Privacy Notice
1. Scope and profile visibility
This notice covers Muslim marriage profiles, introduction requests, online marriage events, in-person marriage events, private video calls, purchases, support and safety. We do not sell personal data.
Full Prospects browsing is an authenticated service for every approved, eligible signed-in user. They may browse eligible unseen profiles, Save, Pass and request a private video call, subject to safety rules, recipient capacity and daily-use controls. Preferences, blocks and availability still apply. Free access to authorised incoming profiles, event partners and established Connections remains available. When someone asks to meet you, we show you their first name, age, area, authorised photos, note and proposed time before you answer, and we may email you their first name, age and area (never a photo) so you can respond. The sender can see whether you opened their request, and nothing else about your activity.
Free Prospects previews contain up to four eligible profiles with server-produced blurred photos and recorded age, occupation, broad area and marriage timeline only. They contain no names, account identifiers, full profiles, original images or contact information. Preview selection is stable, rechecked for safety and separate from full browsing: it does not use an allowance, notify anyone or mark a profile viewed.
Pending introduction requests remain actionable until their original deadlines. Accepted and scheduled calls remain available after membership expiry. Historical records and decisions keep their original access and disclosure rules.
During online marriage events, waiting participants remain private and each pair sees only their authorised partner and call. Final Interested/Pass decisions remain private unless both choose Interested. After completion, members may reveal those mutual matches and initiate follow-up. Free results contain mutual-match counts and anonymous placeholders only. One-sided choices and one-sided interest counts are never revealed in this programme.
When your booking for an upcoming event is confirmed, your profile photo or a default avatar is shown on that event card to approved signed-in members, without names or profile links. Waiting-list places are not shown, and cancelling your place or the event finishing removes the image. Bookings made before this change keep the privacy rules they were made under. We do not import Eventbrite attendees or their photos. Eventbrite ticket holders use their own ticketing service; app check-in records cover app-issued tickets.
Where you live — clarification, 9 October 2026
We ask which town you live in so we can show you people near you first, and so that we only introduce members who live in the UK. You can type your town or tap Use my location; if you do, your device's location is used once to find your nearest town and is not kept: we keep only the town you confirm. Other members see your town, never an exact location. You can change it in Me at any time. Town names and positions come from GeoNames (geonames.org, CC BY 4.0).
Find Friends clarification — 30 September 2026
Find Friends shows members of the same gender to each other, to arrange a friendly private video call. Unless you switch it off, your profile can be shown there to same-gender members who are looking for friends, even if you are looking for marriage. What they see is limited to your first name, age, photos, city, work and the details you chose to share about yourself; marriage details such as marital status, children and marriage timeline are never shown in Find Friends. Switch off Show me in Find Friends in Me at any time and you stop appearing there straight away. It does not change who sees you for marriage.
Private-call clarification — 27 September 2026
For bookings using the new call controls, we keep a separate booking identifier, proposed and agreed times, confirmations, join attempts, device-setup failures, connection changes, received-media reports, heartbeats and outcomes. These operational checks help provide the call, investigate failures and avoid unfair missed-call decisions. Obtaining room access alone does not establish attendance. Provider-verified channel events and authenticated client reports are recorded separately.
A problem report may include your booking, attempt, agreed time, observed failure time, platform, release and a limited set of technical error codes. We show that these details are included. We do not attach access tokens, raw request headers, audio, video or unrelated activity. You can still ask for help when a booking is no longer available. Recorded support replies can be viewed in the app. Private explanations and internal support notes are not shared with the other participant.
Routine terminal call history targets 90 days. Evidence needed for an open support case or dispute follows the support retention policy below. Export and deletion requests include the new call records, subject to those existing retention exceptions. Optional analytics remains controlled by your analytics choice. A push ticket means the service accepted a submission; a provider delivery receipt is not proof that you read it.
2. Data we collect
- Account and contact: user ID, name, phone, email, authentication and verification state, notification choices and account status.
- Profile and preferences: date of birth, age, gender, postcode and derived area, authorised photos, profession, education, height, lifestyle, marital and family information, partner preferences, biography, profile answers and quiz responses.
- Sensitive or special-category information: details that reveal or may allow us to infer religion, sect, practice, prayer, hijab or halal preferences, ethnicity, health-related or private-life information, marital/family background and the importance of these factors to you. Optional identity verification may involve biometric data processed by Stripe Identity.
