Acceptance spec: ChurchWise Safe Church Tracker
Status: All decisions made (FOUNDER, 2026-09-26). Awaiting the founder's approval to build. Prod DDL and the live Stripe product each need confirmation at build time.
Owner: founder · Drafted: 2026-09-26 · Related: churchwise-compliance-kit.md, the protection-policy generator (live on churchwise.ca).
Why
- The protection policy a church adopts on churchwise.ca only protects children if the church keeps it: screened volunteers, trained volunteers, renewals on time, and a policy reviewed every year.
- Most small churches track this in a spreadsheet, or not at all.
- Market research (report 01) ranked police-check renewal tracking as a top opportunity: it recurs, it is driven by insurers, and there is no incumbent in Canada.
- For ChurchWise it is the first reason to come back, and the first paid product.
Founder decisions (final)
-
Price:
- Paid ChurchWise plan: $9.95/mo (CAD in Canada, USD in the US, the same numerals), 14-day free trial.
- Annual: $99.50/yr (FOUNDER, 2026-09-26). Unlimited volunteers; 1 owner plus up to 3 coordinators.
- The protection-policy generator stays free.
-
Included free for churches on any ChurchWiseAI plan:
cwa_website,cwa_phone,cwa_complete(+ annual), and the grandfathered plans. -
Reminders go to the coordinator AND to the volunteers.
- The coordinator gets a monthly "who's due" summary.
- Each volunteer gets their own reminder 60 and 30 days before a date expires, sent as "from [Church name] via ChurchWise", with an unsubscribe link.
-
Police checks are NEVER stored:
- no documents;
- no results;
- no check numbers;
- no uploads.
Only the dates: completed on, and renew by.
-
ChurchWise branding, AI-quiet. The tracker lives on churchwise.ca under the ChurchWise brand, with no AI wording. "AI" appears only in the FAQ answer, as on the other tools.
What the church can do (expected output)
Account
- Sign in on churchwise.ca with a magic link (no password), using the existing Supabase Auth, the same pattern as ChurchWiseAI.
- Roles:
- the account owner is the Safeguarding Coordinator;
- they can invite up to 3 more coordinators (e.g. the pastor, the children's ministry lead);
- everyone else is a volunteer, with no login.
- Plan detection:
- if the church's email or church record matches an active ChurchWiseAI plan, the tracker is unlocked with no charge, and the page says "Included with your ChurchWiseAI plan";
- otherwise the church starts the 14-day trial and then goes to Stripe checkout at $9.95/mo.
Volunteer roster
- Add volunteers one at a time, or by CSV upload (name, email, ministry). The CSV parser from the receipts tool is reused.
- Per volunteer: name, email, ministries (children, youth, vulnerable adults, other), and four dated items, each "completed on" plus "renew by":
- Policy signed: set automatically by the sign-off link (item 8), or entered manually.
- Training: the church sets its renewal cycle (default 2 years).
- Police check (vulnerable sector): the church sets its renewal cycle (default 3 years). Help text explains that the church keeps the check itself, and ChurchWise records only the dates.
- Reference / interview: optional, a date only.
- Status at a glance:
- each volunteer shows Current, Due soon (within 60 days), Overdue, or Missing;
- the dashboard leads with the counts, e.g. "3 overdue, 5 due in the next 60 days";
- the list is sorted by urgency.
- Export the roster to CSV at any time. It's the church's data.
Policy sign-off
- The coordinator uploads or links their adopted policy: the ChurchWise-generated PDF, or their own.
- ChurchWise emails each volunteer a personal link: "Please read and confirm our child protection policy."
- The volunteer opens it, reads the policy, and types their name to confirm "I have read and will follow this policy".
- That records the date and the policy version.
- The volunteer needs no account.
- When the church adopts a new version of the policy, the coordinator can ask everyone to re-confirm. The old confirmations stay in the history.
Reminders
- To the coordinator:
- a monthly summary email on the 1st of each month, listing who is due in the next 60 days and who is overdue;
- a yearly "time to review your protection policy" email on the policy's adoption anniversary.
- To volunteers:
- reminders before any item expires, and one on the day it becomes overdue, sent "from [Church name] via ChurchWise";
- Reminder timing is a dashboard setting (FOUNDER, 2026-09-26). Coordinators set how many days before expiry the reminders go out, from one to three reminders. The default is 60 and 30 days before, plus the day it becomes overdue. Allowed values are 1–180 days, with no two reminders on the same day. The same setting drives the "Due soon" window in item 6, which uses the largest value. Changes apply to future reminders only; reminders already sent are never re-sent. The monthly coordinator summary uses the same window;
- each reminder says what to renew and whom to contact (the coordinator's name and email);
- every email has a one-click unsubscribe. An unsubscribed volunteer is flagged to the coordinator ("Not receiving reminders"), and the coordinator still gets their due dates.
