Skip to main content
Guide

Is Tap-to-Give Safe for Churches?

It is a fair question to ask before you mount anything on a pew. Here is the honest security picture for pastors and board members: what the plate stores, whether it can be tampered with, where the payment safety actually lives, and what your donors’ data does and does not do.

July 29, 2026
8 min read
A custom NFC tap-to-give plate with a church logo, showing the tap-to-give front face

Yes. Tap-to-give is as safe as the online giving your church already offers, and in one way safer: the plate never touches a card number or a bank detail. Each Tap.Giving plate holds only your church’s public giving URL, and it ships locked so that address cannot be overwritten by a passing phone. The payment happens on your existing giving platform’s secure, PCI-compliant page, exactly as it does when someone gives from your website.

What the plate can’t do

It cannot read your card, store a donation, or connect to the internet. It has no battery and no memory beyond a single web address.

Locked by default

Every plate ships write-protected, so the encoded URL cannot be changed by tapping another phone against it.

See your church's plate and price in 30 seconds

Design it yourself on the next page. From $3.50 per plate, free shipping, no monthly fees.

No charge until checkout. 30-day money-back guarantee.

What Actually Happens When Someone Taps a Plate

The tap does one thing: it hands the phone a web address. Nothing more moves between the plate and the phone. Understanding that single fact answers most of the security question by itself.

When a member holds their phone within an inch or two of the plate, the phone’s reader briefly powers the chip and receives the URL stored on it. The phone shows a small banner, the giver taps it, and their browser opens your church’s giving page. From that point on, it is identical to a member typing your giving link into their phone at home. The plate is out of the loop the moment the page opens.

NFC works only at very short range, a few centimeters, so a phone cannot pick up a plate from across the room or in a passing pocket. If you want the full step-by-step, we wrote a plain-English walkthrough of how tap-to-give works.

Does the Plate Store Any Card or Bank Information?

No. The chip stores one small piece of text, a web address, and nothing else. There are no card numbers on it, no bank details, and no donor records.

This matters because the thing people worry about, a device holding sensitive financial data, simply does not exist here. The URL burned onto the plate is the same link already published on your website and in your bulletin. Reading the plate reveals a public address, not a secret.

What the chip holds

  • One public giving URL
  • That is the entire contents

What it never holds

  • Card or account numbers
  • Donor names or gift history
  • Any live internet connection

For a deeper look at the chip and the standard behind it, our tech team wrote NFC giving explained.

Can an NFC Giving Plate Be Hacked or Reprogrammed?

Not by a tap. Tap.Giving plates ship locked, so the encoded URL is write-protected and cannot be overwritten by another phone. This is the single most common worry, and locking closes it.

Even if a plate were left unlocked, reading it would only reveal your public giving link, so there is no hidden data to extract and no payment to intercept. The chip is passive: it does nothing until a phone powers it, and all it can do is repeat one address.

The one realistic risk, and how to handle it

The honest risk is physical, not digital: someone could peel off a plate and stick their own tag or sticker in its place, pointing to a different page. That is the same risk a printed QR code carries, and it is easy to defeat. Mount plates securely, and glance at them during your normal sanctuary walk-through. If a plate ever looks wrong, tap it yourself and confirm it opens your real giving page.

Because we sell hardware and not a payment system, we can also lock a plate to a redirect you control, so you can re-point it later without reprinting. That keeps the address in your hands, not a stranger’s.

Where Does the Payment Security Actually Live?

On your giving platform, which is exactly where it lives today. Tap.Giving is hardware, not a payment processor, so the money never flows through us and we never see a card.

The donation happens on the same checkout your members already use online. Reputable giving platforms such as Tithely, Pushpay, Subsplash, and Donorbox run PCI-DSS-compliant payment pages, the industry security standard for handling card data. Adding a plate does not change that page or its protections in any way.

When a giver pays with Apple Pay or Google Pay, it is safer still. Their real card number is never shared with your church or your platform. A device-specific token stands in for the card, and the payment is confirmed with a face scan, a fingerprint, or a passcode on the giver’s own phone.

