Privacy Policy
Salah Time ("we", "our", or "us"), developed by Salah Time Corp, is committed to protecting your privacy. This Privacy Policy describes how we collect, use, and safeguard your personal information when you use the Salah Time mobile application ("the App"). We have designed this application with a security-first architecture aligned with industry best practices.
We collect only the minimum data necessary to provide our services:
🔒 We do not collect your name, phone number, physical address, payment card details, or any biometric data. We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
Salah Time uses a passwordless, email-based One-Time Password (OTP) authentication system. When you sign in or verify your account, a cryptographically generated 6-digit code is dispatched to your email address via TLS-encrypted SMTP. Each OTP:
OTP codes are stored transiently in server-side memory only and are never persisted to the database.
Our server-side infrastructure is designed with defence-in-depth principles. Our backend API is deployed on Railway, a secure cloud platform with automatic TLS/SSL certificate provisioning, ensuring all data in transit between the App and our servers is encrypted using TLS 1.2 or higher (HTTPS). No cleartext HTTP communication is used in production.
User data is stored in Supabase, a PostgreSQL-based cloud database. We implement Row-Level Security (RLS) policies at the database layer to enforce strict data isolation. RLS ensures that even if an API endpoint were misconfigured, a user's record could never be read or modified by any other user — access control is enforced at the database engine level, not just the application layer.
All database operations from our backend use a service role key with scoped permissions, stored exclusively as a server-side environment variable and never exposed to clients.
Salah Time enforces a session-based, single active device policy per account. Your subscription is validated server-side on each app launch. This prevents unauthorised account sharing while ensuring your data remains associated exclusively with your verified email identity.
All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor —
the highest level of payment security certification. We never process, store, or transmit raw credit or
debit card numbers. Salah Time's servers only receive and store Stripe-issued customer and subscription
identifiers (e.g. cus_xxx, sub_xxx).
Stripe webhooks — used to sync subscription lifecycle events — are verified server-side using HMAC-SHA256 signature validation before any action is taken, preventing webhook spoofing attacks.
Your account data (email and subscription status) is retained for as long as you hold an active subscription. Upon cancellation, your data is retained for a reasonable period for billing dispute resolution, after which it is purged. To request immediate deletion of your data, contact us at the email below.
Salah Time is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe your child has provided us with personal data, please contact us immediately and we will delete it.
You have the right to:
To exercise any of these rights, contact us at salahtimesupport@gmail.com.
We may update this Privacy Policy from time to time. Material changes will be communicated via the App or email. Continued use of the App after changes constitutes acceptance of the revised policy. The "Last updated" date at the top of this page reflects the most recent revision.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Salah Time Corp
Email: salahtimesupport@gmail.com