Privacy policy
Draft — awaiting review by a Jordanian lawyer before launch
Version 0.1 (draft) · Issued: . This text is not approved yet and may change before the app launches. The Arabic text is authoritative; this English text is a translation of it.
1. Summary
- Marakez (مراكز) is a free waqf app for Quran memorization centres in Jordan, run by a non-profit entity.
- We process only what is needed to run your account and follow your memorization. We treat religious-education data as sensitive data, and we add special protection for anyone under 18.
- No ads, no third-party tracking or analytics tools, and no selling or sharing of data for commercial purposes.
- Data is stored in the European Union because our database provider has no servers in the Middle East, and only with your explicit consent.
- From inside the app you can download a copy of your data, ask for corrections, withdraw your consent and delete your account at any time.
2. Who is responsible for your data
Marakez is run by the non-profit entity (entity name — set by the owner before launch), which is the “controller” of your personal data under the Jordanian Personal Data Protection Law No. 24 of 2023. Quran memorization centres use the platform to manage their students under an agreement with the entity, and each centre's staff can reach only what their role allows.
Data protection officer: (to be named before launch). Contact details are in section 17.
3. The data we process
3.1 Account data
- Name: first name, father's name and family name.
- Gender: to apply the separation of boys and girls in groups and lists.
- Date of birth: to know whether you are under 18. If your date of birth is unknown, we treat you as a minor.
- Login number: 7 digits issued by the system for signing in; it is not a secret. We derive an internal sign-in address from it that cannot receive any mail: we never ask for your email address and never send text messages.
- Password: you choose it yourself when you activate your account, and the sign-in provider stores it in a hashed form that cannot be recovered. Neither centre staff nor the platform team can see it.
- For anyone under 18: the guardian's name, relationship and phone number, and the record of their consent (how it was given, when, which staff member recorded it, and a photo of the signed paper form if there is one).
- For adults: a phone number, if the centre records one.
- Your preferences and consents: language, how your name appears on group boards, notification settings, and the record of each consent (its purpose, the version of the notice, its duration and its status).
3.2 Religious-education data — treated as sensitive
Because this data indicates religious practice, we treat it as sensitive data under the law:
- Memorization progress: the ayat, pages and juz memorized, and what needs review.
- Recitation and review sessions and their grades.
- Results of the juz exam (سَبْر الجزء, “sabr”).
- The hadith you have memorized.
- Levels, points and ranks.
- Membership of centres and groups, and enrollment and transfer requests.
- Warnings, expulsions and appeals, with their reasons and evidence.
3.3 Mushaf notes
- Your private notes on your mushaf: nobody but you can see them — not your teacher, not your centre's administration, not the platform team. The only exception is a formal, documented legal procedure, which is recorded in the audit log.
- Teacher notes (your teacher's corrections on your mushaf): you and your teachers at your current centre can see them. You can hide them from your view.
3.4 Achievements and files
- Your achievements and verified texts, the evidence files you upload (photos or documents), and appeal files.
- We strip location data and other metadata (EXIF) from photos when they are uploaded, or we reject the file.
- Before your first upload we remind you: do not upload photos that show other children's faces.
3.5 Notifications
In-app notifications, and your device's push token, which is needed to deliver them.
3.6 Device and security data
- An app installation identifier and a hash of your IP address, used only to prevent abuse and to enforce attempt limits.
- An audit log of important actions (who did what and when), without IP address or location, and without copying reasons or private data.
- Technical logs kept by our hosting and sign-in providers (such as request logs and sign-in attempts) may include your IP address; the provider keeps them for a short time for security.
- A check that you are human, using Cloudflare Turnstile, when you sign in and on public forms.
3.7 Crash reports
Technical crash reports (error type, app version, device model) through Sentry, without names, login numbers, IP addresses or any other personal data.
3.8 Data about people without an account
- A visitor's request to join a centre: name, phone number and what the centre needs to get in touch, plus the centre's log of contacting the applicant.
- A request to register a new centre: the centre's details, its contact person and its documents.
- A “nuisance report” from a centre's staff: a hash of the nuisance phone number, to stop repeated harassment.
3.9 What we do not collect
- No national ID number, no phone number of a minor student, no profile photos of students (the feature is switched off for everyone), and no advertising identifiers of devices.
- Location: if you allow it, the app uses your approximate location only while you use it, to show centres near you, and does not save it to your account. You can decline and choose your area by hand.
