Privacy Policy
Last updated 1 October 2026
This Privacy Policy explains how ZikkLabs ("ZikkLabs", "we", "us") handles personal data in InflowBooks (the "Service"). InflowBooks is a record-keeping and management tool for masjids. It is not a payment gateway and does not collect, hold, transfer or refund any funds. Donations are made directly between a donor and a masjid, outside the Service.
Who we are
The Service is operated by ZikkLabs, a sole proprietorship based in Kerala, India. Its full business details are on our Contact page. For any question about this policy or your data, contact us at [email protected].
Data Fiduciary and Data Processor
Each masjid that uses InflowBooks decides what member and donation records it keeps and why. For that data the masjid is the Data Fiduciary and ZikkLabs acts as its Data Processor, handling the data only to provide the Service on the masjid's instructions. For the committee account data we need to run and bill the Service (see below), ZikkLabs is the Data Fiduciary. These are the terms used by India's Digital Personal Data Protection Act, 2023; they correspond to “controller” and “processor” under other data protection laws.
Information we collect
Committee account data
- Name, email address and the role assigned to a committee member.
- The sign-in details needed to log in and keep the account secure.
Records entered by a masjid
- Member and household details a committee chooses to record, such as name and contact details.
- Subscription amounts, funds, campaigns and the payment entries a committee records for its own bookkeeping.
Payment entries are bookkeeping records of money a masjid has already received. We do not process card, UPI or bank transactions, and we do not collect donor payment details.
Details provided by members
A masjid may share a registration link inviting a household to enter its own details. Through that link a person may provide their own and their family members' information, such as name, phone and WhatsApp number, email, date of birth or age, gender, marital status, occupation, education, and optionally the house's location (map coordinates) if they choose to share it. These submissions are held for the relevant masjid to review before they are added to its member register.
Technical data
- Log and device information such as IP address, browser type and timestamps, used to operate and secure the Service.
- Essential cookies that keep you signed in. We do not use advertising or tracking cookies.
Product usage
To decide what to build and what to fix, we record which screens are opened, whether a form saved or was rejected, how long our server took to respond, and whether the device was a phone. We record screens by their internal page pattern and never by the web address, so member identifiers, receipt numbers and anything typed into a search box are not collected. Form contents, amounts and names are never collected.
People are counted, not identified. Each signed-in user is turned into a one-way code that changes every day, so these records cannot be used to follow an individual over time or to review any one volunteer's work. This information is held for 90 days, after which only totals remain, and it is deleted along with a masjid's other records if the masjid is deleted. We do not share it, and it is never used for advertising.
How we use data
- To provide, maintain and secure the Service.
- To check who is signing in, and to keep each masjid's access separate.
- To respond to support requests and send essential service messages such as sign-in and password emails.
- To meet legal obligations and prevent misuse.
Member payment lookup
A masjid may turn on a payment lookup page on its public site. It is off unless the masjid enables it. Through that page, a member can view their own pending payments and issued receipts by entering the phone number and exact date of birth held in the masjid's register; where the member heads a family, the page also shows the pending payments and receipts of that household. The lookup shows bookkeeping records only, never profile details, works only where the register holds a full date of birth, and is rate limited to deter guessing. The masjid, as the Data Fiduciary, decides whether to offer this lookup to its members.
Receipt verification
A masjid may choose to print a random verification code, shown as a QR link, on the receipt documents it issues. Anyone holding such a receipt can open that link to confirm the receipt's number, amount and date against the masjid's records; a copy that has been altered will not verify. The code reveals nothing to someone who does not already hold the receipt, and checks are rate limited. This printing is off unless the masjid turns it on.
Sharing and sub-processors
We do not sell personal data. We share data only with infrastructure providers that help us run the Service, under appropriate safeguards. These currently include our hosting and database providers (for example Supabase and Cloudflare). Data may be stored on servers located outside India, with safeguards consistent with applicable law.
Security
Each masjid's records are kept separate in the database, so one masjid cannot see another's data. Access is restricted by role, and changes are recorded. No system is perfectly secure, but we take reasonable technical and organisational measures to protect personal data. If we become aware of a data breach affecting a masjid's records, we will inform the affected masjid without undue delay.
Retention and deletion
We keep data for as long as a masjid's account is active and as needed to provide the Service or to meet legal obligations. A masjid may request export or deletion of its records at any time, subject to any retention required by law.
Details submitted through a member registration link are held only for review. Once a masjid approves a submission the information is moved into its member register and the original submission is cleared; a rejected submission is cleared as well. Submissions that are not acted on can be removed after a short retention period.
When an account is terminated, we delete the masjid's data from the Service 30 days after termination, unless a longer period is required by law. This short window lets a committee export anything it needs and guards against accidental loss. Backups are overwritten on a routine cycle.
Your rights
Subject to applicable law, including India's Digital Personal Data Protection Act, 2023, you may ask to access, correct, update or delete your personal data, and raise a grievance about how it is handled. Because a masjid decides what member data it records, please direct requests about that data to the relevant masjid; we will assist the masjid as its Data Processor. For account data we are the Data Fiduciary for, contact us directly.
To raise a grievance about how your personal data is handled, write to [email protected] and we will respond as required by law.
Children
The Service is intended for use by masjid committee members and is not directed at children. Where a family head provides details of family members, including children, through a registration link, they do so on those members' behalf. The masjid, as the Data Fiduciary, is responsible for any consent required before another person's details are recorded, including the verifiable consent of a parent or lawful guardian for the details of a child under 18.
Changes
We may update this policy from time to time. We will revise the "last updated" date above and, where appropriate, notify account holders of material changes.
Contact
Questions about this policy can be sent to [email protected]. See also our Terms of Service.