Skip to main content
Legal

Privacy Policy

Last updated: July 2026

Our commitment

Halal Finder is built with privacy at its core. We believe you should be able to find halal food without giving up your personal data. This policy explains what we collect (very little) and what we do with it (even less).

We use limited first-party iOS interaction totals and privacy-filtered diagnostics. We do not use third-party analytics, tracking cookies, ad networks, cross-app tracking, or data sales.

What we collect

We only collect what's necessary to make the app work for you:

  • Email address — used for account authentication and secure sign-in.
  • Account identifiers and essential session data — used to keep you signed in and connect your account state across the app and website.
  • Saved venues — your favourites and lists, so they sync across devices.
  • Public list content, venue suggestions, reports, owner claims, and listing media — when you create public list names or descriptions, submit venue suggestions or reports, start business claim onboarding, or explicitly select listing photos for upload, we store that content so the product can process, moderate, and display it. We do not scan or automatically collect your photo library.
  • Notification and billing state — push tokens and notification preferences when you enable alerts, plus membership and purchase-history details needed to keep account access up to date. Delivery records may include the event message, requested audience, device identifier, and a keyed push-token lookup hash. That keyed value is pseudonymous, not anonymous.
  • Limited product analytics and diagnostics — privacy-limited iOS listing views and phone-button taps, deduplicated when available with rotating keyed pseudonymous actor values, plus privacy-filtered errors used for owner totals, reliability, support, and abuse prevention. Those keyed actor values are pseudonymous, not anonymous. These records exclude account IDs, precise location, raw search text, and advertising identifiers; venue interaction events expire after 90 days.

We collect only what is required to run the account, billing, sharing, support, and owner workflows in the product.

What we don't collect

We want to be very clear about what we don't do:

  • No location tracking — we do not build a background location history or sell location data. When you actively use nearby discovery, your current coordinates may be sent to the API to return local venue results.
  • No third-party or cross-app tracking — we don't use Google Analytics, Mixpanel, advertising measurement, data brokers, or tracking across other companies' apps and websites.
  • No advertising cookies — the website may use essential first-party auth/session cookies, but we do not use ad-tech or cross-site tracking cookies.
  • No ad networks or banner ads — owner-paid discovery placement is always labelled Sponsored, and we don't share your data with advertisers.
  • No data selling — your data is never sold, rented, or shared with third parties for marketing.
  • No payment card storage — card and App Store payment details stay with the payment service. We receive membership status and purchase details, not your full card number.

Third-party services

We use a small number of trusted services to operate the app:

  • Account sign-in — authentication and secure session management for your account. Your email and account session data are handled here.
  • Membership services helps us confirm membership and owner-plan status. We receive membership and purchase-history details, not your full payment card details.
  • Payment services — website and App Store purchases are processed by trusted payment services. Their privacy practices are governed by their own privacy policies.
  • Notification delivery — Expo processes push tokens and notification content when you enable alerts so requested notifications can reach your device.
  • Media storage and delivery — Cloudflare stores and delivers venue photos that approved business owners or authorised operators explicitly submit for moderation.

These services receive only the information needed to operate the workflow you use. We do not share your data with them for their own marketing.

Data storage & security

Server-backed account and application records are stored in our Australian-hosted application database. The app also keeps limited device state needed to operate the experience, including secure session credentials, preferences, recent searches, saved-venue identifiers, a short-lived last-known location, and image caches. Data sent to our API is transmitted over HTTPS.

Data retention & deletion

You can delete your account at any time from the Profile screen in the iPhone app or from the signed-in account page on this website. A delete confirmation email from Halal Finder can also finish the request on the web confirmation page. When you delete your account, your account data is permanently removed — including your email, saved venues, lists, reports, suggestions, votes, and claim records.

Minimal keyed email-suppression evidence may remain where needed to honour unsubscribe, bounce, complaint, security, or legal obligations. It does not contain a readable email address without a separately held key. Reversible deletion-workflow references expire after 30 days. Notification recipient, device, keyed token-lookup, message, audience, identity, deduplication, and error details expire after 90 days; after that, only non-identifying event category, terminal status, aggregate delivery counts, and timestamps remain, and older duplicate send-history rows are deleted. Privacy-limited, keyed-pseudonymous venue interaction events also expire after 90 days.

Shared abuse controls retain purpose-separated keyed actor values rather than raw IP addresses. These short-lived entries expire with the relevant abuse-control window and are pruned shortly afterward.

You can also request account deletion by emailing [email protected] and we'll process it within 48 hours.

Children's privacy

Halal Finder is not directed at children under 13. We don't knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we'll remove it promptly.

Changes to this policy

If we make changes to this policy, we'll update this page and notify you through the app. We will never change our core commitment: your data is yours, and we will never sell it.

Contact

Questions about privacy? We're happy to answer. Reach out at [email protected].

Lavon Global Pty Ltd · Melbourne, Victoria, Australia

Explore next

Related pages