Privacy Notice
1. What this notice covers
This notice explains how we handle personal data when you use Social Muslims on the web or mobile app, browse the Private Network, send or respond to introduction requests, schedule Connections, join video calls or Thursday events, ask the real team for help, receive communications, or interact with our safety and verification systems. We do not sell personal data.
2. Data we collect
- Account and contact: user ID, name, phone number, email, authentication state, notification choices and account status.
- Profile and preferences: date of birth and age, gender, city or broad location, photos, profession, education, marital and family information, lifestyle, partner preferences, biography, tags and answers you choose to provide.
- Sensitive or special-category data: information that may reveal religion, sect, ethnicity, health or sexual orientation, and information about private life, where you choose to provide it. The service is designed for marriage-minded Muslim adults, so religious information is central to its purpose.
- Introductions and events: profiles viewed or passed, Intro balance and ledger, offers, acceptance or decline, selected contact method, contact snapshots, connection records, event reservations, private interest signals, pairings, call scheduling, room joins and attendance metadata.
- Safety and verification: verification results, reports, blocks, moderation decisions, evidence submitted to support, fraud and abuse signals. Private video content is not recorded by Social Muslims by default.
- Payments: product, price, currency, order or subscription identifiers, status, timestamps and provider references. Payment providers handle full card or funding details; we do not normally receive them.
- Technical and usage: IP address, device and browser information, release version, security logs, cookie choices, feature events, errors, delivery status and limited analytics.
- Communications: support messages, email/SMS/WhatsApp delivery events and separate consent or opt-out records.
3. Why we use data and our lawful bases
| Purpose | Usual lawful basis |
|---|---|
| Create and secure accounts; provide Prospects, Intros, calls, events, Connections and support | Contract; legitimate interests in operating and securing the service |
| Use sensitive profile information for eligibility, recommendations, profile display, introductions, events and safety review | Your explicit consent under UK GDPR Article 9(2)(a), alongside contract or legitimate interests for the ordinary personal-data elements |
| Process payments, maintain purchase evidence, prevent fraud and meet accounting obligations | Contract, legal obligation and legitimate interests |
| Send account, Intro, accepted-contact, call, security, billing and reservation messages | Contract and legitimate interests; these are service communications, not permission for unrelated marketing |
| Send optional event invitations, product news or offers | Consent or another PECR-compliant basis documented for the channel. Signup marketing boxes are optional and initially off |
| Moderate, investigate reports, enforce blocks, prevent abuse and protect legal claims | Legitimate interests, legal obligation, substantial public interest or establishment/defence of legal claims where applicable |
| Essential storage, security diagnostics and optional analytics | Strict necessity, legitimate interests, or consent for non-essential technologies |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not make earlier processing unlawful. Withdrawing special-category consent may mean we cannot continue to provide profile matching, introductions or events.
4. Profiles and contact sharing
Approved profile information and photos can be shown to other eligible signed-in members. It is not intended for public indexing. When you send a phone or email Intro, we snapshot only the selected saved contact detail and disclose it only to the intended recipient after acceptance. We do not disclose the recipient's contact detail in reverse. Accepted details may remain in that recipient's Connections and may already have been copied off-platform.
When team assistance is requested, the target profile reference and request status are shared with authorised Social Muslims staff and placed in the requester's Connections. The target's private contact details appear only after lawful agreement.
5. Recommendations and automation
We use rules, compatibility signals, ranking and operational judgement to decide eligibility and order Prospects or event pairings. Staff may review results. We do not intend to make a solely automated decision that produces legal or similarly significant effects without the safeguards required by law. You may ask for information or human review through support.
6. Who receives data
- Other eligible members, only to the extent needed for profiles, accepted Intros, calls, events, reports and blocks.
- Google Firebase and Google Cloud for hosting, authentication, database, storage and operational logging.
- Twilio for phone verification, SMS and optional WhatsApp service messages.
- Brevo for email delivery and email engagement/delivery events.
- Agora for real-time video calls and technical call metadata.
- PayPal, Stripe and Apple for applicable purchases, subscriptions, verification and payment support.
- Analytics, error-monitoring, identity-verification or AI service suppliers where configured and needed for the described purpose, under appropriate contracts and data-minimisation controls.
- Professional advisers, insurers, auditors, prospective corporate transaction parties, regulators, courts and law-enforcement bodies where lawful and necessary.
We require processors to act on our instructions and protect the data. A current high-level vendor and transfer register is maintained internally.
7. International transfers
Some providers process data outside the UK. We use a lawful transfer mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, and associated transfer risk assessments and supplementary safeguards.
8. Marketing and communication choices
Email-event and SMS-event consent are separate, optional choices. WhatsApp service-message consent is also separate and does not authorise event marketing. You can withdraw email marketing through the unsubscribe instruction, SMS marketing by replying STOP, WhatsApp permission through settings/support, or any channel by contacting us. Operational messages needed for an Intro, call, reservation, payment, safety issue or account may continue while the relevant service remains active.
9. Cookies and local storage
We use essential storage for sign-in, security, session continuity, payment return and consent records. Optional analytics is enabled only after the relevant choice. Details and controls are in our Cookie Policy.
10. Retention
- Account/profile: while active; after closure, deleted or anonymised through the operational deletion process unless another period below applies.
- Pending Intro and event operational records: normally 90 days after their terminal state, unless needed for connections, billing, safety or disputes.
- Accepted contact/connection records: while the relevant account and connection are active, then deletion/anonymisation subject to legal and safety exceptions.
- Payment, tax, consent and accounting evidence: normally 6 years after the relevant transaction or relationship ends.
- Safety, blocks, complaints and enforcement: normally up to 6 years where needed to prevent rematching, establish facts or defend legal claims; shorter where the risk no longer justifies retention.
- Support: normally 24 months after closure of the issue unless linked to a longer legal, payment or safety record.
- Analytics and routine logs: normally up to 12 months, with shorter security logs where practical; aggregated statistics may no longer identify a person.
- Backups: deleted through rolling backup cycles and disaster-recovery schedules.
These are maximum operational targets, not promises to keep every record for the full period. We periodically review necessity.
11. Your rights
Subject to legal conditions, you may request access, correction, erasure, restriction, portability, objection, withdrawal of consent and information about certain automated processing. You can use in-product export/deletion controls where available or email socialmuslims02@gmail.com. We may verify identity and ask you to clarify a broad request. We normally respond within one month, subject to lawful extensions.
Erasure may not remove minimal payment, consent, block, fraud, safety, complaint or legal-claim evidence that we must or are entitled to retain. We will restrict access and minimise retained data.
12. Complaints
Use our Complaints Procedure for a privacy complaint. We will acknowledge and investigate it in line with applicable UK data-protection complaint requirements. You may also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or call 0303 123 1113.
13. Security and children
We use access controls, authentication, encryption in transit, logging, provider security controls, least-privilege practices and incident procedures. No system is risk-free. Social Muslims is for adults aged 18 or over. We do not knowingly provide it to children; suspected underage accounts are restricted and investigated.
14. Changes and contact
We may update this notice when law, suppliers or the product changes. Material changes will be highlighted and, where a new consent is required, we will ask for it separately. Questions and requests: SOCIALMUZ LTD, 20-22 Wenlock Road, London, N1 7GU; socialmuslims02@gmail.com; +44 7779 305853.