Legal

Privacy Policy

Last updated: August 19, 2026

1.Who We Are

This Privacy Policy explains how Cyber Shillings Data Services Inc.(corporation number 1089626-8), operating as Minaret Network (“we,” “us”), collects, uses, discloses, and protects personal information through the Minaret Network platform at minaretnetwork.ca, serving the Greater Toronto Area and surrounding communities.

Minaret Network is a community professional directory. Members search for and contact professionals; professionals list their services. We do not independently verify professional credentials, licences, qualifications, or mosque affiliation. Mosque affiliation is self-reported by the professional — see Section 4.

2.Information We Collect

2.1 At registration

First name, last name, display name, email address, avatar (optional), phone number (optional), WhatsApp number (optional), preferred contact method (email/phone/WhatsApp), mosque affiliation (optional for members, required for professionals), Google account ID/name/email if signing in with Google OAuth, age-attestation timestamp and version, Terms of Service acceptance timestamp and version.

2.2 Professional listings

Business name, professional title, bio, primary and optional secondary categories, service areas (selected from a defined list of GTA-area cities), languages spoken, years of experience, qualifications and licences (self-reported), uploaded credential files (not independently reviewed by us — see Section 4), gender (optional), business address (optional), contact details the professional chooses to display (phone, email, website, WhatsApp), profile photo, logo, gallery images, and whether walk-ins are accepted.

2.3 Service requests

Description of the request, category, selected service area, contact name, email, phone number, preferred contact method, preferred date, and a broadcast-consent timestamp and version (see Section 9A).

2.4 Messages

Content of messages exchanged between a member and a professional through the Platform’s messaging feature, timestamps, and read status.

2.5 Event listings

Event title, description, date/time, location, organizer information, price paid (if any), event image, and whether the event is declared as mosque-organized.

2.5A Community Offers

When an approved professional posts a Community Offer, we collect the offer title, description, optional image, start date, and end date. The professional’s phone number and/or WhatsApp number — already on file from their professional profile — are displayed on the offer card so members can contact them directly. No separate contact information is collected for Community Offers.

We also derive and store the offer’s GTA region from the professional’s service areas, so offers are shown only to members whose selected region matches. A compliance-acknowledgment timestamp and version is logged at the time of submission, confirming the professional accepted the Community Offers terms.

2.6 Recommendations and reports

Recommendation content, moderation status and history, reports submitted about a listing or recommendation, and related admin notes.

2.7 Automatically collected / technical information

  • Essential cookies — required for authentication sessions and saved preferences; cannot be declined.
  • mn_region cookie — stores only the name of the GTA region you select when searching (e.g., “York South”), used to show geographically relevant Featured Businesses on the homepage. No personal information. 30-day lifespan.
  • Analytics cookies (optional, consent-gated) — Google Analytics and Contentsquare, described in Section 8. These do not load unless you choose “Accept all” in the cookie banner.
  • Standard server/proxy logs (including IP address) via our CDN provider, Cloudflare.

2.8 Analytics per professional listing

Profile views, search appearances, and contact clicks (phone/website/WhatsApp), and — for Featured placements — impressions and card/website/phone/WhatsApp clicks. This is aggregated performance data shown to the professional about their own listing; we do not sell or share this data with third parties.

2.9 Consent audit trail

We keep a record of consent events (age attestation, Terms acceptance, broadcast consent, cookie choice) including the version consented to, the timestamp, and the IP address at the time of consent, for accountability and compliance purposes.

