Privacy Notice
1. Scope and profile visibility
This notice explains how we handle personal data when you create a Social Muslims account, browse profiles, send or receive Meet requests, form Connections, join calls or events, buy a service, contact support or use safety and verification features. We do not sell personal data.
Social Muslims is an authenticated network, not a publicly indexed directory. A completed approved profile that is enabled for matchmaking may be shown in full to eligible approved signed-in free and paid users as they browse eligible unseen profiles. More than one eligible viewer may be able to see the profile during the same period. Display is subject to directional preferences, blocks, prior interactions, eligibility, safety controls and request capacity; there is no viewer-exposure cap.
The full safe profile may include authorised photos, first name, exact age, area, profession, verification indicator, profile answers and compatibility reasons. We withhold UIDs, contact details, precise activity, internal scores, original storage paths and operational flags. Users may Pass, Block, Report or send a Meet request.
A free recipient of a current-policy incoming Meet receives only a separately generated blurred-photo derivative, five-year age band, broad region, verification indicator, up to two compatibility reasons and expiry urgency. The free client does not receive the sender's name, original photos, UID or full profile. Active membership permits full-profile reveal and acceptance; Decline remains free.
2. Data we collect
- Account and contact: user ID, name, phone, email, authentication and verification state, notification choices and account status.
- Profile and preferences: date of birth, age, gender, postcode and derived area, authorised photos, profession, education, height, lifestyle, marital and family information, partner preferences, biography, profile answers and quiz responses.
- Sensitive or special-category information: details that reveal or may allow us to infer religion, sect, practice, prayer, hijab or halal preferences, ethnicity, health-related or private-life information, marital/family background and the importance of these factors to you. Optional identity verification may involve biometric data processed by Stripe Identity.
- Browsing and Meets: profile cards issued, views, Pass reasons, saved profiles, blocks, reports, compatibility reasons, Meet creation, sender and recipient roles, request status, expiry and counters.
- Connections and calls: scheduling, room IDs, joined, left and finished timestamps, lifecycle state, private Yes/No decisions, mutual outcomes, call duration and technical metadata. Leave is reversible during an open call window; Finish is terminal and records a private decision. Social Muslims does not record private call audio or video by default.
- Events: reservations, cancellations, waitlists, attendance, private interest decisions, pairing, round and result records.
- Safety and verification: reports, blocks, moderation and enforcement decisions, evidence, identity-verification result and fraud or abuse signals.
- Payments: product, price, currency, order/subscription identifiers, status, timestamps, consent evidence and provider references. Payment providers retain full funding details.
- Technical and communications: IP, device/browser, release, security logs, cookie choices, delivery status, analytics, support content and email/SMS/WhatsApp permissions and opt-outs.
3. Purposes and lawful bases
| Purpose | Usual lawful basis |
|---|---|
| Create and secure accounts; provide profile browsing, Meets, Connections, calls, events and support | Contract and legitimate interests in operating and protecting the service |
| Use religion, ethnicity, marital/family background, private-life information and preferences for eligibility, profile display, recommendations, matching, Meets, events and safety | Your explicit consent under UK GDPR Article 9(2)(a), alongside contract or legitimate interests for ordinary personal data |
| Optional biometric identity verification | Your explicit consent for biometric processing and our legitimate interests in preventing impersonation |
| Rank eligible profiles, create compatibility reasons and interpret private Pass feedback | Contract and legitimate interests; explicit consent where supplied text contains special-category data |
| Process payments, preserve purchase/consent evidence, prevent fraud and maintain accounts | Contract, legal obligation and legitimate interests |
| Send factual account, Meet, Connection, call, event, billing, legal and safety communications | Contract and legitimate interests; these do not authorise unrelated marketing |
| Send optional promotions or event invitations | Consent or a separately documented PECR-compliant soft opt-in, with a simple opt-out |
| Moderate content, investigate reports, enforce blocks and defend legal claims | Legitimate interests, legal obligation, substantial public interest or establishment/defence of legal claims where applicable |
You may withdraw consent at any time. Withdrawal does not make earlier processing unlawful. Withdrawing matchmaking-sensitive-data consent removes your profile from browsing and prevents new matching, Meets and event activity because those services depend on that information. Account access, billing cancellation, data rights, reports, support and existing accepted or scheduled calls remain available.
4. Recommendations and AI
Rules, compatibility signals, ranking and operational judgement determine eligibility and profile order. Selection applies the viewer's directional preferences; the displayed person's preferred age range does not block an inbound Meet. On-demand selection and immediate continuation after a Pass or confirmed Meet are automated, but do not produce legal or similarly significant effects. You may ask for an explanation or human review.
