Members Church of God International
MCGI LiftMember ride coordination

Privacy policy

Last updated 16 September 2026

MCGI Lift is a private, scheduled volunteer-ride coordination service for approved participants. This policy explains the information used by the service and the controls available to participants. The service does not support fares, tips, reimbursements, or payment processing.

Information we handle

  • Google or Apple sign-in identity and the member identifier returned by the identity service.
  • Registration details such as name, email, phone number, address, church membership or affiliation, baptism date, and local congregation; application answers, reviewer decisions, and required evidence. Driver applications also include licence, and vehicle details. Accessibility needs can reveal disability or health information and are used for ride suitability.
  • Ride requests, offers, confirmations, messages, boarding checks, and trip status.
  • Exact meeting and destination details. Public ride discovery uses only general areas; exact details are limited to confirmed participants and authorized operations staff.
  • Foreground location, shared automatically with device permission while a driver is online or a confirmed trip is active under the terms accepted at signup. The app does not request background location.
  • If you enable device alerts, an installation identifier, a push delivery token, your device platform, and the registration expiry are linked to your member account. These credentials support notification delivery and are not used for advertising.
  • Safety reports, blocks, private feedback, and the audit records needed to review them.
  • Server security and reliability logs. Optional mobile app-launch and performance diagnostics are disabled in this release. Operational logs must not include message bodies, boarding PINs, identity documents, or exact locations.

For new Apple sign-ins, an encrypted provider refresh token is kept only to manage and revoke Apple authorization when the account is deleted. It is excluded from member exports and operational logs, then removed after revocation succeeds. Older accounts without a token have instructions for removing Apple authorization in Apple Account settings.

Why we use this information

Information is used to verify access, coordinate mutually confirmed rides, show the right trip details to the right participants, support safety review, prevent misuse, maintain service reliability, and meet accountable operational or legal obligations.

Disclosure and service providers

Information is disclosed only as needed to confirmed ride participants, authorized MCGI Lift reviewers and operations staff, and contracted infrastructure or notification providers acting for the service. Information is not sold and is not used for advertising. A valid legal request may require disclosure where applicable law requires it.

Google and Apple process sign-in requests. DigitalOcean hosts the web service and database; Expo provides app delivery and updates. Map and route requests use the configured Mapbox mapping service and may contain a search query or coordinates needed to return a place or route. Nearby vehicle displays use approximate, short-lived markers. Exact trip locations are limited to confirmed participants, authorized staff, and any trusted-contact link you explicitly create. A trusted-contact link can be revoked.

Optional iOS device alerts use Expo and Apple notification services. These providers receive the device delivery token and a generic activity message. Push payloads contain no member name, trip details, exact location, message content, or boarding PIN. Open the app and sign in to view the activity. Device alerts can be delayed and do not provide emergency monitoring.

Android activity updates are available in the authenticated in-app inbox, which refreshes while open. Android does not use Firebase notification services or receive activity alerts when the app is closed.

Retention and deletion

Active account and ride information is retained while needed to provide the service. Members can request account deletion through the published account-deletion process. We complete deletion requests within 30 days and confirm completion. Security, safety, dispute, consent, and audit records may need to be retained after account deletion; the response to a deletion request will identify any information that cannot yet be deleted and the reason it must be retained.

Device alert registrations expire after 30 days without renewal. Turning alerts off or signing out removes the registration when the app can connect; offline removal is retried on a later launch or connection attempt. Approved account deletion also removes device registrations. An alert already handed to a provider may still arrive. To stop alerts on the device immediately, turn off MCGI Lift notifications in device settings.

Member choices

Location sharing during confirmed rides is included in the terms accepted at signup. Device permissions remain under your control. If permission is denied, the app explains how to restore it; manual pickup entry, trip details, cancellation, and safety help remain accessible. Sharing stops when the ride ends or the app leaves the foreground. Trusted-contact links require a separate action and can be revoked. Members may sign out, request profile corrections, or request account deletion.

Security and contact

MCGI Lift uses access controls, encrypted transport, restricted operations views, and audit records. No system can promise absolute security. For privacy questions or requests, email [email protected] with “MCGI Lift privacy” in the subject line. Do not include identity documents or exact ride locations in ordinary email.

Adult-only pilot

The current pilot is for approved adult members. It is not intended for children and does not knowingly provide child accounts.