The Cowboy Christian platform is coming soon. Join the wait list for early access

Cowboy Christian — Health Cost Sharing Platform

Legal

Privacy Policy

Last updated: August 26, 2026

Cowboy Christian, LLC ("Cowboy Christian," "we," "us") respects your privacy. This notice explains what information we collect, how we use it, and the choices you have. It covers both halves of this site: the public pages anyone can read, and the member portal you sign in to. We keep it in plain language, because that is how we intend to operate.

What We Collect

When you browse our public pages. You do not need an account to read them, and we do not build a profile of you. If you open the chat window, we receive whatever you type into it. If you suggest a facility for one of our state guides, we receive the facility details and any note you add, and your IP address is used briefly to limit how many suggestions can arrive from one connection.

When you write to us. If you send us a message through our contact form, we receive your first and last name, your email address, the topic you choose from the list, and whatever you write in the message. We save all of it so our team can read it. Your IP address is used briefly to limit how many messages can arrive from one connection, and it is not saved with your message. You do not need to be a member to write to us.

When you join and use the member portal. Running a membership takes real information, so here is all of it:

  • Who you are: your name, email address, date of birth, home address, and your phone number if you give us one.
  • Your household: the name, date of birth, and relationship of each dependent you add, including a minor child.
  • Your membership: the plan you choose, any add-on you select, your membership status, your monthly amount, and the date you accepted our Statement of Beliefs.
  • Payment details: you enter your bank or card information directly into a form served by Stripe, our payment processor. Those numbers go to Stripe and are never stored on our systems. We keep the Stripe reference for your account, along with the record of what was charged and what was shared.
  • Health information you give us: when you open a sharing request you describe the medical need, the amount you were billed, and what you have already paid, and you upload supporting documents such as bills and statements from your provider.
  • Security records: we log important actions taken in an account so we can investigate problems. Those records identify the account and the action, and they store a one-way scrambled version of the IP address the action came from rather than the address itself.
  • Notes our team writes: when a member of our team changes something about your membership, such as putting it on hold or pausing it, they may record a short note about why. That note is written by us rather than by you, it is encrypted where it is stored, and it is visible to our staff and not on your account pages.

How We Use Your Information

  • To set up and run your membership, including your household and your plan.
  • To process your monthly membership fee and the amounts you share with other members.
  • To review a sharing request against the member guidelines and to keep you posted on where it stands.
  • To respond when you contact us.
  • To keep the platform secure and to look into misuse.
  • To meet our financial, tax, and legal recordkeeping obligations.

We do not use your information to advertise to you, and we do not use it to build a profile of you for anybody else.

Analytics and Tracking

This site runs no analytics service and no advertising or social media tracking pixels. There is no Google Analytics, no Meta pixel, and no session recorder. We do not build a profile of you, and we have nothing about your visit to hand to an advertiser.

One third party does see browsing activity, and only on our public pages: the chat window. Our chat provider records which public pages a visitor viewed, so that whoever answers a chat can see what you were reading. The chat window is not loaded inside the member portal, so it never sees anything you do in your account.

Keeping trackers off this site is a deliberate design choice, not an oversight. Members trust us with health information, and we treat sending any of it to an advertising or analytics network as a breach of that trust. Every change to this site runs through an automated check that scans it for tracking and analytics software, and that check fails when it finds any. Adding analytics of any kind takes a documented compliance review and a founder decision first.

Cookies and Browser Storage

We do not use cookies to advertise to you or to follow you around other websites, and our own code sets no cookies at all. Here is what a visit actually puts on your device.

  • Signing in: Clerk, the service that runs accounts and sign-in for us, sets cookies on this site to create your session, keep you signed in, and protect the sign-in process from abuse. Sign-in is reachable from every page, so these load on our public pages too, including for visitors who never sign in.
  • Paying: on the two pages where you add or update a payment method, the payment form itself is served by Stripe, which sets its own cookies to keep the form working and to detect fraud. These load only on those two pages.
  • Chat: when the chat window is available on a public page, Crisp, our chat provider, sets its own cookies and browser storage so a conversation can pick up where it left off. We do not pass your name, email address, or membership details into chat, so a chat is anonymous unless you type something that identifies you. Chat is not loaded inside the member portal.
  • The one thing we store ourselves: if you dismiss the one-time hint on our bottom navigation bar, your browser records that single dismissal in session storage under the name "cc-dock-hint-dismissed". It holds no identifier, it disappears when you close the tab, and it is never sent to us or to anyone else.

