Privacy Policy

Tawhid
Last updated: 24 August 2026 · Version 2.3

Data controller: TAWHID DIGITAL TECHNOLOGIES INC. (British Columbia, Canada · BC1599227)

Contact: info@tawhidapp.com

This page explains how we handle your information in the Tawhid mobile apps and on tawhidapp.com.

Quick Summary

  • We use location (with permission) to compute Prayer Times, Qibla, and Nearby Places.
  • The app UI is available in 10 languages — English, Arabic, Urdu, Persian, Bengali, Hindi, Indonesian, Turkish, French, and Russian — with Quran translations in 50+ languages also available.
  • We collect device & usage data (e.g., crashes, performance, screens used) to improve reliability.
  • We do not sell your personal information. Limited sharing with vendors is required to run the Services.
  • Questions? Email info@tawhidapp.com.

Who We Are

Tawhid (“Tawhid”, “we”, “us”, “our”) is operated by TAWHID DIGITAL TECHNOLOGIES INC., a company incorporated under the laws of British Columbia, Canada (Incorporation No. BC1599227). We provide mobile applications and websites that help Muslims with daily worship.

TAWHID DIGITAL TECHNOLOGIES INC. is the data controller (and, under Canadian law, the organization accountable) for personal information processed through the Services. Our registered office is:

TAWHID DIGITAL TECHNOLOGIES INC.
5050 Halifax Street, Unit 906
Burnaby, British Columbia  V5B 2N5
Canada

For any privacy-related request or concern, email info@tawhidapp.com. Email is our primary and fastest contact channel and we aim to respond within 30 days.

Scope

This policy covers our mobile apps (Android/iOS) and websites, including tawhidapp.com and related pages (the “Services”).

Sensitive Information & Religious Beliefs

Please read this carefully.

Because Tawhid is designed for Muslim worship, your use of the Services may imply information about your religious beliefs. Under the EU/UK GDPR (Article 9), Quebec Law 25, and similar laws, religious belief is considered a special category of personal data requiring heightened protection.

By installing and using the Services, you provide your explicit consent to our processing of this inferred information for the sole purpose of delivering the worship features you request (e.g., Prayer Times, Qibla, Quran, Hadith, Duas, Tasbih, Azan notifications). We do not use this information for advertising, profiling, or any purpose unrelated to the Services.

If you do not consent to this processing, please do not install or use the Services. You may withdraw consent at any time — see Withdrawing Consent.

Information We Collect

CategoryExamplesPurpose
Account & Contact Name, email (when you email us or if an account feature is used in future) Support, respond to inquiries
Device & Usage App version, OS version, device model, performance, crash logs, feature usage Diagnostics, app improvement, fraud & abuse prevention
Location (with permission) GPS coordinates / coarse location Prayer Times, Qibla, Nearby Places
Notifications Push token (non-content) Send Azan & feature alerts you enable
Content Delivery IP and minimal tech data to stream Makkah Live/Islamic Radio Deliver streams from third parties
Web Cookies Preferences, session, analytics cookies Website functionality & insights (see “Cookies”)
Inferred (sensitive) Religious belief, inferred from use of the app Provide worship features only — see Sensitive Information

What we do not collect: We do not show third-party advertising in the app and do not use advertising identifiers (IDFA on iOS, AAID on Android) to build behavioral profiles or share with ad networks. We do not knowingly collect government IDs, payment card numbers, biometric data, or precise health data.

How We Use Information

We use the information we collect for the following specific purposes:

  1. Services delivery — provide core features (Prayer Times, Qibla, Quran & translations, Hadith, Duas, Tasbih, events/reminders, Makkah Live / Islamic Radio streams).
  2. Reliability & improvement — diagnose crashes, measure performance, and improve user experience.
  3. Communication — respond to support requests and notify you of important changes to the Services or this policy.
  4. Security — investigate and prevent abuse, fraud, and security incidents.
  5. Legal compliance — comply with applicable laws and lawful requests from authorities.

We do not use your information for behavioral advertising, sell it to data brokers, or share it with advertising networks.

Sharing & Disclosures

We share limited data only with the following categories of recipients:

  • Service providers / sub-processors — vendors who process data on our behalf under contractual confidentiality and data-protection obligations (see list below).
  • Legal & safety — authorities, courts, or other parties where disclosure is required by law or necessary to protect rights, safety, or property.
  • Business transfers — if the Services or substantially all of their assets are acquired, merged, or transferred to another team or entity, your information may be transferred as part of that transaction. We will require any successor to honour this policy or notify you of any material change.

We do not sell your personal information in the ordinary sense, and we do not share it for cross-context behavioral advertising. The category of personal information that may be shared with the above recipients is limited to: identifiers (e.g., device ID, IP), device & usage data, location (only with service providers needed to fulfil the location-based features you request), and crash/diagnostic data.

