Privacy Policy
Last updated: August 26, 2026
Who we are
Hiba Central is a software platform operated by KamsTech LLC (“we,” “us”). We provide mosques, Islamic centers, and similar community organizations with tools for donations, membership, and educational programs.
Two different roles — and why it matters to you
Most of the personal information on this platform does not belong to us. When you donate to a mosque, enroll a child in its weekend school, or become a member, that organization decides what information to collect and how to use it. We hold and process that information on their behalf, under their instructions.
For questions about your records — corrections, deletion, or how your information is used — contact the organization directly. They can act on your request immediately. We will help them do so, but we do not make those decisions independently.
We act on our own behalf only for our public website and for our relationship with the organizations that are our customers.
Information collected through the platform
- Identity and contact details — name, email address, postal address, phone number, and household or family relationships.
- Donation and payment records — amounts, dates, designated funds, pledges, recurring giving schedules, invoices, and receipts.
- Membership records — status, tier, and history with the organization.
- Program and enrollment records — classes, placements, attendance, and, where an organization uses those features, guardian relationships and notes about a student.
- Communication records — messages sent to you, delivery outcomes, and your consent choices for each channel.
- Technical information — IP address, browser type, and timestamps, recorded with certain actions for security and fraud prevention.
Payment information
Card payments are processed by Stripe. Card numbers are entered directly into Stripe’s systems and are never transmitted to or stored on our servers. When you choose to save a card for future giving, Stripe stores it and returns a token to us — we retain only that token, the card brand, and the last four digits.
Communications and your consent
Organizations use the platform to send you email and text messages. These fall into two groups, and we treat them differently:
- Transactional messages — receipts, tax statements, invoices, enrollment confirmations, and payment notices. These are sent because you took an action that requires a response.
- Announcements — general messages from an organization to its community. These are sent only where consent is on record, and every one carries an unsubscribe link.
Your consent is recorded separately for each organization and each channel, along with when and how it was given. Consent given to one organization is never applied to another.
You can unsubscribe from announcements at any time using the link in any such message, or by replying STOP to a text message. Opting out is honored immediately and cannot be reversed by an administrator. If an email address hard-bounces or is reported as spam, we stop sending to it entirely — including transactional messages.
Information about children
Organizations use the platform to run educational programs that enroll minors. Records about a student are provided by a parent or guardian, or by the organization, and are visible to that organization’s staff and to the linked guardians.
We do not knowingly collect information directly from children under 13, and we do not sell any student’s information or use it for advertising or profiling. A parent or guardian who wants to review or delete a student’s records should contact the organization.
Cookies and analytics
We use cookies that are necessary for the service to work — principally to keep you signed in. These are configured to resist cross-site misuse and cannot be turned off without breaking sign-in.
We use Vercel Web Analytics and Speed Insights across the platform to understand aggregate usage and performance. These record page views and general device and location information without cookies and without any cross-site identifier, and are never used to profile or advertise to you.
An organization may also enable Google Analytics on its own public fundraising pages. Where it does, that page sets Google’s analytics cookies, and that organization is responsible for that choice and for any disclosure or consent it owes you.
Service providers we rely on
We share information with the following providers, only as needed to operate the service:
| Provider | Purpose |
|---|---|
| Vercel | Application hosting and cookieless usage analytics |
| Supabase | Database, authentication, and file storage |
| Stripe | Payment processing and card storage |
| Amazon Web Services | Email delivery |
| Twilio | Text messaging |
| Cloudflare | DNS, network security, and email routing |
This list reflects our current providers and may change as we add or replace them; the current list is always shown here.
We do not sell personal information, and we do not share it for advertising or cross-context behavioral advertising.
How long information is kept
Records are retained for as long as the organization maintains its relationship with you, and afterwards where retention is required — donation and tax-receipt records in particular are kept to meet the organization’s own charitable-reporting obligations.
If an organization stops using Hiba Central, its data is exported to it and removed from our active systems.
Where your information is stored
Your information is stored and processed primarily in the United States. Some of our service providers may process limited information elsewhere in the course of operating their global networks.
Security
Information is encrypted in transit and at rest. Each organization’s records are isolated from every other organization’s and enforced at the database level, so one organization’s staff cannot reach another’s data. Access is limited to the roles that require it, and changes to financial and membership records are recorded in an audit log. Most people sign in with a one-time code rather than a password, and card numbers are handled by Stripe and never stored on our servers.
No system is perfectly secure. If a breach affects your information, we will notify the affected organization promptly so it can inform you, and we will notify you directly where the law requires it.
Your choices
- Ask an organization for a copy of the information it holds about you, or to correct it.
- Ask an organization to delete records it is not required to keep.
- Unsubscribe from announcements at any time, without affecting transactional messages.
- Ask an organization to stop contacting you on a particular channel.
Depending on where you live, you may have additional rights under state privacy law. We are not currently subject to the California Consumer Privacy Act (CCPA), but either way we do not sell or share your personal information, and if you are a California resident you may contact us to access or delete the information we hold. For records an organization holds, contact that organization first; if you cannot reach them, contact us and we will help.
Changes to this policy
We will update this page when our practices change, and revise the date at the top. Material changes will be communicated to the organizations we serve.
Contact us
KamsTech LLC — privacy@hibacentral.org
For information an organization holds about you, please contact that organization directly — they can act on your request fastest.