4. Why we process your data
- To run your account: activation, sign-in, and recovery through your centre.
- To follow memorization, recitation, sabr exams and hadith, to calculate levels, points and ranks, and to show group and centre boards.
- To manage centres, groups, enrollment and transfers, and to apply the separation of boys and girls.
- To apply the discipline rules (warnings, expulsions and appeals) and to stop an expulsion being bypassed with a new account.
- In-app communication: announcements, events and notifications, and tasks for centre staff to contact guardians.
- To protect the platform and its users: preventing abuse and password guessing, audit, and reviewing content and reports.
- To meet our legal obligations: answering requests about your rights, notifying breaches, and keeping proof that deletion requests were carried out.
- To fix crashes using reports that carry no personal data, and to compute overall operating figures from our own data without tracking tools.
We do not use your data for advertising or marketing, or for any purpose not listed here.
5. Legal basis: your explicit consent
We process your data on the basis of your explicit consent, documented electronically, given for each purpose separately and for a stated duration (by default: until you withdraw it).
For anyone under 18 full solar years, or whose date of birth is unknown, the guardian's consent is required. Centre staff record it when they create the account (in person, by phone or with a signed paper form); a minor's account cannot be created without a guardian and their consent.
| Purpose | What it covers | Required? |
|---|---|---|
| Core processing | Running the account: progress, membership and discipline | Required to create an account |
| Storage outside Jordan | Storing the data in the European Union (section 8) | Required to create an account |
| Public list of verified students | Showing first name, the initial of the family name, governorate, the verified text and its date | Optional and off by default; for a minor it needs the guardian's consent and confirmation by the platform team |
| Event participation | Extra data that a specific event asks for | Optional, asked when needed |
| Staff member on the centre's public page | The staff member's name on their centre's page | A yes-or-no question for each staff member |
If the purposes or the notice text change, we ask for your consent again. You can withdraw any consent at any time (section 10); withdrawing one of the two required consents means deleting the account, because it cannot work without them.
6. Who sees your data
| Who | What they see |
|---|---|
| You | All your data, your private notes, your active warnings (with the issuer's role, not their name), and your expulsion notice if there is one. |
| Your teachers | Your progress, your recitations and their notes on your mushaf, the number of your active warnings, and only the warnings they issued themselves. They cannot see your private notes. |
| Your centre's administration | What each role's permissions allow: your data at the centre, and the centre's warnings and expulsion decisions, current and past. Your private data (date of birth and guardian's phone) is visible only to staff who hold that specific permission. |
| Other centres | Nothing — unless you apply to join or transfer to another centre, or become a member there. Then its authorized managers can see, through an action recorded in the audit log, your expulsion record within one year of the expulsion, and your warnings from previous centres issued in the last 365 days. |
| Other students | Never anything about your warnings or expulsion. In centre lists and group boards your name appears the way you choose (initials by default, first name, or hidden), and only to students of your gender and members of your own groups. |
| The platform team | What their roles need (review, moderation, support and appeals), with two-step verification and entries in the audit log. They cannot read your private notes except through a formal, documented legal procedure. |
| Visitors and the public | Nothing about you. The only exception is optional: if you agree (and your guardian agrees, if you are a minor), you appear on the public list of verified students with your first name and the initial of your family name (for example “Muhammad A.”), your governorate, the verified text and its date only — no photo, age, phone, father's name or centre name. You can hide yourself from it with one tap. |
| Ministry of Awqaf reviewers and app store reviewers | They get accounts inside an isolated demo centre to check the mushaf and content as users see them, with no access to any real student's data. |
Photos: profile photos of students are switched off for everyone. Photos of female students are never public and never shown to other centres; if profile photos are ever switched on, a female student's photo is visible only to her and her centre's staff. Photos of centre achievements are reviewed before publication with the rule: no photos of female students, and preferably no children's faces.
