Noor Hidayah

Privacy policy

Draft for legal review. Not yet in force.

What Noor Hidayah collects, why, where it is kept, for how long, and how to use your rights.

Last updated: 27 Sept 2026

Who we are

Noor Hidayah is an app and a website for pilgrims travelling for Umrah and Hajj, and a dashboard for the tour operators who take them.

Noor Hidayah is run by SOSA, a company registered in India. Registered name: [to be confirmed: registered name exactly as printed on the certificate of incorporation (FB-7)]. CIN: [to be confirmed: Corporate Identification Number (FB-7)]. Registered office: [to be confirmed: registered office address (FB-7)].

This policy explains what personal data Noor Hidayah handles, why, where it is kept, for how long, and how you use your rights under India's Digital Personal Data Protection Act, 2023 and its Rules.

Our role and your operator's

Many pilgrims are registered by their tour operator before they first open the app. For the details your operator enters, your operator decides why they are collected and is the data fiduciary; SOSA processes them on the operator's behalf, under a data-processing agreement, and your operator gives you its own notice for them.

Once you activate your account, and for everything you add in the app yourself, SOSA is the data fiduciary for your account. If you download the app without an operator, SOSA is the data fiduciary for all of it.

[to be confirmed: which party is the data fiduciary and which the processor for each data flow (CL-3)]

What we collect and why

Each group below says what is collected and what it is used for. You agree to most of it when you create your account, in a notice that lists each purpose. The rest is kept because it may be needed to protect your life, to keep the service secure, or because the law requires it, and the group says so.

Names, phone numbers and email

  • Passport name: your name exactly as printed on your passport. Your operator needs it for your visa and the Nusuk Masar submission, and it appears on your certificate. Your operator corrects it; you cannot change it in the app, because it must match your passport.
  • Display name: the name other pilgrims in your group see, on your group card, in chat and in the member list. You can change it.
  • Indian mobile: the number you sign in with. We send it your sign-in code and your operator's invitation, by WhatsApp or SMS.
  • Saudi mobile: optional, a number to reach you while you are in Saudi Arabia. It is never used to sign in.
  • Email: optional, for notices and for sending you a copy of your data.

Your profile

  • Photo: for your pilgrim card, so your group leader recognises you, and for your certificate.
  • Date of birth or age: needed for the visa and Nusuk Masar, and to suit the guidance to your age.
  • Gender: needed for the visa, and for the rules on travelling with a mahram and on accommodation.
  • Nationality: needed for the visa and Nusuk Masar.
  • Language: the language the app and its content are shown in.
  • Fiqh preference: not collected. The app has no field for your school of thought.

Passport, visa and travel documents

  • Passport number: your operator submits it to Nusuk Masar. It is encrypted on our servers before it is stored and is shown masked; your operator sees it in full only by asking to, and every time it is shown is recorded.
  • Visa number: for travel and immigration, encrypted and masked in the same way.
  • Document files: copies of your travel documents that you may need offline during the trip.
  • Document trip link and kind: which trip a document belongs to and what kind of document it is, so that your operator's copy is removed on time after that trip.

We never collect the twelve-digit identity number issued by UIDAI, and never a fingerprint, face or iris template. The phone's own fingerprint or face unlock may lock your documents on your phone; nothing from it reaches us.

Your group and your trip

  • Group membership: which of your operator's groups you travel with.
  • Member display card: what the other members of your group see of you, with the group leader marked.
  • Group check-ins: whether you have answered your group leader's roll call that you are here, seen by you, your leader and your operator's staff, never with your location.
  • Group and trip dates: when your group leaves and returns. The return date starts the clock for removing your documents.
  • Itineraries and announcements: your group's programme and your operator's messages to the group.
  • Itinerary reads: which parts of the programme you have seen, so your operator can help.
  • Announcement receipts: whether an announcement reached you, and whether you read and acknowledged it, counted for your operator.
  • Pilgrim invites: the invitation your operator sends you, by WhatsApp or SMS, to join the app.
  • Join attempts: attempts to join a group with a code, counted so that codes cannot be guessed.

