BADAL

Privacy Policy

Last updated: 26 August 2026

Badal Umrah respects your privacy and the privacy of the person you name in a booking. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it — under the European General Data Protection Regulation and under United States state privacy law.

Who we are and how to contact us

Badal Umrah is an online-only service operated from Stockholm, Sweden. We arrange for an Umrah — or, where booked, a Hajj Badal — to be performed in Makkah on behalf of a person you name, and we deliver the proof of completion to you digitally. We are the data controller for the personal data described in this policy, which means we decide why and how it is processed.

We have not appointed a Data Protection Officer because we are not required to do so. Privacy questions are handled directly by the people who run the service, and you can reach them by email or post at the details below.

info@badalumrah.org
FARSTA, Stockholm, Sverige

What this policy covers

This policy covers the personal data we process through our website, our booking and checkout flow, customer accounts, our email and messaging correspondence, our partner-application form, and the delivery of photographs, videos and completion certificates. It applies wherever you live. If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, the sections referring to the GDPR apply to you. If you are in the United States, please also read the dedicated section on United States privacy rights below.

Personal data we collect

We collect only what we need in order to accept your booking, perform the service, prove that it was performed and meet our legal obligations. Depending on how you use the site, this may include:

  • Customer contact details — your name, your email address and, if you choose to give it, your telephone or WhatsApp number, together with the messages you send us.
  • Beneficiary details — the name of the person on whose behalf the Umrah or Hajj is performed, their status (for example deceased, elderly or seriously ill), your relationship to them, any du'a text or special wishes you write, an optional photograph, and any date you ask us to observe.
  • Account information — your email address and a password stored only as a salted cryptographic hash, never in readable form, together with the bookings linked to your account.
  • Order and payment information — the package and extras you select, your display currency, the amount charged, the booking reference and the payment status. Card numbers, expiry dates and security codes are entered directly into Stripe and never reach our servers.
  • Delivered media — the photographs, video clips and completion certificate produced for your booking, together with the private delivery link that lets you view and download them.
  • Partner application data — if you apply to perform on our behalf, the identity, residence and qualification documents you upload, together with the information in your application form.
  • Essential cookies and technical data — a session cookie while you are logged in, your language preference, your display-currency preference, and standard server logs (IP address, browser type, time of request) kept for security and troubleshooting.
  • Correspondence and support history — the emails, contact-form messages and chat messages you exchange with us, so that we can follow up properly on your request.

Data about other people, including deceased persons

A Badal booking is, by its nature, about somebody other than you. When you give us a beneficiary's name, status, relationship, photograph or du'a, you are giving us personal data about a third party. You confirm that you are entitled to share that information with us for this purpose and that, where the beneficiary is living and able to understand, they are aware of the booking and agree to it.

Under the GDPR, information about a person who has died is not that person's personal data. We nevertheless treat it with the same confidentiality and the same security measures, out of respect for the family and because it is normally linked to you as a living person. Information that a named living beneficiary is ill or infirm can amount to health data. Where that is the case we rely on your explicit consent, given when you submit the booking, and we use it only to arrange and perform the service you asked for.

Please do not send us more information about a beneficiary than the booking form asks for. In particular, do not send us medical records, official identity documents or financial documents relating to the beneficiary — we do not need them and will delete anything of that kind that reaches us.

Legal bases for processing (GDPR Article 6)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract, Article 6(1)(b) — to accept and confirm your booking, take payment, arrange and perform the Umrah or Hajj, deliver your photographs, videos and certificate, and handle cancellations and refunds.
  • Compliance with a legal obligation, Article 6(1)(c) — to keep accounting records under the Swedish Bookkeeping Act (bokföringslagen) and to meet tax, consumer-law and anti-fraud requirements.
  • Legitimate interests, Article 6(1)(f) — to keep the website and accounts secure, prevent fraud and abuse, answer support enquiries, assess partner applications, and retain a record of what we delivered in case of a dispute or chargeback. We weigh these interests against your rights and proceed only where yours do not override them.
  • Consent, Article 6(1)(a) — and Article 9(2)(a) for information relating to health — for an optional beneficiary photograph, for information that a living beneficiary is ill, for any public use of media connected to your booking, and for our newsletter. You may withdraw consent at any time; that does not affect processing carried out before you withdrew it.
  • We do not rely on the vital-interests or public-task bases, and we do not carry out automated decision-making or profiling that produces legal or similarly significant effects for you.

