Privacy notice · version 2026-08-29
Your information stays part of a private process.
This notice explains what Mithaq collects, why it is used, who supports the service, and the controls available to every member.
What Mithaq collects
- Account identity, verified email, profile name, and security information.
- Survey answers about religious practice, values, family expectations, and goals.
- Privacy choices, consent timestamps, blocks, reports, and account visibility.
- Compatibility scores, introduction decisions, imam reviews, and family messages.
- Meeting-package and membership payment status; full card details stay with Stripe.
- Operational logs needed to diagnose errors and protect the service.
Why the information is used
Mithaq uses member data to operate private matchmaking, apply the fixed compatibility rubric, support human imam review, arrange family-involved meetings, provide safety controls, process payments, and meet legal obligations. Compatibility results support a decision; they do not make a final introduction automatically.
Compatibility processing and OpenAI
Compatibility scoring begins only after an adult member accepts this notice and gives explicit compatibility consent. The fixed Mithaq rubric remains the main score. When separately consented, anonymised multiple-choice answers may be sent to OpenAI for a limited secondary review. Names, contact details, account IDs, and free-text answers are excluded, and the request asks the provider not to store model input.
Consent can be withdrawn in Privacy & settings. Withdrawal stops future processing; it does not invalidate processing already completed before withdrawal.
Service providers
- Supabase hosts the database and authentication service.
- Vercel hosts the web application, functions, analytics, and performance metrics.
- OpenAI is used only for the consented, bounded compatibility review described above.
- Stripe processes payments after the relevant member and imam approvals.
Provider agreements, international-transfer safeguards, and the final subprocessor list must be confirmed during the pre-launch legal review.
Retention schedule
| Record | Target retention |
|---|---|
| Incomplete accounts | 12 months after the last account activity |
| Compatibility results | 12 months after they are superseded, unless the account is deleted sooner |
| Introductions and family messages | 24 months after the introduction closes |
| Safety reports and admin audit history | Up to 6 years for safeguarding and accountability |
| Payment and accounting records | Up to 7 years where UK tax or accounting rules require it |
| Deleted account backups | Removed from active systems promptly and from backups within 30 additional days |
These are pre-launch operational targets. Legal holds, safeguarding duties, chargeback evidence, or statutory rules may require a longer period, which must be documented.
Your controls and rights
Signed-in members can hide or pause a profile, limit anonymous fields, block a member, report a concern, download a structured copy of their data, withdraw future compatibility consent, and delete their account after a recent sign-in.
UK data-protection rights can also include access, correction, erasure, restriction, objection, portability, and a review of significant automated processing. Mithaq’s final controller contact and ICO complaint wording must be added before public launch.
Open my privacy controlsSecurity and safeguarding
Sensitive trust records are not directly exposed to member clients. Administrator actions require multi-factor authentication and are recorded in append-only audit history. Imam access is limited to verified, active imam accounts. No online service can promise absolute security; suspected incidents should be reported through the signed-in safety controls while the public contact route is finalised.