Last updated: June 2026
Privacy is not a feature of Zaijat — it is the foundation. The platform was built so that sisters' modesty is protected by design: no photos are ever collected or displayed, shortlists are completely private, and your contact details are never visible to any other member until you both choose to proceed.
This policy explains what we collect, why, how long we keep it, and the rights you hold over your data. We follow GDPR principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, and integrity) regardless of where you are located.
Account information: email address, hashed password, gender, phone number (for contact reveal only).
Matrimonial profile: name, age, height, weight, build, aqidah, nationality, ethnicity, country, marital status, hijab type, bio, and other optional fields you choose to fill.
Activity data: interests sent/received, shortlists, filter preferences, and in-app messages with matched profiles.
Technical data: IP address (for fraud and abuse detection), browser / device type, and session tokens. We do not use third-party tracking pixels or behavioural advertising cookies.
Verification documents: if you submit ID for verification, the document is reviewed by our admin team and then deleted; we retain only the verification status (verified / unverified).
Your phone number is collected at onboarding but is never shown to any other memberunless both you and the other member independently accept the same interest. Only at that moment do we reveal the phone numbers to each other. No exceptions, no workarounds.
After contact is revealed, the in-app interest is closed. Neither party's phone number is stored in our system longer than the platform requires to operate.
We share your data only in these limited circumstances:
Active accounts: your profile data is kept for as long as your account is active. Deleted accounts: all personal profile data is permanently erased within 30 days of deletion. Moderation records (reports, bans) may be retained for up to 2 years to prevent re-registration of removed accounts. Payment records are retained for 7 years as required by accounting law.
We use only essential session cookies — one token to keep you logged in. We use no analytics cookies, no advertising cookies, and no third-party trackers. There is no cookie consent banner because there is nothing to consent to beyond session management.
Passwords are hashed with bcrypt (never stored in plain text). All traffic is encrypted via HTTPS. Our database and file stores are access-controlled and monitored. No system is perfectly secure, but we apply industry-standard measures and patch vulnerabilities promptly.
Zaijat is strictly for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If we become aware that a minor has created an account, we delete it immediately and report any safeguarding concern to the relevant authorities. If you believe a minor is using the platform, please report it to safety@zaijat.com.
To exercise any right, email privacy@zaijat.com. We respond within 30 days.
We will notify members of material changes by email and update the "Last updated" date above. Continued use of the platform after the effective date constitutes acceptance of the updated policy.