Third-Party Websites & Services

The Services may link to or embed third-party websites, app-store pages, social media, or streaming sources (e.g., Makkah Live providers). We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy policies before providing information.

Retention

We keep personal information only as long as we need it for the purposes described above, to meet legal obligations, resolve disputes, and enforce our terms. Where we can state a definite period, we do:

InformationHow long we keep it
Account and profile information Until you delete your account, then removed within 30 days — see Delete My Data.
Backups you create Until you delete the backup or your account.
Support conversations and attachments A conversation closes automatically after 30 days of inactivity. We keep closed conversations while they remain useful for answering follow-up questions from you and for handling any related dispute, and delete them once neither applies.
Contribution and purchase records 6 years from the end of the relevant tax year, as Canadian tax and corporate record-keeping law requires. We hold the transaction record only — never your card details.
Subscription and entitlement events 400 days, then deleted.
Referral link click data 7 days, then deleted.
Crash reports and diagnostics Held by our diagnostics provider on its own schedule — currently 90 days for Firebase Crashlytics.
Server and security logs Kept for as long as needed to investigate abuse, security incidents and faults, and routinely rotated out. They are not used to build any profile of you.
Deleted data sitting in backups Purged within 90 days as encrypted rolling backups are overwritten.

Where law requires us to keep something longer — for example a tax record, or information subject to a legal hold — we keep it for that period and no longer. If you ask us to delete your information while such an obligation applies, we will tell you what we must keep and why.

Your Rights

Depending on where you live, you may have the following rights regarding your personal information:

  • Access — request a copy of the personal information we hold about you and the sources from which it was collected.
  • Correction / rectification — ask us to correct inaccurate or incomplete information.
  • Deletion / erasure — ask us to delete your personal information.
  • Restriction or objection — ask us to restrict or object to certain processing.
  • Portability — receive your information in a structured, machine-readable format.
  • Withdraw consent — see Withdrawing Consent.
  • Not be subject to solely automated decisions with legal or similarly significant effects. We do not currently make such decisions about you.
  • Complain to your data-protection authority.

How to exercise these rights: email info@tawhidapp.com with the subject “Privacy Request” and tell us which right you want to exercise. We may need to verify your identity before responding. We aim to reply within 30 days and will not charge a fee for reasonable requests.

Canada (PIPEDA / Quebec Law 25): Residents of Canada have rights under PIPEDA and, in Quebec, additional rights under Law 25 including the right to data portability and to be informed of automated decision-making. TAWHID DIGITAL TECHNOLOGIES INC. is accountable for compliance and is the contact for privacy concerns at info@tawhidapp.com. You may also file a complaint with the Office of the Privacy Commissioner of Canada or, for Quebec residents, the Commission d’accès à l’information.

EEA / UK: You may lodge a complaint with your local supervisory authority. A list of EU authorities is available at edpb.europa.eu. UK residents can contact the ICO.

US State Privacy & “Do Not Sell/Share”

This section provides additional disclosures for residents of California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, and other US states with comprehensive privacy laws.

  • We do not sell personal information for monetary consideration, and we do not share it for cross-context behavioral advertising as those terms are defined under California law.
  • Global Privacy Control (GPC): we recognize GPC browser signals on our website as a valid opt-out of any sale/share, where applicable.
  • Right to limit use of sensitive personal information: California residents may limit our use of sensitive personal information (including inferred religious belief) to what is necessary to provide the Services. Use of the app for worship features is, by its nature, this necessary use; we do not use sensitive information for any other purpose.
  • Minors: we do not knowingly sell or share personal information of users under 16.
  • Shine the Light (California Civil Code §1798.83): California residents may request information about disclosures of personal information to third parties for those third parties’ direct marketing purposes. We do not make such disclosures, but you may confirm this by emailing us with the subject “Shine the Light Request”.
  • Non-discrimination: we will not deny you Services, charge different prices, or provide a different level of quality because you exercised your privacy rights.

To exercise any of these rights, email info@tawhidapp.com, or use our Delete My Data page for deletion requests. This website runs no advertising or analytics cookies, so there is nothing to opt out of for site tracking. You may also designate an authorized agent to submit requests on your behalf.

International Transfers

TAWHID DIGITAL TECHNOLOGIES INC. operates from British Columbia, Canada, and our service providers (e.g., Google Firebase, hosting/CDN) operate globally. Your information may therefore be processed in Canada, the United States, the European Union, and other countries with different data-protection laws than yours.

Where required by law, we rely on appropriate safeguards for cross-border transfers, including the European Commission’s Standard Contractual Clauses, the UK Addendum, and the safeguards built into our vendors’ data-processing agreements. By using the Services, you acknowledge that your information may be transferred internationally for the purposes described in this policy.

