Privacy Policy
Last Updated: July 2026
1. Introduction
Muslims After Midnight ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
By using our services, you consent to the practices described in this Privacy Policy. We collect only the minimum information necessary to provide our platonic friendship community services.
2. Data We Collect
We collect the following types of information:
Account Information
- Email address
- Username
- Age (required - must be 18+)
- Password (hashed with bcrypt - we never see your actual password)
Profile Information (Optional)
- Location
- Bio
- Shift schedule
- Interests
- Profile photos (hosted on Cloudinary)
Usage Information
- Messages you send through our platform
- Community posts (ticker messages)
- Connection requests and interactions
- Last active timestamp
Technical Information
- IP address (stored for security and fraud prevention)
- Browser type
- Device information
- Cookies and session data
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send you technical notices and support messages
- Respond to your comments and questions
- Monitor and analyze usage patterns
- Detect, prevent, and address fraud or abuse
- Provide customer support
- Comply with legal obligations
Data Minimization: We only collect information that is necessary for the functioning of our service. Optional fields can be left blank.
4. Legal Basis for Processing (GDPR)
If you are located in the European Union or European Economic Area, we process your data under the following legal bases:
- Contract: Processing necessary to provide our services to you
- Consent: You have given explicit consent for specific processing activities
- Legitimate Interests: Security, fraud prevention, and service improvement
- Legal Obligation: Compliance with applicable laws
5. Information Sharing
We do NOT sell your personal information to third parties. We may share your information with:
- Service providers: Companies that help us operate our platform (hosting, payment processing, email delivery)
- Legal requirements: When required by law or to protect our rights
- Business transfers: In connection with a merger, acquisition, or sale of assets
Your profile information is visible to other registered users of our platform.
6. Data Security
We implement appropriate security measures to protect your information:
- Passwords are hashed using bcrypt (industry standard)
- Session data is stored securely in SQLite with encryption
- HTTPS encryption for all data transmission
- Rate limiting to prevent brute force attacks
- CSRF protection on all state-changing requests
- Input sanitization to prevent XSS and SQL injection
- Security headers (HSTS, CSP, X-Frame-Options, etc.)
While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
7. Cookies
We use cookies to:
- Keep you logged in (essential)
- Remember your preferences
- Prevent fraud and ensure security
For more details, see our Cookie Policy.
8. Data Retention
We retain your information:
- For the duration of your account being active
- For up to 30 days after account deletion (grace period for recovery)
- As required by law for tax and accounting purposes
After deletion, your data is permanently removed from our active systems within 30 days.
9. Your Rights (PIPEDA & GDPR)
You have the right to:
- Access: Request a copy of all personal data we hold about you
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion of your account and all associated data
- Restriction: Request we limit how we process your data
- Portability: Receive your data in a structured, machine-readable format
- Object: Object to certain types of processing
- Withdraw Consent: Withdraw consent at any time where processing is based on consent
- Lodge Complaint: File a complaint with your local data protection authority
To exercise these rights:
- Use our self-service tools in Settings
- Email: support@muslimsaftermidnight.com
We will respond to all requests within 30 days as required by PIPEDA.
10. Children's Privacy
Our services are strictly for users 18 years of age or older. We do not knowingly collect information from anyone under 18. Age verification occurs at registration. If we learn that we have collected information from a minor, we will take immediate steps to delete that information.
11. Third-Party Services
We use third-party services for:
- Railway: Hosting and server infrastructure
- Stripe: Payment processing for premium subscriptions
- Cloudinary: Image hosting for profile photos
- Email Service: For transactional emails
These services have their own privacy policies. We encourage you to review them.
12. International Data Transfers
Your information may be transferred to and processed in countries other than Canada, including the United States. When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) for EU/EEA transfers
- Adequacy decisions where applicable
- Data Processing Agreements with all processors
13. PIPEDA Compliance (Canadian Privacy Law)
Muslims After Midnight complies with the Personal Information Protection and Electronic Documents Act (PIPEDA), the federal privacy law for private sector organizations in Canada.
Our 10 PIPEDA Principles:
- Accountability: We are responsible for the personal information under our control
- Identifying Purposes: We collect personal information only for identified purposes
- Consent: We obtain your consent to collect, use, or disclose personal information
- Limiting Collection: We limit collection to what is necessary
- Use, Disclosure, and Retention: We use and disclose only with consent, retain only as needed
- Accuracy: We keep personal information accurate and up-to-date
- Safeguards: We protect personal information with appropriate security measures
- Openness: We make information about our privacy practices readily available
- Individual Access: We provide access to your personal information upon request
- Challenging Compliance: We provide mechanisms to challenge our compliance
14. CASL Compliance (Anti-Spam Law)
Muslims After Midnight complies with Canada's Anti-Spam Legislation (CASL).
- We only send electronic messages to you with your explicit consent
- All commercial electronic messages include our contact information
- All messages include a clear and easy unsubscribe mechanism
- We process unsubscribe requests within 10 business days
15. Data Breach Response
In the event of a data breach:
- We will notify affected users within 72 hours of becoming aware
- We will report to the Office of the Privacy Commissioner of Canada as required
- We will take immediate steps to contain and remedy the breach
- We will document all breaches in our incident log
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting a notice on our website for 30 days
- Sending an email to the address associated with your account
- Updating the "Last Updated" date at the top of this policy
Your continued use of our services after changes become effective constitutes acceptance of the new policy.
17. Contact Us
If you have questions about this Privacy Policy, PIPEDA compliance, GDPR, or CASL, please contact us:
Email: support@muslimsaftermidnight.com
Response Time: We will respond to your inquiry within 30 days.
For GDPR-related requests from EU/EEA residents:
You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.