Back to Home

Privacy Policy

Last updated: July 30, 2026

1. Who We Are

Minara Platform is operated by Miftaah Institute. Minara is a community engagement and household intelligence SaaS platform that helps community organizations manage people, families, events, and analytics across their programs.

For privacy-related inquiries, contact us at privacy@minara.app.

2. What Minara Does

Minara Platform is a subscription SaaS application that enables community organizations to manage their membership, track event registrations, handle donations, run engagement analytics, and maintain household records. Organizations use Minara to understand and serve their communities more effectively.

3. Information We Collect

What We Do NOT Collect

  • No precise GPS or real-time location data
  • No contact lists or address books from your device
  • No biometric data (fingerprints, face scans)
  • No social media credentials or third-party account passwords

Account Data

When an organization administrator creates an account, we collect: name, email address, organization name, and role. Authentication is managed through Supabase, which stores session tokens and authentication credentials securely.

People & Family Data

Organizations may enter information about their community members, including: names, email addresses, phone numbers, mailing addresses, family/household relationships, and demographic information. This data is entered and managed by the organization, not collected directly from community members (unless via embeddable registration forms).

Event & Registration Data

When individuals register for events (including through embeddable forms), we collect: name, email, and any additional fields the organization has configured for that event.

Donation Data

Donation records imported or tracked through the platform include: donor name, email, donation amount, date, and campaign attribution. Payment processing is handled by third-party processors (e.g., FundraiseUp) — Minara does not process or store credit card numbers or bank account details.

Analytics & Usage Data

We collect aggregated engagement analytics including: event attendance frequency, donation patterns, engagement scores, and program participation. We also collect standard web analytics (page views, browser type, device type, referrer) for platform improvement.

4. How We Use Information

  • Service provision: To operate the platform and deliver its core features to organizations
  • Engagement analytics: To generate engagement scores, dashboards, and community insights for organizations
  • Identity resolution: To deduplicate records and maintain accurate household data
  • Transactional email: To send event confirmations, notifications, and account-related communications via Resend
  • Platform improvement: To analyze usage patterns and improve the platform experience
  • Security: To detect and prevent unauthorized access or abuse
  • Legal compliance: To comply with applicable laws and regulations

We do not sell personal information. We do not use your data for advertising purposes.

5. Cookies

We use the following cookies:

CookiePurposeDurationHow to Opt Out
sb-*Supabase authentication sessionSession / 7 daysClear browser data
__next*Next.js framework functionalitySessionClear browser data

We do not use advertising cookies. We do not engage in cross-site tracking.

6. Third-Party Processors

ProviderPurposePrivacy Policy
SupabaseAuthentication & database hostingsupabase.com/privacy
VercelApplication hosting & CDNvercel.com/legal/privacy-policy
UpstashServer-side caching (Redis)upstash.com/trust/privacy
ResendTransactional email deliveryresend.com/legal/privacy-policy

7. Data Retention

  • Account data: Retained for the duration of the active subscription; deleted within 30 days of account closure upon request
  • People & family data: Retained as long as the organization's account is active; deleted upon organization request or account closure
  • Event registration data: Retained as long as the organization's account is active
  • Analytics aggregates: Retained for up to 24 months for trend analysis
  • Server logs: Retained for 30 days for security and debugging
  • Cache data: Automatically expires based on configured TTL (typically minutes to hours)

8. Your Rights

GDPR (EEA/UK Residents)

If you are located in the European Economic Area or the United Kingdom, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure of your data
  • Restrict processing
  • Data portability
  • Object to processing
  • Lodge a complaint with your local supervisory authority

Legal basis for processing: consent (for optional features), contract performance (for service delivery), and legitimate interest (for security and platform improvement).

CCPA (California Residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of personal information

Minara Platform does not sell personal information.

How to Exercise Your Rights

Contact us at privacy@minara.app. We will respond within 30 days. We may need to verify your identity before processing your request.

9. International Transfers

Our servers and third-party processors are primarily located in the United States. If you access the platform from outside the United States, your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses and processor agreements to safeguard international data transfers where required by law.

10. Children

Minara Platform is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has submitted personal information through the platform, please contact us at privacy@minara.app and we will promptly delete it.

11. Security

  • All data in transit is encrypted via TLS/HTTPS
  • Data at rest is encrypted by our hosting and database providers
  • Authentication is managed through Supabase with secure session handling
  • Role-based access control limits data access within the platform
  • We conduct regular security reviews of our codebase and infrastructure

In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected organizations and, where required by law, individuals within 72 hours of becoming aware of the breach.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted with an updated "Last updated" date at the top of this page. For significant changes, we will notify organization administrators via email. We encourage you to review this policy periodically.

13. Contact

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

Miftaah Institute
Email: privacy@minara.app
We will respond within 30 days.

Disclaimer: This Privacy Policy is provided for informational purposes and has been drafted to cover common privacy requirements. It is not a substitute for professional legal advice. We recommend consulting with a qualified attorney for jurisdiction-specific compliance.