BLUSHROOMS – PRIVACY POLICY

BlushRooms Digital Ltd – Trading as "BlushRooms"

Last updated: 25 March 2026

1. Who We Are

BlushRooms Digital Ltd ("we", "our", "us") operates the BlushRooms platform ("BlushRooms").

We provide a digital-only platform where adult Content Creators can upload and monetise digital content, and Members can browse, message, and purchase content.

We are committed to protecting your privacy and complying with:

  • UK GDPR
  • Data Protection Act 2018
  • Age verification regulations
  • Payment security standards (Stripe)

Contact us at: 📧 info@blushrooms.com

2. Data We Collect

We collect four categories of data:

2.1 Information You Provide Directly

  • Email address
  • Username
  • Password
  • Profile information
  • Uploaded photos/videos/text
  • Account preferences
  • Messaging content
  • Support enquiries
  • Creator verification info (via AgeChecked or Stripe)

2.2 Age Verification Data (Creators & Members)

Age verification is handled by AgeChecked, an approved UK age-verification provider.

We receive only:

  • Confirmation that you are 18+
  • A verification token/flag
  • Outcome metadata

We do not receive or store:

  • Passport scans
  • Driving licence images
  • Full ID documents
  • Selfie images

AgeChecked retains those securely on its own system.

2.3 Payment & Payout Information

All payments and payouts are handled by Stripe.

We receive:

  • Stripe account ID
  • Status of payouts
  • Last 4 digits of bank accounts (Creators)
  • Payment outcomes (success/fail/refund)
  • Token purchase history

We do not store:

  • Full card numbers
  • CVV codes
  • Bank logins

2.4 Automatic Data Collection (Technical Data)

When you use the platform, we automatically collect:

  • IP address
  • Device type
  • Browser information
  • Country/region (via IP)
  • Login timestamps
  • Site usage analytics
  • Cookies and tracking data
  • Security logs
  • Error tracking data

This helps us maintain security and improve performance.

3. How We Use Your Data

We process your data for the following purposes:

3.1 To Operate the Platform

  • Account creation and login
  • Displaying Creator profiles
  • Uploading and hosting content
  • Delivering messages
  • Showing search results
  • Delivering purchased digital content
  • Processing payments and payouts

3.2 Legal & Safety Obligations

We process data to:

  • Verify age and prevent minors accessing the platform
  • Investigate reports of abusive or illegal behaviour
  • Detect fraud and scams
  • Enforce the Terms & Conditions
  • Assist with legal obligations or enquiries
  • Maintain audit trails for compliance

3.3 Moderation & Security

For safety purposes, we may review:

  • Reported content
  • Reports of abusive messages
  • Accounts flagged for suspicious behaviour
  • Metadata from uploads
  • Browser/IP information
  • Moderation logs

We do not monitor all messages, but we may analyse message content when:

  • A report is submitted
  • Abuse is detected
  • Fraud is suspected

3.4 Communications

We may contact you for:

  • Account verification
  • Age verification
  • Payment/payout updates
  • Support responses
  • Platform updates
  • Token expiry notices
  • Legal changes

We do not send marketing emails without consent.

3.5 Improving the Platform

We use analytics to:

  • Understand usage
  • Improve performance
  • Fix bugs
  • Develop new features
  • Enforce security

Data is anonymised whenever possible.

4. Legal Bases for Processing

Under UK GDPR, we process your data under:

  • Contract – necessary to provide the service
  • Legal obligation – age verification, fraud prevention
  • Legitimate interests – safety, security, analytics
  • Consent – for cookies and optional communications

5. How We Store Your Data

Your data is stored securely using:

  • Supabase (EU/UK servers) – content, accounts, messaging
  • Stripe – payment/payout data
  • AgeChecked – age verification
  • Encrypted internal systems – moderation records, security logs

We use:

  • Encryption at rest and in transit
  • Strict access control
  • Audit logs
  • Internal role-based access
  • Regular security reviews

6. How Long We Keep Data

  • Account data – while account is active
  • Uploaded content – until deleted by Creator
  • Moderation logs – up to 5 years
  • Payment & tax records – 6 years (HMRC requirement)
  • Age verification flags – indefinitely
  • Credit balances – expire after 12 months of inactivity (see T&Cs)
  • Messages – for as long as your account exists unless deleted

You may request deletion (see section 9).

7. Who We Share Your Data With

We only share data where required to operate the service:

7.1 AgeChecked

Age verification processing.

7.2 Stripe

Payments, fraud prevention, payouts.

7.3 Hosting Providers

Supabase, Vercel, and related infrastructure partners.

7.4 Moderation/AI Safety Tools

If implemented (e.g., for detecting banned content).

7.5 Legal Authorities

Only when legally required.

7.6 Contractors Working on the Platform

Developers who need access (e.g., Cosmin) under confidentiality agreements and narrow access rights.

We do not sell personal data.

8. Cookies & Tracking

We use cookies for:

  • login and authentication
  • security
  • analytics
  • performance
  • personalised browsing

You can manage cookies in your browser settings.

A full cookie policy will be available on the site.

9. Your Rights (UK GDPR)

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent
  • Lodge a complaint with the ICO

To exercise any right: 📧 info@blushrooms.com

We will respond within 30 days.

10. External Communications

If you choose to contact or interact with someone outside BlushRooms (WhatsApp, Telegram, etc.):

  • that communication is not monitored by us
  • it is not covered by this Privacy Policy
  • security is your personal responsibility

11. Data Transfers Outside the UK

Where data is transferred internationally (e.g., via Stripe):

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions
  • Equivalent security measures

are used to ensure compliance.

12. Children's Privacy

BlushRooms is strictly 18+.

We do not knowingly collect data from minors.

Accounts belonging to minors will be removed immediately.

13. Changes to This Policy

We may update this Privacy Policy periodically.

Significant updates will be communicated via email or platform notifications.

14. Contact Us

For privacy questions, concerns, or rights requests:

BlushRooms Digital Ltd

📧 info@blushrooms.com