Legal

Privacy Policy

Last updated: August 17, 2026

This policy explains how HalalTrust processes organization account data, private evidence, public publication artifacts, Guided Implementation information, billing records, transactional email, and aggregate QR analytics.

1. Information you provide

When an owner creates an account, HalalTrust collects the organization name, owner name and email address, password, and any optional phone number or organization description the owner submits.

Workspace users may provide halal-related evidence and disclosures, including managed uploads or external document links, document details, supplier or counterparty information, practices, organization details, and other content supported by the selected workflow.

Guided Implementation applicants may provide a name, job title or role, work email, optional phone number, organization and website details, industry or organization type, total location count, proposed primary location, certificate or evidence-record and supplier ranges, current certification or oversight arrangement, evidence-management process, operational difficulty and timing trigger, and desired onboarding timeframe. Qualification applications do not collect payment-card details or document uploads.

2. Account credentials and sessions

HalalTrust does not store the owner’s password in plaintext. The application stores a one-way scrypt password hash used to authenticate the account.

After registration or login, HalalTrust uses an essential HTTP-only session cookie to keep the owner signed in. The current session configuration may remain valid for up to seven days unless the owner logs out or the session is otherwise cleared.

When password recovery is requested, HalalTrust may process the normalized account email, a hashed rate-limit key, and a cryptographically random, short-lived reset token. Only the token hash is stored. A successful reset marks the token used, changes the password hash, and revokes existing owner sessions.

3. Private evidence and public publication

Uploaded source evidence is private by default and protected by authenticated organization authorization. Uploading a file does not make it public. An authorized publication reviewer may access a private source only when it is tied to the frozen candidate currently under review; that access does not allow unrestricted workspace browsing.

Public sharing is a separate reviewed action that creates an explicit publication snapshot and separate public artifacts. Private source URLs are not public publication URLs. Approved TrustProfiles may display organization-selected details, disclosures, document information, supplier or counterparty information, practices, and public artifacts. Public artifacts can be revoked.

Owner email addresses, phone numbers, password hashes, session data, account membership records, Stripe customer or subscription identifiers, internal audit or security records, owner QR analytics, and Guided Implementation application answers are not included in the public TrustProfile response.

Approved TrustProfiles are accessible to anyone with the profile URL or QR code while publication access remains active. Organizations should not place unnecessary personal, confidential, or sensitive information in public-facing fields.

4. Billing information

HalalTrust uses Stripe for optional subscription checkout, recurring billing, and the customer billing portal. Payment information entered during checkout is processed by Stripe under Stripe’s own terms and privacy practices.

HalalTrust stores limited billing records needed to operate the subscription, such as Stripe customer and subscription identifiers, subscription status, billing-period dates, and Stripe event identifiers. HalalTrust does not receive or store a full payment-card number in the application database.

Submitting a Guided Implementation qualification application does not create an account, process payment, execute an agreement, reserve implementation capacity, or enroll the organization.

5. Guided Implementation and transactional email

Guided Implementation application answers are used to evaluate workflow fit, responsible ownership, scope, timing, and current implementation capacity. An application does not guarantee qualification, acceptance, enrollment, implementation, certification, compliance, or any commercial outcome.

HalalTrust uses Resend to deliver transactional messages such as password-reset, application, billing, and account-deletion messages. Guided application notification and receipt content is redacted in HalalTrust’s delivery outbox after successful delivery according to current behavior.

For an account-deletion completion message, HalalTrust redacts the recipient, message body, and provider message identifier in its outbox after successful delivery. Failed delivery may retry up to five attempts; exhausted failed completion content is eligible for redaction after 30 days through a confirmed maintenance procedure. HalalTrust outbox redaction does not delete a message or backup held by Resend.

6. Security, operational, and QR analytics records

HalalTrust creates internal audit records for account creation, protected workspace actions, publication review, publication, revocation, export, and lifecycle operations. These records may include the account, organization, action type, affected record, timestamp, and limited action metadata.

The application also maintains login-throttling records to reduce repeated unauthorized login attempts. Shared login-rate-limit keys are derived using a one-way hash of the normalized email address.

The Guided Implementation application uses short-lived throttling records derived with a keyed one-way hash of the normalized work email and, when available, the request network address. Raw network addresses are not stored in the application throttle table.

When a visitor opens an approved TrustProfile through its HalalTrust QR code, HalalTrust records only an organization-level daily aggregate count and the first and most recent open times for that day. QR analytics count opens rather than unique people and may include repeat opens. HalalTrust does not store visitor names, IP addresses, user-agent fingerprints, precise locations, referrers, device identifiers, or browsing histories for this feature.

