Masjid Sync
Privacy Policy
Last updated: 19 July 2026
This Privacy Policy explains how Masjid Sync (“we”, “us”, “our”), operated at masjidsync.uk, collects, uses, and protects personal data when you use our website, admin tools, public masjid pages, and related services (the “Service”).
By using the Service you acknowledge this policy. If you do not agree, please do not use the Service.
1. Who we are
Masjid Sync provides software for masjid committees to manage prayer times, donations, announcements, displays, and related community tools.
When a masjid committee creates an account and stores donor or worshipper data, that masjid is typically the data controller for that community data. We act as a processor / service provider for platform hosting, authentication, and features they enable. For account data we collect directly (for example your login email), we are the controller.
2. Data we collect
Depending on how you use the Service, we may process:
• Account data: name, email, password hash, role, and session information. • Masjid profile data: name, address, location, contact details, branding, and verification materials you upload. • Operational data: prayer times, events, announcements, expenses, assets, nikah requests, and similar records entered by the committee. • Donor and giving data: names, amounts, methods, campaign links, and optional phone or identity details the committee chooses to store. • Payment data: online card payments are handled by Stripe; we receive limited payment status and identifiers, not full card numbers. • Technical data: IP address, device/browser type, approximate location from IP, cookies or similar technologies, and logs needed for security and reliability.
We do not intentionally collect special-category data beyond what a committee voluntarily enters for its own operations.
3. How we use data
We use personal data to:
• provide, maintain, and improve the Service; • authenticate users and protect accounts; • host public masjid pages and hall displays as configured by each committee; • process or facilitate donations and receipts where enabled; • send transactional emails (verification, password reset, important service notices); • detect abuse, prevent fraud, and keep the platform secure; • comply with law and enforce our Terms.
We do not sell personal data.
4. Lawful bases (UK GDPR)
Where UK GDPR applies, we rely on one or more of: performance of a contract (providing the Service you signed up for); legitimate interests (securing and improving the Service, preventing abuse); consent (where we ask for it); and legal obligation (where the law requires us to retain or disclose information).
5. Sharing and processors
We share data only as needed to run the Service, including with:
• hosting, database, email, and storage providers; • Stripe for online payments when a masjid enables card checkout; • professional advisers or authorities when legally required; • a successor entity if we reorganise or transfer the business, under appropriate safeguards.
Masjid committees may publish limited information on their public pages (for example prayer times, announcements, or first names of donors if they choose). Sensitive donor fields such as phone numbers and CNIC are not shown on public pages or TV displays by design.
6. Donor privacy
Committees control what they record about donors. We design the Service so donor phones and national identity numbers are kept for committee use and are not displayed on public or TV surfaces.
If you are a donor and want correction or deletion of your records, contact the relevant masjid committee first. You may also email us at legal@masjidsync.uk and we will help route the request where appropriate.
7. Retention
We keep personal data only as long as needed for the purposes above, including account life, financial record-keeping expectations for masjid operations, security logs, and legal claims. When an account or masjid workspace is deleted, we delete or anonymise associated personal data within a reasonable period, except where retention is required by law or legitimate dispute resolution.
8. Your rights
Subject to UK data protection law, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. You may also complain to the UK Information Commissioner’s Office (ICO).
To exercise rights about your Masjid Sync account, email legal@masjidsync.uk. For data held inside a specific masjid’s workspace, the committee usually needs to action the request; we will assist reasonably.
9. Cookies and similar technologies
We use essential cookies and similar storage for sign-in sessions, language preference, and security. These are required for the Service to work. We do not use advertising trackers as part of the core product.
10. Security
We use industry-standard measures such as encrypted transport (HTTPS), access controls, and hashed passwords. No method of transmission or storage is perfectly secure. You are responsible for keeping your login credentials confidential and for using strong passwords.
11. Children
The Service is intended for masjid administrators and adult users. We do not knowingly collect personal data from children under 13 for account registration. If you believe a child has provided personal data inappropriately, contact legal@masjidsync.uk.
12. International transfers
We may process data in the United Kingdom, European Economic Area, or other countries where our infrastructure providers operate. Where required, we use appropriate safeguards for international transfers.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the Service after an update means you accept the revised policy, except where applicable law requires a different approach.
For privacy or legal requests, email legal@masjidsync.uk. We aim to respond within a reasonable time.