Privacy Policy
Last updated: 20 May 2026
1. Introduction
Salawat Streak ("we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service"). Please read this policy carefully. Salawat Streak, operating the Service at salawatstreak.co.uk, is the data controller for personal data collected through the Service.
2. Data We Collect
2.1 Information You Provide
- Account data: name, email address, and password (stored as a secure hash).
- Profile data: display name and any optional profile information you add.
- Donation data: donation amounts and associated payment metadata (payment card details are handled directly by Stripe and never stored on our servers).
2.2 Data Collected Automatically
- Usage data: Durood counts, streak history, daily goal progress, and badge achievements.
- Device data: device type, operating system version, and push notification token (for sending reminders you opt into).
- Log data: IP address, timestamps, and error logs for security and debugging purposes.
3. How We Use Your Data
- To create and manage your account.
- To display your personal statistics, streaks, and leaderboard rankings.
- To send push notifications for reminders and badge achievements (only if you grant permission).
- To process donations securely through Stripe.
- To improve and maintain the Service.
- To comply with legal obligations.
4. Legal Basis for Processing (UK GDPR)
We process your personal data on the following legal bases:
- Contract: processing necessary to provide the Service you have signed up for.
- Legitimate interests: to maintain security, prevent fraud, and improve the Service.
- Consent: for push notifications and any optional marketing communications.
- Legal obligation: where required by applicable law.
5. Data Sharing
We do not sell your personal data. We may share data with:
- Stripe: for secure payment processing. Stripe's privacy policy applies to data shared with them.
- Firebase (Google): for push notification delivery. Only your device push token is shared.
- Infrastructure providers: cloud hosting providers who process data on our behalf under data processing agreements.
- Law enforcement: where we are legally required to do so.
6. International Data Transfers
Some of our service providers, including Stripe (payment processing) and Google Firebase (push notifications), are based in the United States, outside the United Kingdom and European Economic Area (EEA). When personal data is transferred to these providers, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner or the European Commission. For further information about these safeguards, please contact us at support@salawatstreak.co.uk.
7. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes.
8. Your Rights
Under the UK GDPR and Data Protection Act 2018, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), available via the "Delete Account" option in Settings.
- Restrict processing of your data in certain circumstances.
- Data portability: receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time for consent-based processing (e.g., push notifications).
To exercise any of these rights, contact us at support@salawatstreak.co.uk.
9. Cookies
Our website uses essential cookies to maintain your login session. We do not use tracking or advertising cookies. You can control cookie settings through your browser.
10. Security
We implement appropriate technical and organisational measures to protect your personal data, including encrypted storage of passwords, HTTPS for all data in transit, and restricted access to production systems.
11. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via the App or by email. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact & Complaints
For privacy-related enquiries, contact us at support@salawatstreak.co.uk. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.