MasjidPilot provides software for masājid, maktabs, Islamic schools and Islamic organisations. This Privacy Policy explains what personal information we handle, how we use it, who we disclose it to, how we protect it, and how individuals can access, correct or request deletion of their information.
By using MasjidPilot, creating an account, submitting a public form, registering for an event, donating through a MasjidPilot-powered page, using a parent, student or teacher portal, or interacting with a MasjidPilot public page, users agree to this Privacy Policy.
- In short
- 1. Operator details
- 2. Who we are
- 3. Information we collect
- 4. Sensitive information
- 5. Children and student data
- 6. Parental / guardian consent
- 7. How we collect information
- 8. Unsolicited personal information
- 9. Why we collect and use information
- 10. Public pages and public forms
- 11. Disclosure of information
- 12. Service providers and subprocessors
- 13. Overseas disclosure
- 14. Users outside Australia (EU / UK)
- 15. Cookies and browser storage
- 16. Security
- 17. Data retention
- 18. Access, correction, deletion and export
- 19. Complaints
- 20. Data breaches
- 21. Marketing communications
- 22. Changes to this Privacy Policy
- 23. Version history
- 24. Contact
In short
- We provide software for masājid, maktabs and Islamic organisations.
- Organisations enter and control most student, guardian, staff and public content data.
- We use providers including Supabase, Cloudflare, Resend and Stripe to operate the service.
- We use cookies and browser storage, including localStorage, to keep users signed in and operate the app.
- We do not sell personal information.
- We take reasonable security steps, but no online service is completely secure.
- You can contact us to request access, correction, export or deletion of your personal information.
1. Operator details
- Operator: MasjidPilot
- Legal entity: Legal entity and ABN details will be updated before paid subscriptions are launched.
- Location: New South Wales, Australia
- Privacy contact: privacy@masjidpilot.com
- Legal contact: legal@masjidpilot.com
- Support: support@masjidpilot.com
2. Who we are
MasjidPilot is a software platform for managing masjid operations, maktab administration, public event and donation pages, display screens, registrations, attendance, fees, resources, reports and communication. In this policy, "MasjidPilot", "we", "us" and "our" refer to the operator identified above.
The organisation using MasjidPilot — such as a masjid or maktab — is responsible for the information it enters about its own students, parents, guardians, teachers, staff, volunteers, donors and attendees. MasjidPilot provides the software platform and stores and processes that information to provide the service.
3. Information we collect
Account and user information
- Name
- Email address
- Phone number
- Password and authentication details
- Role and permissions
- Organisation membership
- Login activity
- Support requests
Organisation information
- Organisation name and public display name
- Address and location
- Phone numbers and email addresses
- Branding and logo
- Prayer time settings
- Screen settings
- Public website content
- Donation and payment instructions
- Event and program information
Maktab and student information
- Student names, date of birth or age, and gender if provided
- Class enrolments and assigned resources
- Attendance records
- Exam results and reports
- Notes
- Fee records and payment status
- Parent and guardian links
- Emergency contacts
Parent and guardian information
- Name and relationship to student
- Phone number and email address
- Address, if provided
- Portal access status
- Communication history
- Payment proof submissions
Teacher and staff information
- Name and contact details
- Assigned classes
- Attendance activity
- Portal access
- Notes or internal records
Event, registration and donation information
- Public registration form submissions
- Attendee names and contact details
- Event preferences or responses
- Donation campaign interaction data
- Donor name and email, if provided
- Donation reference, receipt or payment proof, if submitted
- Public page interactions
Payment and billing information
- Subscription plan and status
- Billing email and contact
- Invoice and payment metadata
- Active student counts for Maktab billing
- Stripe customer and subscription identifiers where payments are enabled
MasjidPilot does not store full card numbers. Card details are handled by Stripe. Some Stripe features may be in test mode, development mode, or not enabled for every organisation.
Technical and usage information
- IP address
- Browser and device information
- Log data and pages visited
- Error logs
- Security and audit logs
- Cookies, localStorage and similar technologies
- Analytics data, where enabled
Uploaded content and files
- Logos, flyers and posters
- Class resources and PDFs
- Payment proof files
- Public website content
- Any files uploaded by organisation users
4. Sensitive information
Some information we handle may be sensitive under Australian privacy law, including health or medical notes, emergency information, religious affiliation or participation where apparent from the nature of the service, information about children, and notes relating to students, welfare or support needs.
We only handle sensitive information where it is provided by the organisation or user, where it is reasonably necessary to provide the service, or where consent or authorisation is given. Organisations should only enter sensitive information that is necessary for administration, safety, teaching, attendance, reporting or communication purposes.
5. Children and student data
MasjidPilot may store information about children and students because maktabs, Qur'an schools and Islamic education programs use the platform.
- Student data is usually entered by the organisation or by a parent or guardian through a form or portal.
- Access is restricted based on roles and permissions.
