Privacy Policy
Operator: Muhkam Limited · Effective 30 August 2026
Muhkam Limited operates Masajidna. This policy explains the information handled by the Masajidna customer app, mosque administration app, display app, and website.
Information we handle
Depending on the feature used, Masajidna may handle administrator account details, mosque applications, public mosque profiles and prayer schedules, display identifiers, correction reports, optional device location, diagnostics, and limited product events where a Masajidna product explicitly enables them.
The customer app requires no user-facing account or sign-up. Firebase creates a pseudonymous anonymous service identity so protected public APIs can reject abuse; Masajidna does not use it as a customer profile. Home Masjid, favourites, language, a bounded public-catalogue cache, and random installation identifiers are stored on the device. If location permission is granted, location is used to show nearby masjids, calculate distance, and estimate whether a user can arrive before iqama. Customer app version 1.1.0 does not include Firebase Analytics or another product-analytics SDK.
Location and Catch Prayer
Location is requested only when you use a location-dependent feature. You can still search by name or suburb without granting permission. In Customer app version 1.1 and later, Catch Prayer sends your current latitude and longitude, the selected walking or driving mode, and up to eight eligible masjid coordinates through an app-integrity-protected Firebase function to the Mapbox Matrix API. Mapbox uses that information to return route distance and duration. During the controlled version 1.0 retirement period, version 1.0 sends the same routing coordinates and mode through its separate protected function to Google Routes Compute Route Matrix.
The provider request sent from Masajidna to Mapbox does not include your Firebase service identity, local installation identifier, prayer choice, iqama time, safety buffer, masjid name, or Masajidna database ID. The app-protected Customer 1.1 function does receive the pseudonymous Firebase service identity and random installation identifier, and derives a one-way-hashed identifier from the requesting IP address, to enforce abuse and owner-cost limits. Its rate-limit records contain one-way-hashed subject identifiers, the limit type, billed-element count, and window/update timestamps; they do not store the raw IP address or forward these identifiers to Mapbox. The legacy Customer 1.0 function instead keeps its pseudonymous Firebase service UID with a limit count and timestamps, but does not receive an installation ID or store an IP address. Masajidna does not save or log your precise Catch Prayer origin or route result as route history. The result is held temporarily on the active search screen so local calculations can reuse it without another route request. Version 1.1 calls Mapbox only after you apply or refresh Catch Prayer and does not refresh routes in the background. While Catch Prayer remains enabled, legacy version 1.0 can refresh Google Routes after five minutes for driving or ten minutes for walking and can update its origin after movement of at least 50 metres.
How information is used
- Authenticate mosque administrators and review mosque applications.
- Publish approved mosque information, prayer times, facilities, and announcements.
- Provide nearby search, map directions, and arrival estimates.
- Pair and operate mosque display devices.
- Protect the service, diagnose failures, and improve reliability.
Service providers
Masajidna uses service providers including Google Firebase for authentication, database, hosting, app-integrity protection, and analytics only in products where analytics is explicitly enabled. Mapbox processes Customer 1.1+ Catch Prayer route coordinates only when a user requests a route check, under the Mapbox Terms of Service and Mapbox Privacy Policy. Those results show localized “Directions powered by” text, the linked official Mapbox logo, and a linked “© OpenStreetMap” copyright label. Google Routes processes the equivalent route coordinates for distributed Customer 1.0 builds under the Google Maps Platform Terms and Google Privacy Policy while those builds remain runnable. The Admin app's separate Photon/OpenStreetMap address lookup processes an address query only when an administrator asks for suggestions and is not used for Catch Prayer. Opening directions transfers the chosen destination to the installed Apple Maps or Google Maps app. Provider processing may occur outside New Zealand under applicable safeguards.
Sharing, advertising, and tracking
Masajidna does not sell personal information and does not include an advertising SDK. Information is shared only with service providers needed to operate a requested feature, with an authorised mosque administrator where appropriate, or when required by law.
Retention and security
Information is retained only for as long as needed to operate the service, protect users, meet legal obligations, resolve disputes, and maintain appropriate audit records. Customer correction reports have a 90-day expiry field. Customer 1.1 Mapbox rate-limit records have expiry fields no later than 48 hours after the latest allowed request; legacy Customer 1.0 Google rate-limit records have an expiry field ten minutes after the latest request attempt, including a denied attempt. Firebase's asynchronous time-to-live deletion may occur after either expiry time. Clearing saved data or uninstalling the app does not immediately delete an already-created server-side rate-limit record, which expires through that automatic process. Security controls include access rules, role boundaries, App Check, encrypted network transport, input validation, and separation of public and administrator data.
Your choices and rights
You can decline location permission and still search by name or suburb. The app's Clear saved data action removes local customer preferences, cached public catalogue data, and random installation identifiers; removing the app also clears app-local data. It does not immediately remove short-lived server-side abuse-prevention records, which expire as described above. Security service identities and random identifiers may be recreated when the service is used again. You may request access to or correction of personal information, or request deletion where applicable, by following the data-deletion instructions.
Contact and complaints
Contact support@masajidna.app with a privacy question or request. New Zealand users may also contact the Office of the Privacy Commissioner. Material policy updates will be published on this page with a revised effective date.