before the change takes effect. Continuing to use the Service after a change takes effect constitutes acceptance of the updated policy.
17. Contact Us
- Privacy: privacy@greetyr.com
- General support: support@greetyr.com
- Mailing address: Greetyr, 5900 Balcones Drive, STE 100, Austin, TX 78731, USA

