Last reviewed 15 August 2026
This policy covers barakahbookings.com and the pages organisers publish through it. It is written for two different people: the organiser running a program, and the attendee booking a place at one. Where those two are treated differently, it says so.
01
When somebody books a place, the organiser decides why that information is collected and what happens to it afterwards. They are the data controller. Barakah Bookings holds and processes it on their instructions, as their processor.
For our own account holders, the organisers themselves, we are the controller of the account details we hold.
02
Only what is needed to give somebody a place and let the organiser run the day.
Card numbers are never collected by us. Payment details are entered directly into Stripe’s own payment form and never reach our servers.
03
An email address and password for the account, the workspace and brand settings entered, and the Stripe account identifier returned when payments are connected. We never receive the organiser’s bank details.
04
Two anonymous cookies are set: one that lasts a year to tell a returning visitor from a new one, and one that expires after thirty minutes of inactivity to group a visit into a session. Both hold random identifiers and nothing else. Alongside them we record page views, which steps of a booking were reached, the device type, browser and referring site.
This is first-party and is used to show organisers how their own pages performed. It is not sold, not shared with advertising networks, and is not used to build a profile of anybody across other websites.
05
Transactional email, a booking confirmation, a reminder before the day, a thank-you afterwards, is sent because somebody booked a place. Marketing email is only sent to people who have opted in, and every one of them carries a way to stop receiving it.
We do not email an organiser’s attendees on our own behalf, and we never use one organisation’s list to promote another.
06
Each of them acts on our instructions for the purpose named. Nobody else is given access, and no data is sold to anybody, ever.
07
Every page and email is served over HTTPS, records are encrypted at rest, and backups are encrypted too. Access inside a workspace is governed by roles, and rows are separated at the database level so one organisation cannot read another’s. Refunds, deletions and changes of role are recorded with a name and a time.
08
Booking and payment records are kept while the account is open, and afterwards for as long as tax and financial-record rules require. Everything else is deleted when the organiser deletes it or closes the workspace.
09
An organiser can export their contacts and bookings at any time from the portal, and can delete them. An attendee who wants a copy of their information, a correction, or its deletion should ask the organiser they booked with, since it is their list. If they cannot reach the organiser, write to us at salam@barakahbookings.com and we will help.
Australian organisers and attendees are covered by the Privacy Act 1988. Where an organiser takes bookings from the United Kingdom or the European Economic Area, we handle that information to the standard the UK GDPR and the GDPR require, including the rights of access, correction, erasure, restriction and portability.
10
Accounts are for adults. Where a program is for families, the adult booking is the person whose details we hold. We do not knowingly collect information directly from children.
11
If this policy changes in a way that matters, account holders are told by email before it takes effect. Questions, requests and complaints all go to salam@barakahbookings.com, and a person answers, usually the same day. Barakah Bookings is based in Sydney, Australia.