1. Who we are
SRAAT is a platform that delivers authenticated daily Islamic content — Ayah, Hadith, and Dua cards — to individuals, masjids, schools, and organizations over WhatsApp, email, and public share pages.
For the purposes of applicable data-protection law, Red Bee Solutions (trading as SRAAT) acts as a data controller for account holders (subscribers and administrators) and as a data processor for the recipient contact lists our customers upload to send cards.
2. Scope
This policy applies to:
- Visitors to the SRAAT marketing website.
- Registered account holders and their team members.
- End recipients whose contact details are added by a SRAAT customer to receive Daily Islamic Cards.
It does not apply to third-party sites we may link to. Those sites have their own privacy policies.
3. Information we collect
Information you provide. Name, email, password (hashed), phone number, organization details, billing and address information, branding assets (logo, colors, footer text), delivery schedule preferences, template selections, and any content or messages you submit through the app or support channels.
Recipient information you upload. Names, phone numbers, email addresses, language, and timezone of the recipients you choose to send Daily Islamic Cards to. You must have a lawful basis and, where applicable, prior consent to add each recipient.
Information collected automatically. Device and browser type, IP address, pages viewed, referring URL, session identifiers, and diagnostic logs (errors, crashes). Delivery metadata for each card: sent / delivered / read / failed status, and delivery timestamp.
Payment information. Card and payment details are handled by our PCI-compliant payment processor. We store only a token and the last four digits of the card, not the full number.
We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact privacy@sraat.app and we will delete it.
4. How we use information
We use the information we collect to:
- Provide the SRAAT service — authenticate users, render cards, deliver them on your schedule, and show you accurate analytics.
- Process payments, manage subscriptions, and issue invoices and refunds.
- Send transactional emails (receipts, delivery status, security alerts) and, with consent, product announcements.
- Provide customer support and respond to your requests.
- Detect and prevent fraud, abuse, spam, and violations of our Terms.
- Improve the product — aggregate, de-identified signals may inform new features.
- Comply with legal obligations and enforce our agreements.
We do not sell your personal data. We do not use recipient content for advertising or model training.
5. Legal bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we process personal data on one or more of the following legal bases:
- Contract — to deliver the service you signed up for.
- Legitimate interests — to secure the platform, prevent abuse, and improve the product.
- Consent — for optional analytics cookies, marketing emails, and non-essential communications. You may withdraw consent at any time.
- Legal obligation — to meet tax, accounting, and regulatory requirements.
7. International data transfers
SRAAT operates from and processes data in multiple regions. When we transfer personal data outside your country of residence, we rely on lawful transfer mechanisms — including the European Commission's Standard Contractual Clauses, the UK IDTA, or equivalent safeguards.
8. Data retention
We keep personal data only as long as needed for the purposes described in this policy:
- Account data — for the life of your account, then deleted or anonymized within 90 days of account closure.
- Delivery logs — up to 24 months for support and audit, then anonymized.
- Billing and tax records — up to 7 years to meet legal requirements.
- Backups — up to 35 days after deletion from live systems.
9. Security
We use industry-standard measures to protect personal data: TLS in transit, encryption at rest for databases and backups, role-based access controls, least-privilege administrative access, audit logging, and regular dependency and security reviews. No online service can guarantee absolute security; you are responsible for protecting the credentials you use to access SRAAT.
10. Your rights
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated personal data.
- Export your data in a portable format.
- Restrict or object to certain processing.
- Withdraw consent where we rely on consent.
- Lodge a complaint with your local data-protection authority.
You can exercise most of these rights directly from Settings → Privacy in your account, or by emailing privacy@sraat.app. We respond within 30 days.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced at least 30 days in advance via email or in-product notice. The "Effective" date at the top of this page reflects the current version.
13. Contact us
For any privacy question or to exercise your rights:
- Privacy team: privacy@sraat.app
- Data Protection Officer: dpo@sraat.app
- Support: /contact
