01
Introduction
The App is offered in Switzerland. We process personal data in accordance with the Swiss Federal Act on Data Protection (“FADP”) and its implementing ordinance.
Where the EU General Data Protection Regulation (“GDPR”) applies to a particular processing activity, the additional rights set out in section 14 apply.
If you do not agree with this Policy, please do not use the Services.
02
Who is responsible for your data
| Item | Details |
|---|---|
| ItemLegal entity | DetailsOsman Mohamud |
| ItemCommercial register number | DetailsCHE-482.376.436 |
| ItemRegistered address | DetailsKirchbachstr. 15, 8600 Dübendorf, Switzerland |
| ItemGeneral contact | Detailsinfo@islam2go.ch |
| ItemPrivacy enquiries | Detailsinfo@islam2go.ch |
We are established in Switzerland and offer the App in Switzerland only. We have not appointed a Data Protection Officer, as we are not required to do so under Article 10 FADP.
03
Scope
This Policy applies to personal data we process about users of the App, visitors to the Website, individuals who contact us, and individuals whose details appear in venue listings.
It does not apply to third-party services you reach through the Services, including the websites and social media pages of listed venues. Those are governed by their own privacy policies.
04
Personal data we collect
Account data
An account is required to use the App. There is no guest mode.
| Data | Purpose |
|---|---|
| DataName | PurposeIdentifying your account; displayed on the leaderboard |
| DataEmail address | PurposeAccount identification, service messages, password reset |
| DataPhone number | PurposeOptional profile information; stored only if you add it in your profile |
| DataDate of birth | PurposeOptional profile information; stored only if you add it in your profile |
| DataPassword | PurposeAccount security |
| DataProfile photo | PurposeDisplayed on your account and on the leaderboard |
Passwords and sign-in
We offer three sign-in methods. (a) Email and password. Passwords are hashed using bcrypt on our own servers. We never store or transmit passwords in plain text and cannot recover them.
(b) Sign in with Google and (c) Sign in with Apple. These use Firebase Authentication solely to verify the identity token issued by Google or Apple. We receive a unique identifier and, depending on your settings with those providers, your name and email address. We never receive your Google or Apple password. Email and password accounts do not pass through Firebase.
Location data
The App uses your device’s precise location to show nearby restaurants and mosques, to retrieve local prayer times, and to orient the Qibla compass. How location is handled:
- Nearby search: your coordinates are transmitted to our server with each request so that we can calculate which venues are near you. The coordinates are used to compute the response and are not written to our database or linked to your account. However, the address of each request, which includes your coordinates, is recorded in our server logs; the web server log also records your IP address. These logs are used only to operate, secure and troubleshoot the Services, are not used to identify you, and are deleted automatically after 14 days.
- Prayer times: your device sends your coordinates directly to the external prayer times service Aladhan. Because your device contacts this service directly, Aladhan also receives your IP address.
- Qibla compass: calculated entirely on your device using its location and magnetometer. No data is transmitted.
We do not build a location history linked to your account, and we do not derive approximate location from your IP address.
Photos and camera
If you grant permission, the App can access your camera and photo library so that you can: (a) upload photos to listings you submit; (b) set a profile photo; (c) scan product barcodes and packaging using the halal scanner.
We only access images you actively select or capture. We do not scan your photo library.
Halal scanner
The App includes a scanner that helps you check packaged products. How it works:
- You scan a product barcode or capture a photograph of a product or its ingredient label.
- Where you scan a barcode, our server queries the Open Food Facts open database for product and ingredient information, using the barcode only. Your IP address is not passed on to Open Food Facts.
- Where further interpretation is needed, our server transmits to the OpenAI API either the ingredient list, product name and category as text or, where you captured a photograph, the photograph itself. OpenAI analyses the ingredients and returns an assessment. Where a product can be identified, OpenAI may additionally perform a web search to verify product information.
- Where your App language is not English, the explanation is translated using Google Cloud Translation.
- The result is displayed to you.
What is transmitted and stored: (a) Images. A barcode or ingredient scan sends text only. A photo scan sends the whole photograph to OpenAI.
(b) No account identifier. No name, email address, account number, phone number or IP address accompanies the request. OpenAI does not receive information identifying you.
(c) Scan history. We store your scan history against your account so that it is available to you in the App. Each record contains the barcode or ingredient text you submitted, the photograph where you captured one, the product identified, and the resulting assessment. Photographs are stored with our image storage provider Cloudinary. You can delete any individual scan in the App, which also deletes the stored photograph. Authorised Islam2Go administrators can access scan history for support and quality-control purposes.
