How the Muslim Student Council collects, uses and protects your information — on absoc.uk and in the ABSoc mobile app.
Last updated: 17 July 2026 · Applies to www.absoc.uk and the ABSoc mobile app ("the services"), operated by the Muslim Student Council ("MSC", "we").
Account details — when you create a member
account we collect your full name, email address, phone number,
university (or alumni status) and a password, which is stored
only in securely hashed form.
Profile content — anything you choose to add:
a display name, a short bio and a profile photo.
Activity — your event check-ins (passport
stamps), the ABSocs you follow, friend connections and requests,
blocks, and comments you post on events.
Technical data — IP addresses are processed
briefly for security rate-limiting (for example, limiting
sign-in and check-in attempts). We do not use analytics
trackers or advertising identifiers.
We use your information solely to run the member network: creating and verifying your account (a verification code is emailed to you at signup), showing your profile to other signed-in members, recording your event passport stamps, powering the shared events calendar, enabling friendships and follows, moderating comments, and keeping the services secure. We do not sell your data, and we do not use it for advertising.
Your profile (display name, photo, bio, university, badges, passport stamps, friends and followed ABSocs) is visible to signed-in members only — never to the public. Your phone number is visible only to you and to MSC administrators, never to other members. Your email address is never shown to other members. ABSoc and MSC administrators can view member details for the societies they are responsible for, in order to run the network.
The ABSoc app asks for camera access for one purpose: scanning the QR code shown at events so you can check in. The scanner reads codes only — it does not capture, store or upload photos or video.
We use a small number of service providers to operate the services: Supabase (database, authentication and file storage), Netlify (website hosting), Resend (delivery of verification emails) and Stripe (donation payments — card details are entered on Stripe's own secure pages and never touch our servers). These providers process data on our behalf and are not permitted to use it for their own purposes.
We keep your account data for as long as your account exists. You can edit your profile at any time in the app or on the website. To delete your account and its data, contact us via the contact page from your registered email address and we will remove it.
Under UK data protection law (UK GDPR) you have the right to access the personal data we hold about you, to correct it, to have it deleted, and to object to or restrict its processing. To exercise any of these rights, reach us through the contact page. If you are unhappy with how we handle your data you may also complain to the Information Commissioner's Office (ico.org.uk).
If this policy changes we will update this page and the date at the top. Significant changes will be announced to members.