ReedVerde brandmarkReedVerde
    Back to Blog

    Why I No Longer Help Churches Build Member Directories

    Reed VerdesotoReed VerdesotoDigital Systems Architect
    Why I No Longer Help Churches Build Member Directories, custom Subsplash blog by ReedVerde

    This post reflects my personal position as an independent consultant. It is not the official position of Subsplash or any other platform.

    I have completed more than 500 church technology implementations. I no longer assist churches with building member directories. This post is the full explanation of why.

    What is PII?

    PII stands for Personally Identifiable Information. It is any data that can be used to identify a specific person, either by itself or combined with other data.

    A name by itself is generally not PII. But a name combined with any of the following becomes PII:

    Home address.

    Phone number.

    Email address.

    Photo. Any combination of details that narrows down who and where a specific person is.

    A church member directory is not just a list of names. It is a collection of PII. The combination of name plus address plus phone number makes it possible to locate and contact a specific person. That creates risk that most churches are not accounting for.

    The Shared Password Problem

    The most common version of this is a password protected web page. One password, shared with anyone who asks. No individual login. No account. No record of who got in or when.

    There is no way to know who has the password. There is no way to remove access for one person without changing it for everyone. The password can be texted, emailed, or said out loud to anyone at any time. A printed church directory was once traded to a door to door vacuum salesman in exchange for a discount. A shared password web page is easier to pass along than a printed book.

    This is not security. There is no audit trail, no access control, and no way to revoke access once the password is out.

    The Credentialed Login Problem

    Tools that offer individual logins and authenticated access carry their own serious risk. Most allow anyone to create an account and receive immediate access to the directory. Someone requests access, the system sends them a verification link, they click it and they are in. There is rarely a human in the middle confirming that the person who just signed up is a current member or should have access to that information at all.

    A credential is only as trustworthy as the verification process behind it. In most church directory tools that process does not exist in any meaningful way.

    The Consent Problem

    This is the risk that most churches never consider.

    Consent given years ago is not current consent. A member who opted into a directory when they first joined a church may today be in a completely different legal situation.

    They may be a foster parent. Pennsylvania law (55 Pa. Code Section 3130.44) states that information used to identify a foster child or their placement address is confidential and cannot be shared with people who have no need to know it. The Pennsylvania Foster Parent Manual states that violations could result in legal action against the foster parent. A foster parent still listed in a church directory with their home address may be in violation of their placement agreement right now without knowing it because they forgot they ever opted in.

    They may be a domestic violence survivor. Forty five states plus Washington DC operate Address Confidentiality Programs that provide survivors a substitute legal address specifically because a real address in the wrong hands can be life threatening.

    They may have a protection order. The person they are protected from does not need to circumvent security. They only need to find someone with access to the directory.

    No directory tool has a mechanism that prompts members to update their status when their life circumstances change. The directory sits there indefinitely and the risk accumulates.

    The Legal Exposure

    Churches are legal entities. Nonprofit status does not provide immunity from negligence claims or invasion of privacy claims. If a member is harmed because someone accessed their personal information through a church directory, prior consent is not a reliable defense if that member's circumstances changed and the church had no mechanism to know or account for that change.

    This is a decision that requires input from your church leadership, your legal counsel, and your insurance provider before you build or share anything.

    What the Right Architecture Looks Like

    The underlying need is legitimate. Members want to connect with each other and the church should facilitate that. The way to do it has to change.

    The right model on any platform is this: one verified person reaches out to another verified person and asks directly for their information. That second person has to have chosen to be on that platform in the first place. They are not listed by default. They are not included because they filled out a connection card five years ago. They chose to be there and they choose what to share and with whom.

    Subsplash messaging is a good example of this done right. Every user has individual credentials tied to a verified account. If a member wants to connect with another member they initiate the conversation themselves inside the app. The person asking is identified. The person sharing makes the decision in real time. No contact information sits on a page waiting to be accessed by whoever has a password or whoever created an account. The church facilitates the connection. The member controls their own PII.

    This philosophy applies to any platform. The architecture is the point, not the tool.

    Churches have operated prayer lists, birthday card rotations, and member directories for decades. Those systems existed in a different world and served real purposes. The world has changed. Bad actors have exploited every open system that existed, and the laws now in place exist specifically because of that exploitation. Those laws are not bureaucratic obstacles. They are protections for the people sitting in your congregation, people who may be in situations your church does not know about and cannot account for.

    Coming into compliance with the reality of today is not a loss of community. It is a protection of it.

    About Reed Verdesoto

    I'm Reed Verdesoto, an independent Subsplash architect. I've built custom apps, websites, and communication systems for 500+ churches, ministries, and organizations, and I help teams turn a scattered digital presence into one that actually works and keeps working.

    If something on your setup feels broken, disconnected, or harder than it should be, reach out. I'd rather have a real conversation about what you're dealing with than sell you a package.

    Get in touch

    Originally published on reedverde.com