Privacy Policy
How MerkezCore handles information on this public website — contact requests, certificate checks, and the line between marketing visits and school product data.
Last updated: September 2026
Who we are
MerkezCore is multi-tenant school software for Islamic schools and Quranic academies (merkezzes). It connects three surfaces that share one school record: the Director web app, the Ustaz mobile app, and the Family mobile app.
The product and this public marketing website are built by Arsion Tech, headquartered in Addis Ababa, Ethiopia (Bole Sub-City). In this policy, “MerkezCore”, “we”, and “us” mean the operators of this public site and the MerkezCore platform.
MerkezCore is designed for regional realities: Ethiopian bank-slip tuition (CBE, Awash, Telebirr), classroom attendance, Hifz / Murajaah tracking, and QR-checkable certificates — with English, Arabic (RTL), Afaan Oromoo, and Amharic.
Scope of this policy
This Privacy Policy applies only to the MerkezCore public website — Home, Product, Mobile, How It Works, About, Contact / demo request forms, Privacy, Terms, and the public Verify Certificates page at /verify.
It does not replace the customer agreement, data-processing terms, or school-admin policies that apply once a merkez becomes a paying MerkezCore customer. Inside a customer school, operational records (students / deresa, staff, fees, attendance, certificates, and family accounts) are governed by that school’s contract and the roles the school assigns.
Browsing the marketing site, submitting a lead, or checking a certificate serial are covered here. Signing into the web app or mobile apps as a school user is covered by product terms and your school’s administrators.
What we collect on this site
Contact / demo form. When you submit a request, MerkezCore stores the fields you provide: full name; optional school / merkez name; email; phone / WhatsApp; optional country and city; enquiry category (demo, sales, partnership, support, or other); your free-text message; preferred locale (en, ar, om, or am); and the source page URL. A honeypot field is included solely to reject automated spam — humans should leave it empty, and submissions that fill it are discarded without creating a lead.
Technical request data. To operate and secure the public API we may process IP address, user agent, timestamps, and rate-limit signals. These help block abuse and keep the form and verify endpoints available.
Certificate verification. When you use Verify Certificates, we process the serial number or verification token you enter (or that arrives from a QR deep link). We also record that a verification attempt occurred (query, result, IP, user agent) for security auditing. A successful match may return limited public credential facts needed for authenticity — not private fee or family account data.
We do not ask for payment card numbers on this marketing site, and we do not upload student rosters through the public contact form.
How we use information
Lead handling. We use contact submissions to reply to your enquiry, schedule academy walkthroughs, qualify sales or partnership conversations, route support questions, notify platform operators by email, and display the lead inside the MerkezCore platform desk for follow-up.
Security and integrity. We use technical and honeypot signals to reject spam, enforce rate limits, and protect the public API from automated flooding.
Public authenticity checks. Verification lookups confirm whether a MerkezCore-issued credential is valid, revoked, or not found, and maintain an audit trail of public checks so forged or mass-enumerated serials can be investigated.
We do not sell personal information. We do not sell marketing leads to brokers. We do not use public-site contact details to build third-party advertising audiences or retargeting pixels.
Cookies and analytics
This public website is designed to work without invasive tracking. We do not place third-party advertising cookies or marketing pixels on Privacy, Terms, Verify, Contact, or the core marketing pages.
Locale routing uses the URL path (for example /en/… or /ar/…) rather than a tracking profile. Your browser may keep ordinary session or preference state needed for navigation and language switching.
If we introduce optional first-party analytics later (for example aggregate page-view counts), we will update this section before enabling them and describe what is measured. Until then, treat the site as free of advertising trackers.
Public certificate verification
Purpose. Every issued MerkezCore certificate can carry a unique tenant serial (for example SEL-2026-K7M2P) and a QR code that opens the public verify page. Anyone — families, employers, partner schools — can check authenticity without signing in.
What a lookup returns. If a match is found and the paper is not a draft, the registry may show: issuing school name, name printed for the student / deresa, credential type (such as year completed, Hifz, Qirat, attendance, achievement, participation, or custom), certificate number, issue date, valid-until date when set, and — if revoked — revocation time and reason. Valid certificates may allow a public PDF download subject to rate limits and platform controls.
