Effective date: 17 August 2026
App: ABIC
Operator: Ahl Al Bait Islamic Centre (ABIC), Australia
Contact: admin@ahlalbait.org
This policy explains how the ABIC mobile app handles information. Most of the app can be used without creating a general member account. Prayer times, the Islamic calendar, articles, announcements, lectures and mosque information are available as guest features. The current public and testing builds do not expose the restricted Staff Broadcast Centre or Towards Infinity member sign-in; the sections below also explain those controlled features for authorised internal builds and future releases.
For deletion instructions, see Data deletion requests.
Information handled by the app
App preferences and saved content
The app stores the following information locally on your phone so that it can remember your choices and keep useful content available offline:
- your manually selected prayer-time city;
- onboarding and notification preferences;
- saved prayer times, calendar events, articles, lecture listings, announcements, inspirations and donation campaign information;
- notification and event-reminder identifiers; and
- which announcements you have marked as read.
ABIC does not request precise or approximate device-location permission to choose a city. The manually selected city is sent to ABIC's service when the app requests the matching timetable or events. As with ordinary internet requests, ABIC's hosting provider may temporarily process the request, IP address and basic network information needed to return and protect the service.
The app does not request your contacts, does not create an ABIC advertising profile and does not include an ABIC advertising or analytics/crash-reporting SDK. Embedded YouTube or other third-party media may display advertising controlled by that provider.
Notifications
If you allow notifications, the app may schedule prayer-time alerts, event reminders and optional daily Qur'an and Ahl al-Bayt quote notifications directly on your phone.
For ABIC community announcements, the app sends ABIC's server:
- an Expo push token for the installed app;
- the device platform (iOS or Android); and
- the notification topics you select, such as all-community, school, youth or sisters' updates.
The push registration is not linked by the app to a general member name or email address. ABIC uses it only to deliver the notifications you have selected. Delivery involves Expo Push Service and the notification service operated by Apple or Google for your device.
You can change notification choices in the app and can also disable notifications in your phone settings. Turning off Community alerts asks ABIC's server to remove that installation's push token.
Calendar access
ABIC requests calendar access only after you choose Add to calendar or Sync complete calendar. To provide this feature, the app checks the calendars available on your phone, creates or reuses a separate ABIC Islamic Calendar, and reads, adds, updates or removes only ABIC-marked events in that calendar so published dates stay current. Existing calendar information is not uploaded or transmitted to ABIC, and the app does not manage unrelated events.
Authorised staff Broadcast Centre
This feature is not available in the current public or testing builds. In an authorised internal build, the Broadcast Centre is an optional, restricted feature for people specifically approved by ABIC. If you use it, ABIC handles:
- your authorised name, email address and permitted audiences;
- a six-digit email sign-in code and rate-limit/failed-attempt information;
- a revocable app session;
- the audience, title and content of messages or live-program notices you submit; and
- an audit record containing the sender, audience, message, app destination, delivery device count and time.
The six-digit code expires after 10 minutes. After successful verification, a session token is stored on the device and a one-way hash of that token is stored on ABIC's server. The server session expires after 30 days. An ABIC administrator can remove a broadcaster's access earlier, which also removes that broadcaster's active server sessions.
Towards Infinity member library
This member sign-in is not available in the current public or testing builds. In an authorised internal or future build, the Towards Infinity member library opens ABIC's protected website inside the app. If you choose to sign in, the website may use your email address, verification link or code, access entitlement, cookies and web session information to confirm access. Those website records are handled by ABIC's website access system; the native app does not create a separate general member account or copy the website passwordless login into its normal app-preference cache.
YouTube and live programs
The app retrieves ABIC lecture listings from ABIC's YouTube channel and can play YouTube videos in an embedded player. It may also open an ABIC live-program URL supplied through YouTube or Restream. When you load or play third-party media, that provider receives the requests needed to deliver it and may process approximate location inferred from the IP address, device or browser identifiers, cookies and viewing interactions under its own privacy terms. Those providers may use that information for delivery, security, analytics, personalisation or provider-controlled advertising. The app may also let you open the same content in the provider's app or website.
Instagram feed and links
The Home screen retrieves ABIC's public Instagram feed through ABIC's website. Images are normally delivered by ABIC; if that image service is unavailable, the app may request the public image directly from Instagram's content-delivery network. In that case, Meta/Instagram may receive the IP address and basic device, browser and network request information needed to deliver the image under its own privacy terms. Tapping a post or Follow us opens Instagram's app or website.
Donations
The app displays public ABIC donation campaign information retrieved from ABIC's GiveWP system. When you choose to donate or manage donations, the app opens ABIC's donation checkout or donor portal in your external browser. GiveWP and Stripe handle the information needed for the donation, receipt, payment method and any recurring contribution.
The mobile app does not receive or store your full card number, card security code or Stripe password. Deleting the app does not cancel a recurring donation or delete donation and receipt records. Those actions must be completed through the secure donor portal or by contacting ABIC.
How ABIC uses information
ABIC uses the information described above only to:
- provide app features and keep selected content available offline;
- deliver the prayer, inspiration, event and community notifications you choose;
- authenticate authorised broadcasters and limit them to approved audiences;
- publish and audit authorised community messages and live-program notices;
- confirm access to protected ABIC content; and
- connect you to ABIC's donation and donor-management services.