7. How information is used

HalalTrust uses information to create and secure accounts; provide password recovery; operate organization workspaces, evidence workflows, publication review, TrustProfiles, QR codes, aggregate QR analytics, billing features, and Guided Implementation qualification review; send transactional messages; display organization-selected public content; respond to correction, support, deletion, or legal requests; prevent abuse; investigate errors or security incidents; and maintain the service.

HalalTrust does not sell personal information or use owner account data, application answers, private evidence, or QR analytics for third-party behavioral advertising.

8. Authorized access and service providers

Authorized HalalTrust operators may access customer information only when reasonably necessary for publication review, support, security, deletion, incident response, or operation of the service and within their authorized role. HalalTrust does not give ordinary staff unrestricted permission to browse all customer files.

HalalTrust uses Vercel for application hosting and managed file storage, Neon for the application database, Resend for transactional email, and Stripe for payment and subscription processing. These infrastructure providers may technically process or access information under their service-delivery, support, security, legal, and recovery roles.

HalalTrust may disclose information when reasonably necessary to comply with law or legal process, protect the rights and safety of users or others, investigate fraud or security incidents, enforce agreements, or complete a business reorganization or transfer subject to appropriate protections.

9. Owner export

An organization owner may export a TAR archive containing a manifest, structured workspace records, eligible managed source files, and a SHA-256 checksum for each exported source. The current product limit is 100 source files and 100 MiB of source bytes.

The export excludes passwords and password-reset material, session data, provider credentials or tokens, internal security controls, other organizations, provider-managed backup records, and provider-managed billing records. It is not a copy of every record held by every service provider.

10. Cookies and tracking

HalalTrust uses an essential session cookie for authenticated owner access. The cookie is configured as HTTP-only and SameSite=Lax, and it is marked secure in production. Public visitors who do not already have an owner session cookie are not intentionally assigned authenticated session state merely for viewing public pages or submitting the Guided Implementation application.

QR analytics do not require an identity cookie, advertising cookie, cross-site identifier, or visitor profile. HalalTrust does not currently use third-party advertising trackers on TrustProfiles.

11. Retention and deletion

HalalTrust generally retains live account, workspace, subscription, aggregate QR analytics, audit, security, and evidence information while it is needed to provide and protect the service. Reference-aware deletion prevents removal of a source that remains tied to a protected relationship. Public artifacts can be revoked independently from their private sources.

An owner can confirm unpublishing and directly revoke public TrustProfile access from dashboard Settings. Permanent account deletion is a separate request and cancellation-window process. When an eligible deletion is separately operationally authorized, the application removes the live organization and owner credential, public-profile eligibility, organization records and relationships, managed Vercel Blob objects in the exact workspace prefix, linked outbox PII, and applicable throttle hashes. External document URLs supplied by a customer are outside HalalTrust’s control and cannot be deleted by the application.

The application retains a minimal pseudonymous completion ledger and durable recovery evidence designed to prevent a deleted account from being silently restored after database recovery. No fixed retention duration for that evidence is promised. The deletion procedure does not mutate Stripe.

Guided Implementation qualification applications are scheduled for deletion 90 days after submission. Their notification email content is redacted from HalalTrust’s delivery queue after successful delivery, and expired throttle keys are eligible for deletion after 24 hours. Legal holds, security incidents, disputes, provider backups, or other approved exceptions may affect final deletion timing.

The Production database currently has seven days of point-in-time recovery history. That recovery setting does not mean every provider copy is necessarily destroyed after seven days. Database backups, Vercel caches, logs, build records and deployments, Resend records, and Stripe billing or transaction records expire or may be retained under the applicable provider lifecycle, technical constraints, legal obligations, fraud controls, tax, accounting, or financial-reporting requirements. HalalTrust does not promise immediate universal erasure from provider systems.

12. Security

HalalTrust uses measures such as password hashing, HTTP-only sessions, organization authorization checks, rate limiting, parameterized database queries, audit records, and signed Stripe webhooks. No online service can guarantee absolute security.

Do not submit identification, payment details, confidential contracts, passwords, or other sensitive documents through the Guided Implementation application or ordinary email.

Owners are responsible for using a strong, unique password and protecting access to their email and devices.

13. Children’s privacy

HalalTrust is a business service and is not directed to children. HalalTrust does not knowingly create accounts for or solicit Guided Implementation applications from children under 13.

14. Changes and contact

HalalTrust may update this policy as the product, service providers, or legal requirements change. The updated date will appear on this page.

Privacy questions and account, application, or data requests may be sent to support@halaltrust.co.