Privacy Policy
Last updated: August 2026
- Serafa has no user accounts, no sign-up and no payments — there is nothing to register for and no card details to give us.
- Nothing you type into the converter or the calculators is sent to us. Amounts, currencies and Zakat figures are worked out in your browser and stay there.
- We measure traffic with Google Analytics and record one approximate-location entry per visit. Both run only if you accept analytics cookies, and you can withdraw that at any time.
- We show no advertising, use no ad network, and never sell or share your data.
1. Who is responsible for your data
The controller of the personal data described in this policy — the party that decides why and how it is processed — is Adem Zeina, operating as Serafa, at [to be confirmed before launch].
For anything in this policy, including a request to exercise the rights in section 9, write to [to be confirmed before launch]. We answer within one month, and will tell you if we need the further two months that the GDPR allows for complex requests.
This policy covers Serafa at serafa.net and the widgets we serve from it.
2. What we collect
Four things, in decreasing order of how much they say about you:
- A visit record — when you accept analytics cookies, we look your IP address up with the geolocation service ipapi.co and store what it returns: the IP address itself, your network operator and its ASN, city, region, country, postal code, approximate latitude and longitude, timezone, local currency and languages. We add the hostname of the site that referred you — google.com, say, never the full referring URL. One record per browsing session.
- Usage and device data — Google Analytics records which pages you view, which tools you use, your approximate location, and your browser and device type. This too runs only once you accept analytics cookies; before that, Google Consent Mode v2 keeps all storage denied.
- Request logs — our hosting and API servers log the IP address, timestamp, URL and browser user-agent of each request, as any web server must in order to serve pages and to investigate abuse.
- Anything you write to us — if you email us, we keep your message and your address so we can answer and keep a support history.
3. What we do not collect
This section exists because the previous version of this policy claimed otherwise. To be unambiguous:
- No accounts. There is no public sign-up, so we hold no username, password, name or telephone number for you. A sign-in exists for site administrators only; if you are one, we hold your name, email address and session tokens.
- No payments. We take no money, so no card, bank or billing data ever reaches us.
- No advertising. We run no ad network and no ad tags. Google's advertising signals stay switched off even when you accept analytics cookies.
- No tool inputs. Amounts, currencies, weights, karats and Zakat figures are calculated in your browser and never sent to our servers. Your preferences — theme, language, display currency, saved conversions — are written to your own device's local storage, where we cannot read them. Two features are exceptions, and both are described in section 5: a watchlist, which holds which public assets you asked us to watch; and My Money, which does hold quantities — it cannot value 50 grams of gold without being told about the 50 grams. Neither exists until you create it, and neither is created by looking at a page.
- No special-category data. We do not ask for, or knowingly infer, anything about your health, beliefs, politics or biometrics. Choosing a Zakat calculator or an Arabic interface is not treated as a statement about your religion.
4. Why we process it, and our lawful basis
Under Article 6(1) of the GDPR, every purpose needs a lawful basis. Ours are:
- Understanding how the site is used, so we know which tools and languages to invest in — your consent, Article 6(1)(a). This covers both the Google Analytics data and the visit record. You give it through the cookie banner and can withdraw it there at any time; withdrawing does not affect processing already carried out.
- Serving the pages you request, keeping the site available, and investigating abuse or attacks — our legitimate interests, Article 6(1)(f). Running a working, secure website is the interest; it is met with request logs that are short-lived and never combined into a profile, so it does not override your interests.
- Answering your messages — our legitimate interests, Article 6(1)(f), in responding to someone who contacts us; or Article 6(1)(b) where your message is a step towards an agreement between us.
- Administering the site — our legitimate interests, Article 6(1)(f), in restricting the administration area to authorised operators. Relevant only to administrators.
- Keeping your watchlist and sending the price alerts you set up — performance of a contract at your request, Article 6(1)(b), or our legitimate interests, Article 6(1)(f), in providing a feature you asked for. Nothing is stored until you create a watchlist, and deleting it removes it.
