Privacy Policy
Privacy Policy for Zakatek
Effective Date: 2026-05-18
At Zakatek ("we", "us", "our"), accessible from https://zakatek.app, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform for crowdfunding and donation management.
If you have questions or concerns, contact us at privacy@zakatek.app.
1. Information We Collect
We collect personal information that you voluntarily provide when you register, make a donation, create a project, or communicate with us.
● Account Data: name, email address, password hash, profile image, role preferences.
● Donation Data: donation amount, currency, project supported, transaction ID, recurring donation plan details (frequency, billing cadence), and donor location (optional). Payment card numbers, CVV, and expiry are never stored by Zakatek — these are processed and vaulted exclusively by Square. We do store card descriptors (card brand, last four digits, expiry month and year) returned by Square solely to display your saved payment method in your account dashboard.
● Recurring Support Data: if you enroll in recurring giving, we store a Square subscription ID, a Square customer ID, and a Square card vault token (an opaque reference — not raw card data) to enable ongoing billing. Square's cardholder data environment is PCI-DSS certified.
● Project Data (for campaign creators): organisation name, tax ID (if applicable), bank account details for payouts, project description, updates, photos.
● Usage Data: IP address, browser type, operating system, referring URLs, pages visited, date/time stamps.
● Communication Data: emails, support tickets, survey responses.
We also collect non-personal information aggregated for analytics (e.g. number of visitors per page).
2. How We Use Your Information
We use your information to:
● Create and manage your account.
● Process one-time and recurring donations and payouts.
● Manage your recurring support commitments, including pausing, resuming, and cancelling subscriptions on your instruction.
● Verify eligibility for Zakat compliance.
● Communicate project updates, receipts, and service announcements.
● Improve our platform (analytics, debugging).
● Comply with legal obligations (anti-money laundering, tax reporting).
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area, we process your data based on:
● Contract performance: to provide the service you requested.
● Legitimate interests: to improve security, prevent fraud, and analyse usage.
● Consent: for marketing communications (you can opt out anytime).
● Legal obligation: for tax or anti-fraud reporting.
4. Sharing Your Information
We do not sell your personal data. We share it only in these limited circumstances:
● Payment Processors: Square — to process one-time and recurring card payments, vault payment methods, and manage subscriptions. Square receives payment and card data and is PCI-DSS certified. NCBA — to process M-Pesa STK push payments for KES donations.
● Service Providers: hosting (GCP), email delivery (Google Mail), analytics (Google Analytics) — under confidentiality agreements.
● Legal Compliance: if required by law or to protect rights and safety.
● Business Transfers: in case of merger or acquisition (you will be notified).
5. Cookies and Tracking Technologies
We use cookies for essential functions (authentication, session management), analytics, and optional preferences. You can disable cookies via browser settings, but some features may break. Third-party analytics services (e.g. Google Analytics) set their own cookies.
6. Data Retention
We retain your account data as long as your account is active plus 3 years for backup, legal, or fraud prevention purposes. Donation and recurring support records are kept for 7 years to comply with tax laws. Card descriptor data (brand, last four digits, expiry) is retained while your payment method is active and deleted upon your request or when no active subscriptions reference it. You may request deletion of your data, subject to legal retention obligations.
7. Your Rights
Depending on your location, you may have the right to:
● Access, correct, or delete your personal data.
● Object to or restrict processing.
● Data portability.
● Withdraw consent at any time.
Submit requests to admin@zakatek.app. We will respond within 30 days.
8. Children's Privacy
Our service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with data, contact us to remove it.
9. Security
We implement industry-standard measures (encryption in transit via TLS, hashed passwords, access controls) but cannot guarantee absolute security. Card numbers and CVV are never transmitted to or stored on Zakatek servers — all card entry is handled via Square's Web Payments SDK, which renders a PCI-compliant iframe. In case of a data breach, we will notify affected users and regulators as required by law.
10. International Data Transfers
Your data may be stored on servers in the United States or the European Union. For transfers outside your jurisdiction, we rely on Standard Contractual Clauses or adequacy decisions.
11. Changes to This Policy
We may update this Privacy Policy. Material changes will be notified via email or a prominent notice on our website. The "Effective Date" at the top indicates when the policy was last revised.
12. Contact Us
Zakatek
Email: admin@zakatek.app