ABIC does not sell app information and does not use it for third-party advertising.
Service providers and external services
Information may be processed by the services needed to provide a feature, including:
- ABIC's website, WordPress and hosting systems for content, access and notification registration;
- Expo and the applicable Apple or Google notification service for push delivery;
- YouTube/Google and, when used for a live program, Restream for media delivery;
- Meta/Instagram and Facebook when you view public social content or open ABIC's official profiles; and
- GiveWP and Stripe for donation checkout, receipts and donor management.
These providers process information under their own terms and may operate infrastructure outside Australia. ABIC only sends each service the information needed for the feature you choose.
Retention
| Information | Current retention approach |
|---|---|
| Local preferences, cached public content, read markers and reminder identifiers | Kept on the device until refreshed, cleared through the phone's app-storage controls, or removed by deleting the app. Entries in the ABIC Islamic Calendar remain on the phone until you remove them through the app's sync controls or the phone's calendar app; deleting ABIC does not automatically remove system calendar entries. |
| Push token, platform and selected topics | Kept on ABIC's server while community alerts are enabled. Turning off Community alerts asks the server to remove the token. ABIC may also remove failed, stale or inactive registrations and processes valid deletion requests. |
| Sign-in code and rate-limit data for authorised broadcasters | Code verification data expires after 10 minutes; rate-limit and failed-attempt data expires after approximately 1 to 15 minutes. |
| Authorised broadcaster session | The server session expires after 30 days and is removed earlier if ABIC revokes the broadcaster's access. Signing out removes the token stored by the app on that device. |
| Authorised broadcaster profile | Kept while the person is authorised and afterwards as an inactive access-control record until it is no longer needed or a valid deletion request is completed. |
| Broadcast message audit | Kept for operational accountability and security. The current system has no automatic expiry period; ABIC will assess deletion or anonymisation requests subject to any record it reasonably needs to retain. |
| Towards Infinity access records and website session data | Managed by ABIC's website access system. They are not duplicated in the app's normal preference cache. |
| Donation, receipt and recurring-contribution records | Managed through ABIC's GiveWP/Stripe services and retained separately from the app for donor administration, transaction records, dispute prevention and applicable record-keeping needs. |
Data security
The app connects to ABIC and the named service providers using encrypted HTTPS connections. Authorised broadcaster codes are short-lived, the app session token is stored using the phone's protected credential storage, server session tokens are stored as one-way hashes, and audience permissions are checked before a broadcast is accepted. Payment details are handled in the external secure checkout or donor portal rather than by the mobile app.
No internet or storage system can be guaranteed completely secure. Please protect access to your phone and sign out of the Broadcast Centre on a shared device.
Your choices
You can:
- use the public app features without a general member account;
- choose a prayer-time city manually without location permission;
- allow, decline or later disable notifications;
- select or remove optional community notification topics, or turn off Community alerts to unregister that installation from ABIC push delivery;
- choose whether to add one ABIC event, sync the complete ABIC calendar, stop syncing, keep existing events or remove the ABIC calendar;
- sign out of the authorised staff Broadcast Centre; and
- clear local app data or delete the app at any time.
Data deletion requests
Delete information stored on your phone
Use your phone's app-storage controls to clear ABIC's local data, or delete the ABIC app. On iPhone, use Delete App rather than Offload App if you also want its local documents and data removed. Events in the ABIC Islamic Calendar remain in the system calendar unless you remove them through ABIC's calendar-sync controls or delete them in the calendar app.
Request deletion of information held by ABIC
Email admin@ahlalbait.org with the subject ABIC app data deletion request. In the message:
- state whether the request concerns a push-notification registration, authorised broadcaster access, Towards Infinity access, or another ABIC app feature;
- provide the email address used for the restricted feature, if applicable; and
- state whether you use iOS or Android and provide enough information for ABIC to identify the relevant record.
ABIC may ask you to verify your identity or control of the relevant email/device before deleting personal or access records. Guest push registrations are intentionally not linked to a name or email, so ABIC may need to work with you to identify the relevant device token.
Once a request is verified, ABIC will delete or anonymise the relevant app record where it can do so, revoke related access and active sessions, and explain if a limited record must be retained for security, transaction, dispute or other applicable record-keeping needs. ABIC will respond and process verified requests as soon as reasonably practicable.
Deleting mobile-app information does not automatically delete separate donation transactions, cancel recurring contributions, remove system-calendar entries or erase third-party media activity. Please identify those services in your request so ABIC can explain the appropriate process.
Age audience
The app's intended store audience is people aged 13 and over and is primarily adults and older teenagers. The app does not provide general member account creation or targeted advertising. If you believe information about a child under 13 has been submitted through a restricted ABIC service, contact admin@ahlalbait.org.
Changes to this policy
ABIC may update this policy when app features or data practices change. The published policy will show the effective date. Material new collection or use should be explained before the related feature is enabled.
Contact
For privacy questions, access or correction requests, or data deletion requests, contact:
Ahl Al Bait Islamic Centre (ABIC)
Email: admin@ahlalbait.org