- Valuing the assets you record in My Money — performance of a contract at your request, Article 6(1)(b), or our legitimate interests, Article 6(1)(f), in providing a feature you asked for. We hold what you entered so we can price it and show how that price has moved; we do not analyse it, profile you against it, or use it for any other purpose. Nothing is stored until you add something, and deleting an asset removes it.
- Meeting a legal obligation, such as responding to a lawful order — Article 6(1)(c).
5. Cookies and on-device storage
Only the consent record and the security of the site require storage on your device. Everything else waits for your choice. Rejecting non-essential cookies leaves the site fully usable — nothing behind a cookie wall.
- cookie_consent (local storage, kept until you clear it) — the choice you made in the banner, together with the date you made it and the version of the notice it applied to. Strictly necessary: without it we would have to ask again on every page.
- serafa_consent (cookie, 180 days) — the same choice, in a form the server can read before the page is built, so that analytics is never loaded on a page served to someone who has not accepted it. Strictly necessary, and it holds nothing but that choice.
- Preferences (local storage, kept until you clear it) — theme, language, display currency and saved conversions. These never leave your device.
- serafa.watchKey (local storage, kept until you clear it) — a random identifier we issue the first time you add something to a watchlist, so that the list is still there on your next visit. It is meaningless to anyone else, we store only a one-way hash of it, and it identifies a list rather than a person: we do not link it to your name, your address, or anything you do elsewhere on the site.
- Watchlist and price alerts (our servers, for as long as you keep them) — the assets you asked us to watch, the price conditions you set, and a record of which of those conditions were met and when. This has to reach our servers: an alert that only existed in your browser could not tell you anything while the page was closed. It holds no quantities and no holdings — "tell me when gold passes 500" says nothing about whether you own any.
- My Money (our servers, for as long as you keep it) — what you told us you own: an asset, a quantity, a unit, a purity, and, only if you chose to enter them, a price you paid, a date and a name for the row. Unlike the watchlist, this is a statement about your holdings, and we treat it as the most sensitive thing we store: it is reached only through your own session, it is never included in analytics, its values are never written to our operational logs, and the page it appears on is blocked from search engines. We hold nothing about where the assets are, who else knows about them, or any account they might sit in — only the figures you typed, and only so we can price them.
- serafa.myMoney.count and serafa.myMoney.anon (local storage, kept until you clear it) — a count of how many assets you have recorded, and a flag noting that they were recorded before you signed in. The first lets the site decide whether to show a link to your dashboard without asking our servers on every page; the second lets us record that the handover to your account worked. Neither holds a value, an amount, or anything about what you own.
- visitor_tracked (session storage, deleted when you close the tab) — stops us recording the same visit twice.
- _ga and _ga_* (cookies set by Google Analytics, up to 2 years) — distinguish visitors and sessions. Set only after you accept analytics cookies; if you later decline, we delete them and stop loading Google Analytics altogether.
- Administrator session tokens (local storage) — set only when an administrator signs in.
6. Who receives your data
We disclose personal data to the following categories of recipient, and to no one else. We do not sell it, rent it, or share it for anyone's advertising.
- Google Ireland Limited and Google LLC — Google Analytics 4, our traffic measurement provider.
- ipapi.co — the IP geolocation lookup behind the visit record described in section 2. Your IP address reaches them by the nature of the lookup.
- Our hosting and infrastructure providers, who process request logs on our behalf in order to serve the site.
- Public authorities, where we are legally obliged to disclose — and only to the extent of that obligation.
- Upstream market-data providers supply us with prices. Price data flows one way, towards you; we send them nothing about you.
7. Sending data outside the EEA and the UK
Our analytics and geolocation providers are established in, or transfer data to, the United States, so using this site involves an international transfer of the data in section 2.