How we use your personal data

We use your personal data for these purposes and no others:

  • Accepting, confirming and administering your booking, including confirmations and status updates.
  • Taking payment and issuing receipts, refunds and, where applicable, invoices.
  • Instructing the performer in Makkah so that the act is carried out for the correct beneficiary, with the correct intention and with your du'a.
  • Producing and delivering your photographs, videos and completion certificate.
  • Answering your questions and handling complaints, cancellations and refunds.
  • Keeping our books, meeting our legal obligations, and protecting the service against fraud and misuse.

We do not use your personal data for behavioural advertising, we do not build marketing profiles about you, and we do not sell or rent your data to anyone.

Payments

Payments are processed by Stripe. When you pay, your card or wallet details are collected in a Stripe-hosted field or checkout page and transmitted directly to Stripe. We never see, store or process your full card number, expiry date or security code. Stripe is certified to PCI-DSS Level 1, the highest level of payment-card security certification.

Stripe returns to us only what we need to run the booking: whether the payment succeeded, the amount and currency, the brand and last four digits of the card, and a payment reference. Stripe also processes some of your data as an independent controller for its own fraud-prevention and regulatory purposes, under its own privacy policy, which we encourage you to read.

Photographs, videos and certificates

The media we produce for your booking is stored on our hosting infrastructure and made available to you through a private delivery link containing a long, unguessable token. Anyone who holds that link can view the files, so please share it only with people you want to see it.

We never publish media connected to an identifiable booking — for example in our website gallery or on social media — unless you have given us separate, specific consent for that particular use. You may withdraw that consent at any time, and we will remove the material from our own channels as soon as reasonably possible.

Partner applications

If you apply to join us as a performer, we process your application form and the documents you upload in order to verify your identity, your residence status in Saudi Arabia and your religious qualification to perform Badal. Access to these documents is restricted to the people who assess applications. We keep unsuccessful applications for up to twelve months so that we can reconsider you if circumstances change, and then delete them. You may ask us to delete your application sooner at any time.

Cookies and similar technologies

We use only cookies that are strictly necessary for the website to work. We do not use advertising, retargeting or cross-site tracking cookies, and we do not embed third-party analytics that profile you across websites.

  • A session cookie, set only when you log in, that keeps you signed in to your account.
  • A language preference cookie, so that the site opens in the language you chose.
  • A display-currency preference cookie, so that prices appear in the currency you chose.

Because these cookies are strictly necessary to provide a service you requested, they do not require consent under the EU ePrivacy rules, and we therefore do not show a cookie banner. You can still block or delete cookies in your browser settings, but the site may then be unable to keep you logged in or remember your language and currency.

Who we share your data with

We share personal data only with the providers we need in order to run the service. Each of them acts as our processor under a written data processing agreement, may use the data only on our documented instructions, and may not use it for its own purposes:

  • Stripe — payment processing, fraud prevention, refunds and chargeback handling.
  • Our email and SMTP provider — sending booking confirmations, status updates and delivery links.
  • Our hosting and storage provider — running the website, the database and the media files.
  • Our performers and coordinators in Makkah — they receive the beneficiary's name, status, your relationship to them and your du'a or special wishes, and nothing more, so that the act can be performed correctly for the right person.
  • Our professional advisers — accountants and, where ever necessary, lawyers, all under a duty of confidentiality.

We may also disclose data where we are required to by law, by a court or by a competent authority, or where disclosure is necessary to establish, exercise or defend a legal claim. If our business is ever transferred to another owner, personal data may transfer with it; we would tell you before that happened and the new owner would be bound by this policy.

We do not sell personal data, we do not rent it, and we do not share it for cross-context behavioural advertising.

International transfers outside the EEA

We are based in Sweden and keep our core records within the European Economic Area. Two transfers outside the EEA are inherent to this service. First, the beneficiary information needed to perform the act is transferred to our performers and coordinators in the Kingdom of Saudi Arabia, a country the European Commission has not recognised as providing an adequate level of data protection. Second, some of our providers, including Stripe, may process data in the United States.

For these transfers we rely on the European Commission's Standard Contractual Clauses, supplemented where appropriate by additional technical and organisational measures such as strict data minimisation, encryption in transit, access controls and confidentiality undertakings. Where a transfer to Saudi Arabia is strictly necessary in order to perform the contract you asked us to carry out, we may additionally rely on Article 49(1)(b) of the GDPR. You may ask us for a copy of the safeguards we use by writing to the address at the end of this policy.

