PewPin attendance tracking · Last updated 17 August 2026
PewPin is a seat-by-seat church attendance tool operated by Roberto Aguilera, trading as PewPin ("PewPin", "we"), based in the United States.
Contact for any privacy question or request:
privacy@pewpin.app
PewPin holds two kinds of information, and our responsibility is different for each.
| Information | Who decides how it is used |
|---|---|
| Attendance and visitor names — which seats were occupied, and the optional name of a visitor | The church. Each church decides whether to record anything, who may see it, and how long it is kept. The church is the data controller. PewPin only stores and displays it on the church's instructions — we are the data processor. |
| Staff account records — the email address, display name and role of the people who sign in | PewPin. These exist so we can run the service, sign people in and keep churches separate from one another. For these we are the data controller. |
In plain terms: your church decides what is recorded about the people who attend it. We decide only what is needed to give your church a working account. We do not use any church's attendance data for our own purposes.
| Information | Why it is held |
|---|---|
| Your email address and display name | To sign you in and show who recorded what |
| Your role (owner, usher, viewer) | To control what you can see and change |
| Which seat was occupied, in which service, on which date | To produce attendance counts and reports |
| Whether an attendee was counted as an adult, a child, or a visitor | To break attendance down by group. This is a count only — no name is attached to adults or children |
| A visitor's name, only where a volunteer chooses to enter one | Optional, and off unless enabled. Used by the church to welcome and follow up with people visiting for the first time |
| Whether a visitor was attending for the first time | To support welcome and follow-up |
Attendance can be — and by default is — recorded entirely as anonymous counts. The visitor name field is the only place any attendee is identified, it is always optional, and the app never asks for it automatically unless a volunteer switches that prompt on.
PewPin will not store a name against a seat marked as a child. The name field is offered for visitors only; it is hidden when a seat is set to adult or child, anything typed there is discarded, and a name already recorded for a visitor is removed automatically if that seat is later changed to a child.
Children appear in this service only as an anonymous number — that a seat was occupied by a child, in a given service, on a given date. Nothing identifies which child.
The visitor name field is for a first name or family name and nothing else. It must never be used for phone numbers, email addresses, postal addresses, dates of birth, photographs, health or medical information, disability information, prayer requests, or safeguarding notes. The app actively refuses entries that look like an email address or a phone number, or that contain health, prayer or safeguarding wording, and limits the field to 60 characters — but churches should instruct volunteers not to enter such information in the first place.
PewPin does not track you across other websites or over time. There is no advertising, no analytics and no tracking of any kind in this app, so a Do Not Track signal has nothing here to switch off, and we do not respond to those signals differently. We do not permit any third party to collect personally identifiable information about your activity across different websites through PewPin.
Access is limited to people the church has admitted:
People join using a 6-character code issued by an owner. An owner can change that code at any time, and can remove a member, which ends their access immediately.
On the PewPin side, access is limited to Roberto Aguilera, who operates the service. We do not browse church data, and we would only look at a specific church's records where it is necessary to fix a fault the church has reported to us.
PewPin runs on services provided by other companies. These are our sub-processors:
| Provider | What they do |
|---|---|
| Google Firebase (Google Cloud) | Stores the database, handles sign-in, and holds the daily backups in Google Cloud Storage. Servers are in the United States (Google Cloud region us-central1). |
| Netlify | Serves the app itself to your browser. Netlify records standard web-server logs, which include IP addresses. |
Google's handling of the data is governed by its own terms: firebase.google.com/support/privacy. We will tell church owners before adding or changing a sub-processor.
PewPin is operated from the United States and all data is stored in the United States. If you use it from another country, your information is transferred to and stored in the United States.
If your church is in the United Kingdom or the European Economic Area, please contact us at privacy@pewpin.app before you start using PewPin. A written data processing agreement and an appropriate transfer mechanism need to be in place first, and we will arrange that with you rather than leave you to assume it already exists.
No system is perfectly secure, and we cannot guarantee absolute security.
| Information | Kept for |
|---|---|
| Visitor names | 90 days after the service, then deleted automatically by the app the next time an owner opens it. An owner may shorten this to 30 days or extend it to 1 year, and may delete every name held by the church at any time. Automatic deletion cannot be switched off. |
| Attendance counts (seat, service, date, adult/child/visitor, first-time) | Kept until the church deletes them or closes its account. These identify no one once names are removed. |
| Staff account records (email, display name, role) | While the account is active, and up to 12 months after it is removed or the church closes its account. |
Restore points and downloaded backups are snapshots taken before major changes. Restore points do not contain visitor names. A backup file downloaded by an owner is that owner's responsibility once it leaves the app.
System backups. We also take an automatic daily backup of the whole database, held in Google Cloud Storage in the United States and kept for 30 days before being deleted. These backups do include visitor names, so a name may still exist in a backup for up to 30 days after it was deleted from the live service. The backups are not public, and are used only to restore the service if something goes wrong. If you ask us to delete a name we remove it from the live service immediately; it then disappears from the backups as they age out.
There is no option to keep visitor names indefinitely. The longest an owner can choose is one year, and names older than the chosen window are removed the next time an owner opens the app.
Depending on where you live, you may have the right to ask what is held about you and get a copy, have inaccurate information corrected, have information deleted, object to or restrict how it is used, withdraw consent where consent was relied on, and complain to a data-protection regulator — in the UK, the Information Commissioner's Office (ico.org.uk/make-a-complaint); in the EEA, your national data-protection authority; in the United States, your state attorney general where applicable.
Contact privacy@pewpin.app. We respond within 30 days, and we may ask you to confirm your identity first. Where a request concerns a church's data, we will assist that church in answering it rather than act on our own.
Because the app does not record children's names, it holds nothing that identifies a child. A parent or guardian who believes a child has been identified in error may contact the church, or us, and it will be removed.
Where UK or EU data-protection law applies, the basis differs by role.
| Information | Basis |
|---|---|
| A visitor's name | Decided by the church as controller. PewPin is built on the assumption that a volunteer asks the visitor before recording a name and explains why — giving it is voluntary, refusing has no consequence, and it can be withdrawn at any time. A church that records names differently must set and state its own basis. |
| Anonymous attendance counts | Decided by the church as controller — typically legitimate interests in knowing how many people attend, to plan seating, staffing and services. No individual is identified. |
| Staff account records | PewPin, on the basis of contract and legitimate interests — these are the people who run a church's account, and the records exist to give them access and keep churches separate. |
Two design choices make this simpler than it would otherwise be: attendance is recorded as anonymous counts by default, and the only identifying field — a visitor's name — is optional, entered by a volunteer in front of the person, and deleted automatically.
If we make a significant change we will update the date at the top and notify church owners. Continuing to use PewPin after a change means you accept the updated policy.