Markaz Privacy Policy
Clear, transparent, and accurate disclosure of how the Markaz Islamic Education & Madarsa Management application collects, utilizes, safeguards, and handles your personal data.
Zero Data Selling
We NEVER sell, trade, or rent personal or student data to third parties.
Location for Prayers
Used strictly for accurate local Salah times and Qibla direction.
Child & Student Safety
Institutional consent, no ads, and zero behavioral tracking for students.
Easy Deletion
Direct in-app delete or online deletion request at /delete-account.
1. App & Developer Identity
Official Legal Entity DisclosuresThis Privacy Policy governs the collection, processing, and protection of personal and institutional data within the Markaz application (also known as MarkazulIlm / مرکز العلم), available on Google Play and across authorized web portals.
By accessing or using the Markaz application or web services, you acknowledge that you have read, understood, and consented to the practices described in this Privacy Policy.
2. Information We Collect
Accurate and Precise Data CategorizationMarkaz only collects information necessary to deliver educational, Madarsa management (ERP), and Islamic spiritual tools. We collect data in the following distinct categories:
A. Account & Identity Information
- Full Name & Contact: Name, Email address, and Phone number (used for login, SMS alerts, and parent-madarsa communications).
- Authentication Credentials: Passwords are protected using irreversible industry-standard cryptographic hashing (e.g., bcrypt / Argon2) prior to storage. Passwords are NEVER stored in plain text.
- User Roles: Role categorization (Administrator, Principal, Teacher, Staff, Student, or Parent/Guardian) to enforce strict access control.
B. Madarsa & Educational Records
- Institutional Details: Madarsa/School name, branch, and class/section rosters.
- Academic Progress: Subject enrollments, Quran memorization (Hifz) tracking, exam marks, and report cards.
- Attendance Logs: Daily student and teacher attendance timestamps.
- Fee & Financial Records: Tuition fee invoices, payment receipts, balance records, and institutional expense vouchers (managed strictly by authorized madarsa accountants).
C. Location Information (Sensitive Data Disclosure)
Markaz accesses device approximate (coarse) or precise (GPS) location with your explicit in-app consent:
- Purpose: Solely to calculate astronomical Islamic Prayer Times (Fajr, Dhuhr, Asr, Maghrib, Isha) and calculate the real-time Qibla compass bearing to Makkah.
- When Collected: Only when the user actively opens Prayer Times, Athan reminders, or the Qibla Compass feature.
- Third-Party Sharing: Zero Sharing. Location data is never shared with third-party advertisers, data brokers, or commercial analytics.
D. Photos & Documents (Voluntary User Selection)
Markaz utilizes the secure Android Photo Picker framework. The app does NOT request broad permission to scan your entire storage or photo gallery. When you voluntarily select an image (for user profile avatars, homework assignment submissions, or receipt vouchers), only the selected file is transmitted securely to our servers for that specific feature.
E. Device & Technical Telemetry
- Device model, manufacturer, and Android OS build version.
- App version, locale/language selection, and network connectivity state.
- Crash logs and diagnostic telemetry via Firebase Crashlytics to identify and fix software bugs, performance bottlenecks, and app stability issues.
3. How We Use Information
Legitimate Purposes & Operational NeedsWe process the collected data strictly for lawful, educational, and operational purposes:
4. API & Server Processing
Encrypted Data in TransitSecure Transmission Guarantee: Markaz communicates with its backend cloud servers exclusively through encrypted HTTPS / TLS (Transport Layer Security 1.2 and 1.3) protocols.
All requests between the mobile application and our servers are authenticated using signed cryptographic session tokens (JWT). Sensitive data fields are encrypted prior to transmission, ensuring that user data cannot be intercepted or tampered with by unauthorized intermediaries.
5. Data Sharing & Third-Party SDKs
Zero-Sale Policy and Disclosed SDKsOur Absolute Commitment:
We do NOT sell, trade, or rent users' personal or sensitive information. We do not engage in behavioral profiling, data broker exchanges, or third-party ad networks.
To operate app features reliably, Markaz integrates with verified, industry-standard third-party service providers and SDKs:
Used for authentication management, dispatching real-time push notifications (attendance & prayer reminders), and collecting anonymized crash logs for debugging.
Provides essential Android system APIs, app updates, and integrity verification.