What it does not return. Verification does not expose family login accounts, fee invoices, bank-slip images, attendance ledgers, staff payroll, or unrelated students in the same school.
Safeguards. Lookups are rate-limited (to limit bulk guessing), logged, and can be disabled globally or per school via platform emergency controls if abuse is detected. Schools remain responsible for issuing and revoking credentials inside their tenant.
Where information is stored
Public leads are stored in MerkezCore’s platform database so authorized operators can review and follow up. They are not written into a school’s student or fee tables.
Certificate verification events are stored as security / audit records tied to the certificate when a match exists, or as anonymous failed lookups when nothing matches.
Infrastructure uses access-controlled cloud systems. Each customer school (tenant) keeps operational data behind isolation boundaries so one merkez cannot read another merkez’s deresa, finance, or staff records. Platform staff access to production systems is limited to roles required for support, operations, and security.
How long we keep it
Contact leads are retained while your request is active and for a reasonable business period afterward (follow-up, dispute handling, spam investigation). When a lead is no longer needed, we delete or anonymize it.
Verification logs are kept long enough to investigate abuse, forged papers, and registry integrity, then aged out according to operational practice.
If you become a customer, retention of school product data (rosters, fees, certificates) is defined by your customer agreement and the school’s own record-keeping duties — not solely by this marketing-site policy.
Sharing and processors
We share public-site information only as needed to run MerkezCore: hosting and database providers that store platform data; transactional email providers that deliver lead notifications to our desk; and security tooling that protects the API.
Those processors act on our instructions and are not authorized to use your data for their own marketing. We may disclose information if required by applicable Ethiopian law or other lawful process, or when necessary to protect MerkezCore, our users, or the public from fraud, abuse, or security threats.
We do not sell leads. We do not share contact-form contents with unrelated schools.
School product data
Inside a customer tenant, MerkezCore may process deresa (student) profiles and guardians; ustaz / staff accounts; class and halaqah attendance; Hifz and Murajaah progress; tuition invoices and bank-slip uploads; payroll visibility for teachers where enabled; announcements; and issued or revoked certificates with serials and signatures.
The school is the customer and primary decision-maker for who may access that data (directors, registrars, accountants, teachers, guardians). Role permissions and multi-campus isolation are configured for that tenant.
This marketing Privacy Policy does not grant MerkezCore a right to use tenant student or fee data for advertising. Platform engineering may access tenant systems only under support, security, or contractual operations rules. Public verify reveals only the limited authenticity fields described above — not the full school ledger.
Children’s privacy
The public website and contact forms are intended for adult decision-makers: directors, administrators, teachers, and guardians evaluating MerkezCore. We do not knowingly collect marketing-site leads directly from children.
Student records that appear later inside a customer school (including minors enrolled in a merkez) are collected and managed under that school’s authority, for educational and administrative purposes defined by the school and its customer agreement.
Parents using the Family App interact with school-controlled data through credentials issued by their merkez — not through this public Privacy Policy alone.
Your choices
For this public site you may: request correction or deletion of a contact lead you submitted; ask what lead data we hold about a specific submission; and ask privacy questions about marketing pages or public verify.
Send requests to contact@merkezcore.com or use the Contact page. We may need enough detail to locate your submission (for example the email and approximate date you used on the form).
If you are a parent, teacher, or student inside a customer school, most requests about classroom, fee, or attendance records should go first to your school’s administrators. They control tenant access. MerkezCore can assist the school under the customer relationship when appropriate.
Changes to this policy
We may update this Privacy Policy as MerkezCore’s public site, verify registry, or lead workflows evolve. When we make material changes, we revise the “Last updated” date at the top of this page.
Continued use of the public website after an update means you acknowledge the revised policy. For customer schools, material product-data changes may also be communicated through contractual or in-product notices where required.
Contact
Privacy questions about the MerkezCore public website, demo leads, or the public certificate registry:
Email: contact@merkezcore.com
Headquarters reference: Arsion Tech · Addis Ababa, Ethiopia · Bole Sub-City.
For signed-in product support inside an active school tenant, use the channels your school administrator provides, or contact the platform desk through your customer agreement.