Your journey, history and certificates

These show your religious practice, so we treat them as sensitive.

  • Journey progress: the ritual steps you mark done, and when, which decide whether a certificate can be issued. Your group leader and your operator's staff can see it.
  • Hajj and Umrah history: the years you completed Umrah or Hajj, if you add them, shown as marks on your profile. Your group leader and your operator's staff never see them.
  • Certificates: the certificate of completion you can share, with its code. Anyone with the code can check it on our website, and your name shows there only as you choose: in full, as initials, or not at all.
  • Operator ratings: the stars and the comment you give your operator after a trip. Other people see only the average and the number of ratings; only SOSA reads your comment.

Safety and SOS

Your emergency contacts are kept with your consent. The SOS records are kept because they may be needed to protect your life, which the law allows without consent; withdrawing a consent never hides an SOS that is still open.

  • Emergency contacts: up to three people to reach if you ask for help.
  • Operator SOS contacts: your operator's staff numbers that you can dial from the SOS screen, kept on your phone so they work offline.
  • SOS events with location: when you press SOS, your location and the time, sent to your group leader and your operator so that someone can reach you.
  • Location pings during an open SOS: your location, updated until your leader reaches you.
  • SOS acknowledgements: who answered your SOS and when, so you know someone is coming.
  • Owner's SOS escalation number: SOSA's own number, called when nobody answers an SOS in time.

Outside an open SOS the app never tracks your location. Prayer times and the Qibla are worked out on your phone, and that position is never sent to us.

Chat, reports and contacts

  • Chat messages: your messages in group chats and direct messages. Personal details are taken out of a message before it is stored, and the original text is never kept.
  • Reports and blocks: the messages or people you report, and the people you block, for safety and moderation. A report is kept after you delete your account, without your identity.
  • Contact hashes: if you choose to find co-travellers from your phone's contacts, the numbers are turned into one-way codes on your phone and only those codes are sent. They are compared and discarded at once, and never stored.
  • Contact match pairs: the pairs of people who found each other that way, so that a direct message can open between them. Turning the feature off deletes them.
  • Moderation actions: what a moderator decided about one of your messages or about your chat, such as approving or removing a message, a warning, a mute or a ban, with the reason shown to you. Your operator's administrators (for your group chats) and SOSA keep the record; you are never shown who decided.
  • Chat restrictions: a mute or a ban on sending messages, kept until it ends or is lifted.
  • Contact discovery: if you let people who have your number find you, a one-way code made from your own mobile number. Turning the feature off deletes it.
  • Contact match runs: how many codes each search from your contacts sent and how many people it found, so that searches can be limited. No number or code is kept.
  • Feature flags: the switches that turn chat, finding co-travellers from contacts, the essentials guide and Hajj mode on or off for everyone, for an operator or for a group. They hold nothing about you.

Plus

  • Plus entitlements: whether you have Plus, where it came from (your operator's seat or a store purchase) and until when.
  • Store transactions: the record of a Plus purchase from the App Store or Google Play, so we can verify it and honour a refund. The store takes the payment; we never see your card or bank details.

Your account, devices and security

  • Account link and profile status: the link between your sign-in and your pilgrim record, and whether your account is active, suspended or being deleted.
  • Pending account deletion: while the 7 days after a deletion request run, your profile is hidden from everyone and you can still cancel.
  • Device push tokens: the address that lets us send notifications to your phone. A notification carries no message text and no personal data.
  • Device records: the phones signed in to your account, so you can see and remove them.
  • Watch companion state: if you use the Noor Hidayah app on a Wear OS watch paired with your phone, what your phone sends it to show: the prayer times and your city's name (never your exact position), your next step, your group's and your leader's names, emergency numbers, whether your phone has synced, and the state of your SOS. Google Play services carries it between your phone and your watch, and may pass it through Google's servers when the watch is not connected to the phone by Bluetooth.
  • Sign-in session metadata: your sign-in sessions, so they can be listed, ended, and checked for unusual sign-ins.
  • OTP sends: how many sign-in codes were sent to a number, to limit abuse.
  • Rate-limit buckets: short-lived counts per network address that limit certificate checks and usage-statistics uploads.
  • Notification log: whether a notification was delivered, to find and fix delivery problems.
  • Audit log: who revealed a passport or visa number, who exported a list and who read personal data, kept as the DPDP Rules require.

