~ what we collect, why ~

Privacy policy

Last updated: June 16, 2026

The short version

muftiEats is a halal restaurant directory. We collect the minimum amount of data we need to make the product work, to know whether it's working, and to keep it honest. We don't sell your data. We don't share it with advertisers. We use one session-recording tool (Microsoft Clarity) with strict text masking so we can see UX problems without seeing what you type.

What we collect

  • Page visits + clicks. Routes you visit and a small number of named events (e.g. vouch_submitted, chat_query) via Vercel Analytics. Aggregated; no per-person identification.
  • Page performance. Real-user Web Vitals (load speed, interactivity, layout shift) via Vercel Speed Insights. Anonymous, aggregated.
  • Session recordings + heatmaps. Microsoft Clarity. Records mouse movement, scrolls, and clicks. Text fields are masked by default — we cannot see what you type. Used to understand how people use the site, not to identify you.
  • Location. Only if you tap “Use my phone's location” or type a neighborhood. Stored in your browser's localStorage and a city cookie — never sent to advertisers. You can clear it anytime via the LocationChip's “turn off location” option or by clearing your browser data.
  • Halal vouches. When you tap VOUCH, we save a row with the restaurant, an optional display name, and a timestamp. We use these to power the neighbor-vouches count on listings.
  • Owner accounts. If you claim your restaurant, we collect your email address and any certificate uploads you submit. Used to verify ownership and to display the verified badge on your listing.
  • Suggested restaurants. If you submit a spot via /suggest, we save the form data so Mufti can vet it.
  • Cookies. Authentication (when signed in as an owner or admin), the city cookie that remembers your chosen city, and Clarity's anonymous session cookie.

What we don't collect

  • Your name, unless you give us one as a display name.
  • Your phone number, payment info, or any other contact info beyond email (for owners only).
  • The contents of any form field you don't submit — Clarity masks text input before it leaves your browser.
  • Your data, for resale.

Third parties we use

  • Vercel — hosts the site, runs Vercel Analytics and Speed Insights. Vercel privacy policy.
  • Supabase — Postgres database and authentication. Supabase privacy policy.
  • Microsoft Clarity — session recordings + heatmaps with text masked. Microsoft privacy statement.
  • Google Places — Mufti consults Google Places API for restaurant photos, hours, reviews, and addresses. Your queries to Mufti chat are not sent to Google.
  • Anthropic Claude — Mufti chat uses Anthropic's Claude API for the conversational interface and for extracting verdicts from review data. Anthropic privacy policy.

Your rights

Email hello@muftieats.com if you want to:

  • See what we have on you
  • Delete your owner account or your confirmations
  • Ask us to stop processing your data
  • Report a privacy concern

We'll respond within 30 days. We'll also retain deletion logs sufficient to honor your request without keeping the data itself.

Children

muftiEats is not directed at children under 13. We don't knowingly collect data from anyone under 13. If you think we have, email hello@muftieats.com and we will delete it.

Changes to this policy

If we change anything material, we'll update the “Last updated” date and (if you're an owner with an account) send you an email.

Contact

This document is provided for transparency. It is not a contract and not a substitute for legal advice. If you have concerns please reach out and we'll work with you to resolve them.