You can block or clear cookies in your browser settings. Sign-in and the payment form need their cookies to work. The rest of the site does not.

Information You Choose to Make Public

When you open a sharing request you can write a short summary and choose whether to share it on the prayer wall so other members can pray over your need. Only that summary is ever shown to other members, and only if you opt in. The full description you write and the documents you upload go to our review team, and they are not shown on the prayer wall. The prayer wall is not open yet. When it opens, only requests that opted in will appear on it, and you can turn your opt-in off at any time.

What We Never Do

We do not sell your personal information, and we do not share it with third parties for their own marketing. No spam, no list-renting, no gimmicks. We do not share your health information with anyone outside the people and services needed to review your sharing request and get it paid.

Service Providers

We use a small number of trusted providers to run the platform. Each one handles only the information it needs for its job, on our behalf, under its own privacy and security commitments.

  • Clerk: accounts, sign-in, and session security.
  • Resend: the service that delivers our member emails, such as a notice about your membership. It receives the message we are sending you. Beyond that message, the only details about you it receives are your email address and your first name, which lets us greet you by name.
  • Twilio: the service that will deliver our text messages when we turn them on. We do not send text messages yet. When we do, it will receive the message we are sending you, and beyond that message, only your phone number and your first name.
  • Stripe: payments. Stripe collects your bank or card details directly and charges your monthly membership fee.
  • Neon: the database that holds member records and the messages sent through our contact form.
  • Vercel: website hosting, plus the private storage where uploaded documents are kept.
  • Upstash: rate limiting, which protects the platform from automated abuse.
  • Axiom: our application and security logs, which we use to find and fix problems.
  • Google (Google Chat): the internal team space where our own staff alerts are posted, such as a notice that a membership payment has not gone through. These alerts carry a count and a link to our admin pages. No member name, no member contact details, and no health information are sent to Google.
  • Crisp: the chat window on our public pages.

We send member emails about your account, such as a notice about your membership, and Resend delivers them. We do not send text messages yet; when we turn them on, Twilio will deliver them. Clerk, our sign-in provider, sends the account emails that signing in requires, such as a verification code. Google Chat carries internal alerts to our own team and is never used to message members. If we add another way of reaching you, or another provider that carries your messages, it will be named here first.

How We Protect Your Information

The most sensitive fields you give us are encrypted where they are stored: your name, email address, phone number, date of birth, street address, city, ZIP code, the names and dates of birth of your dependents, and the full description you write in a sharing request. The state you live in is the one part of your address we do not encrypt. The name, email address, and message you send through our contact form are encrypted where they are stored too. Documents you upload are held in private storage that is not reachable from a public link, and their file names are encrypted too. Notes our team writes about your membership are encrypted where they are stored as well. Access to member records is limited to the people who need it, and important actions are written to a security log.

No system is perfect and we will not pretend otherwise. If we learn that member information has been exposed, we will investigate it, work to contain it, and notify affected members and regulators as the law requires.

Your Choices

  • See and correct your information: your account pages show the information you have given us about you and your household, and you can update most of it yourself. To ask what our team has recorded about your membership, write to us at the address below.
  • Choose what we send you: notification preferences live in your account settings.
  • Ask us to delete something: email us at privacy@joincowboychristian.com and we will tell you what we can remove and what we have to keep for financial and legal recordkeeping.

Data Retention

If you send us a message through our contact form, we keep the message and the details you sent with it, including after our team has read it. We have not set a fixed schedule for deleting contact messages yet, so a message stays with us until we set one or until you ask us to remove it. You can ask at any time, whether or not you are a member, by writing to the address under Your Choices above.

While your membership is active we keep the membership information described above so the platform can do its job. After a membership ends we keep the records we need for financial, tax, and dispute-resolution purposes. If you want your information removed sooner, write to the address under Your Choices above and we will tell you what we can remove and what we have to keep.

Children

Our public pages are not directed to children, and we do not knowingly collect information directly from a child. A child cannot create an account here. A member can add a dependent to a household, including a minor child, and in that case it is the parent or guardian who gives us that child's name and date of birth.

Changes to This Policy

If we update this policy, we will post the new version here and revise the "Last updated" date above.

Contact

Cowboy Christian, LLC — Franklin, Tennessee
info@joincowboychristian.com