- Browsing and invitations: profile cards issued, views, Pass reasons, saved profiles, blocks, reports, compatibility reasons, event selections and dispatches, historical request status, versioned browsing allowance records, reset time, membership state and deterministic action receipts used to prevent duplicate counting.
- Connections and calls: scheduling, room IDs, joined, left and finished timestamps, lifecycle state, private Yes/No decisions, mutual outcomes, call duration and technical metadata. Leave is reversible during an open call window; Finish conversation ends an established conversation; the private decision is separate. Social Muslims does not record private call audio or video by default.
- Marriage events: time, reservation and admission evidence, complimentary-ticket usage and restoration, gender-specific seats and waitlists, cancellations, app QR check-in, attendance, final decisions, pairings, rounds and results. Historical programmes retain their original records.
- Safety and verification: reports, blocks, moderation and enforcement decisions, evidence, identity-verification result and fraud or abuse signals.
- Payments: product, price, currency, order/subscription identifiers, status, timestamps, consent evidence and provider references. Payment providers retain full funding details.
- Technical and communications: IP, device/browser, release, security logs, cookie choices, delivery status, analytics, support content and email/SMS/WhatsApp permissions and opt-outs.
3. Purposes and lawful bases
| Purpose | Usual lawful basis |
|---|---|
| Create and secure accounts; provide profile browsing, Personal Introductions, Connections, calls, events and support | Contract and legitimate interests in operating and protecting the service |
| Use religion, ethnicity, marital/family background, private-life information and preferences for eligibility, profile display, recommendations, matching, Personal Introductions, events and safety | Your explicit consent under UK GDPR Article 9(2)(a), alongside contract or legitimate interests for ordinary personal data |
| Optional biometric identity verification | Your explicit consent for biometric processing and our legitimate interests in preventing impersonation |
| Rank eligible profiles, create compatibility reasons and interpret private Pass feedback | Contract and legitimate interests; explicit consent where supplied text contains special-category data |
| Process payments, preserve purchase/consent evidence, prevent fraud and maintain accounts | Contract, legal obligation and legitimate interests |
| Send factual account, Meet, Connection, call, event, billing, legal and safety communications | Contract and legitimate interests; these do not authorise unrelated marketing |
| Send optional promotions or event invitations | Soft opt-in for existing customers under PECR regulation 22(3) for our own similar events, or consent where you have given it — with a simple opt-out in every message |
| Moderate content, investigate reports, enforce blocks and defend legal claims | Legitimate interests, legal obligation, substantial public interest or establishment/defence of legal claims where applicable |
You may withdraw consent at any time. Withdrawal does not make earlier processing unlawful. Withdrawing matchmaking-sensitive-data consent removes your profile from browsing and prevents new matching, Meets and event activity because those services depend on that information. Account access, billing cancellation, data rights, reports, support and existing accepted or scheduled calls remain available.
4. Recommendations and AI
Rules, compatibility signals, ranking and operational judgement determine eligibility and profile order. We do not label individual profiles with their subscription or payment status. Selection applies the viewer's directional preferences; the displayed person's preferred age range does not block an inbound Meet. On-demand selection and immediate continuation after a Pass or confirmed Meet are automated, but do not produce legal or similarly significant effects. You may ask for an explanation or human review.
Google Gemini services may help structure private Pass feedback, draft compatibility reasons and compare answers. Limited relevant profile facts and answers may be processed, including special-category information where you have explicitly consented. We do not send names, contact details or photos for these tasks. Quiz answers may also be converted to numerical representations to compare compatibility.
5. Meets, contact and staff access
Private introduction records contain the proposal, response deadline, permitted profile access, response and arranged call. We use only the information needed for delivery, scheduling, safety and audit. Receiving a request does not imply acceptance. Contact details are shared only through the authorised, consensual number-sharing journey.
For an existing Personal Introduction case, authorised staff may review relevant safety context, a note and proposed time. Email outreach may disclose the sender's first name and proposed time; the full note and profile remain inside authenticated Social Muslims. SMS is a permitted fallback when email cannot be used. A blocked or failed send does not start a response deadline. Channel replies do not automatically accept an introduction; the recipient responds in the app.