(d) No model training. Under the OpenAI API terms, data submitted through the API is not used to train OpenAI’s models. OpenAI may, however, retain submitted requests, including photographs, for a limited period in accordance with its API data retention policy.
The scanner is an automated aid, not a religious ruling, and you should read the product label yourself.
Leaderboard and other users
The App awards points for certain activity and displays a leaderboard. Your name, profile photo, points and rank are visible to other users of the App on that leaderboard.
There are no public profile pages, no follow system, no reviews and no comments. Other users cannot see your email address, phone number, date of birth, location, favourites or scan activity.
There is currently no setting to hide your name from the leaderboard or to appear under a different display name. Appearing on the leaderboard is part of the points feature. If you do not want your name and photo to be visible to other users, please contact us at info@islam2go.ch, or delete your account.
Content you submit
You can submit new restaurants and mosques, including photographs. Mosque submissions are held in an approval queue and reviewed before publication. Submitted content becomes part of the public directory.
Favourites
Restaurants and mosques you mark as favourites are stored on our servers against your account, so that they are available across sessions and devices.
Support correspondence
Messages you send through the in-app contact form, together with your name and email address, are retained for 24 months.
Technical data
We collect your app version and device language so that we can serve compatible content.
What we do not collect
We want to be specific about this, because it is unusual:
- No analytics. We use no analytics tool and do not record screen views, feature usage or behavioural data.
- No crash reporting. No crash-reporting or diagnostics SDK is integrated.
- No advertising. No ad network, no advertising identifiers, no advertising.
- No tracking. We do not track you across other companies’ apps or websites, and the App therefore does not display Apple’s App Tracking Transparency prompt.
- No device identifiers. We do not collect IDFA, IDFV, Android ID or similar.
- Short-lived logs only. Our web server records IP addresses in its access log for security and troubleshooting; these logs are deleted automatically after 14 days. Security logs (firewall and administrator login records, including IP addresses) are kept for up to 5 weeks. Our application logs contain no IP addresses.
- No cookies or tracking technologies in the App or on the Website.
- No contacts, microphone or calendar access.
- No push notifications are sent, and no push tokens are collected.
- No payment data. The App is free, with no subscriptions and no in-app purchases.
- We do not sell personal data and do not share it with data brokers.
05
Why we process your data, and on what basis
Under the FADP, processing personal data does not generally require a specific legal basis, but must be lawful, proportionate, carried out in good faith, and recognisable to you. Where a justification is required (in particular for sensitive personal data) or where the GDPR applies, we rely on the following.
| Purpose | Justification / legal basis |
|---|---|
| PurposeCreating and operating your account | Justification / legal basisPerformance of the contract with you (Art. 31(2)(a) FADP; Art. 6(1)(b) GDPR) |
| PurposeShowing nearby venues, prayer times, Qibla | Justification / legal basisPerformance of the contract |
| PurposeHalal scanner | Justification / legal basisPerformance of the contract; your consent for the associated transfer to the United States |
| PurposeLeaderboard | Justification / legal basisPerformance of the contract |
| PurposePublishing content you submit | Justification / legal basisPerformance of the contract |
| PurposeOperating and securing the Services | Justification / legal basisOverriding private interest (Art. 31(1) FADP; Art. 6(1)(f) GDPR) |
| PurposeCompiling and publishing venue listings | Justification / legal basisOverriding private interest in operating a public directory |
| PurposeResponding to enquiries | Justification / legal basisPerformance of the contract or overriding private interest |
| PurposeMarketing emails | Justification / legal basisYour consent; Art. 3(1)(o) Swiss Unfair Competition Act |
| PurposeAccounting records | Justification / legal basisLegal obligation (Art. 958f Swiss Code of Obligations) |
| PurposeDefending legal claims | Justification / legal basisOverriding private interest |
Religious data
Islam2Go is an app for Muslim users. We do not ask about your religion and we do not store religious belief as a data field. Your use of the Services could nonetheless imply religious affiliation, and data revealing religious views is sensitive personal data under Article 5(c) FADP. We therefore:
- treat your account data, favourites and scan activity as sensitive;
- rely on your express consent, given when you create an account, for processing in this context (Art. 6(7)(a) FADP; Art. 9(2)(a) GDPR where applicable);
- do not disclose this data to third parties for their own purposes.
You may withdraw consent at any time by deleting your account.