Where the recipient is certified under the EU-US Data Privacy Framework — Google LLC is — the transfer relies on the European Commission's adequacy decision for that framework, and on the UK extension for readers in the United Kingdom. Where no adequacy decision covers a recipient, we rely on the European Commission's Standard Contractual Clauses together with the additional safeguards those clauses require. Write to us at the address in section 1 for a copy of the clauses relied on.
8. How long we keep it
- Google Analytics data — 14 months from your last visit, the retention period configured on our GA4 property, after which Google deletes the underlying user and event records. Aggregate reports that identify nobody may be kept longer.
- Visit records — 14 months, then deleted.
- Request logs — 30 days, unless a specific log is needed longer for an ongoing security investigation.
- Email correspondence — 24 months from our last exchange.
- Administrator sessions — until the session expires or the administrator signs out.
- Watchlists and alerts kept without an account — 180 days after the device last used it, then deleted along with their alert history. A watchlist attached to an account is kept until you delete it or close the account.
- My Money assets recorded without an account — 180 days after the device last used it, then deleted with the rest of that device's data. Assets attached to an account are kept until you delete them or close the account.
- On-device preferences — until you clear your browser storage. We cannot delete these for you, and we never see them.
9. Your rights
If the GDPR or the UK GDPR applies to you, you have all of the following. Exercise any of them by writing to [to be confirmed before launch]; we will not charge you or make you give a reason.
- Access (Art. 15) — a copy of the personal data we hold about you, and confirmation of how it is processed.
- Rectification (Art. 16) — correction of anything inaccurate or incomplete.
- Erasure (Art. 17) — deletion, where we have no overriding basis to keep it.
- Restriction (Art. 18) — a freeze on processing while a dispute about accuracy or grounds is resolved.
- Portability (Art. 20) — the data you gave us on the basis of consent, in a structured, machine-readable format, sent to you or directly to another controller.
- Objection (Art. 21) — you may object at any time to processing based on our legitimate interests, and we must stop unless we show compelling grounds that override your rights.
- Withdrawal of consent (Art. 7(3)) — reopen the cookie banner and choose to reject. Analytics stops immediately; anything done beforehand remains lawful.
- Freedom from automated decision-making (Art. 22) — not something we do. Nothing on this site profiles you or decides anything about you automatically.
- Complaint to a supervisory authority (Art. 77) — you may complain to the data protection authority in your country of residence, your place of work, or the place of the alleged infringement, whether or not you have raised the matter with us first. We would rather you contacted us too, but you are not required to.
10. When we cannot identify you
Most of what section 2 describes is tied to an IP address and a session, not to a name. If we genuinely cannot work out which records are yours, Article 11 of the GDPR lets us say so rather than guess — but we will not use that as a way of avoiding a request. Tell us the approximate date and time of your visit and the IP address you used, and we will look.
11. California residents
Under the CCPA as amended by the CPRA, we collect the categories described in section 2: identifiers (IP address), internet and network activity, and coarse geolocation. We collect them for the purposes in section 4 and keep them for the periods in section 8.
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months — and we do not do either now. We collect no sensitive personal information for the purpose of inferring characteristics, and we offer no financial incentive in exchange for your data.
You may request to know, delete or correct your personal information, and you may not be discriminated against for asking. Send the request to [to be confirmed before launch]; we may need to ask for enough detail to locate your records.
12. Children
Serafa is a reference tool for exchange rates and metal prices. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.
13. Security
The site is served over HTTPS, the administration area is restricted to authenticated operators, and we hold as little as the purposes in section 4 require — the most effective protection being data we never collected. No transmission over the internet can be guaranteed secure, and we make no claim that ours is an exception.
14. Changes to this policy
The date at the top of this page is the date of the current version. If we change what we collect, why, or who receives it, we will update this page and — where the change concerns anything you consented to — ask for your choice again through the cookie banner rather than treating the old consent as covering it.
15. How to contact us
Privacy questions and rights requests: [to be confirmed before launch].
Postal address: Adem Zeina, operating as Serafa, [to be confirmed before launch].
For anything unrelated to privacy, our Contact page is the faster route.