Privacy Policy
Last updated 28 June 2026
This Privacy Policy explains how InflowBooks (the "Service", "we", "us") handles personal data. InflowBooks is a record-keeping and management tool for masjids. It is not a payment gateway and does not collect, hold, transfer or refund any funds. Donations are made directly between a donor and a masjid, outside the Service.
Who we are
The Service is operated by InflowBooks, based in Kerala, India. For any question about this policy or your data, contact us at inflowbooks@pm.me.
Controllers and processors
Each masjid that uses InflowBooks decides what member and donation records it keeps and why. For that data the masjid is the data controller and InflowBooks acts as a processor, handling the data only to provide the Service on the masjid's instructions. For the committee account data we need to run and bill the Service (see below), InflowBooks is the controller.
Information we collect
Committee account data
- Name, email address and the role assigned to a committee member.
- The sign-in details needed to log in and keep the account secure.
Records entered by a masjid
- Member and household details a committee chooses to record, such as name and contact details.
- Subscription amounts, funds, campaigns and the payment entries a committee records for its own bookkeeping.
Payment entries are bookkeeping records of money a masjid has already received. We do not process card, UPI or bank transactions, and we do not collect donor payment details.
Details provided by members
A masjid may share a registration link inviting a household to enter its own details. Through that link a person may provide their own and their family members' information, such as name, phone and WhatsApp number, email, date of birth or age, gender, marital status, occupation, education, and optionally the house's location (map coordinates) if they choose to share it. These submissions are held for the relevant masjid to review before they are added to its member register.
Technical data
- Log and device information such as IP address, browser type and timestamps, used to operate and secure the Service.
- Essential cookies that keep you signed in. We do not use advertising or tracking cookies.
How we use data
- To provide, maintain and secure the Service.
- To check who is signing in, and to keep each masjid's access separate.
- To respond to support requests and send essential service messages such as sign-in and password emails.
- To meet legal obligations and prevent misuse.
Sharing and sub-processors
We do not sell personal data. We share data only with infrastructure providers that help us run the Service, under appropriate safeguards. These currently include our hosting and database providers (for example Supabase and Cloudflare). Data may be stored on servers located outside India, with safeguards consistent with applicable law.
Security
Each masjid's records are kept separate in the database, so one masjid cannot see another's data. Access is restricted by role, and changes are recorded. No system is perfectly secure, but we take reasonable technical and organisational measures to protect personal data.
Retention and deletion
We keep data for as long as a masjid's account is active and as needed to provide the Service or to meet legal obligations. A masjid may request export or deletion of its records at any time, subject to any retention required by law.
Details submitted through a member registration link are held only for review. Once a masjid approves a submission the information is moved into its member register and the original submission is cleared; a rejected submission is cleared as well. Submissions that are not acted on can be removed after a short retention period.
When an account is terminated, we delete the masjid's data from the Service 30 days after termination, unless a longer period is required by law. This short window lets a committee export anything it needs and guards against accidental loss. Backups are overwritten on a routine cycle.
Your rights
Subject to applicable law, including India's Digital Personal Data Protection Act, 2023, you may ask to access, correct, update or delete your personal data, and raise a grievance about how it is handled. Because a masjid controls the member data it records, please direct requests about that data to the relevant masjid; we will assist the masjid as its processor. For account data we control, contact us directly.
To raise a grievance about how your personal data is handled, write to inflowbooks@pm.me and we will respond as required by law.
Children
The Service is intended for use by masjid committee members and is not directed at children. Where a family head provides details of family members, including children, through a registration link, they do so on those members' behalf. The masjid, as controller, is responsible for any consent required before another person's details are recorded, including a parent's or guardian's consent for a child's details.
Changes
We may update this policy from time to time. We will revise the "last updated" date above and, where appropriate, notify account holders of material changes.
Contact
Questions about this policy can be sent to inflowbooks@pm.me. See also our Terms of Service.