3.Why We Collect and Use Information

  • To create and administer accounts, including authenticating you via email/password or Google OAuth.
  • To operate the professional directory — publish and display professional listings (including self-reported mosque affiliation and credentials), route them through admin review before they go live, and let members search and browse them.
  • To connect members and professionals — process service requests, display them to eligible professionals in their leads dashboard (see Section 9A), and enable in-Platform messaging.
  • To display Recommendations and badges submitted or awarded through the Platform, subject to moderation.
  • To assist category-matching for service requests using AI — see Section 6.
  • To show relevant Featured Businesses by region, using the mn_region cookie.
  • To operate Community Offers — display admin-approved promotional offers to members in the professional’s region, using the professional’s contact details already on file.
  • To operate paid placements (Featured Business, Sponsored Listing, Event Listings) and process the associated payments through Stripe.
  • To maintain Platform security and integrity — detect fraud, impersonation, abuse of messaging, and violations of our Terms of Service.
  • To communicate with you about your account, service requests, messages, and Platform updates. We do not currently send direct marketing communications.
  • To analyze and improve the Platform, using Google Analytics and Contentsquare where you have consented (Section 8).
  • To comply with legal obligations and enforce our Terms of Service.

4.Mosque Affiliation — Self-Reported, Not Verified

Mosque affiliation displayed on a professional’s listing, and the “Mosque Affiliated” badge, reflect what the professional themselves has stated. Minaret Network does not have a formal relationship with any mosque, does not maintain a verified or approved list of mosques, and does not confirm a professional’s stated affiliation with the mosque in question. A professional’s affiliation claim is not endorsed, confirmed, or vouched for by the named mosque, and appearing with a mosque’s name on a listing does not mean that mosque has any relationship with Minaret Network or has reviewed the professional in any way.

We treat mosque affiliation as sensitive personal information. In practice this means: we ask for explicit, separate consent before a professional’s mosque affiliation is published (distinct from general account consent), and we do not infer or publish a member’s own religious affiliation from their activity on the Platform.

⚠ Note: Do not describe mosque affiliation anywhere on the Platform as “confirmed,” “community-attested,” “verified,” or as being with a “participating” mosque — these terms imply a level of confirmation or formal mosque relationship that does not exist. Use “self-reported” consistently in all user-facing copy.

5.The “Highly Recommended” Badge

Some professionals display a “Highly Recommended” badge, awarded by Minaret Network administrators based on the volume and quality of Recommendations a professional has received on the Platform. Unlike Sponsored or Featured placement, this badge is not purchased — it reflects our own internal assessment of community feedback patterns, using criteria we may change over time.

It is not a guarantee of a professional’s licensing, insurance, quality of work, or any outcome, and it is not independent verification of anything the professional has told us. A clear disclaimer appears directly wherever the badge is displayed.

6.AI-Assisted Category Matching

When you submit a service request, we use an AI system (OpenAI) to help match your request description to the right professional category. The AI receives your request description, an approximate location text, and the list of available categories. It does not receive your email or phone number. If the AI service is unavailable, local matching rules are used instead.

If a broader AI assistant feature is added in the future, this section will be updated and users will be provided with appropriate guidance before that feature goes live.

7.Location

Minaret Network does not collect precise device GPS coordinates. Location-based features work by manually selecting a service area (a city within a defined list covering the GTA and surrounding areas) — there is no location permission prompt and no precise-coordinate data collected or stored.

8.Cookies, Analytics, and Third-Party Services

Cookie consent.On your first visit, a banner offers two choices: “Essential only” or “Accept all.” Your choice is stored in your browser (localStorage). Google Analytics and Contentsquare do not load unless you choose “Accept all.” You can withdraw consent at any time by clearing your site data in your browser, which resets the banner.

Third parties who process information on our behalf:

ServicePurposeWhat’s sent
Supabase (self-hosted in Canada)Confirm hosting location remains Canada if infrastructure changes.Authentication, database, file storageAll application data
StripePayment processing for Event Listings and paid placementsPayment details (never stored by us directly), email, name
OpenAIAI-assisted category matching for service requestsRequest description, approximate location text, category list — not email or phone
Google (OAuth)Optional sign-inGoogle account ID, email, name
Google Analytics (opt-in)Usage analyticsAnonymized page views and interactions
Contentsquare (opt-in)Confirm specific data-hosting region before publication.Heatmaps, session replay, feedback toolsAnonymized interaction data
CloudflareCDN and DDoS protectionIP addresses (standard proxy/security logging)

Cross-border processing. Stripe, OpenAI, Google, Google Analytics, and Contentsquare all involve processing outside Canada to varying degrees (primarily the United States). Supabase is currently self-hosted in Canada — this is our lowest cross-border exposure vendor; we will update this Policy if the infrastructure location changes.