So the security you are counting on is your platform’s security, the protection your church already relies on for every online gift. The plate simply gets a member to that page faster.

What About Donor Privacy?

Tap.Giving collects nothing about the giver, because there is no app and no account on our side. The tap opens a web page in the phone’s browser, and that is the end of our involvement.

There is no download that asks for permissions, no login that creates a profile, and no tracking baked into the plate. Your giving platform records the gift the same way it always has, under the same privacy policy your members already agreed to. Adding plates does not create a new place your donors’ data is stored or a new company that holds it.

For many congregations, that is the appeal of the no-app model in the first place. If a member can give without downloading anything, they can also give without handing personal information to one more vendor. We wrote more about why app-free giving wins if that is the direction your church leans.

How Does It Compare to Cash, Checks, and QR Codes?

Measured against the offering methods your church already uses, tap-to-give holds up well and beats some of them. Here is the honest comparison.

Method Main security exposure Traceable record
Cash Can be miscounted or lost in handling before it reaches the bank None
Checks Carry a routing and account number in plain print Paper trail
QR code Printed image can be covered or swapped; giver reaches the same web page Platform record
Tap-to-give plate Physical swap only; the plate can be locked and re-pointed Platform record

Cash leaves no record and can go missing between the plate and the count. A check hands over a bank account number in plain sight. Tap-to-give and QR both route to your secure platform, but the plate has an edge: it can be write-locked, and if you use a redirect you control, you can change where it points without reprinting a single thing.

What Your Board Should Check Before Rolling It Out

Due diligence here is short, because most of the security is inherited from tools you have already vetted. Run this list at your next meeting.

  1. Confirm your giving platform is PCI-DSS compliant. Nearly every mainstream church platform publishes this on its security page.
  2. Ask for plates to ship locked so the URL cannot be rewritten. This is our default.
  3. Point the plates at a giving URL you own or a redirect you control, so you can update it later without new hardware.
  4. Decide who does a monthly glance at the mounted plates to catch a physical swap, the same person who already tidies the pews is fine.
  5. Confirm nothing new stores donor data: the plate does not, and your platform’s existing policy still governs the gift.

That is the whole review. There is no new processor to audit, no contract that touches your donor database, and no vendor added to your list of data holders.

Once the security question is answered, the rest is simple. Plates are a one-time purchase from $3.50 to $4.50 each, with free shipping and no monthly fees, and they work with the giving platform you already trust.

See your church’s plate, pointed at your own secure giving page

Design it in a minute, locked to your existing platform. One-time cost, no monthly fees, delivery 2-3 weeks from artwork approval.

FAQ

Is tap-to-give safe for churches?

Yes. It is as safe as the online giving your church already offers, and in one way safer: the plate never touches a card number or a bank detail. Each plate holds only your public giving URL and ships locked, and the payment happens on your existing platform’s secure, PCI-compliant page.

Does the NFC plate store card or bank information?

No. The chip stores one small piece of text: a web address. It holds no card numbers, no bank details, and no donor records. There is nothing to steal from the plate itself, because the only thing on it is a URL that is already public on your website.

Can an NFC giving plate be hacked or reprogrammed?

Tap.Giving plates ship locked by default, so the encoded URL cannot be overwritten by a tap. Even an unlocked tag holds nothing but your public giving link, so reading it reveals no secret. The realistic risk is physical: someone swapping a plate for their own sticker, which is the same risk a QR code carries and is easy to spot during a normal walk-through.

What donor data does Tap.Giving collect?

None from the giver. There is no app to install, no account to create, and no tracking on the plate. The tap opens your giving page in the phone’s browser, and your platform records the gift the same way it always has.

Related Articles

See your church's plate and price

One-time hardware. No monthly fees. Enter your email and design your plate on the next page.

  • Works with your existing giving platform
  • From $3.50/plate at 400+, $4.50 at 100
  • Free shipping, delivery 2-3 weeks from artwork approval

No spam. We reply within 24 hours.