Consent and your requests

  • Consent notices: the exact text of each notice, in each version and language.
  • Consent records: what you agreed to, in which version, and when, so it can be shown.
  • Deletion and rights requests: your requests to see, correct or delete your data, your grievances, and what was done about them.

Crash reports and usage statistics

  • Crash reports: when the app crashes, a technical report goes to Sentry, with personal data removed and your user id replaced by a one-way code.
  • Product analytics events: which features are used, counted with nothing that links them to you. You can turn them off in the app under Settings, Usage statistics.

If you work for an operator

  • Operator organisation data: your company's details, for its identity, its invoices and its Nusuk Masar link.
  • Operator staff accounts: the sign-in accounts of an operator's staff, with a second sign-in step.
  • Staff invites: the email that invites a new staff member.
  • Seat allocation: how many pilgrim seats an operator uses, for its invoices.
  • Export jobs: a record of every pilgrim list an operator exports. The file itself is deleted after 24 hours.
  • Partner directory listing: an operator's public listing, when it has agreed to be listed.

On the website

  • Website contact form: when the website's contact form opens, what you write to us, so we can answer.
  • Our public pages set no cookies of their own. The account-deletion and certificate-check pages ask Cloudflare Turnstile to check that the visitor is a person.

Where your data is stored

Your data is stored in India, in Mumbai, with Supabase, our database host. Passport and visa numbers are stored there only in encrypted form, with the key kept apart from the database, so the host cannot read them.

Others handle some data for us, each only for the task named:

  • Amazon Web Services, in Mumbai, runs the service that keeps your phone's offline copy up to date. It passes on only what you may already see.
  • Meta, through WhatsApp Business, receives your Indian mobile and the text of your sign-in code or invitation, to deliver it.
  • MSG91, in India, receives the same, to deliver it by SMS when WhatsApp cannot.
  • Firebase Cloud Messaging, run by Google, receives your phone's notification address and a notice with no message text and no personal data.
  • Google Play services carries what your Wear OS watch shows between your phone and your watch, if you use one, and may pass it through Google's servers.
  • Sentry, in the European Union, receives crash reports with personal data removed.
  • Apple and Google verify Plus purchases made through their stores.
  • Vercel serves this website, with its server functions in Mumbai.
  • Cloudflare Turnstile checks that a visitor is a person on the website's deletion and certificate pages.

Your operator sees the data of the pilgrims it manages, and your group leader sees what the group needs. No party in Saudi Arabia receives your data from us: your operator makes its own Nusuk Masar submission.

Amazon links in the essentials guide open in your browser and send Amazon nothing from the app. The offline map is built in advance from OpenStreetMap and sends nothing when you use it.

We do not sell your data and do not share it for advertising.

If a breach affects your data, we report it to the Data Protection Board of India and tell you, in your language, what happened and what you can do.

