1. Who We Are
Minara Platform is operated by Miftaah Institute. Minara is a community engagement and household intelligence SaaS platform that helps community organizations manage people, families, events, and analytics across their programs.
For privacy-related inquiries, contact us at privacy@minara.app.
2. What Minara Does
Minara Platform is a subscription SaaS application that enables community organizations to manage their membership, track event registrations, handle donations, run engagement analytics, and maintain household records. Organizations use Minara to understand and serve their communities more effectively.
3. Information We Collect
What We Do NOT Collect
- No precise GPS or real-time location data
- No contact lists or address books from your device
- No biometric data (fingerprints, face scans)
- No social media credentials or third-party account passwords
Account Data
When an organization administrator creates an account, we collect: name, email address, organization name, and role. Authentication is managed through Supabase, which stores session tokens and authentication credentials securely.
People & Family Data
Organizations may enter information about their community members, including: names, email addresses, phone numbers, mailing addresses, family/household relationships, and demographic information. This data is entered and managed by the organization, not collected directly from community members (unless via embeddable registration forms).
Event & Registration Data
When individuals register for events (including through embeddable forms), we collect: name, email, and any additional fields the organization has configured for that event.
Donation Data
Donation records imported or tracked through the platform include: donor name, email, donation amount, date, and campaign attribution. Payment processing is handled by third-party processors (e.g., FundraiseUp) — Minara does not process or store credit card numbers or bank account details.
Analytics & Usage Data
We collect aggregated engagement analytics including: event attendance frequency, donation patterns, engagement scores, and program participation. We also collect standard web analytics (page views, browser type, device type, referrer) for platform improvement.
4. How We Use Information
- Service provision: To operate the platform and deliver its core features to organizations
- Engagement analytics: To generate engagement scores, dashboards, and community insights for organizations
- Identity resolution: To deduplicate records and maintain accurate household data
- Transactional email: To send event confirmations, notifications, and account-related communications via Resend
- Platform improvement: To analyze usage patterns and improve the platform experience
- Security: To detect and prevent unauthorized access or abuse
- Legal compliance: To comply with applicable laws and regulations
We do not sell personal information. We do not use your data for advertising purposes.
5. Cookies
We use the following cookies:
| Cookie | Purpose | Duration | How to Opt Out |
|---|---|---|---|
sb-* | Supabase authentication session | Session / 7 days | Clear browser data |
__next* | Next.js framework functionality | Session | Clear browser data |
We do not use advertising cookies. We do not engage in cross-site tracking.
6. Third-Party Processors
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Supabase | Authentication & database hosting | supabase.com/privacy |
| Vercel | Application hosting & CDN | vercel.com/legal/privacy-policy |
| Upstash | Server-side caching (Redis) | upstash.com/trust/privacy |
| Resend | Transactional email delivery | resend.com/legal/privacy-policy |
7. Data Retention
- Account data: Retained for the duration of the active subscription; deleted within 30 days of account closure upon request
- People & family data: Retained as long as the organization's account is active; deleted upon organization request or account closure
- Event registration data: Retained as long as the organization's account is active
- Analytics aggregates: Retained for up to 24 months for trend analysis
- Server logs: Retained for 30 days for security and debugging
- Cache data: Automatically expires based on configured TTL (typically minutes to hours)
8. Your Rights
GDPR (EEA/UK Residents)
If you are located in the European Economic Area or the United Kingdom, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure of your data
- Restrict processing
- Data portability
- Object to processing
- Lodge a complaint with your local supervisory authority
Legal basis for processing: consent (for optional features), contract performance (for service delivery), and legitimate interest (for security and platform improvement).
CCPA (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information
Minara Platform does not sell personal information.
How to Exercise Your Rights
Contact us at privacy@minara.app. We will respond within 30 days. We may need to verify your identity before processing your request.
9. International Transfers
Our servers and third-party processors are primarily located in the United States. If you access the platform from outside the United States, your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses and processor agreements to safeguard international data transfers where required by law.
10. Children
Minara Platform is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has submitted personal information through the platform, please contact us at privacy@minara.app and we will promptly delete it.
11. Security
- All data in transit is encrypted via TLS/HTTPS
- Data at rest is encrypted by our hosting and database providers
- Authentication is managed through Supabase with secure session handling
- Role-based access control limits data access within the platform
- We conduct regular security reviews of our codebase and infrastructure
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected organizations and, where required by law, individuals within 72 hours of becoming aware of the breach.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted with an updated "Last updated" date at the top of this page. For significant changes, we will notify organization administrators via email. We encourage you to review this policy periodically.
13. Contact
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
Miftaah Institute
Email: privacy@minara.app
We will respond within 30 days.
Disclaimer: This Privacy Policy is provided for informational purposes and has been drafted to cover common privacy requirements. It is not a substitute for professional legal advice. We recommend consulting with a qualified attorney for jurisdiction-specific compliance.