Skip to content

Draft: this document is under review while Makatib.App is in beta. It reflects our intended practices; the final version will be published before full launch.

Privacy policy

Last updated: 28 July 2026

1. Who we are

Makatib.App is operated by Project Paced Ltd, a company registered in England & Wales (Company Number 16969966). Registered office: International House, 64 Nile Street, London, N1 7SR, United Kingdom.

This policy explains how personal data is handled on the Makatib.App website and in the Makatib.App service, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For privacy questions or to exercise your rights, contact privacy@makatib.app.

2. The two roles we play

Makatib.App is used by madrassas to manage their own classes, which means we handle data in two capacities:

  • As a processor. Student and family records (names, dates of birth, attendance, Quran progress, guardian contact details) are entered and managed by your madrassa. The madrassa decides what is recorded and who may see it, and is the data controller for those records. Project Paced Ltdprocesses them only to provide the service, on the madrassa's instructions.
  • As a controller. For account data (staff and guardian logins), beta interest submissions, customer-contract and billing contacts, website enquiries, consent choices, service-security records and technical logs, Project Paced Ltd is the data controller. Stripe is an independent controller for payment data it needs to provide regulated payment services, prevent fraud and meet its legal obligations.

3. Information we collect

Provided by you or your madrassa

  • Account details: name, email address and role (management, teacher or guardian) for people who sign in. Legal basis: performance of a contract.
  • Student and family records, entered by madrassa staff: student names, dates of birth, class membership, attendance, tasks, Quran progress logs, and guardian contact details. Processed on the madrassa's instructions (see section 2).
  • Messages: content of teacher–guardian messages and announcements sent through the service.
  • Fee and payment records, where your madrassa collects fees through the service: what was invoiced, when it was due, what has been paid and by which method, plus any note or reference the madrassa records. Processed on the madrassa’s instructions. Where a madrassa marks a family as exempt or on a reduced rate, any reason it records is visible only to that madrassa’s management. The madrassa determines the lawful basis for these records; we process them under its instructions and our Data Processing Agreement.
  • Card and bank details are never sent to us. When you pay through the portal, your card number or bank details go directly to Stripe, who process the payment for your madrassa. We receive only the outcome: an amount, a date, a payment method type, and the last few digits where Stripe provides them.
  • Beta interest form: madrassa name, contact name, email, optional phone number, location, approximate student count, role and any message you include. Legal basis: our legitimate interest in responding to your enquiry, and steps taken at your request prior to entering a contract.

Collected automatically

  • Cookies and analytics: essential storage keeps you signed in and remembers your cookie choice. If you consent, Google Analytics collects usage information such as pages visited, approximate location, device and browser information, and referral source. Legal basis: consent. We do not send student records or message content to Google Analytics, and we do not use advertising cookies. See the cookie policy.
  • Technical logs: IP address, browser type and request logs generated by our hosting providers, retained briefly for security and reliability. Legal basis: legitimate interest in keeping the service secure.

Where the information comes from

Account and enquiry data comes from the person concerned or their organisation. Customer Data comes from the madrassa, its authorised staff, guardians using the portal and service-generated activity such as attendance, message, invoice and payment events. Payment outcomes come from Stripe. Security and device information comes from the browser and our infrastructure providers.

Our controller purposes and lawful bases

PurposeLawful basis
Provide and administer user accounts and customer contractsContract, or steps requested before a contract
Respond to enquiries and operate the beta programmeLegitimate interests in customer support and product operation
Secure, troubleshoot and prevent abuse of the serviceLegitimate interests in protecting users, customers and the service
Comply with tax, accounting, court and regulatory requirementsLegal obligation
Optional analyticsConsent, which can be withdrawn through cookie settings

4. Children's data

Students at madrassas are usually children, so we treat their records with particular care:

  • Children never create accounts or sign in. Their records are created and managed by madrassa staff, and viewed by their own guardians.
  • Every record is scoped to a single madrassa and protected by row-level security in the database. Guardians can only ever see children linked to their own account.
  • The madrassa, as controller, is responsible for selecting and documenting the applicable Article 6 lawful basis, giving appropriate notices, keeping records accurate and meeting the enhanced transparency and fairness duties owed to children.
  • We never sell personal data, and we do not use student data for advertising or AI training.

