Privacy Policy
Effective date: 2026-07-29. This Privacy Policy describes how Funkihoo LLC ("funkihoo," "we," "us," or "our") collects, uses, discloses, and protects the personal information of users of our Muslim matrimonial platform available at funkihoo.com and, where offered, through our mobile applications (together, the "Service"). By creating an account or using the Service, you consent to the practices described here. If you do not agree, do not use the Service.
1. Who we are and how to contact us
Funkihoo LLC is a New Jersey limited liability company. Our postal address is 59 Buttonwood Drive, East Brunswick, NJ 08816, United States. For privacy inquiries, contact privacy@funkihoo.com. Users in the European Union or United Kingdom may also contact our EU / UK Data Protection Representative listed in the EU / UK addendum.
2. Information we collect
We collect the following categories of personal information:
- Identity information — email address, phone number, date of birth, display name, photos.
- Profile information — gender, country of residence, sect and sub-sect (self-declared), religiosity self-assessment, education level, profession, languages, marital status, matrimonial preferences, bio and free-text fields, wali (guardian) information if you choose to add one.
- Verification information — a real-time selfie captured during liveness verification. The selfie is compared against your profile photos to detect impersonation and is not retained beyond the check itself.
- Location information — country and city. We do not collect precise GPS coordinates; distance filters use coarse geohash bucketing.
- Communications — messages you send or receive within accepted connections, along with associated metadata (timestamps, delivery status).
- Interaction data — likes, passes, introductions sent and received, matches, blocks, favorites, filter and sort preferences.
- Payment information — for web-based purchases, we collect billing country and the payment method's brand and last four digits; full card numbers are handled by our payment processor (Stripe) and are not visible to funkihoo. For mobile purchases through Apple App Store or Google Play, we receive purchase confirmations from those providers and do not see billing details.
- Device and technical information — IP address, device type, operating system, browser type, session identifiers, timestamps, and app version.
- Support information — content of any messages you send to our support or trust-and-safety channels, plus any information you provide when reporting a user or appealing a moderation action.
- Cookies and similar technologies — see our Cookie Policy for details.
We do not log or store: passwords in plaintext (we use the argon2id hashing algorithm); full payment card numbers; original photo bytes in service logs (only object references); or the plaintext of a liveness selfie beyond the check itself.
3. How we collect information
We collect information (i) directly from you when you sign up, edit your profile, send messages, contact support, or interact with the Service; (ii) automatically when you use the Service, through device and network signals; and (iii) from third parties who provide us information, such as payment processors, verification providers, and ad networks.
4. How we use your information
We use your personal information for the following purposes. Where you are in the European Union, United Kingdom, or another jurisdiction that requires a legal basis for processing, we rely on the legal basis noted in each item.
- Provide and operate the Service — matching, messaging, notifications, subscription and payment processing. Legal basis: performance of a contract with you.
- Verify your identity — email, phone, and liveness checks to reduce impersonation and fake accounts. Legal basis: legitimate interests in preventing fraud and maintaining a safe platform, and, where applicable, your consent.
- Compute compatibility matches — using algorithmic scoring and embeddings computed from canonicalized profile attributes. We do not send email, name, or exact location to embedding models. Legal basis: performance of a contract.
- Enforce our Terms and Community Guidelines — moderation of reports, detection of prohibited behavior, and enforcement actions. Legal basis: legitimate interests in platform safety, and, where required, compliance with legal obligations.
- Prevent fraud and abuse — risk-score signals, off-platform contact detection, photo-theft detection, chargeback investigation. Legal basis: legitimate interests, and compliance with legal obligations.
- Provide customer support — respond to inquiries, resolve disputes, troubleshoot issues. Legal basis: performance of a contract.
- Send transactional communications — account verification, subscription receipts, security alerts, safety notifications. Legal basis: performance of a contract.
- Send optional marketing communications — product updates, feature announcements. Legal basis: your consent, which you may withdraw at any time from Settings.
- Comply with legal obligations — record-keeping, tax reporting, responding to lawful requests from government authorities. Legal basis: compliance with legal obligations.
- Improve the Service — analytics on aggregate usage patterns to identify friction, bugs, and improvement opportunities. Legal basis: legitimate interests. We do not use profile content of individual users to train third-party machine learning systems.
5. Who we share information with
We share personal information only as described in this policy, and only with the following categories of recipients:
- Other users of the Service — the profile information you make available to matches (subject to your privacy settings), as necessary for the matrimonial function of the platform.
- Service providers under contract — including Amazon Web Services (hosting, US East region), Stripe (payment processing), Twilio (SMS verification and delivery), Resend and Postmark (transactional email), Apple and Google (mobile in-app purchase), HelpScout (support ticketing), Sentry (error monitoring), PostHog (product analytics), and Google AdSense / AdMob (advertising, subject to your ad preferences). These providers are contractually restricted to processing your data only for purposes we authorize.
- Law enforcement and government authorities — when required by valid legal process or in accordance with our Law Enforcement Guidelines. We notify affected users of legal requests for their data before responding, except where prohibited by law or where notice would create a substantial risk of harm.
- In the event of a corporate transaction — if funkihoo is involved in a merger, acquisition, financing, or sale of all or substantially all of our assets, personal information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a different privacy policy.
- With your consent — for purposes disclosed to you at the time of consent.
