How the Muslim Student Council collects, uses and protects your information — on absoc.uk and in the ABSoc mobile app.
Last updated: 9 September 2026 · Applies to www.absoc.uk and the ABSoc mobile app ("the services"), operated by the Muslim Student Council ("MSC", "we").
Account details — when you create a member
account we collect your full name, email address, phone number,
university (or alumni status) and a password, which is stored
only in securely hashed form.
Profile content — anything you choose to add:
a display name, a short bio and a profile photo.
Activity — your event check-ins (passport
stamps), the ABSocs you follow, friend connections and requests,
blocks, and comments you post on events.
Notifications — if you allow push
notifications, your device registers a notification token so we
can send them. It identifies the handset, not you, and it is
deleted when you sign out or turn notifications off.
Feedback — if you send a bug report or
suggestion from the app, we store your message along with your
display name, the app version and your device type, so we can
understand and reply to it.
Membership status — whether your account has
been verified by an admin, and any committee role you hold.
Technical data — IP addresses are processed
briefly for security rate-limiting (for example, limiting
sign-in, sign-up and check-in attempts). We also count failed
sign-in attempts against an account so it can be locked
temporarily after repeated wrong passwords. We do not use
analytics trackers or advertising identifiers.
We use your information solely to run the member network: creating and verifying your account (a verification code is emailed to you at signup), showing your profile to other signed-in members, recording your event passport stamps, powering the shared events calendar, enabling friendships and follows, moderating comments, sending you notifications about events and announcements from the societies you follow, and keeping the services secure. Accounts are verified by a person before being given access to the member directory, which is how the network stays students of the ABSocs. We do not sell your data, and we do not use it for advertising.
Your profile (display name, photo, bio, university, badges, passport stamps, friends and followed ABSocs) is visible to signed-in members only — never to the public. Your phone number is visible only to you and to MSC administrators, never to other members. Your email address is never shown to other members. ABSoc and MSC administrators can view member details for the societies they are responsible for, in order to run the network.
The ABSoc app asks for camera access for one purpose: scanning the QR code shown at events so you can check in. The scanner reads codes only — it does not capture, store or upload photos or video.
We use a small number of service providers to operate the services: Supabase (database, authentication and file storage), Netlify (website hosting), Resend (delivery of verification emails) and Stripe (donation payments — card details are entered on Stripe's own secure pages and never touch our servers). These providers process data on our behalf and are not permitted to use it for their own purposes.
We keep your account data for as long as your account exists.
You can edit your profile at any time in the app or on the
website.
To delete your account, open the ABSoc app, tap
the settings icon on your profile and choose
Delete my account. You can also email
secretary@themsc.co.uk
from your registered address and ask us to close it, if you would
rather we did it for you.
Either way you are signed out straight away and your account is
held for 7 days before it is destroyed, so that
a deletion made by mistake can still be undone — signing in again
during those 7 days cancels it and restores everything. After
that we delete your profile, your photo, your comments, your
passport stamps, your notification tokens and your login.
Two things outlive the account, neither of which identifies you:
attendance records are kept without your name, so head counts for
events that have already happened stay accurate; and security
rate-limiting counters expire on their own within 24 hours.
Anything we are required to retain by law is kept no longer than
necessary.
Under UK data protection law (UK GDPR) you have the right to access the personal data we hold about you, to correct it, to have it deleted, and to object to or restrict its processing. Deleting your account is something you can do yourself, in the app, at any time — see section 6. To exercise any of the other rights, email secretary@themsc.co.uk from your registered address, or reach us through the contact page. If you are unhappy with how we handle your data you may also complain to the Information Commissioner's Office (ico.org.uk).
When you buy something from the MSC Shop we collect what is
needed to fulfil the order: your name, email address and phone
number, a delivery address if anything is being posted, the
optional message you leave for us, and whether you ticked the
box to hear about MSC events and products. We use this to
deliver your order, to contact you about it, and to keep the
financial records we are required to keep. We never send
marketing unless you opted in, and you can opt out at any time by
emailing
secretary@themsc.co.uk.
Payments are taken by Stripe. Your card details
go directly to Stripe over their secure checkout and never touch
our servers; we receive only confirmation that you paid and the
contact and delivery details above. Stripe processes your payment
data under its own
privacy policy.
Order records are kept for
six years after the order — the period HMRC expects
financial records to be kept — then deleted.
You can ask us to remove your personal details from an order
sooner by emailing the address above; the transaction itself
(reference, items, amount) is retained as a financial record
without your name attached.
If this policy changes we will update this page and the date at the top. Significant changes will be announced to members.