How long we keep it

  • Your names, Indian mobile, email, photo, date of birth, gender, language, nationality and emergency contacts: for as long as you have your account, and removed within 30 days after you delete it.
  • Your Saudi mobile: until a set number of days after your last trip. [to be confirmed: how many days after the last group's return the Saudi mobile is kept (CL-10)]
  • Passport numbers and document files: your operator's copy leaves the dashboard 30 days after your group returns (90 days if your operator records a reason) and is then erased. [to be confirmed: whether DPDP Rule 8, sub-rule 3, seals the numbers for one year instead of erasing them (CL-5)] After the trip you may choose to let us keep your passport details for your next trip, for 24 months or until the passport expires, and withdraw that choice at any time.
  • Visa numbers: never kept beyond the trip.
  • Group membership, check-ins, trip dates, itineraries, announcements, reads and receipts: [to be confirmed: how long trip data is kept after the group returns (CL-6)]
  • Journey progress, Hajj and Umrah history, certificates and Plus entitlements: for as long as you have your account, and deleted with it. Your operator ratings are then made anonymous: the stars stay in the average and your comment is cleared. [to be confirmed: whether counsel keeps these defaults (CL-6)]
  • Chat: group chats for 90 days after the group returns, direct messages for 180 days, and a removed message for 30 days. Reports and moderation actions for one year; a mute or a ban until it ends or is lifted; blocks for as long as you have your account. Your contact discovery code and contact match pairs until you turn the feature off; the counts of your contact searches for 30 days.
  • SOS events, location pings and acknowledgements: 24 months after the SOS is closed. An open SOS is never deleted.
  • Device push tokens: 30 days after they stop working, and deleted with your account. Device records: for as long as you have your account. What your watch shows: replaced each time your phone sends it, and removed with the app on the watch.
  • Sign-in codes sent: 24 hours. Join attempts and the notification log: 90 days. Rate-limit counts: one hour.
  • Consent records: for as long as you have your account, and 12 months after. Rights requests: 12 months after they are closed. The audit log: 13 months. After you delete your account, a record with no personal details is kept for 12 months so that your consent records still point to it.
  • Crash reports: 90 days at Sentry. Usage statistics: 13 months, with nothing that links them to you.
  • Store transactions and seat invoices: 72 months, as tax law requires.
  • Invitations: 90 days after they expire. An exported list: 24 hours.
  • Operator staff accounts: 12 months after the account is closed. [to be confirmed: whether counsel keeps this period (CL-13)]
  • Operator organisation data and website contact messages: [to be confirmed: retention of operator organisation data and contact-form messages (CL-6)]
  • A partner directory listing: while the operator is listed.

Your rights

Under the DPDP Act you can:

  • get a summary of your data and how it is used, and a copy of it: in the app under More, Settings, Account;
  • have it corrected: you change your display name, language, Saudi mobile and email in the app; your operator corrects your passport name, date of birth, gender and nationality, because they must match your passport, and you ask for that in the app;
  • have it erased: delete your account in the app under More, Settings, Account, or on our account deletion page. Your account is deleted 7 days after you confirm, and you can keep it until then; your data then leaves every system within 30 days, except the records the law requires us to keep, listed above;
  • withdraw a consent at any time, as easily as you gave it; what was done before the withdrawal stays lawful;
  • nominate someone to use these rights for you if you die or cannot use them yourself: [to be confirmed: how a nomination is made (CL-2)];
  • raise a grievance with our grievance officer, named below.

We answer every request within 90 days, in your language. If our answer does not resolve your grievance, you can complain to the Data Protection Board of India.

Grievance officer

  • Name: [to be confirmed: grievance officer's name (FB-3)]
  • Postal address: [to be confirmed: grievance officer's postal address (FB-3)]
  • Email: [to be confirmed: grievance officer's email address (FB-3)]

You can also raise a grievance in the app or through our support page.

Children

The DPDP Act requires verifiable consent from a parent or guardian before a child's personal data is processed. [to be confirmed: how a child's parental consent is recorded, and how a dependant without their own phone is invited (CL-8)]

Noor Hidayah shows no advertising and does not monitor the behaviour of anyone, children included.

In Saudi Arabia

While you are in Saudi Arabia, the Kingdom's Personal Data Protection Law also applies to your data. All processing stays in India, no party in Saudi Arabia receives your data from us, and your Saudi mobile is cleared after your trip, as set out above.

[to be confirmed: whether SOSA appoints a representative in Saudi Arabia or registers with SDAIA, and how to reach them (CL-16)]

Changes to this policy

The date at the top of this page is when this policy last changed. If a change affects what we collect or why, the app shows you the new notice and asks for your consent again before the change applies to you.

We keep every version of the notice, and the version you agreed to is recorded with your consent.

Our terms of use and our company details are on their own pages.