Religious-belief and other special-category data

Attendance at a madrassa, Quran progress and message content may reveal or strongly imply religious beliefs. Religious belief is special-category data. The relevant controller must identify both an Article 6 lawful basis and a separate Article 9 condition before processing it, record that decision and complete any required appropriate policy document. Project Paced does not choose the madrassa's bases; as processor, we handle this data only under the madrassa's documented instructions. If Project Paced ever determines a separate controller purpose involving special-category data, we will document and publish our own Article 6 and Article 9 grounds before starting it.

5. Sharing and sub-processors

We do not share personal data with third parties except the infrastructure providers needed to run and understand the service (hosting, database, email delivery, payment processing and consented analytics). These are listed, with the purpose of each and the applicable transfer mechanism, on the sub-processors page. We may also disclose information where required by law.

Payments are a special case worth stating plainly. Where a madrassa collects fees through the service, that madrassa holds its own account with our payment provider and is the merchant. Project Paced Ltd never receives, holds or moves the money, and takes no share of it. The payment provider is an independent controller of the payment data it handles, and its own privacy notice applies to that. See the payment terms.

6. International transfers

Current processing locations and transfer mechanisms are listed on the sub-processors page and checked against the applicable vendor contract. A restricted transfer is made only where UK adequacy regulations apply or an appropriate safeguard is in place, such as the UK International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses. Where those contractual safeguards are used, we complete and keep the required transfer risk assessment and supplementary-measures decision. A generic reference to contractual clauses is not treated as sufficient on its own.

7. Retention and deletion

  • Madrassa data is retained while its account is active and according to the controller's documented instructions. On leaving, the madrassa can request an export and choose return or deletion under the Data Processing Agreement and offboarding procedure. Production copies are scheduled for deletion within 30 days after that window; encrypted backups expire on their documented rotation unless a valid legal hold applies.
  • Fee and payment records require a controller decision.A madrassa may have tax, accounting, safeguarding, dispute or charity-law retention duties, but those are not automatically Project Paced's own controller obligations. Before offboarding, the madrassa must instruct us which fee records to return, delete or retain, the legal reason and end date. Any retained processor copy is isolated from ordinary service use and deleted when the instruction or valid legal hold ends. Records we hold for our own legal obligations are separately documented and limited to that controller purpose.
  • Beta interest submissions are kept while the beta programme runs and deleted, at the latest, 12 months after the programme closes if no account is created.
  • Technical logs are retained for short, rolling periods by our hosting providers.
  • Google Analytics retention is governed by our Analytics settings and Google's applicable retention controls. Your local analytics cookies last for up to 2 years unless you withdraw consent or delete them sooner.

8. Security

Data is encrypted in transit (TLS) and at rest by our database provider. Access is restricted by role-based permissions and database-level row security, so staff see only their own madrassa and guardians see only their own children.

Our Data Processing Agreement describes the processor obligations, assistance, breach notification, sub-processors, deletion and audit framework that applies to Customer Data.

9. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected, or data deleted where there is no reason to keep it;
  • restrict or object to processing, and receive a portable copy of data you provided;
  • withdraw consent at any time, where processing is based on consent.

Contact privacy@makatib.appand we will respond within one month. If your request concerns student records controlled by a madrassa, we will coordinate with the madrassa, which may need to action it as controller. You can also complain to the Information Commissioner's Office at ico.org.uk.

10. Changes to this policy

We will update this policy as the product develops, including before full launch, when the final version will be published. Material changes will be notified to madrassa administrators by email or in the app. Questions: info@makatib.app.