Privacy Policy

Last Updated: December 6, 2025

Your privacy is important to us. We are committed to a minimalist approach to data collection. This policy explains how we collect, use, and safeguard your information.

1. Information We Collect

We only collect one piece of personally identifiable information from you:

Email AddressRequired solely for account creation, authentication (login), and essential security notifications.

We also store data you voluntarily generate within the application (e.g., portfolios, watchlists). This data is linked to your account ID but is not otherwise associated with your personal identity.

2. Data We Explicitly DO NOT Collect

To protect your privacy, we strictly avoid collecting:

  • Legal Name
  • Physical Address
  • Phone Number
  • Government ID
  • Brokerage Credentials

3. Usage & Security

We use your email address exclusively for providing the HalalFolio service. We do not sell, trade, or transfer your email to outside parties.

Your data is stored securely with our backend provider, Supabase, which handles encryption and authentication services using industry-standard security measures.

4. Your Rights

In accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to access the personal information we hold about you and request its deletion at any time.

5. Data Retention

We retain your personal information (email address) and application data (portfolios, preferences) until you request deletion. We do not impose automatic data expiration. If you delete your account or request data deletion, we will permanently remove your data within 30 days.

6. How to Request Data Deletion

To request access to your personal data or to have it deleted, please contact us at:

support@muslimmoney.co

Please include "Data Deletion Request" in your subject line. We will respond within 30 days.

7. Security Breach Notification

In the event of a data breach that poses a real risk of significant harm, we will notify affected users via email within 72 hours of becoming aware of the breach, in accordance with PIPEDA requirements. We will also report such breaches to the Office of the Privacy Commissioner of Canada.