We do not sell personal information in the sense understood by the California Consumer Privacy Act (CCPA / CPRA) or similar laws. We do use advertising networks that may set cookies or similar identifiers; residents of jurisdictions with specific opt-out rights (including California) may exercise those rights per the applicable regional addendum.
6. International data transfers
funkihoo's infrastructure is hosted in the United States. If you access the Service from outside the United States, your personal information will be transferred to and processed in the United States, where privacy laws may differ from those in your country of residence. Where we transfer personal information from the European Economic Area, United Kingdom, or Switzerland to the United States or another country outside those regions, we rely on Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Agreement, or other lawful transfer mechanisms. See the EU / UK addendum for details.
7. Data retention
We retain personal information for as long as necessary to provide the Service and for the additional purposes described below:
- Active accounts — retained while the account is active.
- Paused accounts — retained while the account remains paused.
- Deleted accounts — retained for a 30-day grace period during which you may restore. After the grace period, personal information is purged from production systems. Encrypted backups may retain data for up to 90 additional days before rolling off.
- Banned accounts — minimal identifiers (email hash, phone hash, device identifier) are retained indefinitely to enforce the ban.
- Payment records — retained for seven (7) years for tax and audit purposes, or longer where required by law.
- Audit and abuse-reporting logs — retained for two (2) years.
- Session and IP logs — retained for ninety (90) days from session close.
- Liveness selfies — not retained beyond the comparison check.
8. Security
We use a layered set of technical and organizational safeguards to protect personal information:
- Transport encryption (TLS 1.2+) for all data in transit.
- Encryption at rest for our primary databases and object storage.
- Argon2id password hashing; no plaintext passwords are ever stored or logged.
- Role-based access controls with least-privilege defaults for employee access to production data; production access is audited.
- Multi-factor authentication for all administrative accounts.
- Automated monitoring for anomalous access patterns, plus periodic third-party security review.
- Cross-service isolation via a private VPC; internal services communicate over authenticated channels.
No system is perfectly secure. If you believe your account may have been compromised, please contact security@funkihoo.com immediately.
9. Children's privacy
funkihoo is a matrimonial platform intended for adults. It is not directed to children under the age of 18 and we do not knowingly collect personal information from anyone under 18. We verify date of birth at signup and reject accounts whose declared date of birth indicates the person is under 18. If we discover that we have collected information from a person under 18, we delete that information and terminate the account. Parents, guardians, or others who believe an under-18 person may have used the Service may contact us at trust@funkihoo.com for immediate action.
10. Your rights
Depending on your jurisdiction, you may have the following rights with respect to your personal information. Users in the EU / UK, Türkiye, India, and California should also review the applicable regional addendum.
- Access. Request a copy of the personal information we hold about you. You can generate a complete data export from your account Settings; SLA is 72 hours.
- Rectification. Correct inaccurate or incomplete personal information about you. Most profile fields can be edited directly; date of birth and gender require admin-assisted correction within 30 days of signup with documentary evidence.
- Erasure ("right to be forgotten"). Delete your account and associated personal information. Deletion is available from account Settings; a 30-day grace period applies before purge.
- Restriction. Request that we restrict processing of your personal information in certain circumstances.
- Objection. Object to processing based on our legitimate interests, including for direct marketing.
- Portability. Receive your personal information in a structured, commonly used, machine-readable format (JSON).
- Withdraw consent. Where processing is based on consent, withdraw that consent at any time from Settings, without affecting the lawfulness of prior processing.
- Complain. Lodge a complaint with a supervisory authority. In the EU / UK, this is your local Data Protection Authority; in the U.S., this may be your state Attorney General or the Federal Trade Commission; in Türkiye, KVKK; in India, the Data Protection Board; and in California, the California Privacy Protection Agency.
To exercise these rights, use the controls in your account Settings or contact privacy@funkihoo.com. We may need to verify your identity before responding.
11. Automated decision-making
funkihoo uses algorithmic ranking to suggest potential matches based on your stated preferences and profile attributes. This algorithmic ranking is not a decision that produces legal effects or similarly significant effects on you within the meaning of Article 22 of the GDPR — it is a set of suggestions you are free to accept, ignore, or act on. All match decisions (like, pass, introduce) are made by you. Automated moderation systems may temporarily restrict specific features (for example, rate-limiting new-account behavior); consequential enforcement actions (bans, permanent removal) always involve human review.
12. Third-party links and services
The Service may contain links to third-party websites or integrate with third-party services (payment processors, verification providers, ad networks). This Privacy Policy does not apply to third-party sites or services; please review the applicable third-party privacy policies before providing personal information to those parties.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you at least thirty (30) days before the changes take effect by (a) posting the updated Privacy Policy with a new Effective date at funkihoo.com/legal/privacy, and (b) sending an in-app banner and an email to the address associated with your account. Non-material changes may take effect on posting.
14. Regional addenda
The following addenda expand this Privacy Policy for the specified jurisdictions:
- European Union and United Kingdom addendum (GDPR, UK GDPR)
- Türkiye addendum (KVKK)
- India addendum (Digital Personal Data Protection Act, 2023)
- California addendum (CCPA / CPRA)
15. Contact
- Privacy inquiries: privacy@funkihoo.com
- Security disclosures: security@funkihoo.com
- General support: support@funkihoo.com
- EU / UK representative: see EU / UK addendum
- Postal address: Funkihoo LLC, 59 Buttonwood Drive, East Brunswick, NJ 08816, United States