Google Gemini services may help structure private Pass feedback, draft compatibility reasons and compare answers. Limited relevant profile facts and answers may be processed, including special-category information where you have explicitly consented. We do not send names, contact details or photos for these tasks. Quiz answers may also be converted to numerical representations to compare compatibility.
5. Meets, contact and staff access
A Meet request expires after 48 hours. We store whether it was accepted, declined, cancelled or expired even though a sender receives the same not-interested wording after Decline and no response. An accepted request creates a Connection and enables in-app scheduling; it does not automatically disclose direct contact details.
If either person asks for Connection-specific scheduling help, authorised staff receive the minimum Connection reference and coordination information needed. Standard membership does not provide general matchmaker support. The separate £999 Private Matchmaker service involves additional staff access and processing described at application and purchase.
6. Recipients and processors
- Eligible approved members, to the extent required for profile browsing, Meets, Connections, calls, events, reports and blocks.
- Google Firebase and Google Cloud for hosting, authentication, database, file storage and logs; Google Gemini for the limited AI processing above.
- Twilio for verification, SMS and optional WhatsApp; Brevo for email delivery and delivery events.
- Agora for real-time video and technical metadata.
- PayPal and Apple for current payments; Stripe for legacy billing and optional Stripe Identity verification.
- Professional advisers, insurers, auditors, corporate-transaction parties, regulators, courts and law enforcement where lawful and necessary.
We apply contracts, role-based access and data minimisation. Current provider and safeguard details, including a copy of the safeguards used for relevant international transfers, are available on request.
7. International transfers
Photos and files are stored in the European Union. Application hosting and some Google, Gemini, Twilio, Agora, Stripe, PayPal and Apple processing may occur in the United States or globally. Brevo processes email in the European Union. Where data leaves the UK we use applicable adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, with transfer-risk and supplementary controls. Copies of applicable safeguards are available on request.
8. Communications
Meet-request emails and SMS, outcome notices, accepted-Connection messages, call reminders, event administration, payment/security notices and material legal updates are factual service communications. Receiving a next profile card or passing a profile does not generate a prospect-ready email or SMS. We use actual in-app teaser rendering—not email-open tracking—to suppress the unviewed-request SMS where applicable.
Marketing choices are optional and channel-specific. Email contains an unsubscribe route; reply STOP to marketing SMS. WhatsApp service-message permission is separate and does not authorise marketing. Opting out of marketing does not stop necessary service messages.
9. Cookies and local storage
We use essential storage for sign-in, security, service continuity, profile/deep-link state, payment return and consent evidence. Optional analytics is enabled only after the relevant choice. See the Cookie Policy.
10. Retention
- Account/profile: while active, followed by deletion or anonymisation through the account-deletion process unless an exception applies.
- Profile cards and terminal Meet/event records: target 90 days after terminal state unless needed for pair history, a Connection, billing, safety or a dispute.
- Accepted Connections: while relevant accounts and the Connection remain active, then deletion/anonymisation subject to legal and safety exceptions.
- Payment, tax, contract and consent evidence: normally six years after the transaction or relationship ends.
- Safety, blocks, complaints and enforcement: normally up to six years where necessary to prevent rematching or establish/defend claims.
- Support: normally 24 months after the issue closes; analytics and routine logs: normally up to 12 months.
These are maximum operational targets rather than promises to retain every item for the full period. Backups expire through rolling recovery schedules.
11. Your rights
Subject to legal conditions, you may request access, correction, erasure, restriction, portability, objection, consent withdrawal and information about automated processing. Use in-app export/deletion controls or email socialmuslims02@gmail.com. We normally respond within one month, subject to lawful extensions. Minimal payment, consent, block, fraud, safety, complaint or legal-claim evidence may be retained where required or justified.
12. Security, children and complaints
We use authentication, access controls, encryption in transit, logging, provider controls and incident procedures, but no system is risk-free. The service is for adults aged 18 or over; suspected underage accounts are restricted and investigated.
Use our Complaints Procedure. You may also complain to the ICO at ico.org.uk/make-a-complaint or 0303 123 1113.
13. Changes and contact
Material changes are highlighted and, where required, presented for separate Terms acceptance, Privacy acknowledgement and explicit sensitive-data consent. Contact SOCIALMUZ LTD at 20-22 Wenlock Road, London, N1 7GU; socialmuslims02@gmail.com; +44 7779 305853.