- Kill switch: reminders never go to anyone the church didn't add. A coordinator can pause all volunteer emails. There is a global env kill switch too (
CHURCHWISE_REMINDERS_DISABLED).
Privacy and compliance
- What is stored: volunteer name, email, ministries, the item dates, sign-off records (name typed, timestamp, policy version) and the email/unsubscribe log. Nothing else. In particular: no police-check documents or results, no dates of birth, no addresses.
- Where: the existing Supabase project, with row-level security scoped to the church account. Each church sees only its own volunteers. Server writes use the service role; client reads go through RLS.
- Privacy policy: a new section on churchwiseai.com/privacy, covering ChurchWise Safe Church Tracker data. The church is the controller of its volunteers' data, and ChurchWiseAI Ltd processes it on the church's behalf. It states the retention rule (item 16) and how volunteers can ask for deletion (through their church, or privacy@churchwiseai.com).
- Retention: when a church cancels, its data is kept for 90 days (so it can export or resubscribe), then deleted. A coordinator can delete a volunteer at any time, and that deletion is permanent.
- CASL and US CAN-SPAM: reminders are non-commercial, relationship messages sent for the church. Each still carries sender identification (the church name, via ChurchWise, and ChurchWiseAI Ltd's mailing address) and a working unsubscribe, which is honoured immediately.
- Sending domain: reminders send from a ChurchWise address, e.g.
reminders@churchwise.ca, via Resend, with Reply-To set to the coordinator. OPEN-1 below: the churchwise.ca DNS records (SPF/DKIM) need adding at Porkbun.
Engineering notes
- Code lives in
churchwiseai-web, under/churchwise/app/*(account area) and/churchwise/confirm/[token](volunteer sign-off). Middleware already routes churchwise.ca. - New tables (a migration in
churchwiseai-web/migrations/, founder confirmation before prod DDL):cw_accounts,cw_coordinators,cw_volunteers,cw_volunteer_items,cw_policy_versions,cw_signoffs,cw_reminder_log. There is no column for police-check content, by design; a contract test asserts that. - Reminders run from a daily Vercel cron (
/api/cron/churchwise-reminders). They are idempotent throughcw_reminder_log(never two reminders for the same item and threshold) and respect the kill switches. - Billing: a new Stripe product, "ChurchWise Office" (live write, so confirm first), handled through the existing webhook inbox. The entitlement check reads active ChurchWiseAI plans for the free inclusion.
- Admin: the tracker has its own ChurchWise dashboard. It is not in the ChurchWiseAI admin (AI-quiet).
- Updates in the same PR:
FEATURE_REGISTRY.md,PRICING.md,knowledge/data/pricing.yaml, andproduct_knowledge(with validation).
Test plan (on the real churchwise.ca host before done)
- Sign up; start the trial; add 3 volunteers by CSV; set dates so that one is overdue, one is due soon and one is current. Check the dashboard counts and order.
- Send a sign-off link. Open it as the volunteer, confirm, and see the date and policy version recorded. Re-send for a new version; the history stays. 3a. Change the reminder setting to 45 / 14 / 3 days in the dashboard. The next cron run uses the new days, already-sent reminders are not repeated, and invalid values (0, 200, or two identical values) are rejected with a clear message.
- Run the reminder cron against a test church whose volunteers use
john+…@churchwiseai.comaliases. Check the correct 60- and 30-day and overdue emails, with no duplicates on a second run, and that unsubscribe works and is flagged to the coordinator. - A church on a ChurchWiseAI plan is unlocked with no charge; a church without one is shown the $9.95 trial.
- RLS: church A can never read church B's volunteers (a negative test with two accounts).
- No police-check field exists anywhere: schema, API or UI.
- A paying-customer smoke test after deploy (the middleware and shared code are touched).
Decisions log (formerly OPEN)
Sending domainDECIDED (FOUNDER, 2026-09-26):reminders@churchwise.ca. Setup, before the reminder build ships: in the Resend dashboard, add the domain churchwise.ca, then add the SPF/DKIM (and optional DMARC) records it shows at Porkbun, and verify. The app's RESEND_API_KEY is send-only and cannot add domains.Coordinator seatsDECIDED (FOUNDER, 2026-09-26): 1 owner plus up to 3 more coordinators (4 total).Annual priceDECIDED (FOUNDER, 2026-09-26): $99.50/yr (2 months free, the house convention).Volunteer limitDECIDED (FOUNDER, 2026-09-26): unlimited volunteers.