9.Recommendations, Reports, and Messages

Recommendations submitted by members go through admin moderation before publication — they are not visible until reviewed and approved. Admins may reject or later remove a Recommendation that violates our Community Standards. Anyone can report a published Recommendation or an event listing for review.

Messages sent through the in-Platform messaging system are visible to their intended recipient. We do not routinely read message content, but may access it to investigate suspected abuse, fraud, or violations of our Terms, or to respond to a valid legal request.

9A.Service Requests and the Leads Dashboard

When you submit a service request, we ask for your explicit, separate consent (distinct from general account consent) confirming that your request details will be shared with multiple eligible professionals. Eligible professionals — those with an approved listing, broadcast-eligible status, and a matching category and service area — see your request in their leads dashboard within the Platform.

Your email and phone number are not shown in the leads dashboard. Professionals see your request description and contact name only. Your full contact details are shared only once you initiate direct contact with a specific professional or choose to include them in a message.

Regulated professions (doctors, dentists, lawyers, and similar categories) are excluded from this feature — service requests cannot be submitted for these categories and members must contact these professionals directly through their listing. No third-party messaging platform (e.g., WhatsApp) is involved in distributing service requests; this is a fully in-Platform feature.

9B.Contact Information on Community Offers

When a Community Offer is active, the professional’s phone number and WhatsApp number — as stored in their professional profile — are displayed on the offer card and on the public Community Offers page. This lets members contact the business directly about the offer. No email address is displayed.

We do not broadcast this contact information through any third-party platform. The professional controls their phone and WhatsApp numbers through their profile settings; updating or removing those numbers from the profile removes them from any active offer card as well.

10.Data Retention

CategoryApproach
Account informationRetained while active; period after account deletion to be confirmed.
Professional listingsRetained while active/approved; period after withdrawal or rejection to be confirmed.
Service requests and messagesRetention period to be confirmed — retained as needed to support dispute resolution.
RecommendationsRetained as part of the public record unless removed through moderation.
Consent audit trail (including IP)Recommended: life of the account plus a defined window afterward, as evidentiary record of consent. Period to be confirmed.
Analytics dataPer Google Analytics / Contentsquare's own retention settings — confirm with vendors.
Payment records (Stripe)As required by Canadian tax law — generally at least 6 years.
Community Offer content (title, description, image, dates)2 years after the offer expires or is cancelled, for audit and dispute-resolution purposes, then deleted.
⚠ Note: Specific retention periods are not yet finalized. The items marked “to be confirmed” above must be set before this Policy is considered complete. Indefinite retention without a stated period is not compliant with PIPEDA.

11.Your Rights

You may request access to, correction of, or deletion of your personal information, and may withdraw consent, subject to legal limits. To exercise these rights, contact our Privacy Officer (Section 13). Some account and listing data can also be updated or removed directly through your dashboard.

12.Complaints

If you have a privacy concern, please contact our Privacy Officer first (Section 13). If the concern is not resolved to your satisfaction, you may have the right to complain to the Office of the Privacy Commissioner of Canada. Ontario does not currently have its own general private-sector privacy regulator.

13.Contact

Legal entity: Cyber Shillings Data Services Inc. (corp. #1089626-8), operating as Minaret Network
Privacy Officer: Syed Nafeez Ul Haq
Email: salam@minaretnetwork.ca
Mailing address: 330 Highway 7 East, Richmond Hill, Ontario, L4B 3P8