Al Muhrim (mvumrah) · app, website and agency portal · Last updated —
Draft — five things must be fixed before this is published
This policy was written from an audit of what the code actually does. Five statements below are not yet true and are marked [FIX FIRST]. Publishing a privacy policy that misdescribes reality is worse than having none, because it is a public representation you can be held to. Fix those five, then delete this box. Items marked [CONFIRM] need a fact only you know.
[CONFIRM: registered company name, registration number and address] operates the Al Muhrim mobile app, the mvumrah.com website and the agency portal. In this policy "we" means that company and "you" means anyone using the app or portal.
Contact for anything in this policy: support@mvumrah.com
Nothing in this section happens unless you actively submit the form in question.
| When you… | We receive | Why |
|---|---|---|
| Book a Hajj or Umrah package | Your name, phone number, national ID number, party size, an email address if you give one, and any notes you write | The agency needs these to register you for the pilgrimage. The ID number is required for Hajj and Umrah registration. |
| Place a shop order | Your name, phone number, island, delivery address, what you ordered, and an email address if you give one | To take payment and deliver the goods. |
| Buy a travel eSIM | Your phone number, and an email address if you give one | To issue the eSIM and let you retrieve it later. |
| Upload a bank transfer slip | The photograph you take, which usually shows your name, your account details and the amount | To confirm your payment. |
| Rate an agency | Your phone number, your star rating and your comment | To show ratings and stop the same person rating twice. |
| Register as an agency | Agency name, email, phone, password, your licence or permit document, and the date, time and IP address of your acceptance of the terms | To create and approve the agency account, and to keep a record that the terms were accepted. |
Your phone number is your key. Because there are no accounts, we use your phone number to prove an order or booking is yours when you check its status. Anyone who knows your phone number and your order reference could see that order's details, so treat your reference number as private.
The app shows sponsored cards. To count how many times a card was shown or tapped, the app creates a random identifier the first time it runs and stores it on your phone. It is generated on the device, is not derived from anything about you or your hardware, and is sent only with the card's identifier and whether it was seen or tapped. It tells us nothing else about you, and deleting the app deletes it.
Push notifications are delivered by Google Firebase Cloud Messaging. When the app first runs it registers with Google, which issues a token identifying your installation. We store that token so we can tell you when your order status changes.
Google's push component also generates its own installation identifier and sends operational diagnostics to Google. We do not receive that information; its handling is covered by Google's privacy policy.
[FIX FIRST] You can turn notifications off at any time in the app's settings, and in your phone's system settings. Not yet true: the app subscribes every install to a promotional topic at first launch with no in-app way to opt out. Either add the opt-out or delete this sentence and describe what actually happens.
Your reading progress, completed guide steps, Tawaf and Sa'i counts, packing checklist, saved duas and preferences are stored only on your device. We never receive them.
Android backup is switched off for this app, so that on-device data is not copied to Google Drive and does not transfer to a new phone. Uninstalling the app erases all of it.
We do not send marketing email or SMS. We have no email or SMS system connected at all.
[FIX FIRST] Payment slips you upload are stored privately and are visible only to our staff.
Not yet true. Slips are currently written to a public folder and can be opened by anyone who guesses the filename, which is derived from a sequential reference and a timestamp. This must be fixed before this policy is published — see the note at the end.
[FIX FIRST] We keep booking, order and eSIM records for [CONFIRM: how long — a common choice is 24 months after the trip, or 7 years if Maldivian tax law requires it], then delete them. Payment slips are deleted once the payment is confirmed and any refund window has closed.
Not yet true. Nothing is deleted today — there is no retention period and no deletion job anywhere in the system, so records accumulate indefinitely. Decide a period, implement it, then state it here.
The app is intended for adults arranging their own pilgrimage. We do not knowingly collect data from children. A booking may include children in the party size, but we collect no personal details about them beyond the count.
Traffic between the app and our servers is encrypted in transit. Agency and staff accounts are password-protected and passwords are stored hashed, never in readable form.
No system is perfectly secure. If we become aware of a breach affecting your data we will tell you [CONFIRM: by what means].
We will update this page when our practices change, and change the date at the top. Material changes will be announced in the app.
Delete this box before publishing — fix list
public/
and serve them through an authenticated route. Verified live: an unauthenticated request returns
the image.
Separately, not a policy matter but an App Store blocker: the iOS app has no
PrivacyInfo.xcprivacy manifest, and the full APNs device token is printed to the
system log in release builds (ios/Runner/AppDelegate.swift:28).
Al Muhrim · mvumrah.com