Privacy policy
What the Jamiat Finance System collects, why, who can see it, and how long it is kept.
In effect from 3 September 2026
Who this applies to
This policy covers the JFS mobile app and this website, jfs.jamiat.org.pk. The records in JFS belong to Islami Jamiat Talaba Pakistan, which decides who may see them and how long they are kept. The app is published and operated on the organisation’s behalf by Idara Matbuat-e-Talaba (Private) Limited.
Two kinds of people appear in it. Members are the office bearers who hold an account and enter records. Donors do not have accounts; their details are entered by a member so that a receipt can be issued to them.
Accounts are issued, not opened
There is no sign-up. An account exists only because a Nazim sent an invitation to a specific email address, naming the unit and the role. Accepting that invitation is what creates the account. Nobody can register themselves, and this website cannot create, change or read any account.
What the app collects
Your account
Your name, the email address the invitation was sent to, your password, an optional phone number, and the role you hold in each unit. Your password is stored only as a hash — it is never kept, logged or transmitted in a form anyone can read, and no one at JFS can tell you what it is.
You may also add a profile picture. That is the only optional personal item the app asks for, and removing it removes it.
Your device
Every request the app makes carries a device identifier, the device’s name, the platform it runs, its operating system version and the app version. This is not analytics. An account is deliberately bound to one device at a time, so that a stolen password is not enough to sign in from somewhere else; those values are how the server recognises the device you registered and refuses the rest.
The identifier comes from the operating system’s own per-app value — the Android ID, or iOS’s identifier for vendor. It is not an advertising identifier, it is not shared with anyone, and it changes if you uninstall and reinstall.
The records members enter
This is the substance of the app, and it is entered deliberately by a person, not collected in the background:
- Receipts — the donor, the amount, the date, how it was paid, whether it is general or special, whether it is Zakat, and an optional photograph.
- Expenses and events — a title and description, a category, an amount, a date, who was paid, and photographs of the bills.
- Donors — name and location, and where a member records them, a profession, phone number, email address, postal address, pledged amount, payment schedule and notes.
- The unit’s finances — opening balances, budgets, assets, liabilities, bank account details and period closures.
A donor’s email address is used for one thing: sending that donor their receipt and, if the member who recorded them deliberately turned it on, a payment reminder. It defaults to off.
What is recorded about actions
Who created, edited, submitted, reviewed, approved, rejected or reversed each record, and when. This trail is the point of the product rather than a side effect of it, and it is described under How long it is kept.
Camera and photo library
The app asks for the camera and the photo library for exactly two reasons: to attach a photograph of a bill to an expense or an event item, and to set a profile picture. It asks at the moment you tap to attach something, never at startup, and declining leaves every other part of the app working.
The app has no access to your photo library beyond the images you choose. Before an image is uploaded it is resized and re-encoded as a JPEG, which does not carry the original file’s embedded metadata — including any location the camera recorded — forward with it.
Face ID and fingerprint
If you turn on biometric unlock, the check is performed entirely by your phone. iOS and Android answer the app with yes or no; they never hand over a face or a fingerprint, and the app has no way to ask for one.
What the app stores is a random secret it generated on your device, kept in the iOS Keychain or the Android Keystore and marked so that reading it requires a successful biometric check. The matching value on the server is what proves the unlock happened. No biometric data of any kind leaves your device, is transmitted to us, or is stored by us.
Turning biometric unlock off, or signing out, deletes that secret from the device.
What the app does not do
- No advertising, no advertising identifier, and no advertising network.
- No analytics or crash-reporting service. There is no Firebase, Sentry, Amplitude, Segment, Mixpanel or comparable SDK in the app. The charts inside JFS are computed by the organisation’s own server from the organisation’s own records.
- No tracking across other apps or websites, and no data broker.
- No location. The app never requests location permission.
- No contacts, calendar or microphone. The app has no code that records audio. An unused microphone permission is currently declared in the Android build, is not used by anything, and is being removed.
- No push notifications. Notifications are shown inside the app while you are using it; no push token is created and nothing is sent to your device when it is closed.
