Privacy Policy
How Faiz-e-Hussaini Kuwait collects, uses and protects your personal information — on this website and in our mobile app.
Faiz-e-Hussaini Kuwait ("we", "us") organises ziyarat tours for mumineen. This policy covers the Faiz-e-Hussaini Kuwait website at fehkw.com and the Faiz-e-Hussaini Kuwait mobile application. We are the controller of the information described below.
Want your data deleted? Email [email protected] from your registered address, or message us on WhatsApp at +965 5549 2821, and we will delete your account and personal data. See Deleting your account and data below for what we must keep and why.
Information we collect
We only collect what is needed to place you on a tour and get you through the border. Specifically:
- Identity — your ITS (MuminID), name in English and Arabic, gender, date of birth, place of birth, nationality, Civil ID number, marital status, misaq status, jamaat, and whether you are a Kuwait resident or a visitor.
- Contact — mobile number, WhatsApp number, email address, and postal address.
- Travel documents — images of your passport pages, Kuwait Civil ID, Kuwait visit visa, photographs, vaccination certificates and similar documents, together with their document numbers, issuing country, and issue and expiry dates.
- Health and safety information — blood group, any medical notes you choose to give us, and your emergency contact's name, number and relationship to you. We ask for these so that we can help you if you fall ill while travelling.
- Family links — your head-of-family and, for travellers under 18, the parent accompanying them. Iraq will not issue a visa for a minor travelling without a parent, so we must record this.
- Booking and payment records — the tours you book, your fellow travellers, room and meal preferences, special needs, amounts due and paid, the method used (cash, KNET, card, bank transfer or cheque), and any refunds. We never see or store your card number, PIN or CVV — card and KNET payments are handled by the bank, and we record only the outcome.
- Account and device data — your password (stored hashed, never in readable form), one-time login codes, sign-in times, and — if you use the mobile app and allow notifications — a push-notification token together with your platform (Android or iOS) and app version, so we can send you messages about your booking.
- Support messages — anything you write to us through the support screen.
What we do not do
- We do not sell your personal information, and we never have.
- We do not share it with advertisers or use it for advertising.
- We do not track you across other apps or websites, and we do not collect an advertising identifier.
- We do not collect your location.
Why we collect it
Every item above exists to run the tour you booked: confirming your seat and price, applying for visas on your behalf, meeting airline and hotel manifest requirements, issuing receipts, contacting you about departures and changes, and helping you in an emergency abroad. We also keep accounting records because Kuwait law requires it.
Signing in with ITS
You may sign in using your ITS (eJamaat) credentials. When you do, ITS confirms your identity to us and provides your basic profile so you do not have to type it again. We do not receive or store your ITS password. Your MuminID is treated as confidential: it is never used to look up another person's details, and it is not exposed to other members.
Who we share it with
We share the minimum necessary, only with parties directly involved in delivering your journey:
- Visa authorities and processing agents — for Iraq, Saudi Arabia and other destinations. This necessarily includes your passport images and photograph.
- Airlines, hotels and ground-transport operators — passenger manifests and rooming lists.
- Banks and payment processors — to collect payment and issue refunds.
- Hetzner Online GmbH — hosts the servers and database that run this service, in their Finland data centres.
- Amazon Web Services — we send our email through Amazon Simple Email Service, hosted in the Asia Pacific (Mumbai) region.
- Google Firebase — delivers push notifications to the mobile app. Google receives the notification token, not your personal details.
- Google Analytics — tells us which pages and screens are used, on the website and in the app, so we know what to improve. Google receives a one-way, salted hash of your account ID — never the ID itself — so that your web and app activity can be recognised as the same person without Google or anyone else being able to work backwards to who you are. Google Signals is switched off: we do not let Google link this to your other Google activity, and we do not collect an advertising ID.
Where your information is held
Our servers and database are located in Finland, in the European Union, operated on our behalf by Hetzner. Our email provider processes messages in India, and push notifications are delivered through Google's infrastructure. Your travel documents are additionally sent to the visa authorities of the country you are visiting, such as Iraq or Saudi Arabia.
This means your information is transferred out of Kuwait and stored abroad. Hosting it in the EU places it under a recognised data-protection regime. Wherever it goes, we share only what that recipient needs for its specific role, and we require our providers to keep it secure and use it for nothing else.
How we protect it
Traffic to the site and app is encrypted in transit. Passwords are hashed. The database sits behind an IP firewall and is not reachable from the open internet. Identity documents are visible only to the members of our team whose role requires them, and every view and change is recorded in an audit trail. Access is restricted by role, so staff see only what their job needs.
Travellers under 18
The app is intended for adults. A parent or head of family books on behalf of children and provides their details. We collect a minor's information only as part of a family booking and only to the extent visas and airlines require. A parent may review, correct or ask us to delete a child's information at any time using the contact details above.
Deleting your account and data
You can ask us to delete your account and personal data at any time — by email to [email protected] from your registered address, or by WhatsApp to +965 5549 2821. We will act on your request within 30 days.
On deletion we remove your profile, contact details, uploaded identity documents, photographs, health and emergency-contact information, saved preferences and notification tokens. Two things we cannot delete immediately:
- Accounting records of money you paid or we refunded, which Kuwait law requires us to retain. These are kept for the statutory period and then destroyed.
- Records for a tour that has not yet departed, where a visa application is already lodged with a foreign authority. We will delete these once the journey is complete.
If you only want to stop notifications, you can turn them off in your device settings without deleting your account.
How long we keep it
Profile and booking information is kept while your account is open. Financial records are kept for the period Kuwait's accounting and audit rules require. Identity documents are kept while they remain valid and relevant to a booked tour; expired documents are superseded when you upload a replacement.
Your rights
You may ask us to show you the information we hold about you, correct anything wrong, delete it, or stop using it for a particular purpose. Much of it you can review and edit yourself in your profile. For anything else, write to [email protected].
Changes to this policy
If we change how we handle your information we will update this page and change the date below. Material changes will also be notified in the app.
Contact us
Faiz-e-Hussaini Kuwait
Email: [email protected]
WhatsApp: +965 5549 2821
If you have a concern about how your information has been handled, write to us first — we would rather hear it directly and put it right.
Last updated: 9 August 2026