7. Service providers (processors)
We use providers that process data on our behalf and on our instructions; they may not use it for their own purposes:
| Provider | Service | Data | Where |
|---|---|---|---|
| Supabase | Database, sign-in, file storage and server functions | All the account data described above | European Union (Germany) |
| Cloudflare | Hosting this website and the admin panel (Pages), storing encrypted backups, centre maps and content packs (R2 and Workers), and the human check (Turnstile) | IP address and technical browser data; the backups are encrypted and the provider cannot read them | Global network |
| Expo | Building the app, and the push notification service | Push token and notification text | Outside Jordan |
| Apple and Google | Delivering notifications to devices | Push token and notification text | Outside Jordan |
| Sentry | Crash reports | Technical data without personal data | Outside Jordan |
| GitHub | Running the encrypted backup job every 6 hours | The data passes through a temporary runner and is encrypted while it is read; nothing is kept at GitHub | Outside Jordan |
| Quran Foundation (mushaf fonts) | Downloading the mushaf page fonts when a page is opened | Only the IP address and the requested font file; nothing about your account | Outside Jordan |
We do not send your personal data to anyone else. Internal operations alerts to the platform team (via Telegram) carry no personal data, only technical identifiers and event types. The app is distributed through the App Store and Google Play under their own policies.
8. Transfers outside Jordan
- Our database provider (Supabase) has no servers in the Middle East, so your data is stored in the European Union (Germany). This means all of your data is transferred outside the Kingdom.
- No official list of countries with an adequate level of protection under Jordanian law has been published yet, so we base this transfer on your explicit consent (or your guardian's), given after being informed of this: the “storage outside Jordan” consent requested when the account is created.
- The encrypted backups at Cloudflare are a transfer too, as is the limited data handled by the other providers in the previous section, such as push tokens.
- Wherever the data is, we apply the safeguards described in section 12.
- Withdrawing this consent means deleting the account, because we cannot run it without it.
9. How long we keep data
A daily job deletes data when its period ends. The validity of warnings and the visibility of expulsion records are checked at every read, so they never stay visible longer if the deletion runs late.
| Data | Kept for |
|---|---|
| Your profile, progress, teacher notes on your mushaf, achievements and verified texts | The life of the account |
| Consents and photos of paper consent forms | The life of the account; a withdrawn consent is kept 3 years as proof |
| Evidence files of your achievements | Follow the achievement's status and are deleted with the account |
| Traces of deleted mushaf notes | 90 days |
| Warnings, with their reasons | Deleted one year after they were issued (a warning is active for 30 days only) |
| Expulsions | When the one-year visibility ends, or when the expulsion is cancelled: the reasons, the fingerprint, the student's name, identifier and membership are erased for everyone, including the centre that issued it; an anonymous outline (centre, dates, status) is kept 3 years |
| An expulsion cancelled before its second signature | Its reasons are erased at once |
| Appeals | The appeal text and evidence are erased 90 days after the decision; the decision stays linked to what was appealed |
| Requests to join centres | Personal data erased 90 days after the request is closed; an anonymous record remains |
| Requests to register new centres | 180 days |
| Centre documents (licences, letters from supervising bodies) | While the centre is active, then one year after it is archived |
| Transfers between centres | Two years after the request is closed |
| Answers in live challenges | 12 months, then summaries only |
| Notifications | 180 days |
| Push tokens | Until the device stops accepting them, or 180 days unused; revoked at once on sign-out, account recovery, suspension or deletion |
| Content reports, guardian-contact tasks, and centres' contact logs with applicants | One year after closing |
| The list of users you have blocked | Until you unblock them or the account is deleted |
| Internal notes of the platform team | As long as the data they are about |
| Audit log | 3 years, without reasons or private data |
| Account deletion requests | 3 years, as proof of execution |
| Requests to exercise your rights | 3 years |
| Your data download files | 7 days; downloaded through a link that is created when you tap and works for 10 minutes |
| Student import files and their rows | Files 7 days; personal data in the rows erased after 30 days |
| Activation and recovery codes | Their fingerprints are erased 30 days after use or expiry |
| Centre join codes | 30 days after use or expiry |
| Unfinished account-creation requests | 24 hours after they expire |
| Request logs / attempt-limit counters | 7 days / 2 days |
| Integrity flags / operations alerts | One year after resolution / one year |
| Our encrypted database backups | 30 days (one every 6 hours); the database provider's daily backups 7 days |
| Crash reports | The provider's default period; they carry no personal data |
If we ever have to restore a backup, we re-run every deletion request completed after the date of that backup, so a deleted account never comes back.