- No cookies, tags or analytics on this website. It sets nothing, follows nobody, and loads no fonts, scripts or images from anyone else’s server.
Where the information is kept
The records live in the organisation’s own database and are reachable only through its own API. Four outside services are involved in running it, and none of them is sent anything beyond what the task needs:
- Railway
- Hosts the server and the database.
- Cloudflare R2
- Stores the photographs — bills and profile pictures. Uploads and downloads go directly between your device and R2 using a short-lived, single-purpose link the server issues.
- The organisation’s email provider
- Delivers invitations, receipts, reminders and one-time password-reset codes. It sees the recipient’s address and the contents of that email.
- Expo
- Distributes app updates. When the app starts it asks Expo whether a newer version of its code exists, which tells Expo the platform, the app version and the release channel.
Who can see what
Nobody in JFS can see everything. Every record belongs to exactly one pocket — one unit’s ledger — and what you can see is decided by the role you hold in that pocket and where the pocket sits in the organisation. The server decides it, on every request; hiding a button in the app is a convenience, never the boundary.
- A Nazim or Mutamid sees their own pocket and the pockets beneath it. Nothing above, and nothing sideways.
- An auditor sees only the pockets they have been assigned to, and cannot hold an operating role in a pocket they audit.
- An Assistant Incharge Finance cannot see balances at all; the server refuses the request rather than the screen hiding the number.
- The Nazim-e-Aala can read across the organisation, but writing outside the central pocket is limited to two actions and requires re-entering a password each time.
- Donor names are never published. The public receipt check, which anyone can use with a serial number, returns the amount, the date and the unit — and no donor.
How long it is kept
Financial records are kept for as long as the organisation’s audit requires, and some of them are deliberately permanent:
- Receipts are immutable. Once issued, a receipt cannot be edited or deleted by anyone, at any level, including us.
- The audit trail only grows. Entries are never edited or removed; the interface for doing so was deliberately taken out of the system.
- A closed period is a locked snapshot and stays one.
- Accounts are deactivated, not erased. A deactivated account cannot sign in, and the records that person entered stay attributed to them, because an audit trail that quietly loses its authors is not an audit trail.
- Donors are deactivated rather than deleted, for the same reason: their receipts must remain verifiable.
On your own phone, less is kept. Your sign-in tokens are cleared every time the app starts fresh, so each new launch re-authenticates. Signing out removes the JFS data saved on the device and turns off biometric unlock. Unsent offline entries and notification history are held for thirty days.
Sharing
Nothing in JFS is sold. Nothing is shared with advertisers, ad networks, data brokers or analytics companies. Nothing is used to build a profile of you, and nothing is used to train anything.
Information is shared only with the four service providers listed above, only to the extent needed to run the service, and where the organisation is required to disclose something by law.
Your requests, and closing an account
Write to it@jamiat.org.pk from the address your account uses, or to the postal address below, and say what you want. You can ask for a copy of the personal information held about you, ask for something inaccurate to be corrected, or ask for your account to be closed.
Being straightforward about closure: there is no self-service delete button in the app. When you ask, the organisation deactivates the account so it can no longer sign in, and removes the personal details that are not part of a financial record — your phone number and your profile picture among them. The financial records you entered, and your name against the actions you took, remain, because the organisation’s audit depends on them and receipts issued to donors have to stay verifiable. If that distinction matters to you, ask before you decide.
A donor who wants their contact details removed from a unit’s records should write to the same address; the receipts issued to them remain, and their contact details do not have to.
Children
JFS is a tool for appointed office bearers of the organisation. It is not designed for, marketed to, or intended to be used by children, and accounts are only ever created by invitation from a Nazim.
Changes to this policy
When this policy changes, the date at the top changes with it. A change that alters what is collected or who can see it will be announced in the app as well, rather than left for you to notice.
Contact
it@jamiat.org.pk
Idara Matbuat-e-Talaba (Private) Limited
1-A Zaildar Road, Ichra, Lahore, Pakistan
For questions about how to use the app rather than about your information, the support page is quicker. The terms of use cover the rest of the arrangement.