Dhakker ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our mosque digital signage platform.
1. Information We Collect
1.1 Account Information
When you use Dhakker, we collect the following information:
- Email address - Used for authentication and account management
- Display name - Used to identify you within the admin dashboard
- User role - Used to determine your access permissions (viewer, editor, admin)
1.2 Mosque Configuration Data
We store configuration data related to your mosque's digital signage setup:
- Prayer times and iqama times
- Design content (text, images, backgrounds)
- Display settings and preferences
- Asset library content (uploaded images, templates)
1.3 Donation Campaign Data
If you use our donation campaign features, we collect:
- Campaign name and description
- Target donation amount
- PayPal donation link information
- Donation tracking data (amounts collected)
1.4 Technical Information
We automatically collect certain technical information:
- Browser type and version
- Device type and operating system
- IP address (temporarily, for security purposes)
- Usage logs and analytics data
2. How We Use Your Information
We use your information for the following purposes:
- Service delivery - To provide and maintain the Dhakker platform
- Authentication - To verify your identity and manage access
- Content management - To store and display your mosque's signage content
- Translation services - To provide AI-powered Arabic-German translation using OpenAI's API (see Section 4)
- Communication - To send important service updates or respond to inquiries
- Improvement - To analyze usage patterns and improve our platform
- Security - To detect and prevent abuse, fraud, or unauthorized access
3. Data Storage and Processing
3.1 Primary Data Processor: Firebase/Google Cloud
All user data, mosque configuration, and content is stored on Firebase (a Google Cloud Platform service). Firebase provides:
- Authentication services (Firebase Auth)
- Database storage (Cloud Firestore)
- File storage (Cloud Storage for Firebase)
- Hosting services (Firebase Hosting)
Google Cloud infrastructure is SOC 2, ISO 27001, and GDPR compliant. Your data is stored in secure data centers and encrypted both in transit and at rest.
Firebase Privacy Information: https://firebase.google.com/support/privacy
3.2 Sub-Processor: OpenAI
When you use the AI-powered translation feature (Arabic text translation), your text content is sent to OpenAI's API for processing. OpenAI is used exclusively for:
- Translating Arabic text to German
- Generating Islamic content (Quranic verses, hadiths, duas)
OpenAI does not store your text data beyond the processing period required to fulfill the translation request. OpenAI's API usage is governed by their data processing policies.
OpenAI Privacy Policy: https://openai.com/privacy
4. Data Retention
We retain your data for the following periods:
- Account data - Retained while your account is active, and for 30 days after account deletion
- Mosque content - Retained while your account is active; deleted permanently upon account deletion
- Analytics data - Aggregated and anonymized, retained for up to 12 months
- Logs - Stored for up to 90 days for security and troubleshooting purposes
5. Data Sharing and Third Parties
We do not sell, rent, or share your personal data with third parties, except:
- Service providers - Firebase/Google Cloud (data storage), OpenAI (translation services)
- Legal obligations - If required by law, court order, or government regulation
- Business transfers - In the event of a merger, acquisition, or sale of assets (with prior notice)
6. Your Rights (GDPR Compliance)
If you are located in the European Economic Area (EEA), you have the following rights under GDPR:
- Right to access - Request a copy of the personal data we hold about you
- Right to rectification - Request correction of inaccurate or incomplete data
- Right to erasure ("right to be forgotten") - Request deletion of your personal data
- Right to data portability - Request a copy of your data in a machine-readable format
- Right to restriction of processing - Request that we limit how we use your data
- Right to object - Object to our processing of your data
- Right to withdraw consent - Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, please contact your mosque administrator or reach out to us using the contact information below.
7. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest (Firebase Cloud Firestore and Storage)
- Role-based access control (RBAC)
- Regular security audits and monitoring
- Content Security Policy (CSP) headers to prevent XSS attacks
However, no system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. Cookies and Tracking
Dhakker uses essential cookies and local storage to:
- Maintain your login session (Firebase Auth tokens)
- Store user preferences (display settings, language)
- Enable offline functionality (PWA caching)
We do not use third-party advertising cookies or tracking scripts. All cookies are strictly necessary for the platform to function.
9. Children's Privacy
Dhakker is not intended for use by children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
10. International Data Transfers
Your data may be transferred to and processed in countries outside your own, including the United States (where Google Cloud and OpenAI operate). We ensure that such transfers comply with GDPR requirements through:
- Standard Contractual Clauses (SCCs)
- Data Processing Agreements with sub-processors
- Adequate safeguards as defined by GDPR Article 46
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
If we make significant changes, we will notify you via email (if you have provided one) or through a prominent notice on the platform.
12. Contact Us
Questions or Concerns?
If you have any questions about this Privacy Policy, or wish to exercise your data rights, please contact:
Your Mosque Administrator
For mosque-specific data inquiries, please reach out to your local mosque administrator who manages your Dhakker instance.
Dhakker Platform Team
For general privacy inquiries or platform-level concerns, you can reach us at:
Email: privacy@dhakker.app
13. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of Germany and the European Union (GDPR). Any disputes arising from this policy will be resolved in the courts of Germany.