What we collect, what we don't

Your pilgrimage, your data.

We collect very little. The substance of your trip — your tawaaf circuit count, your dua bookmarks, your prepare-page checklist — lives on your device and never leaves it. We do count aggregate page visits on our own server, in a way designed so no individual person can be identified. No cookies. No third parties. Full details below.

Change notice, April 2026. As of this update we run first-party, aggregate analytics on our own server. No third-party service is involved, no cookies are set, and no individual visitor can be identified. This section explains exactly what changed and why. The older version of this policy said "no analytics"; this is the 30-day homepage-disclosure clause that the policy promised, honored.

The short version

What stays on your device: your tawaaf circuit count, your dua bookmarks, your prepare-page checklist. None of it is transmitted to us. Ever.

What we count on our server: an anonymous tally of which pages are visited, from which country, on what kind of device. No names, no accounts, no cookies, no third parties, no individual profile of you. The raw IP and user-agent that come in with any web request are parsed into an aggregate category (e.g. "Chrome on iOS from Saudi Arabia") and then discarded in the same request — they are never written to our database.

If you want the long version: keep reading. If you'd rather not, the short version is the whole truth.

What lives on your device, not ours

You can inspect any of this yourself in your browser's developer tools. None of it leaves your device.

What we count on our server (the aggregate analytics)

When you visit any page on tawaaf.com, our own server logs a single row containing:

What we deliberately do NOT collect:

We do NOT use: Google Analytics. Plausible. Fathom. Hotjar. Mixpanel. Amplitude. Heap. Segment. Meta pixel. TikTok pixel. Any A/B testing service. Any tag manager. Any third-party CDN that wasn't strictly necessary. Cookies of any kind.

Retention. Raw pageview rows are automatically purged after eighteen months. We may retain aggregate counts (e.g. "total visits per month") indefinitely for long-term trend understanding, but those aggregates contain no per-visitor data.

Why we do it. So we can see, at a weekly level, which pages are being read and which are being ignored, and improve the site accordingly. That's it. We don't run ads, we don't sell data, and we don't share data with anyone. If you want to see the exact code that runs on the server, it lives in api/track.php in the site repository.

Do-Not-Track & Global Privacy Control. If your browser sends either of these signals, we don't run the tracking beacon at all. It is a no-op in your browser. You can test this in your browser's devtools.

Third-party services we depend on

Three remote services see one piece of information about you when you use specific features:

We do not store the coordinates you share — they leave your browser, hit the third-party API, and the result is rendered on your screen. Nothing is logged on our end.

The contact form

When you submit the contact form, the message you write — together with the name and email you provide — is delivered by email to contact@tawaaf.com via our hosting provider's PHP mail. The form itself does not write your message to a database. We retain inbound email for as long as we'd retain any other piece of correspondence; you may ask us to delete your message at any time by writing back to the same address.

Cookies

We do not set any cookies on the public site. The aggregate analytics beacon described above is explicitly cookie-free. An HTTP-only session cookie is set only on /admin/ URLs, which are used by the site operators to view the aggregate dashboard — it is never set in your browser unless you are signing into the admin area.

Your browser may set its own cookies for fonts and other host-level concerns; those are out of our control and out of our visibility.

Server access logs

Separate from the aggregate analytics above, our hosting provider (HostGator) keeps standard web server access logs of every HTTP request. These contain your IP address, the URL you requested, the timestamp, your user-agent, and the referer, and are kept on the host's default schedule (typically a few weeks). We do not export, analyse, syndicate, or correlate these logs. They exist for diagnostic purposes only.

Children

The site is suitable for all ages. We do not knowingly collect personal information from anyone, of any age. If you are concerned about a child's interaction with the site, write to us.

Changes to this policy

If we materially change anything on this page — for example, if we ever add tracking beyond what is described above, or introduce a new third party — we will say so on the homepage for at least 30 days and date the change at the bottom of this policy. We will never quietly add tracking. The April 2026 update (adding first-party aggregate analytics) was announced on the homepage for 30 days under this same clause.

Your rights, briefly

Because we hold so little of your data — and because the data we do hold cannot be linked back to you as an individual — the rights jurisdictions like the EU's GDPR or California's CCPA grant you are largely already satisfied by default. If you want a confirmation that we hold nothing identifying about you, write to contact@tawaaf.com and we'll reply with what we can confirm. If you want any inbound email we have from you deleted, the same address.

Last updated: 24 April 2026 (added first-party aggregate analytics; see change notice above) · Previously updated April 2026 (launch) · Questions? contact@tawaaf.com