06
Device permissions
| Permission | Purpose |
|---|---|
| PermissionLocation, while using the app | PurposeNearby venues, prayer times, Qibla compass |
| PermissionCamera | PurposePhoto upload and the halal scanner |
| PermissionPhoto library | PurposeSelecting existing photos to upload |
| PermissionMotion and orientation sensors | PurposeOperating the Qibla compass |
The App does not request background location, push notifications, Bluetooth, contacts, microphone or calendar access. You can grant or revoke each permission at any time in your device settings. Some features will not work if a permission is denied.
07
Service providers and third parties
| Provider | Function | Location | Role |
|---|---|---|---|
| ProviderHostinger | FunctionServer hosting our backend, PostgreSQL database, admin panel and server logs | LocationFrankfurt, Germany (EU); backups in Lithuania (EU) | RoleProcessor |
| ProviderCloudinary | FunctionStorage and delivery of user-uploaded images and videos and halal scanner photographs | LocationUnited States | RoleProcessor |
| ProviderOpenAI, L.L.C. | FunctionHalal scanner analysis, including web search to verify product information | LocationUnited States | RoleProcessor |
| ProviderGoogle (Firebase Authentication) | FunctionVerifying Google and Apple identity tokens | LocationUnited States | RoleProcessor |
| ProviderGoogle (Cloud Translation API) | FunctionTranslating halal scanner explanations into your App language | LocationUnited States | RoleProcessor |
| ProviderGoogle Maps SDK and Google Places API | FunctionMap rendering and venue search | LocationEU and United States | RoleIndependent controller |
| ProviderApple (Apple Distribution International Limited, Ireland; Apple Inc., United States) | FunctionSign in with Apple; App Store distribution | LocationIreland (EU) and United States | RoleIndependent controller |
| ProviderAladhan (api.aladhan.com) | FunctionPrayer time calculations. Your device contacts this service directly, so it receives your IP address together with your coordinates. | LocationOperated by Mamluk LLC-FZ (United Arab Emirates); hosted on the Bahriya platform with data centres in Europe, Asia-Pacific and North America | RoleIndependent controller |
| ProviderOpenFoodFacts | FunctionProduct and ingredient data (queried by our server using the barcode only) | LocationFrance (EU) | RoleIndependent controller |
| ProviderHostpoint AG | FunctionTransactional email (account verification and password reset) | LocationSwitzerland | RoleProcessor |
When you view a map or search for a venue, Google receives technical data including your IP address, and may set identifiers, in accordance with the Google Privacy Policy (policies.google.com/privacy) and the Google Maps Platform Terms of Service, which are incorporated into this Policy by reference as Google requires.
08
Transfers outside Switzerland
Our servers and backups are in the European Union. Switzerland recognises the EEA as providing adequate protection, so no additional safeguards are required for those transfers.
The following transfers go to the United States:
| Provider | What is transferred |
|---|---|
| ProviderCloudinary | What is transferredPhotos and videos you upload and photographs you capture in the halal scanner |
| ProviderOpenAI | What is transferredIngredient text, product photographs you capture, and the resulting scan analysis |
| ProviderGoogle / Apple | What is transferredSign-in identity tokens; map and search requests; halal scanner explanation text for translation |
The Swiss Federal Council recognised the Swiss-US Data Privacy Framework as providing adequate protection with effect from 15 September 2024. Where a provider is certified under that framework, transfers may proceed without additional safeguards. Where a provider is not certified, we rely on the European Commission Standard Contractual Clauses as recognised by the Swiss Federal Data Protection and Information Commissioner with Swiss adaptations.
The mechanism applying to each United States provider is as follows:
| Provider | Swiss-US DPF | Mechanism |
|---|---|---|
| ProviderCloudinary | Swiss-US DPFCertified | MechanismAdequacy under the Swiss-US DPF |
| ProviderGoogle | Swiss-US DPFCertified | MechanismAdequacy under the Swiss-US DPF |
| ProviderApple | Swiss-US DPFNot relied on | MechanismPersonal data of users in Switzerland is controlled by Apple Distribution International Limited (Ireland); Apple’s onward transfers are governed by Standard Contractual Clauses |
| ProviderOpenAI | Swiss-US DPFNot certified | MechanismStandard Contractual Clauses with Swiss adaptations, as part of OpenAI’s Data Processing Addendum, which forms part of our agreement with OpenAI; for the halal scanner, additionally your consent |
Aladhan is operated from the United Arab Emirates, which Switzerland does not recognise as providing adequate data protection, and may process requests in data centres outside Europe. We have no contract with Aladhan. Your device contacts the service directly when you use the prayer times feature. We rely on the exception for disclosures directly connected with the performance of our contract with you (Art. 17(1)(b) FADP).
You may request a copy of the safeguards applying to a specific transfer by contacting us.
