Legal

Privacy Policy

Last updated: July 22, 2026

This policy explains the information processed by the HalalTrust Founding Restaurant Pilot and distinguishes public restaurant content from private owner, security, and billing records.

1. Information provided by restaurant owners

When an owner creates an account, HalalTrust collects the restaurant name, owner email address, password, and any optional phone number or restaurant description the owner submits.

Owners may also submit or list public-facing restaurant content such as a logo URL, document title, issuing organization, issue and expiration dates, external document link, supplier information, supplier website, and restaurant-stated sourcing or preparation practices.

2. Account credentials and sessions

HalalTrust does not store the owner’s password in plaintext. The application stores a one-way scrypt password hash used to authenticate the account.

After registration or login, HalalTrust uses an essential HTTP-only session cookie to keep the owner signed in. The current session configuration may remain valid for up to seven days unless the owner logs out or the session is otherwise cleared.

3. Public and private information

Public Trust Profiles may display the restaurant name, logo, public description, last-updated date, active restaurant-listed documents, supplier information, restaurant-stated practices, and external links selected by the restaurant.

Owner email addresses, phone numbers, password hashes, session data, account membership records, Stripe customer or subscription identifiers, and internal audit or security records are not included in the public Trust Profile response.

Trust Profiles are accessible to anyone with the profile URL or QR code. Owners should not place unnecessary personal, confidential, or sensitive information in public-facing fields.

4. Billing information

HalalTrust uses Stripe for optional subscription checkout, recurring billing, and the customer billing portal. Payment information entered during checkout is processed by Stripe under Stripe’s own terms and privacy practices.

HalalTrust stores limited billing records needed to operate the subscription, such as Stripe customer and subscription identifiers, subscription status, billing-period dates, and Stripe event identifiers. HalalTrust does not receive or store a full payment-card number in the application database.

5. Security and operational records

HalalTrust creates internal audit records for account creation and protected owner actions. These records may include the account, restaurant, action type, affected record, timestamp, and limited action metadata.

The application also maintains login-throttling records to reduce repeated unauthorized login attempts. Shared login-rate-limit keys are derived using a one-way hash of the normalized email address.

Hosting, database, and payment providers may process technical request, security, and service-operation information as part of providing their services. HalalTrust does not currently provide QR-scan analytics or advertising tracking within the launch product.

6. How information is used

HalalTrust uses information to create and secure owner accounts; operate the dashboard, Trust Profiles, QR codes, and billing features; display restaurant-selected public content; respond to support or legal requests; prevent abuse; investigate errors; and maintain the service.

HalalTrust does not sell personal information or use owner account data for third-party behavioral advertising.

7. Service providers and disclosure

HalalTrust relies on service providers for database hosting, application hosting, and payment processing. Those providers may process information only as needed to provide their services, comply with law, protect their systems, or enforce their terms.

HalalTrust may disclose information when reasonably necessary to comply with law or legal process, protect the rights and safety of users or others, investigate fraud or security incidents, enforce agreements, or complete a business reorganization or transfer subject to appropriate protections.

8. Cookies and tracking

HalalTrust uses an essential session cookie for authenticated owner access. The cookie is configured as HTTP-only and SameSite=Lax, and it is marked secure in production.

The launch product does not currently use advertising cookies or offer restaurant owners QR-scan analytics. If analytics or additional cookies are introduced later, this policy and any required consent controls should be updated before those features are enabled.

9. Retention and deletion

HalalTrust retains account, restaurant, subscription, audit, and security information for as long as reasonably needed to provide the service, maintain security and billing records, resolve disputes, comply with law, and enforce agreements.

Owners can update public restaurant information and delete individual document, supplier, and practice records through the dashboard. Account deletion is not currently an automated self-service workflow. Owners may request account or data deletion by contacting HalalTrust, although some security, billing, legal, or backup records may be retained when necessary or permitted by law.

10. Security

HalalTrust uses measures such as password hashing, HTTP-only sessions, owner authorization checks, rate limiting, parameterized database queries, audit records, and signed Stripe webhooks. No online service can guarantee absolute security.

Owners are responsible for using a strong, unique password and protecting access to their email and devices.

11. Children’s privacy

HalalTrust is a business service for restaurant owners and is not directed to children. HalalTrust does not knowingly create accounts for children under 13.

12. Changes and contact

HalalTrust may update this policy as the product, service providers, or legal requirements change. The updated date will appear on this page.

Privacy questions and account or data requests may be sent to privacy@halaltrust.co.