10. Your rights and how to use them
| Right | How to use it |
|---|---|
| Access and a copy; data portability | “My account → Privacy → Download my data” (once a day): a compressed JSON file with your own data only, including teacher notes on your mushaf, and no data about other people. The file is kept 7 days and downloaded through a link that is created when you tap and works for 10 minutes. |
| Correction | Ask your centre's administration to correct data the centre holds, or send a request from “My account → Privacy → Request a correction, restriction or objection”. |
| Restriction of processing | From “My account → Privacy → Request a correction, restriction or objection”. |
| Objection, including to profiling | Leaderboards may count as profiling: choose “Hidden” in “My account → Settings → Show my name on the group board” and your name will not appear on them. To object to any other processing, use “Request a correction, restriction or objection”. |
| Withdrawing consent | “My account → Privacy → My consents”. Withdrawing a required consent leads to deleting the account. |
| Erasure (account deletion) | “My account → Privacy → Delete account”, or the Delete account page on this website, with a 14-day grace period during which you can cancel. |
| Being told about a breach | We notify you as described in section 13. |
- Using your rights is free and has no financial consequence. We aim to answer requests within 30 days.
- A guardian uses these rights on behalf of a minor through the centre's administration, which submits the request for them, or by contacting us (support page).
- You also have the right to complain to the Personal Data Protection Unit at the Ministry of Digital Economy and Entrepreneurship.
11. What remains after account deletion
When the 14-day grace period ends, we permanently delete your account, your personal data and your files. Only the following remains:
- The expulsion record, if there is one, without your name or account identifier: the centre, dates, reasons and an encrypted fingerprint stay until its visibility period ends (one year after the expulsion), to stop the expulsion being bypassed with a new account; then the reasons and fingerprint are erased and an anonymous outline is kept 3 years.
- Audit log entries with an anonymous actor that cannot be linked to you, for 3 years.
- Aggregate points of your group and centre, no longer linked to you.
- The deletion request itself, as proof that it was carried out, for 3 years.
- What you wrote as a staff member (such as announcements and teacher notes) stays, attributed to “Deleted user”.
- Encrypted backups until they rotate out within 30 days; if one is ever restored, we re-run the deletion.
12. How we protect your data
- Permissions enforced inside the database on every row, reviewed functions for every sensitive action, and automated tests of the permission rules.
- Encryption in transit and at rest.
- Two-step verification for the platform team, and an audit log that cannot be edited.
- Two different people for sensitive actions, such as expulsions and publishing hadith.
- Nobody ever receives the password of someone else's account: activation and recovery use one-time codes that only the account holder redeems.
- Encrypted backups every 6 hours, and regular restore drills.
- Real minors' data never leaves the production environment for development or test environments.
13. Breach notification
- If a serious breach of personal data happens that could cause harm, we notify the people affected within 24 hours of becoming aware of it: through an in-app notification and message, and centre staff phone the guardians of affected minors, because we do not use email or text messages.
- We notify the Personal Data Protection Unit at the Ministry of Digital Economy and Entrepreneurship within 72 hours.
14. Children
- Anyone under 18 full solar years is a minor, and anyone whose date of birth is unknown is treated as a minor.
- A child cannot create an account on their own: centre staff create it after recording the guardian and their consent.
- We collect as little as possible: no national ID number, no phone number of the minor, no profile photos, and nothing about them is shown to the public without a separate consent from their guardian.
- The centre contacts the guardian about important matters (such as appeal outcomes and a request to delete the account) through contact tasks followed up by staff.
- If a minor asks to delete their account, the request is accepted and the centre is told so that it contacts the guardian. A guardian can ask for their child's account to be deleted through the centre or through the platform team.
- The app is not made for children only: its audience is students of all ages and adult teachers and administrators.
15. No ads, no tracking, no selling
- Marakez is completely free and a waqf: no ads, no in-app purchases, no subscriptions, no requests for donations and no payment links.
- We use no third-party analytics or advertising tools and no advertising identifiers of devices, and we do not track you across apps or websites.
- We do not sell, rent or share your data for any commercial purpose.
- This website sets no cookies of its own and uses no analytics; its fonts are hosted by us. Only the “Delete account” page connects to the sign-in provider and to Turnstile, and it does not store your login number or password.
16. Changes to this policy
- We update this policy when our practices change. Each version carries a number and a date at the top, and we keep a copy of every earlier version.
- We tell you about important changes inside the app before they take effect. If the purposes change, we ask for your consent again, because an earlier consent does not cover new purposes.
17. Contact us
- Controller: (entity name — set by the owner before launch).
- Data protection officer: (to be named before launch).
- Channel to reach the platform team: (set by the owner). More on the support page.
- For everyday account matters, start with your centre's administration — they are closest to you.