Privacy Policy

Last updated: 31. März 2026 · This privacy policy applies to the MuslimRihla app and website.

1. Data Controller

Abdurrahim Schneider

E-Mail: [email protected]

Responsible under GDPR (Art. 4 No. 7 GDPR).

2. Data We Collect

Account Data (on registration)

  • Name and email address (via secure OAuth login)
  • Unique user ID

Usage Data

  • Completed Amals (daily good deeds)
  • Quran reading progress
  • Journal entries (Shukr & Muhasabah)
  • Streak and Hasanat points
  • Friendship connections

Payment Data (Premium/Sadaqah Plus)

  • Payments are processed via Stripe. We only store the Stripe customer ID and subscription status – no card data.
  • Sadaqah donation amount and chosen project

Location Data (optional)

For prayer times and Qibla direction, we request your location. This data is only processed locally in the browser and not stored on our servers.

3. Purpose of Data Processing

• Providing app features (Amals, Quran, Journal, Friends)

• Processing payments and subscriptions

• Calculating and displaying statistics and progress

• Transparent Sadaqah tracking

• App improvement (anonymized usage statistics)

4. Legal Basis

• Art. 6(1)(b) GDPR – Contract performance (app use, subscription)

• Art. 6(1)(a) GDPR – Consent (notifications, location)

• Art. 6(1)(f) GDPR – Legitimate interests (security, fraud prevention)

5. Third-Party Services

Stripe

Payment processing. Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. Privacy: stripe.com/privacy

AlAdhan API

Prayer time calculation. No personal data transmitted (coordinates only).

Islamic Network CDN

Quran audio files. No personal data.

6. Your Rights

• Access to stored data (Art. 15 GDPR)

• Rectification of incorrect data (Art. 16 GDPR)

• Deletion of your data (Art. 17 GDPR) – delete account in settings

• Restriction of processing (Art. 18 GDPR)

• Data portability (Art. 20 GDPR)

• Right to object (Art. 21 GDPR)

To exercise your rights, contact: [email protected]

7. Data Security

All data is transmitted encrypted (HTTPS/TLS). Passwords are not stored – we use OAuth. Database access is restricted to authorized servers.

8. Retention Period

Data is stored as long as your account is active. After account deletion, all personal data is deleted within 30 days. Payment data is retained according to legal requirements (10 years).

Privacy questions?

Contact us: [email protected]