Digital Ethics, Privacy, and Transparency
At Yates Baptist Church, digital trust is a theological and ethical commitment. Every interaction online reflects our life together in Christ and our responsibility to care well for the information you entrust to us.
This page summarizes our approach to privacy, accessibility, performance, and accountability. Technical transparency is part of spiritual accountability—and we welcome your attention and your questions.
Privacy
How we collect, use, and protect personal information—and the choices available to you.
Accessibility
Our WCAG 2.2 AA targets, what we’re improving, and how to report a barrier for quick remediation.
Performance (Redis)
How caching and optimization keep pages fast and reliable—without compromising privacy or content integrity.
Legal Imprint
Responsible publisher, hosting details, and contact information for site administration.
Photo & Media
How we handle photography, livestream visuals, and opt-out requests—curated with care.
Cookie Policy
What cookies we use, why we use them, and how to manage your preferences.
Youth Media & Communications
Consent and communications practices for children and youth within Safe Sanctuary guidelines.
Giving Security
Online payments through PCI-compliant processors. What we store—and what we never store.
Disclaimer
Scope and limits of content, third-party links, and spiritual communications on this site.
Records Retention
Plain-English summary of how long we keep records, with a link to the full schedule.
Terms of Use
Site conduct, intellectual property, and policies for external links and user submissions.
Prayer Requests & Confidentiality
How prayer requests are shared and cared for, including pastoral confidentiality boundaries.
Livestream & Recording
Camera zones, platforms, and archive practices for worship services and events.
Safe Sanctuary & Background Checks
Why and when we screen, who sees results, and how long records are retained.
Copyright & DMCA
How to submit a takedown request and contact our designated DMCA agent.
Security Practices
How we protect our systems, safeguard your data, and respond to security incidents—with technical transparency.
Digital Trust Dashboard
Privacy & Consent
-
✅ Privacy Policy Page PublishedClearly communicating what data is collected and how it is used is foundational to digital trust.
-
✅ Login Page Consent Message ActiveLetting users know that their login actions are logged or monitored upholds informed consent.
-
✅ Login Requires Consent CheckboxA checkbox confirms that users explicitly agree to privacy terms before proceeding.
-
✅ Public Forms Have Consent CheckboxPeople submitting personal info should be informed how it's stored and used.
-
✅ Cookie Disclosure ActiveSome cookies track behavior; users deserve the choice to accept or decline.
-
✅ Registration Forms Clearly LabeledForms should clearly state their purpose to avoid confusion or coercion.
Security & Infrastructure
-
✅ SSL Certificate Enforced via 301 RedirectRedirecting HTTP to HTTPS ensures encrypted communication between browser and server.
-
✅ HSTS Header ActiveHSTS tells browsers to always use secure HTTPS connections, even on first visit.
-
✅ Security Headers ConfiguredThese headers protect your users from clickjacking, code injection, and data leaks.
-
✅ Brute-Force Login Protection EnabledRate limiting or CAPTCHA blocks bots from guessing passwords over time.
-
✅ Admin Backups or Integrity MonitoringIf something breaks, backups allow restoration without loss. Integrity monitoring adds early alerts.
-
✅ Redis Object Cache StatusRedis stores database query results in memory, improving dashboard performance and dynamic page loads.
Pastoral Responsibility
-
✅ No Dark Patterns PresentOur digital spaces should be free of manipulation. We avoid deceptive design that pressures or confuses users.
-
✅ Children's Privacy Statement IncludedWe honor the vulnerability of minors and commit to never knowingly collecting data from children under 13.
-
⬜️ Confidentiality Notice on Contact FormsSpiritual disclosures deserve clarity. We let people know how their messages are received and who sees them.
-
✅ Accessibility ReviewedThe Gospel is for everyone. We review our site for accessibility barriers—visual, auditory, and navigational.
Security Practices
-
✅ XML-RPC Access BlockedXML-RPC allows remote access but is often targeted by bots. Blocking it reduces attack surfaces.
-
✅ Direct Access to Config Files DeniedPrevents outside users from viewing or modifying sensitive files like wp-config.php.
-
✅ Old wp-config.php Backups RemovedBackup files are often forgotten—but still accessible. Cleaning them eliminates a major security risk.
-
✅ Bcrypt Password Hashing ActiveBcrypt is a modern encryption method that better protects user passwords from being cracked.
🔒 Built on trust. Maintained with integrity.
Page updated dynamically as part of our commitment to digital transparency.
