Privacy Policy

Your privacy and data security are our top priorities

Last updated: September 6, 2026

1. Introduction

Shirah Technologies ("we," "our," or "us") operates the Shirah Authentication Service, a centralized authentication microservice that powers user authentication across the Shirah.co platform ecosystem. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our authentication service.

By using our service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our service.

2. Information We Collect

2.1 Personal Information

We collect only the minimum personal information necessary to provide authentication services:

  • Email Address: Used as your unique identifier and for account-related communications
  • Password: Encrypted and stored securely using industry-standard bcrypt hashing
  • Account Creation Date: Timestamp of when your account was created
  • Last Login Time: Timestamp of your most recent authentication

2.2 Technical Information

To ensure service security and performance, we automatically collect:

  • IP Addresses: For rate limiting and security monitoring
  • Authentication Attempts: Successful and failed login attempts for security
  • JWT Token Metadata: Token expiration times and refresh patterns (not token contents)
  • Service Usage: Which Shirah platform services you authenticate with

2.3 Information We Do NOT Collect

  • Personal names, phone numbers, or addresses
  • Browsing history or website activity outside authentication flows
  • Payment or financial information
  • Personal documents or identification

3. How We Use Your Information

We use your information solely for the following purposes:

  • Authentication: Verifying your identity and managing your sessions
  • Security: Detecting and preventing unauthorized access attempts
  • Service Operations: Maintaining and improving our authentication service
  • Communication: Sending account-related notifications (password resets, security alerts)
  • Compliance: Meeting legal and regulatory requirements

We do NOT use your information for marketing, advertising, or any commercial purposes beyond providing authentication services.

4. Information Sharing and Disclosure

4.1 Within Shirah Ecosystem

As a centralized authentication service, we share authentication status and basic user identifiers with authorized Shirah platform services (Portify, Pathway, Studendly, Mploynow) to enable single sign-on functionality.

4.2 Third Parties

We do NOT share your personal information with third parties except:

  • Legal Requirements: When required by law, court order, or government request
  • Security Threats: To protect against fraud, security breaches, or illegal activity
  • Service Providers: With cloud infrastructure providers who assist in service operation (under strict confidentiality agreements)

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to the same privacy protections outlined in this policy.

5. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption: All data is encrypted in transit (HTTPS) and at rest
  • Password Security: Passwords are hashed using bcrypt with salt
  • Access Controls: Strict access controls limit who can view your data
  • Rate Limiting: Protection against brute force attacks
  • Security Monitoring: 24/7 monitoring for suspicious activities
  • Regular Updates: Security patches and updates applied promptly

While we strive to protect your information using industry-standard security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining the highest standards possible.

6. Data Retention

We retain your information for the following periods:

  • Account Information: Until you delete your account or request deletion
  • Login Records: 90 days for security and troubleshooting purposes
  • Security Logs: 1 year for security incident investigation
  • JWT Tokens: Until expiration (typically 24 hours for access tokens)

When you delete your account, we will permanently remove your personal information within 30 days, except for any information we are required to retain by law.

7. Your Privacy Rights

You have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and associated data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing of your information for specific purposes
  • Restriction: Request restriction of processing under certain circumstances

To exercise these rights, please contact us through the appropriate Shirah platform service or through our support channels. We will respond to your request within 30 days.

8. Cookies and Tracking

Our authentication service uses minimal cookies and tracking:

  • Session Cookies: Essential for maintaining your authenticated session
  • Security Cookies: Used for CSRF protection and security measures
  • Preference Cookies: Remember your settings (language, theme preferences)

We do NOT use advertising cookies, analytics cookies, or any tracking technologies for marketing purposes. All cookies used are essential for service functionality and security.

9. International Data Transfers

Your information may be stored and processed in countries where our service providers operate. We ensure that any international transfers comply with applicable data protection laws and implement appropriate safeguards such as:

  • Standard contractual clauses approved by relevant authorities
  • Adequacy decisions where applicable
  • Additional security measures to protect data in transit and at rest

10. Children's Privacy

Our authentication service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

If we discover that we have collected personal information from a child under 13, we will delete such information immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Notify users of significant changes through appropriate channels
  • Provide a clear summary of changes when material updates are made

Your continued use of our service after any changes constitutes acceptance of the updated Privacy Policy.

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us through the appropriate Shirah platform service you are using, or refer to our FAQ page for additional support information.

Shirah Technologies
Authentication Service Privacy Officer
Data Protection and Privacy Team

This Privacy Policy is effective as of September 6, 2026 and applies to all users of the Shirah Authentication Service.