Connection-specific scheduling help and existing paid matchmaker cases retain their agreed staff access. The former £999 service is not offered to new applicants. We retain case and delivery evidence for support, safety and disputes.
6. Recipients and processors
- Eligible approved members, to the extent required for profile browsing, Personal Introductions, Connections, calls, events, reports and blocks.
- Google Firebase and Google Cloud for hosting, authentication, database, file storage and logs; Google Gemini for the limited AI processing above.
- Twilio for verification, SMS and optional WhatsApp; Brevo for email delivery and delivery events.
- Agora for real-time video and technical metadata.
- PayPal and Apple for current payments; Stripe for legacy billing and optional Stripe Identity verification.
- Professional advisers, insurers, auditors, corporate-transaction parties, regulators, courts and law enforcement where lawful and necessary.
We apply contracts, role-based access and data minimisation. Current provider and safeguard details, including a copy of the safeguards used for relevant international transfers, are available on request.
7. International transfers
Photos and files are stored in the European Union. Application hosting and some Google, Gemini, Twilio, Agora, Stripe, PayPal and Apple processing may occur in the United States or globally. Brevo processes email in the European Union. Where data leaves the UK we use applicable adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, with transfer-risk and supplementary controls. Copies of applicable safeguards are available on request.
8. Communications
Email is the first choice for event bookings and changes, introduction requests, arranged calls, results and essential account, billing, support, legal and safety messages. SMS is a permitted last resort when email cannot be used, not a routine duplicate. A failed or uncertain email submission is not treated as permission to send the same message through another channel.
Promotions cover our own online marriage events and in-person marriage events, and nothing else. Where you gave us your details when you registered or enquired, we rely on the soft opt-in for existing customers under PECR regulation 22(3) to tell you about our own similar events. Where you have given recorded channel-specific permission, we rely on that consent. Either way, every message carries a simple opt-out, we honour withdrawals and provider suppression lists immediately and permanently, and a recorded refusal is never overridden by anything. We do not use these details to promote anyone else's products or services, and we do not sell or share them for marketing.
You can change event-email and event-SMS choices in your account. Email has an unsubscribe route; SMS includes STOP instructions. Marketing opt-outs do not stop necessary service notices, but channel suppression and delivery restrictions are still respected. We record consent source, version and time, policy decisions, delivery attempts and suppression evidence. We do not replace retired email campaigns with WhatsApp, push or in-app campaigns.
9. Cookies and local storage
We use essential storage for sign-in, security, service continuity, profile/deep-link state, payment return and consent evidence. Optional analytics is enabled only after the relevant choice. See the Cookie Policy.
10. Retention
- Account/profile: while active, followed by deletion or anonymisation through the account-deletion process unless an exception applies.
- Profile cards and terminal Meet/event records: target 90 days after terminal state unless needed for pair history, a Connection, billing, safety or a dispute.
- Accepted Connections: while relevant accounts and the Connection remain active, then deletion/anonymisation subject to legal and safety exceptions.
- Payment, tax, contract and consent evidence: normally six years after the transaction or relationship ends.
- Safety, blocks, complaints and enforcement: normally up to six years where necessary to prevent rematching or establish/defend claims.
- Support: normally 24 months after the issue closes; analytics and routine logs: normally up to 12 months.
These are maximum operational targets rather than promises to retain every item for the full period. Backups expire through rolling recovery schedules.
11. Your rights
Subject to legal conditions, you may request access, correction, erasure, restriction, portability, objection, consent withdrawal and information about automated processing. Use in-app export/deletion controls or email socialmuslims02@gmail.com. We normally respond within one month, subject to lawful extensions. Minimal payment, consent, block, fraud, safety, complaint or legal-claim evidence may be retained where required or justified.
12. Security, children and complaints
We use authentication, access controls, encryption in transit, logging, provider controls and incident procedures, but no system is risk-free. The service is for adults aged 18 or over; suspected underage accounts are restricted and investigated.
Use our Complaints Procedure. You may also complain to the ICO at ico.org.uk/make-a-complaint or 0303 123 1113.
13. Changes and contact
Material changes are highlighted and, where required, presented for separate Terms acceptance, Privacy acknowledgement and explicit sensitive-data consent. Contact SOCIALMUZ LTD at 20-22 Wenlock Road, London, N1 7GU; socialmuslims02@gmail.com; +44 7779 305853.