Converts geographic coordinates into accurate daily Salah timings and Qibla direction without recording or linking coordinates to individual personal identities.
6. Data Security Measures
Comprehensive Organizational & Technical SafeguardsEnd-to-End Encryption
All data in transit is encrypted using modern TLS 1.3 / 1.2 cryptography. Database records at rest are secured with AES-256 encryption.
Role-Based Access Control (RBAC)
Madarsa records are strictly isolated. Teachers cannot access financial ledgers; students cannot edit marks or view other students' confidential files.
Irreversible Password Hashing
User passwords are never stored in plain text and cannot be retrieved even by system administrators.
Regular Security Audits
Our backend undergoes periodic penetration testing and continuous vulnerability scanning to protect against unauthorized data intrusion.
*Please note: While we implement industry-leading technical measures, no transmission over the internet can be guaranteed 100% secure. Users are responsible for keeping their login credentials confidential.
7. Data Retention Policy
Retention Timelines & Cleanup- Active Accounts: We retain account, student, and Madarsa management data for as long as your institutional account remains active and in good standing.
- Upon Account Deletion: Personal data, login credentials, and profile media are permanently deleted or anonymized within 30 calendar days of a verified deletion request.
- Legal & Institutional Archives: Madarsa financial receipts and statutory accounting records may be retained for the minimum period required by applicable educational/tax regulations before scheduled purging.
8. Account & Data Deletion (Google Play Mandate)
Dual Deletion Paths: In-App and Web PortalIn full compliance with Google Play Developer Policies, Markaz provides users with the right and the technical means to request the permanent deletion of their account and associated personal data. You can delete your account via either of two straightforward methods:
Method 1: Inside the Markaz App
- Open the Markaz app on your Android device.
- Navigate to Settings → Account.
- Tap “Delete Account”.
- Confirm your password/OTP to permanently submit your deletion.
Method 2: Dedicated Web Deletion Portal
If you no longer have the app installed, you can submit an instant deletion request online anytime:
Go to /delete-account Web Portal9. Children & Student Privacy
COPPA / FERPA / Student Data SafeguardsMarkaz serves educational institutions, including Madarsas with minor students. We adhere to rigorous child privacy standards:
10. Android Permissions Disclosed
Exact Manifest Permissions & Usage JustificationsMarkaz only requests permissions strictly required to execute user-requested features:
| Permission | Feature / Usage | Requirement |
|---|---|---|
| ACCESS_COARSE_LOCATION & ACCESS_FINE_LOCATION | Calculating accurate local Prayer Times (Salah) and Qibla Direction. | Optional / In-App Prompt |
| POST_NOTIFICATIONS | Delivering Athan prayer alarms, Madarsa announcements, and student attendance alerts. | User-Controlled |
| INTERNET & ACCESS_NETWORK_STATE | Secure HTTPS synchronization with Markaz cloud servers and database. | Required for Sync |
| Photo Picker (READ_MEDIA_IMAGES) | Voluntary user selection of profile photos or assignment attachments. | Voluntary Selection |
12. Your Rights & Choices
Empowering User Control13. Google Play Data Safety Cross-Reference
Direct Alignment with Play Console DeclarationsThis summary table matches the exact declarations submitted in the Google Play Console Data Safety section:
| Data Type | Collected? | Shared? | Purpose | Encrypted / Deletable? |
|---|---|---|---|---|
| Location (Approximate & Precise) | Yes (Optional) | No (Never Shared) | Prayer times calculation, Qibla compass bearing | Yes (TLS) / Yes |
| Personal Info (Name, Email, Phone) | Yes | No | Account management, authentication, parent alerts | Yes (TLS) / Yes |
| Photos & Documents | Yes (Voluntary) | No | Profile photo, homework/receipt submission | Yes (TLS) / Yes |
| Crash & Diagnostic Logs | Yes | Firebase (Diagnostics) | App stability, crash diagnostics, performance | Yes (TLS) / Anonymized |
| Device Identifiers | Yes | Firebase FCM | Push notifications delivery (Athan / Attendance) | Yes (TLS) / Yes |
14. Contact & Privacy Officer
Direct Inquiries & Legal SupportIf you have questions, data protection requests, or wish to exercise your privacy rights, please contact our designated Privacy Office: