Privacy policy

Updated 16 August 2026

This policy describes how Miqra handles personal data. It is the operational policy for the product as shipped. Counsel has not signed it as a legal opinion.

Who we are

Miqra is operated by Pypapi Technologies Limited together with SonsHub Media (equal partners). Miqra is the church management platform on usemiqra.app and related hosts (workspace.usemiqra.app, tenant church sites on usemiqra.app, chiyah.usemiqra.app, and api.usemiqra.app).

For platform accounts (church admins, members signing into Miqra, billing contacts), Pypapi Technologies Limited is the data controller.

For a church's own membership, giving, pastoral notes, attendance, and sermons, that church is the controller. Pypapi processes that data on the church's instruction. See the Data Processing Addendum.

Privacy requests for platform accounts go to the published mailbox. Write to contact@usemiqra.app.

Law this policy follows

We handle personal data under the Nigeria Data Protection Act 2023 (NDPA) and, where still referred to in our product documents, the Nigeria Data Protection Regulation (NDPR).

If a church has members in the UK, EU, or another country, that church is responsible for any extra notice it owes those people. This policy is written for the platform, not as each tenant's full notice.

Data we handle

Platform accounts: name, email, phone, password hashes, church membership, roles, and session data.

Church-held records the product stores when a church uses a module: member profiles, families, first-timers, attendance, giving (including amounts in kobo), pastoral notes, sermons and media the church uploads, messages, events, welfare requests, and website content the church publishes.

Billing: plan, invoices, Paystack references. We do not store full card numbers. Paystack processes the charge.

Device and site: the miqra_theme cookie (and localStorage) so light or dark mode survives a reload. After sign-in, session cookies described on the Cookies page.

Why we use it

To run the account you asked for: sign-in, the church workspace, member apps, and the public church site if the church turned it on.

To bill the church for the plan and add-ons it selected, and to send receipts the product already generates.

To keep tenants apart, enforce permissions, and keep an audit trail of admin actions, role changes, money movement, and member-data access.

We do not sell member lists. Platform advertising to church members is not offered (that product slice is shelved).

Who else sees it

The church's own authorised users, within the permissions that church assigned.

Processors we use to run the product: hosting, email/SMS delivery the church triggers, Paystack for charges, and object storage for media the church uploads. They see what that job needs, not the whole tenant.

A lawful demand from a Nigerian authority, or another authority where we must comply.

We do not place marketing analytics cookies on usemiqra.app today.

Your rights

You can ask for a copy of your platform-account data, a correction, deletion, or a portable export, subject to NDPA limits (for example, records we must keep for billing or audit).

Member records inside a church tenant are requested through that church. The product includes export and deletion paths the church admin can run. If the church does not respond, contact us and we will tell you how to reach the church's controller contact we have on file.

Giving history and pastoral notes are restricted. They are not published in the directory.

How long we keep it

Platform accounts last until the user or church closes them, plus a short hold so we can finish billing and audit.

Audit logs of admin and money activity are kept for twelve months at the platform operator.

Church-held records last for as long as the church stays on Miqra and does not delete them. After a church tenant is closed, we retain only what the law or an open billing dispute still needs.

Children

Miqra is sold to churches, not to children. Churches may store records of minors in membership. The church is responsible for the consent its own law requires before it enters that data.

Changes

If this policy changes in a way that affects how we use data, we will update the date on this page. Material changes will be pointed out at sign-in or by email to the church admin on file.