How long we keep your data

We keep personal data only for as long as we need it, and then delete it or irreversibly anonymise it:

  • Booking and payment records — seven years from the end of the financial year in which the booking was made, as required by Swedish bookkeeping law.
  • Beneficiary details and du'a text — kept with the booking while the service is being arranged and delivered, then reduced to what the accounting record requires.
  • Delivered photographs, videos and certificates — kept and accessible through your delivery link for twenty-four months, unless you ask us to delete them sooner or to keep them for longer.
  • Account data — for as long as your account remains open. If you close it, we delete the account and keep only what the accounting record requires.
  • Support correspondence — up to twenty-four months after the matter is closed. Unsuccessful partner applications — up to twelve months. Server security logs — up to twelve months.

How we protect your data

We encrypt all traffic to and from the site (HTTPS), store passwords only as salted hashes, restrict access to booking and media data to the people who genuinely need it, protect delivery links with long random tokens, and keep our systems patched. No online service can promise perfect security, but if a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Swedish supervisory authority within 72 hours and inform you directly without undue delay where the law requires it.

Your rights under the GDPR

If the GDPR applies to you, you have the following rights over your personal data:

  • Access — to be told whether we process data about you and to receive a copy of it, together with information about how and why we use it.
  • Rectification — to have inaccurate data corrected and incomplete data completed.
  • Erasure — to have your data deleted where we no longer have a lawful reason to keep it. This does not extend to records we are legally obliged to retain, such as accounting records.
  • Restriction — to have processing paused while an objection is considered or while a question of accuracy is resolved.
  • Portability — to receive the data you gave us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection — to object at any time to processing based on our legitimate interests, and to object absolutely to direct marketing.
  • Withdrawal of consent — to withdraw any consent you gave us, at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, write to us at:

info@badalumrah.org
FARSTA, Stockholm, Sverige

We respond within one month of receiving your request. We may ask you for information that lets us confirm your identity before we act, so that we do not disclose your data to someone else. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

If you believe we have handled your data unlawfully, you may lodge a complaint with the Swedish Authority for Privacy Protection — Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden, imy@imy.se — or with the supervisory authority of the EU or EEA country where you live, where you work, or where the alleged infringement took place.

Your rights if you are in the United States

This section applies in addition to the rest of this policy if you are a resident of the United States. It is written around the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and we voluntarily extend the same rights to residents of every US state, whether or not that state has enacted its own comprehensive privacy law.

  • Right to know — you may ask us what categories and specific pieces of personal information we have collected about you, the sources we collected them from, the business purpose for collecting them, and the categories of third parties we disclosed them to.
  • Right to delete — you may ask us to delete the personal information we collected from you, subject to the exceptions the law allows, such as information we must keep in order to complete a transaction you requested or to comply with a legal obligation.
  • Right to correct — you may ask us to correct inaccurate personal information we hold about you.
  • Right to opt out of sale or sharing — you may direct a business not to sell your personal information and not to share it for cross-context behavioural advertising.
  • Right to limit the use of sensitive personal information — you may ask a business to limit its use and disclosure of sensitive personal information to what is necessary to provide the service you requested.
  • Right to non-discrimination — we will never deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.

We do not sell personal information and we have not sold personal information in the preceding twelve months. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for any purpose other than providing the service you asked for. For those reasons we do not display a “Do Not Sell or Share My Personal Information” link — there is nothing to opt out of.

To make a request, email us at the address at the end of this policy with the subject line “US privacy request”. We confirm receipt within ten business days and respond within forty-five calendar days, extending by a further forty-five days where reasonably necessary and telling you if we do. You may use an authorised agent; we will ask for proof of their authority and may ask you to verify your own identity directly with us.

We do not knowingly collect, sell or share the personal information of children under sixteen years of age. Our service is intended for adults. If you believe a child has given us personal information, contact us and we will delete it promptly.

Notice at collection: the categories of personal information we collect are set out in the section on personal data we collect above; the purposes are set out in the section on how we use it; the categories of recipients are set out in the section on sharing; and our retention periods are set out in the section on how long we keep data. We collect this information directly from you when you use the site, book a service or contact us.

Changes to this policy

We may update this policy as our service, our providers or the law change. The current version is always published on this page with the date of the last update shown at the top. If a change materially affects how we use your personal data, we will tell you by email or by a clear notice on the site before it takes effect.

Contact us

If you have a question about this policy, want to exercise a right, or are unhappy with how we handled your data, please contact us first — we would like the chance to put it right.

info@badalumrah.org
FARSTA, Stockholm, Sverige
Privacy Policy – Badal Umrah