Skip to main content
Hajj & Umrah

Privacy Policy

Your privacy is important to us

Last Updated: December 18, 2024

1. Introduction

Welcome to the Hajj & Umrah Platform ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, website, and services (collectively, the "Platform").

2. Information We Collect

2.1 Personal Information

We collect information that you provide directly to us:

  • Account Information: Name, email address, phone number, date of birth, nationality, passport details
  • Profile Information: Profile photo, preferences, travel history
  • Payment Information: Credit card details, billing address (processed securely through our payment providers)
  • Booking Information: Travel dates, package selections, traveler details, special requirements
  • Communication Data: Messages, reviews, support inquiries, feedback

2.2 Automatically Collected Information

When you use our Platform, we automatically collect:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages viewed, features used, time spent, click patterns
  • Location Data: GPS location (with your permission) for location-based services
  • Cookies and Tracking: We use cookies and similar technologies (see Section 7)

2.3 Information from Third Parties

We may receive information from:

  • Social Media: If you connect via Facebook, Google, or Apple Sign-In
  • Payment Providers: Transaction confirmation from Stripe, PayPal
  • Partners: Vendors, travel agents, service providers
  • Public Sources: Government databases for verification purposes

3. How We Use Your Information

3.1 Service Provision

  • Processing bookings and payments
  • Managing your account and preferences
  • Providing customer support
  • Facilitating communication between users and vendors
  • Sending booking confirmations and updates

3.2 Platform Improvement

  • Analyzing usage patterns and trends
  • Conducting research and development
  • Testing new features and functionality
  • Personalizing your experience

3.3 Safety and Security

  • Verifying identity and preventing fraud
  • Detecting and preventing security threats
  • Enforcing our terms and policies
  • Complying with legal obligations

3.4 Marketing and Communications

  • Sending promotional offers (with your consent)
  • Newsletter and updates about services
  • Surveys and feedback requests
  • Special offers from partners (opt-in only)

4. How We Share Your Information

4.1 Service Providers

  • Vendors: To fulfill your bookings
  • Payment Processors: Stripe, PayPal for payment processing
  • Cloud Providers: AWS, Google Cloud for data storage
  • Analytics: Google Analytics, Mixpanel for usage analysis
  • Communication: Twilio (SMS), SendGrid (email)

4.2 Business Partners

  • Travel agents who assist with your bookings
  • Insurance providers
  • Flight and accommodation partners

4.3 Legal Requirements

We may disclose information when required by law or to:

  • Comply with legal process (subpoenas, court orders)
  • Protect our rights and property
  • Prevent fraud or security threats
  • Protect the safety of users

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Data Security

We implement industry-standard security measures:

  • Encryption: SSL/TLS encryption for data transmission
  • Secure Storage: Encrypted database storage
  • Access Controls: Role-based access limitations
  • Regular Audits: Security assessments and penetration testing
  • PCI DSS Compliance: For payment card data handling

Important: However, no system is 100% secure. We cannot guarantee absolute security of your data.

6. Your Rights and Choices

6.1 Access and Correction

You have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Update your profile and preferences
  • Request a copy of your data

6.2 Data Deletion

You can request deletion of your account and personal data. Some information may be retained for:

  • Legal compliance
  • Fraud prevention
  • Resolving disputes
  • Enforcing agreements

6.3 Marketing Opt-Out

You can opt-out of marketing communications:

  • Click "unsubscribe" in emails
  • Adjust notification settings in your account
  • Contact us directly

6.4 Cookie Management

You can control cookies through:

  • Browser settings
  • Our cookie consent tool
  • Third-party opt-out mechanisms

7. Cookies and Tracking Technologies

We use:

  • Essential Cookies: Required for platform functionality
  • Analytics Cookies: Google Analytics for usage statistics
  • Advertising Cookies: For targeted advertising (with consent)
  • Preference Cookies: To remember your settings

You can manage cookie preferences in your browser settings or our cookie consent tool. For more details, see our Cookie Policy.

8. Children's Privacy

Our Platform is not intended for users under 18. We do not knowingly collect information from children. If you believe a child has provided us information, please contact us immediately at privacy@hajjumrah.com.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses: For EU data transfers
  • Privacy Shield: Where applicable
  • Adequacy Decisions: Based on EU Commission decisions

10. Data Retention

We retain your information:

  • Active Accounts: For as long as your account is active
  • Booking Records: 7 years for legal and tax purposes
  • Marketing Data: Until you opt-out or withdraw consent
  • Legal Requirements: As required by applicable law

12. Regional Privacy Rights

12.1 European Economic Area (EEA) - GDPR

If you are in the EEA, you have additional rights:

  • Right to access, rectification, and erasure
  • Right to data portability
  • Right to restrict or object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with supervisory authority

Legal Basis for Processing: Contractual necessity, Legal obligations, Legitimate interests, Consent (where required)

12.2 California - CCPA

California residents have the right to:

  • Know what personal information is collected
  • Know if information is sold or disclosed
  • Opt-out of sale of personal information
  • Request deletion of personal information
  • Non-discrimination for exercising rights

We do not sell personal information.

13. Updates to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via:

  • Email notification
  • Platform notification
  • Prominent notice on our website

Continued use after changes constitutes acceptance.

14. Contact Us

For privacy-related questions or requests:

Email: privacy@hajjumrah.com

Data Protection Officer: dpo@hajjumrah.com

For GDPR Requests: gdpr@hajjumrah.com

Response Time: We aim to respond within 30 days.

15. Complaints

If you have concerns about our privacy practices, you have the right to lodge a complaint with:

  • Your local data protection authority
  • The supervisory authority where we are established
  • The supervisory authority where the alleged infringement occurred

By using our Platform, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.