Security

  • Encryption in transit, restricted access, environment hardening.
  • Secure development practices and vulnerability remediation.

No method is 100% secure. Please keep your device updated and protected.

If you believe you have found a vulnerability, please tell us — see our security policy for how to report it.

If There Is a Data Breach

If personal information we hold is lost, accessed or disclosed without authorisation, we will investigate immediately, take steps to contain it, and record what happened.

  • Regulators. Where a breach creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada as PIPEDA requires. Where the EU or UK GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to you.
  • You. Where a breach is likely to result in a high risk to your rights, or a real risk of significant harm, we will tell you directly and without undue delay — in plain language, covering what happened, what information was involved, what we have done, and what you can do.
  • Records. We keep a record of every breach and our response, whether or not it was reportable, so a regulator can review it.

We will never ask you for your password, payment details or government ID as part of a breach notification. If you receive such a request claiming to be from us, it is not from us.

Children

The Services are not directed to children under 13 (or the higher minimum age required by your local law, e.g., 14 in Quebec/Spain, 16 in some EU jurisdictions). We do not knowingly collect personal information from children under that age without verifiable parental consent, as required by the US Children’s Online Privacy Protection Act (COPPA), GDPR Article 8, and equivalent laws.

If you are a parent or legal guardian and believe your child has provided personal information to us, email info@tawhidapp.com and we will promptly delete it.

Cookies & Tracking (Website)

This website sets no cookies. We run no advertising networks, no analytics or measurement scripts, and no third-party trackers on tawhidapp.com. Because we place no non-essential cookies or similar technologies, no consent banner is required and none is shown.

The site does use your browser's local storage to remember preferences you set. This information stays on your device, is never transmitted to us, and is not used to identify or track you:

Stored itemPurposeType
tawhid-themeRemembers your light or dark mode choiceStrictly necessary (functional)
tawhid-prayer-method, -school, -methodSettingsRemembers your calculation method and Asr conventionStrictly necessary (functional)
tawhid-prayer-latRemembers the location you last looked up, so the page does not ask againStrictly necessary (functional)
tawhid-prayer-format, -midnight, -tuneRemembers your time format and manual time adjustmentsStrictly necessary (functional)

You can clear all of it at any time by clearing site data for tawhidapp.com in your browser settings. Doing so simply resets the site to its defaults.

This section covers the website only. The mobile apps use Google Firebase for crash reporting and analytics — see Information We Collect and Service Providers for that detail.

Service Providers / Sub-processors

We use these vendors solely to provide the Services. This is the actual list, not an illustrative one. We update it when a vendor changes.

VendorWhat it does for usData it handles
AccuWebHostingHosting for tawhidapp.com and our APIRequest logs, IP addresses, anything you send us through the Services
Google Firebase (Cloud Messaging, Crashlytics)Push notifications such as prayer reminders; crash reportingDevice push token, device model and OS, crash diagnostics
Zoho MailSending transactional and support emailYour email address and the content of the message
Stripe, Inc.Processing contributionsPayment details, handled by Stripe directly — we never receive or store your full card number
RevenueCat, Inc.Managing app-store subscription entitlementsApp-store purchase identifiers and subscription status
Aladhan (Islamic Network)Prayer time and Hijri calendar calculationThe coordinates or city you ask times for
Google Maps / PlacesNearby mosque and place lookupLocation queries, IP address
Streaming providersMakkah Live and radio deliveryIP address, minimal technical headers

Apple and Google are not sub-processors of ours. When you buy or subscribe through the App Store or Google Play, they act as the seller and handle your payment under their own terms, and we receive only the purchase identifier and subscription status.

Questions about a vendor, or want to know where one stores data? Email info@tawhidapp.com and we will tell you.

Changes to This Policy

We may update this policy from time to time. When we do, we will change the “Last updated” date at the top. For changes we believe will have a substantial impact on your rights (for example, new categories of data, new disclosures, or changes to legal basis), we will provide a more prominent notice in the app or on the website, and where required by law we will seek your renewed consent.

Previous versions of this policy are available on request by emailing info@tawhidapp.com. Continued use of the Services after a non-material update means you accept the updated policy.

Contact

TAWHID DIGITAL TECHNOLOGIES INC.
5050 Halifax Street, Unit 906
Burnaby, British Columbia  V5B 2N5
Canada
Incorporation No. BC1599227 (British Columbia)

Email (primary contact for all privacy requests): info@tawhidapp.com

Email is the fastest and authoritative channel for privacy requests, support, and legal correspondence; postal mail sent to the registered office above is also accepted but will take longer to process. We aim to acknowledge privacy requests within 5 business days and respond substantively within 30 days.

For technical support (e.g., wrong prayer time, notification issues), please include your device model, OS version, app version, and screenshots.