09
How long we keep data
| Data | Retention |
|---|---|
| DataAccount data | RetentionWhile your account is active |
| DataDeleted accounts | RetentionFully purged within 30 days, except halal scanner photographs (see section 11) |
| DataUploaded photos and submissions | RetentionWhile the listing is published, or until you delete them |
| DataFavourites | RetentionWhile your account is active |
| DataLocation data | RetentionNot stored in our database. Coordinates appear in server logs and are deleted automatically after 14 days |
| DataServer logs | RetentionWeb server and application logs: 14 days. Security logs (firewall and login records): up to 5 weeks |
| DataHalal scanner queries | RetentionRetained against your account until you or an administrator delete the individual scan, or you delete your account. Photographs are stored with the record. |
| DataSupport correspondence | Retention24 months |
| DataAnalytics and crash logs | RetentionNot applicable (not collected) |
| DataAccounting records | Retention10 years (Art. 958f Swiss Code of Obligations) |
| DataBackups | RetentionApproximately 3 weeks (three most recent weekly backups) |
Deleted data may persist briefly in backups until the ordinary rotation removes it. During that period it is not used for any purpose other than restoring the service.
10
Security
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, bcrypt password hashing, access controls, secure token storage on your device, and automated weekly backups held on separate infrastructure.
Our backend and PostgreSQL database run on our own server in Frankfurt, Germany, so we are responsible for server hardening, patching and database access control. The database requires authentication and accepts connections only from the server itself. A firewall blocks all other access except the website and secure administrator login. Administrative access requires cryptographic keys and two-factor authentication on the hosting account. Our measures also include security headers on all requests, bcrypt password hashing, restriction of cross-origin requests to our own applications, and token-based authentication.
No system is completely secure. Where a breach is likely to result in a high risk to your personality or fundamental rights, we will notify the Federal Data Protection and Information Commissioner and, where required, you (Art. 24 FADP).
11
Your rights
Under the FADP you have the right to:
- Information: know whether we process data about you and what we process;
- Access: receive a copy of your data (Art. 25 FADP);
- Rectification: have inaccurate data corrected (Art. 32(1) FADP);
- Deletion: request deletion of your data;
- Data portability: receive your data in a common electronic format or have it transferred (Art. 28 FADP);
- Object: object to a particular processing activity;
- Withdraw consent: at any time, without affecting prior lawful processing.
We do not carry out automated individual decision-making producing legal effects or similarly significant consequences for you. The halal scanner produces information only; it makes no decision about you.
Exercising your rights
Email info@islam2go.ch. We respond within 30 days and may ask you to verify your identity.
Deleting your account
You can delete your account at any time in the App. Your account data is fully purged within 30 days, other than data we must retain by law. Factual information you contributed that has been incorporated into public listings may remain published without attribution to you; you may request its removal in individual cases.
Complaints
You may report a matter to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern (edoeb.admin.ch).
12
Venues listed in the App
The directory is compiled from our own research and from submissions by users and venue operators.
Where a venue is run by a sole trader, or a listing contains an individual’s name or contact details, that is personal data. We process it on the basis of our overriding private interest in operating a public directory (Art. 31(1) FADP).
Listings are published without prior notice to the venue. If you operate a listed venue and wish to have information corrected or the listing removed, contact us through the in-app contact form or at info@islam2go.ch. We review such requests and act on them where they are well founded or required by law.
13
Marketing
We do not currently send marketing emails. If we introduce them, we will send them only where you have consented. Every marketing email will contain an unsubscribe link. Withdrawal takes effect promptly and does not affect service emails such as password resets.
The App does not currently send push notifications. If they are introduced, we will update this Policy, request the necessary permission, and provide separate controls for functional and promotional notifications.
14
Users to whom the GDPR applies
The App is offered in Switzerland. If the GDPR nonetheless applies to your use of the Services, you additionally have the rights to restriction of processing and to object to processing based on legitimate interests, and you may lodge a complaint with the supervisory authority in your country of residence.
15
Children
The Services are not directed at children. The minimum age to create an account is 16 years. By creating an account, you confirm that you are at least 16 years old.
We do not knowingly process data of anyone under 16. If we learn that we have, we will delete it promptly. Parents and guardians may contact us at info@islam2go.ch.
16
Changes
We may update this Policy. The current version is always available in the App and at islam2go.ch.
Where changes are material, we will notify you in the App or by email before they take effect. Where a change requires your consent, we will ask for it.
17
Contact
Osman Mohamud
Kirchbachstr. 15, 8600 Dübendorf, Switzerland
Email: info@islam2go.ch
