Version 1.3: encrypted support tickets and private reader accounts
Information collected
Participation forms collect the details shown on each form, including your name, email address, country, languages, interests, project preference and recorded consent time. The free reader form collects your name, email address, requested volume, signup source, access activity and referral relationship. Reader passwords are stored only as secure one way hashes. Verification and password reset links are stored as temporary one way token hashes. If you use Google sign in, QuranOfficial stores Google's stable account identifier and verified email result, but never your Google password or Google access token. Support tickets collect your name, email address, category, subject, messages, progress and optional satisfaction feedback.
Why it is collected
Information is used to provide requested reader access, respond to enquiries, match participants with relevant project work, maintain accountable contact records and send communications covered by the consent shown at signup. Personal records are not displayed publicly.
Free reader emails and sponsorship invitations
When you unlock the complete Volume 1, the form asks you to agree to receive the volume and occasional QuranOfficial project updates and sponsorship invitations. Your consent time and campaign source are stored with your private reader record. You can pause future emails from your reader panel at any time without losing access to your unlocked volumes.
Reader referral codes record how many unique people registered through a personal invitation link. A referral counts towards the Volume 2 reward only after the invited reader verifies their email. Referral relationships never expose either reader's identity publicly.
Sign in security records
After a successful reader sign in, QuranOfficial records the method, date, encrypted IP address, encrypted browser user agent and a short device classification for account security and abuse prevention. A separate keyed value permits repeated IP activity to be grouped without exposing the address. Approximate country information is collected only from an explicitly trusted hosting proxy when enabled. No external geolocation service is called.
Login activity is normally retained for 90 days, or the shorter period configured for the service. Only specifically authorised administrators can decrypt it. Each administrator view is recorded in the private audit log. Login IP addresses and browser details are never placed in ordinary notification emails or reader CSV exports. Google access tokens are not stored. You can disconnect Google after setting a local password; permanent account removal deletes the linked Google identity and retained login telemetry.
Support tickets
Support names, email addresses, subjects, messages and optional feedback comments are encrypted in the database. New tickets require a signed in QuranOfficial account and are linked automatically to that account's private Support Inbox. Account ownership is checked on every ticket view and reply. Guest tickets created before account only support continue to use expiring, revocable access tokens whose one way hashes are stored. An invalid reference, another account's ticket or an invalid legacy guest token returns the same not found response.
Administrators may add internal notes for operational work. These notes are excluded from customer database queries and are never included in requester emails. Notification emails contain only the reference, current state and a secure access link. Audit records store actions and limited operational metadata without names, email addresses, subjects, messages or comments.
Retention and security
Form and support records are retained for up to 24 months unless an ongoing relationship, active reader access or legal obligation requires longer retention. Access is restricted to authorised administrators. The site uses encrypted transport in production, application encryption for support content, private database storage, anti spam controls and audit logging.
Sharing and service providers
QuranOfficial does not sell personal information. Limited data may be processed by contracted hosting, email or security providers only where required to operate the service. External fundraising platforms have their own privacy terms.
Cookies
The site uses a strictly necessary session cookie for security, form protection, Google sign in callbacks, returning reader access and administrator access. Reader sessions may remain available for up to 30 days, subject to security checks. Theme preference is stored in your browser. Advertising cookies are not required for Phase 1.
Your rights
You may request access, correction or deletion of your personal information, withdraw consent for future contact, or object to processing where applicable. Identity may need to be verified before a private record is disclosed or changed.
Privacy contact
Use the contact form with the subject “Privacy request”. The responsible project name is QuranOfficial.