Church Membership Database Software

Ekkli's membership database is the admin-side record your church keeps of who's part of the congregation — built for the person who handles admin, not a member database members browse to look up each other's phone numbers. People join through a self-service link or QR code or an emailed invitation, bulk records come in through CSV import, every contact detail is covered by a GDPR-compliant double opt-in consent flow, and each member manages their own data through a self-service profile. It's part of Ekkli's six-month free trial for up to 50 people, the same login as your church's website, worship display, and rota.

This page is a product spec for what the membership database actually does. If you want the fuller, non-legal walkthrough of what GDPR requires for church member data in general — lawful basis, data minimisation, access and erasure requests — see our deeper look at GDPR requirements for church member data. Come back here for how Ekkli's database itself is built.

An admin-side database, not a public directory

Worth stating plainly, because it's the single most common assumption about "membership software": Ekkli's membership database does not give members a page where they can browse each other's contact details. There's no searchable list of "everyone in this church and their phone number" that a member logs in and scrolls through. What exists instead is an administrative record — visible to the people your church designates to manage it — plus each individual member's own self-service view of their own data.

That distinction matters for two reasons: it's simply what's built today, and it's often the safer default anyway — not every member wants their mobile number visible to two hundred people they only recognise by face, and an admin-managed record with member-controlled consent avoids that problem by design rather than an opt-out toggle nobody remembers is there.

How people get into the database

Three ways cover how a church actually builds its membership list, and all three route through the same consent engine described below:

  • Self-service join via a link or QR code. Share a join link on a welcome slide, a bulletin, or a card at the connect table, and a new attender fills in their own details rather than an admin re-typing a paper form. A QR code makes the same link scannable from a phone in the foyer.
  • Invitations. An admin sends a direct invitation to a known contact, and the invited person completes their own profile and consent from the link they receive.
  • CSV bulk import. Migrating from a spreadsheet doesn't mean re-entering every row by hand. Bulk import brings existing records in at once — the difference between "starting from zero" and actually using the database in week one.

All three paths land in the same place: a member record that's only as complete, and only as visible, as the consent that member has actually given.

The GDPR double opt-in consent engine

Every contact channel in the database runs through a double opt-in consent flow, built specifically to hold up under real-world scrutiny rather than just tick a compliance checkbox. Two details make it worth a plain explanation:

  • Mail-scanner-safe. Some corporate and church email systems run automated link-scanners that "click" every link in an inbound email before a human ever opens it — a well-known failure mode that has quietly auto-confirmed consent for plenty of software that wasn't built with it in mind. Ekkli's confirmation flow is designed so an automated scanner visiting the link does not count as consent.
  • POST confirms, never GET. The actual act of confirming consent requires a POST request — a deliberate submit, not just loading a URL — specifically because a GET request is exactly what a link-scanner performs automatically. Consent that could be granted by a bot pre-fetching a link isn't real consent, and the engine is built so that can't happen.

In practice, a member just gives an email address, receives a confirmation message, and takes a genuine action to confirm — the mechanics don't change their side of it. For your church, it means "who has actually consented to what" is a record you can trust, not one quietly inflated by inbox security software acting on its own.

Consent is also tracked per purpose rather than as one blanket yes. A member can be part of the membership record without that automatically meaning every possible use of their data is switched on — the specifics of what's asked and stored are covered in full on our GDPR requirements for church member data page.

Bring your membership list online properly

Import your existing list by CSV or start collecting new members through a join link — free for up to 50 people, no card required.

Start free — no card required

The member's own self-service profile

Every member has their own /me profile — a page that belongs to them, not to the admin team. From it, a member can see exactly what data your church holds on them, update their own contact details when they move house or change their number, and manage their own consent choices, including withdrawing consent, without having to email an admin and wait.

That self-service ownership is doing real work, not just convenience. It's the difference between a record that quietly drifts out of date because only an admin can fix it, and one that stays accurate because the person it belongs to can correct it themselves. It also means "does this person still want us to have their data" isn't a question your admin team has to chase down — the member answers it directly, on their own record, whenever they choose to.

How it fits with the rest of Ekkli

The membership database isn't a bolt-on contact list — it's the record other parts of Ekkli read from. Rota and volunteer scheduling pulls from the same people your church has on record, volunteer availability attaches to the same profiles, and small groups use the same membership base to know who belongs where. One database, one consent record, reused everywhere — instead of a separate contact list per tool that falls out of sync.

It's included on Ekkli's six-month free trial for churches up to 50 people, no card required, alongside the worship display, website, rota, and giving tools under the same login. The six months cover the full platform — see pricing for the full breakdown by plan.

Set up your membership database today

Send your first join link, import your existing list, and let your consent records manage themselves — free trial, no card required.

Start free — no card required

Frequently asked questions

Can members browse each other's contact details in the database?

No. Ekkli's membership database is an admin-side record for the people managing your church's administration, plus each member's own self-service view of their own data. There is no member-facing page where the congregation can look up each other's phone numbers or addresses.

How do new members get added?

Three ways: a self-service join link or QR code, a direct invitation from an admin, or CSV bulk import for bringing an existing spreadsheet or system across in one go.

What does "double opt-in" actually mean here?

A member provides an email address, receives a confirmation message, and takes a genuine action to confirm it — a single unconfirmed signup isn't treated as consent. Confirmation requires a POST request rather than simply loading a link, so an automated email-security scanner that "clicks" links in the background can't accidentally register as a real confirmation.

Can a member update their own details without contacting an admin?

Yes. Every member has a self-service profile where they can see what data is held on them, update their contact details, and manage or withdraw their consent directly.

Is the membership database included on the free trial?

Yes. Self-service join, invitations, CSV import, the consent engine, and every member's self-service profile are all included on Ekkli's six-month free trial for up to 50 people, no card required.

Is this the same thing as a GDPR-compliant public church directory?

No — and that distinction is worth keeping straight. This page describes the membership database itself: how people join it and how consent is captured. For the broader, non-legal explanation of what GDPR asks of any church holding member data — lawful basis, minimisation, access and erasure requests — see our GDPR requirements for church member data guide.

This page is maintained by the Ekkli team, who build and run the membership database described above. For the wider GDPR picture beyond Ekkli's own implementation, see our church member directory GDPR guide.

Select your language