- Parents and guardians may contact the organisation to access or correct their child's information.
- MasjidPilot may help the organisation respond to access, correction or deletion requests.
- Organisations should obtain any required parent or guardian consent before entering or publishing children's information.
Public event pages or websites should not publish personal information of children unless the organisation has appropriate authority and consent.
6. Parental / guardian consent
Where information relates to a child under 15, the organisation should ensure that a parent or guardian provides the information or has consented to the information being entered, unless the organisation has another lawful basis to collect and manage that information.
Public enrolment forms for children include a confirmation that the person submitting the form is the student's parent or guardian, or is authorised by the parent or guardian to submit that information.
7. How we collect information
- When an organisation creates an account.
- When users sign up or log in.
- When admins enter student, parent or teacher records.
- When public users submit event, donation, contact or enrolment forms.
- When users upload files.
- When users contact support.
- Automatically through logs, cookies, browser storage and analytics.
- Through Stripe when payment features are used.
8. Unsolicited personal information
If we receive personal information that we did not request, we will assess whether we could have collected that information under this Privacy Policy and applicable law. If we could not have collected it, and it is lawful and reasonable to do so, we will delete or de-identify it.
Examples include:
- Someone emails us unnecessary student or medical documents.
- Someone uploads unrelated files to the platform.
- Someone sends another person's private information through support.
9. Why we collect and use information
- To provide, operate and improve MasjidPilot.
- To manage organisations and user accounts.
- To run Masjid, Maktab and Website Add-on modules.
- To manage students, classes, attendance, fees, exams and reports.
- To provide parent, student and teacher portals.
- To generate public links, QR codes, display-screen content and public pages.
- To process registrations, enrolments and donation campaign information.
- To send service emails, trial reminders, billing reminders and support messages.
- To provide security, prevent misuse and troubleshoot errors.
- To calculate billing and active student counts.
- To comply with legal obligations.
- To respond to support, privacy or legal requests.
10. Public pages and public forms
Organisations can choose to publish certain content publicly, such as prayer times, notices, event and program pages, registration forms, donation campaign pages, public website content and display-screen content.
The organisation is responsible for deciding what content is published publicly. MasjidPilot provides the tools but does not control the organisation's decision to publish particular content. Organisations should not publish personal information, children's information, sensitive information or private records unless they have the appropriate authority and consent.
Public forms (event registration, donation, enrolment and contact) include a short collection notice near the submit control linking to this Privacy Policy.
11. Disclosure of information
Information may be disclosed to:
- Authorised users within the organisation.
- Parents and guardians through portals where enabled.
- Teachers and staff based on assigned access.
- Service providers who help operate the platform (see the subprocessor table below).
- Professional advisers.
- Regulators, courts, law enforcement or government agencies where required by law.
- Another entity if MasjidPilot is involved in a sale, merger, restructure or business transfer.
We do not sell personal information.
12. Service providers and subprocessors
MasjidPilot uses the following current service providers. Providers may update their own infrastructure and sub-processors from time to time.
| Provider | Purpose | Data processed | Location / transfer |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, row-level security and backend infrastructure. | Account, organisation, student, guardian, staff, attendance, fee, exam, resource, file, public-page and audit data. | Project region configured for our project, and Supabase infrastructure and sub-processors. |
| Cloudflare, Inc. | Edge hosting and SSR (Cloudflare Workers), CDN, security and performance for the website, app and public pages. | IP address, browser and device information, request and security logs, public page and display-screen requests. | Global Cloudflare edge network. Requests may be processed at the edge closest to the user. |
| Resend | Transactional and service emails, including auth emails, trial and billing reminders, invitations and notifications. | Names, email addresses, organisation names, and email content or metadata needed to deliver the message. | United States, and Resend infrastructure and sub-processors. |
| Stripe, Inc. | Payment processing, subscription billing, invoices and payment-related services where payments are enabled. | Billing contact, customer and subscription identifiers, invoice and payment metadata, and card details handled by Stripe. MasjidPilot does not store full card numbers. | Stripe global infrastructure and sub-processors. |
MasjidPilot uses Stripe, Inc. and its related entities for payment processing, subscription billing, invoices and payment-related services where payments are enabled. Some Stripe features may be in test mode, development mode or not enabled for every organisation.
13. Overseas disclosure
Some of the service providers above process or store information outside Australia, including through Cloudflare's global edge network, Resend in the United States, and Stripe's global infrastructure. We take reasonable steps to use reputable providers and to require appropriate security, confidentiality and data-handling measures. Provider locations and sub-processors may change over time.
14. Users outside Australia, including the EU and UK
MasjidPilot is operated from Australia and is primarily intended for Australian masājid, maktabs and Islamic organisations. However, public pages and forms may be accessible by people outside Australia, including the EU and UK.
Where the EU General Data Protection Regulation (GDPR) or UK GDPR applies, we process personal information on appropriate legal bases, which may include performance of a contract, legitimate interests, consent, legal obligations, and the provision of services requested by the organisation or user.
