Privacy Policy
Last updated: July 2026
This Privacy Policy explains how MasjidBase processes personal data — both the account data of the organizations that subscribe to the platform, and the records of members, donors, students and guardians that those organizations manage in it. It should be read together with our Terms of Service.
Who we are — controller and processor
MasjidBase provides a management platform for mosques, Islamic schools and non-profit organizations. For the records your organization stores in the platform (members, donors, students, guardians, donations), your organization is the data controller and MasjidBase acts as its data processor, on documented instructions and under a data processing agreement. For account, billing, website and marketing data, MasjidBase is the controller. You can reach us about anything in this policy at contact@mosquebase.com. The agreement that governs this is published at mosquebase.com/dpa.
Data we process
Account and billing data: administrator name and email, organization details, subscription and payment records — card numbers are handled by our payment providers and are never stored by us.
Organizational records (as processor): member and donor profiles, donation and payment history, student records including name, date of birth, class, attendance, grades and Quran-memorization progress, guardian contact details, and the communications your organization sends.
Usage data: authentication logs, feature usage and device information used to operate, secure and improve the platform.
Special category data
Because MasjidBase serves mosques and Islamic schools, records such as membership, donations and religious-education progress can reveal religious beliefs, which is special category data under Article 9 GDPR. Your organization processes this data in the course of its legitimate activities as a not-for-profit body with a religious aim, relating to its members and regular contacts (Article 9(2)(d) GDPR). MasjidBase processes it strictly on the organization's instructions, never uses it for any purpose of its own, and never discloses it outside the subprocessors listed below.
Children's data
Organizations store student records, and parents or guardians may submit a child's details through public registration forms. Consent is requested from the parent or guardian at the point of collection and recorded with a timestamp and the version of this policy that was accepted. Children cannot create MasjidBase accounts. Children's data is never used for marketing, profiling or advertising, and is only processed to provide the school-management features your organization uses.
Purposes and legal bases
We process personal data to provide the platform under our contract with your organization (Article 6(1)(b) GDPR); to bill, keep accounts and meet legal obligations (Article 6(1)(c)); to secure the platform, prevent fraud and abuse, and improve the service, based on our legitimate interests (Article 6(1)(f)); to send product communications your organization triggers, such as donation receipts and fee reminders (Article 6(1)(b)); to send marketing to prospects who requested a trial, demo or updates, based on consent or applicable soft opt-in rules, with an opt-out in every message; and to run website analytics only with your consent (see Cookies).
AI features
The optional in-app assistant is powered by Anthropic. When a staff member asks it a question, the question and the minimum organizational records needed to answer are sent to Anthropic's API. Under Anthropic's commercial terms this data is not used to train AI models and is retained only briefly for abuse prevention. The assistant makes no automated decisions with legal or similarly significant effects: it drafts and summarizes, and your staff decide and act. AI output can be inaccurate and is not accounting, tax, legal or religious advice — always verify it. If your organization connects a third-party AI client using an API key, the data shared with that client is governed by that provider's terms and remains your organization's responsibility.
Subprocessors and third-party services
We use a small set of providers, each bound by a data processing agreement: Google Cloud / Firebase (hosting, database and file storage, United States), Stripe (payment processing), PayPal (payment processing, where enabled), Amazon Web Services SES (email delivery), Anthropic (AI assistant) and Google Analytics 4 (website analytics, only with consent). We will inform customers before adding a subprocessor and give them the opportunity to object. We never sell personal data and never use organizational records for advertising. The current list is published at mosquebase.com/subprocessors, with its version history.
International data transfers
Our infrastructure is hosted in the United States. Where personal data of individuals in the EU/EEA, the United Kingdom or Switzerland is transferred there, we rely on the EU–US Data Privacy Framework for certified providers and/or the European Commission's Standard Contractual Clauses, with supplementary measures including encryption in transit and at rest. You can request a copy of the relevant safeguards at contact@mosquebase.com.
Data retention
Organizational records are retained for as long as the organization's account is active. After closure, data is kept for 90 days so it can be exported or the account reactivated, then deleted — except financial records that statutory accounting rules require us to keep longer, and minimal security logs kept for up to 12 months. Residual copies in encrypted backups are removed as backups rotate shortly afterwards.
Security and breach notification
All data is encrypted in transit and at rest. Each organization's data is isolated by server-side security rules; access within an organization is role-based, and our own staff access follows least privilege. Financial documents are sequentially numbered and changes are auditable. If a personal data breach affects your organization's data, we will notify the organization without undue delay and support its notification obligations towards authorities and affected individuals.
Your rights
Depending on where you live, you have the right to access, correct, delete and receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time without affecting processing already carried out. If your data is held by an organization that uses MasjidBase, that organization is the controller: contact it first, and we will assist it in answering you. You also have the right to lodge a complaint with your data protection authority — in France, the CNIL (cnil.fr).
California and US state privacy rights
We do not sell or “share” personal information as defined by the California Privacy Rights Act, and we honor opt-out preference signals such as Global Privacy Control for website analytics. Residents of California and of other US states with privacy laws may request access to, deletion or correction of their personal information by writing to contact@mosquebase.com, and will not be discriminated against for exercising their rights. The categories of information we collect and our purposes are those described above.
Cookies
Essential cookies keep you signed in, remember your preferences and make the platform work; they require no consent. Analytics cookies (Google Analytics 4) are set on our website only after you accept them through the cookie banner: they measure aggregated usage and never receive what you type into our forms. You can review or withdraw that choice at any time through “Cookie preferences” in the website footer, or in your browser. We set no advertising cookies. We treat a Global Privacy Control signal as a refusal of analytics.
Marketing communications
We send marketing email only to people who requested a trial, a demo or updates from us. Every message identifies MasjidBase as the sender and contains a working unsubscribe link, which takes effect immediately. Transactional messages triggered by your organization — donation receipts, fee reminders, registration confirmations — are part of the service, not marketing.
Changes and contact
We will post any change to this policy on this page, update the date above and notify organizations of material changes at least 14 days before they take effect. Questions and requests: contact@mosquebase.com.