1. Who we are
Maktub is a product owned and operated by Zerophia (zerophia.com), the data controller, based in the Netherlands. We are an online-only service and do not operate a public physical address.
For any privacy question or to exercise your rights, contact us at info@getmaktub.app.
2. The data we collect
Waitlist: When you join the waitlist, we collect:
- Email address — stored to contact you about your waitlist place.
- Gender (optional) — stored to understand demand; you may leave this blank.
- Any referral code — stored alongside your email address as a signal for measuring interest.
Founding contributions: When you support via Stripe, we collect the email and optional display name you provide, the amount and tier, wall opt-in preference, and payment status. Card details are processed by Stripe; we do not store full card numbers. Stripe may provide us with limited payment metadata needed for receipts, benefits, and refunds.
App (once available): When you create an account and use the app, we additionally collect:
- Profile information — photos, a voice note, age, gender, education, profession, city, and any other biographical details you choose to provide.
- Match preferences — the characteristics you are looking for in a match.
- Wali Mode details — the name and contact details of any guardian you designate, provided with their consent.
- Activity data — interactions within the app such as profiles viewed, salaams sent, and matches made.
- Communications — messages you exchange with other users through the app.
- Account data — email address, account creation date, and any subscription information.
We generate limited service-access logs, such as IP address, timestamp, and pages used, kept for up to 90 days for security and troubleshooting and not used for profiling. If you accept analytics cookies, we also receive usage and advertising measurement data from Google Analytics 4 and Google Ads (see Cookies). We use Google reCAPTCHA on forms to reduce bots and abuse; that may involve processing limited device and browser signals under Google’s terms. We do not knowingly collect data from anyone under 18.
3. Special category data
Maktub is a service for Muslims seeking marriage. By joining the waitlist or using the app you reveal information that relates to your religious beliefs, which is special category data under Article 9 of the GDPR. Profile photos may also reveal your ethnicity or physical characteristics that are similarly sensitive. We only process special category data on the basis of your explicit consent, which you give by ticking the consent box on the waitlist form or, in the app, by creating a profile. You can withdraw this consent at any time (see section 12).
4. Why we use your data and our lawful basis
- To operate the waitlist and contact you about your place and our launch — lawful basis: your consent (Article 6(1)(a)) and explicit consent (Article 9(2)(a)) for religious-context data.
- To operate the app, including account management, displaying your profile to potential matches, and enabling in-app messaging — lawful basis: performance of a contract (Article 6(1)(b)) for non-sensitive data; explicit consent (Article 9(2)(a)) for special category data such as religious identity and profile photos.
- To provide and improve matching suggestions — basis: performance of a contract and your consent.
- To keep the Service secure and meet legal obligations — basis: our legitimate interests and legal obligations.
- To process founding contributions and issue related benefits or refunds — lawful basis: performance of a contract (Article 6(1)(b)) and our legitimate interests / legal obligations for accounting and fraud prevention.
5. Automated processing and matching
The app uses your profile information and preferences to suggest potential matches. This involves automated processing of your personal data. The matching feature does not make solely automated decisions with legal or similarly significant effects — suggestions are presented for you to act on, and you remain in full control of whether and how to engage with them. You have the right to request human review of any decision that affects you significantly by contacting us at info@getmaktub.app.
6. Who we share it with
We do not sell your personal data. We share it only when necessary with carefully selected service providers that process data on our behalf to help us operate, secure, and improve the Service. These providers may support functions such as:
- Hosting, delivery, security, and storage — Cloudflare, to provide and protect the Service.
- Payments — Stripe to process founding contributions and, in future, other charges. Stripe acts as an independent payment controller for card data and as our processor for checkout metadata we receive.
- Security and abuse prevention — including Google reCAPTCHA and similar measures to detect bots, fraud, spam, and other malicious activity.
- Email communications — to send confirmations, receipts, service messages, and waitlist updates using information such as your name, email address, and referral code.
- Analytics and advertising measurement — Google Analytics 4 and Google Ads, only if you accept analytics cookies, to understand how the Service is used and measure campaign performance. We do not share message content or full profile dossiers with advertisers for their own marketing.
We require our service providers to protect personal data, use it only for the services they provide to us (except where they act as independent controllers under their own notices, such as Stripe for card processing or Google for reCAPTCHA/analytics), and comply with applicable data-protection law. We may also disclose data where required by law, to protect our rights or the safety of others, or in connection with a business reorganisation, subject to appropriate safeguards. Our Law Enforcement Guidelines explain how authorised agencies should submit valid requests.
Your app profile is visible to other registered users as intended by the Service. We do not sell your data to unrelated third parties.
7. International transfers
We aim to process and store personal data within the European Economic Area (EEA). Some service providers may process data in countries outside the EEA. Where an international transfer occurs, we use safeguards required by applicable data-protection law, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with additional measures where appropriate.
9. Security of your data
We apply organisational and technical safeguards appropriate to the sensitivity of marriage-related and religious-context data, including in-app messages, in line with Article 32 GDPR. These measures protect data during transfer and storage, limit access to authorised personnel, and are reviewed regularly.
Messages are retained to deliver the Service, enforce our Terms, respond to abuse reports, and comply with valid legal requests. We do not use end-to-end encryption, so authorised staff may access message content where necessary to operate the Service safely. We do not sell messages or use their content for advertising.
Service providers that process data on our behalf are contractually required to implement appropriate safeguards. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work to reduce risk and review our measures regularly. A summary of our Data Protection Impact Assessment for special-category data and messaging is available on request at info@getmaktub.app.
10. Personal data breaches
A personal data breach means a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
If we become aware of a breach that is likely to result in a high risk to your rights and freedoms, we will inform you without undue delay in clear language, describing:
- what happened, in general terms;
- the categories of data affected (for example messages, profile photos, or email address);
- likely consequences and steps we are taking;
- measures you can take to protect yourself, where appropriate;
- how to contact us for more information.
We will also notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of a breach where required by law. Not every incident is reported to users — we assess each case individually. If you believe your account or data has been compromised, contact us immediately at info@getmaktub.app.
11. How long we keep it
Waitlist data is kept until you ask us to delete it, or until 12 months after we decide not to proceed with the product or you have been onboarded — whichever comes first.
App account data is kept for as long as your account is active. When you request account deletion and we process that request, your profile is hidden immediately and you lose access. Associated account data (including profile, media, and message history) is removed from our active product systems within 90 days.
Server logs: Operational server logs are retained for up to 90 days.
Post-deletion compliance archive (Art. 17(3) GDPR): After removal from active systems, we may retain a limited archive for up to 7 years for legal obligation, accounting, dispute resolution, fraud prevention, and safety/abuse investigation. That archive may include: a deletion audit record (account identifiers and request/purge timestamps); purchase / in-app transaction records; and safety records such as reports and blocks (without chat content, photos, or profile biography). Chat messages, photos, voice notes, and profile content are not kept in this archive. After 7 years these records are deleted.
12. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing;
- data portability;
- withdraw consent at any time (this does not affect processing done before withdrawal);
- not be subject to solely automated decisions with significant effects (see section 5).
To exercise any of these rights, email info@getmaktub.app. You can also unsubscribe from our emails at any time using the link in any email we send. We aim to respond within one month.
13. Complaints
If you are unhappy with how we handle your data you can complain to our lead supervisory authority, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl. We’d appreciate the chance to address your concern first.
14. Changes to this policy
We may update this policy from time to time. We will change the “last updated” date above and, for significant changes, notify you by email.