Privacy Policy
Last updated 9 September 2026
This explains what Naji Elqaq ("Nadi") does with personal data. It covers the platform itself. Each community is run by its own owner, and section 2 explains where the line between us falls.
1. In short
- We collect what we need to run accounts, communities, and payments — and not more.
- We do not sell personal data or run advertising trackers. Optional usage measurement runs only if you accept it.
- Card details never reach our servers; our payment provider handles them.
- You can export or delete your data from account settings, or by writing to privacy@nadi.online.
2. Who is responsible for what
For your account — your email, your profile, your billing relationship with us — we are the data controller.
For what happens inside a community, the community's owner is the controller and we act as their processor: they decide who is admitted, what is posted, and what they do with a member list. If you want your data removed from a particular community, ask its owner first; if they do not respond, write to us and we will act.
3. What we collect
- Account data — name, email, handle, password hash, profile photo, bio, and language preference.
- Content — posts, comments, courses and lessons you write, calendar events, direct messages, and anything you upload.
- Membership and activity — which communities you belong to, your role in each, points and level, lesson progress, and event responses.
- Payment data — what you were charged, when, by which community, and the last four digits and brand of the card. Full card numbers go straight to the payment provider and are never stored by us.
- Technical data — IP address, browser and device type, and timestamps, recorded in server logs and used for security, abuse prevention, and debugging.
- Optional signup context — if you accept analytics, we remember a broad arrival source, page type, device and browser category. When you create an account, this context may be attached to it so our team can understand signup friction. It is not shared with community owners. We do not put full URLs, gift tokens, raw browser identifiers or campaign text in this record.
- Licence check-ins — when software licensed by a community checks that your membership is still active, we count that check-in against a one-way hash of your network prefix, never the address itself, so that an owner can see when one key is being used from many places at once.
We do not ask for special-category data — health, religion, politics, sexuality. If you choose to write it in a post, you are making it visible to that community.
4. Why we use it, and on what basis
- To provide the service — creating your account, showing you your communities, taking payments. Basis: performance of our contract with you.
- To keep it safe — detecting fraud, spam, and abuse; enforcing our terms; keeping audit logs. Basis: our legitimate interest in a service that is not overrun.
- To support and improve it — answering your questions, fixing what is broken, understanding which features are used. Basis: legitimate interest.
- To meet legal obligations — tax and accounting records, and responding to lawful requests. Basis: legal obligation.
- Marketing email — only if you opt in, and every message has an unsubscribe link. Basis: consent.
- Optional measurement — signup context and broad page-usage counts help us improve the first visit. Basis: consent. Declining does not change your access to Nadi.
5. Who we share it with
We share personal data only with providers who process it on our instructions, under contract, and only for these purposes:
- Supabase — database, file storage, and authentication.
- PayPal — payments and payouts. PayPal is a controller in its own right for the payment data it collects.
- Our email provider — transactional email such as password resets and receipts.
- Our hosting and error-monitoring providers — running the site and telling us when it breaks.
- Vercel Web Analytics — with your consent, broad page categories and aggregate browser, device and country statistics. We do not send account identifiers, private page paths, gift links or query strings to this analytics service.
Beyond that we share data with a community's owner and moderators for the community you joined; with law enforcement or a court where we are legally required to and, where we are allowed, after telling you; and with a buyer if the business is ever sold, under the same commitments made here.
We do not sell personal data, and never have.
6. Cookies and local storage
Essential cookies keep Nadi working. Optional arrival cookies and usage measurement start only after you accept analytics. You can decline or change your choice on the cookie policy page. We do not use these records to follow you across other sites.
The cookie policy lists every one of them — what it is for, and how long it stays.
7. How long we keep it
- Account and content — while your account is open.
- Optional signup context — the browser arrival cookie lasts up to seven days; a Google signup-start proof lasts up to ten minutes. Context attached to your account remains until you remove it by declining analytics while signed in, ask us to remove it, or delete your account. Clearing a browser cookie alone does not remove a record already attached to your account. You can include this record in your account export.
- After you delete your account — removed or anonymised within 30 days, except where we must keep something longer.
- Payment and tax records — kept as long as tax law requires, typically six to seven years.
- Server and security logs — 90 days.
- Backups — overwritten on a rolling 30-day cycle, so deleted data can persist there briefly.
Posts and comments you made in a community may remain visible to that community after you leave, detached from your profile, so that conversations other people took part in do not fall apart. Ask us if you want them removed as well.
8. Your rights
Depending on where you live you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another service. You can also withdraw consent at any time where consent is what we relied on.
Most of this is self-service in account settings. For anything else, write to privacy@nadi.online — we answer within 30 days. We will never charge you for asking or treat you differently for having asked. If you are unhappy with our answer you can complain to your local data protection authority.
9. International transfers
Our providers operate in several countries, so your data may be processed outside the one you live in. Where it leaves the UK or the EEA we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision covering the destination.
10. Security
Traffic is encrypted in transit, passwords are hashed and never stored in a readable form, access to production data is limited to the people who need it, and rendered content is sanitised so one member cannot run code in another's browser. No system is perfect; if a breach affects you we will tell you and the relevant authority within the time the law sets.
11. Children
Nadi is not for people under 16. If we learn that we hold data on someone younger, we delete it. If you believe a child has an account here, write to privacy@nadi.online.
12. Changes
We will post any material change here and, where it affects you meaningfully, tell you by email before it takes effect. The date at the top always reflects the current version.
13. Contact
Naji Elqaq
[registered address]
privacy@nadi.online
See also our Terms of Service.