Where applicable, individuals in the EU or UK may have rights including:
- Access
- Correction
- Deletion
- Restriction of processing
- Objection to processing
- Data portability
- Withdrawal of consent, where processing is based on consent
International transfers may occur because our service providers, including Supabase, Cloudflare, Resend and Stripe, may process information outside the user's country.
15. Cookies and browser storage
MasjidPilot uses cookies and browser storage, including localStorage, to keep users signed in, manage authentication sessions, remember preferences, maintain security and operate the app. For example, the Supabase authentication session (JWT and refresh token) is stored in browser localStorage on the user's device so that users stay signed in between visits.
We use these mechanisms for:
- Essential login and authentication sessions
- Supabase auth session token / session data
- Security and abuse prevention
- App preferences and UI state
- Session and request logs
- Analytics, only if and when we enable an analytics tool
Disabling cookies or browser storage may prevent login and other app features from working. Essential storage is separate from any analytics cookies that may be enabled in the future.
16. Security
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Examples of measures include:
- Authentication
- Role-based access
- Row-level security and organisation-level data isolation
- Encryption in transit where available
- Restricted administrative access
- Audit and security logs
- Backups where available
- Secure third-party infrastructure
No internet service can be guaranteed completely secure. Users and organisations are responsible for keeping login details secure, using strong passwords, managing invited users and permissions, removing access when staff or teachers leave, and not sharing accounts.
17. Data retention
We keep information for as long as needed to provide the service and to meet legal, billing, dispute, security and backup obligations. The table below sets out our target retention approach. Where the platform does not yet enforce a period automatically, we aim to apply it on request or during periodic clean-up.
| Category | Typical retention |
|---|---|
| Account and organisation data | Life of the account, then typically deleted or de-identified within 90 days after closure, unless needed for legal, billing, dispute, backup or security reasons. |
| Student, guardian, teacher, class, attendance, fee, exam and report records | Controlled by the organisation while the account is active. After account closure, typically deleted or de-identified within 90 days unless legally required or retained in backups. |
| Public form submissions (events, donations, enrolments, contact) | Kept while the organisation needs them, then deleted by the organisation or after account closure. |
| Billing, subscription, invoice and payment records | Up to 7 years, where required for tax, accounting, legal or audit purposes. |
| Security, access and audit logs | Typically up to 12 months, unless needed longer for security, legal, dispute or abuse-prevention purposes. |
| Support emails and enquiries | Typically up to 3 years, unless needed longer for legal, dispute, security or service-history purposes. |
| Backups | Deleted data may remain in encrypted backups for up to 90 days before being overwritten or deleted, unless a longer period is required for security, legal or disaster recovery reasons. |
Organisations remain responsible for retaining records they are legally required to keep.
18. Access, correction, deletion and export
Individuals may request access, correction, deletion or export of their personal information. For information controlled by an organisation using MasjidPilot (such as student, guardian or attendance records), please contact the organisation first where appropriate. MasjidPilot can assist the organisation to respond.
Organisation admins may request export of organisation data in a commonly used format, such as CSV or JSON, where technically available and subject to reasonable verification, security, legal and billing requirements. Some files may be exported separately in their uploaded format, such as PDF or image files.
For account, billing and support data held by MasjidPilot directly, contact privacy@masjidpilot.com. Requests may be subject to identity verification and legal exceptions.
19. Complaints
To make a privacy complaint, contact privacy@masjidpilot.com with your name, contact details and details of your concern. We will aim to respond within a reasonable time, generally within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC), where applicable.
20. Data breaches
If we become aware of a suspected data breach, we will promptly assess it, take reasonable steps to contain and remediate it, and where required by law under the Notifiable Data Breaches scheme, notify affected individuals and the OAIC as soon as practicable.
Organisations must notify MasjidPilot as soon as practicable if they become aware of, or suspect, unauthorised access to their MasjidPilot account or data.
21. Marketing communications
We may send service-related emails, such as login, trial, billing, security, support and product updates. Marketing emails may be sent where permitted, and users can unsubscribe from marketing emails at any time. Service emails may still be sent because they are necessary for the platform.
22. Changes to this Privacy Policy
We may update this policy from time to time. If changes are material, we will take reasonable steps to notify users, such as through the website, app or email. Continued use after changes means acceptance of the updated policy.
23. Version history
- 1 July 2026 — Initial comprehensive public version.
- 1 December 2026 — Named current providers (Supabase, Cloudflare, Resend, Stripe); added subprocessor table, localStorage disclosure, unsolicited-information section, EU/UK posture, parental consent language, concrete retention periods, NDB "as soon as practicable" wording, data export format, and operator details.
24. Contact
Privacy questions: privacy@masjidpilot.com
Business or legal: legal@masjidpilot.com
Support: support@masjidpilot.com
See also our Terms of Use.