BLUSHROOMS – PRIVACY POLICY
BlushRooms Digital Ltd – Trading as "BlushRooms"
Last updated: 25 March 2026
1. Who We Are
BlushRooms Digital Ltd ("we", "our", "us") operates the BlushRooms platform ("BlushRooms").
We provide a digital-only platform where adult Content Creators can upload and monetise digital content, and Members can browse, message, and purchase content.
We are committed to protecting your privacy and complying with:
- UK GDPR
- Data Protection Act 2018
- Age verification regulations
- Payment security standards (Stripe)
Contact us at: 📧 info@blushrooms.com
2. Data We Collect
We collect four categories of data:
2.1 Information You Provide Directly
- Email address
- Username
- Password
- Profile information
- Uploaded photos/videos/text
- Account preferences
- Messaging content
- Support enquiries
- Creator verification info (via AgeChecked or Stripe)
2.2 Age Verification Data (Creators & Members)
Age verification is handled by AgeChecked, an approved UK age-verification provider.
We receive only:
- Confirmation that you are 18+
- A verification token/flag
- Outcome metadata
We do not receive or store:
- Passport scans
- Driving licence images
- Full ID documents
- Selfie images
AgeChecked retains those securely on its own system.
2.3 Payment & Payout Information
All payments and payouts are handled by Stripe.
We receive:
- Stripe account ID
- Status of payouts
- Last 4 digits of bank accounts (Creators)
- Payment outcomes (success/fail/refund)
- Token purchase history
We do not store:
- Full card numbers
- CVV codes
- Bank logins
2.4 Automatic Data Collection (Technical Data)
When you use the platform, we automatically collect:
- IP address
- Device type
- Browser information
- Country/region (via IP)
- Login timestamps
- Site usage analytics
- Cookies and tracking data
- Security logs
- Error tracking data
This helps us maintain security and improve performance.
3. How We Use Your Data
We process your data for the following purposes:
3.1 To Operate the Platform
- Account creation and login
- Displaying Creator profiles
- Uploading and hosting content
- Delivering messages
- Showing search results
- Delivering purchased digital content
- Processing payments and payouts
3.2 Legal & Safety Obligations
We process data to:
- Verify age and prevent minors accessing the platform
- Investigate reports of abusive or illegal behaviour
- Detect fraud and scams
- Enforce the Terms & Conditions
- Assist with legal obligations or enquiries
- Maintain audit trails for compliance
3.3 Moderation & Security
For safety purposes, we may review:
- Reported content
- Reports of abusive messages
- Accounts flagged for suspicious behaviour
- Metadata from uploads
- Browser/IP information
- Moderation logs
We do not monitor all messages, but we may analyse message content when:
- A report is submitted
- Abuse is detected
- Fraud is suspected
3.4 Communications
We may contact you for:
- Account verification
- Age verification
- Payment/payout updates
- Support responses
- Platform updates
- Token expiry notices
- Legal changes
We do not send marketing emails without consent.
3.5 Improving the Platform
We use analytics to:
- Understand usage
- Improve performance
- Fix bugs
- Develop new features
- Enforce security
Data is anonymised whenever possible.
4. Legal Bases for Processing
Under UK GDPR, we process your data under:
- Contract – necessary to provide the service
- Legal obligation – age verification, fraud prevention
- Legitimate interests – safety, security, analytics
- Consent – for cookies and optional communications
5. How We Store Your Data
Your data is stored securely using:
- Supabase (EU/UK servers) – content, accounts, messaging
- Stripe – payment/payout data
- AgeChecked – age verification
- Encrypted internal systems – moderation records, security logs
We use:
- Encryption at rest and in transit
- Strict access control
- Audit logs
- Internal role-based access
- Regular security reviews
6. How Long We Keep Data
- Account data – while account is active
- Uploaded content – until deleted by Creator
- Moderation logs – up to 5 years
- Payment & tax records – 6 years (HMRC requirement)
- Age verification flags – indefinitely
- Credit balances – expire after 12 months of inactivity (see T&Cs)
- Messages – for as long as your account exists unless deleted
You may request deletion (see section 9).
7. Who We Share Your Data With
We only share data where required to operate the service:
7.1 AgeChecked
Age verification processing.
7.2 Stripe
Payments, fraud prevention, payouts.
7.3 Hosting Providers
Supabase, Vercel, and related infrastructure partners.
7.4 Moderation/AI Safety Tools
If implemented (e.g., for detecting banned content).
7.5 Legal Authorities
Only when legally required.
7.6 Contractors Working on the Platform
Developers who need access (e.g., Cosmin) under confidentiality agreements and narrow access rights.
We do not sell personal data.
8. Cookies & Tracking
We use cookies for:
- login and authentication
- security
- analytics
- performance
- personalised browsing
You can manage cookies in your browser settings.
A full cookie policy will be available on the site.
9. Your Rights (UK GDPR)
You have the right to:
- Access your data
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent
- Lodge a complaint with the ICO
To exercise any right: 📧 info@blushrooms.com
We will respond within 30 days.
10. External Communications
If you choose to contact or interact with someone outside BlushRooms (WhatsApp, Telegram, etc.):
- that communication is not monitored by us
- it is not covered by this Privacy Policy
- security is your personal responsibility
11. Data Transfers Outside the UK
Where data is transferred internationally (e.g., via Stripe):
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Equivalent security measures
are used to ensure compliance.
12. Children's Privacy
BlushRooms is strictly 18+.
We do not knowingly collect data from minors.
Accounts belonging to minors will be removed immediately.
13. Changes to This Policy
We may update this Privacy Policy periodically.
Significant updates will be communicated via email or platform notifications.