Privacy Policy
This explains what we hold about you, why we are allowed to, and for how long. It describes what the platform actually does, not what is convenient to claim.
Being a member of this platform reveals something about your sex life. We treat that as the most sensitive category of personal data there is, because in law it is, and because for many members being identified would cost them a great deal.
Who is responsible
[LEGAL ENTITY NAME], of [REGISTERED ADDRESS], is the data controller. Data protection enquiries: info@myswinghub.com.
What we hold
- Account details — email address, display name, date of birth, and the membership type you applied as.
- Profile content — your nearest city and country, anything you choose to write about yourself, and the photographs you upload.
- Identity documents — a photo ID and a verification photograph, held only while a decision is pending.
- Messages — conversations between you and other members.
- Safety records — members you have blocked, and reports you have made or that have been made about you.
- Technical records — failed sign-in attempts, and a log of age-gate confirmations. IP addresses in advertising and referral statistics are stored hashed, never in the clear.
- Transactions — orders and tickets, where you buy something. Where you pay in cryptocurrency you pay us directly, with nobody in between, so we also record the wallet address you sent from and the transaction's identifier on the blockchain. We need both to tell your payment apart from everybody else's and to answer a question about it afterwards. A blockchain is public and permanent: that transaction can be read by anyone, for ever, and neither we nor you can remove it from the network.
- Your recent searches — the last few searches you made in the directory, so you can repeat one. Kept for 30 days at most, never more than a dozen, and you can wipe them yourself from your account at any time.
We never store your password. It is put through a one-way function and only the result is kept, so we can check a password you type but nobody here — including the owner — can read or recover it. If you lose it, it is replaced, never retrieved.
We do not ask for your real name, your address, or your phone number, and there is nowhere on the platform to put them.
Why we are allowed to hold it
Being here says something about your sex life, which is a special category of personal data. We rely on your explicit consent to hold it, given when you apply for membership. You can withdraw that consent at any time by deleting your account, which erases the data — see Your rights.
For everything else:
- To provide the service you asked for — your account, your profile, your messages, your tickets. This is necessary to perform our contract with you.
- To verify your age and identity — a legal obligation for a platform of this kind, and the only honest way to keep minors out.
- To keep members safe — moderation, blocking, reports, and the audit record of what our staff did. This is our legitimate interest, and the interests of every member who trusts the door.
- To prevent abuse of sign-in — the throttle on failed attempts. Legitimate interest.
- To meet accounting and tax obligations — where money changes hands. Legal obligation.
If you ask us to stop processing on the basis of legitimate interest, tell us and we will consider it and reply.
Identity documents
This is the most sensitive thing we hold, so it is handled separately from everything else:
- Encrypted with AES-256-GCM the moment they arrive.
- Stored outside the public web space, so no web-server misconfiguration can expose them.
- Viewable only by a reviewer, and every single viewing is recorded against that reviewer's name — including any look long after the decision.
- Destroyed on a fixed schedule after a decision — see How long we keep it below for the period currently set. There is no setting that keeps them indefinitely: a document with no end date is a risk that only grows.
Honest limitation, stated plainly: the encryption key is held on the same server as the files. This protects against a stolen backup or a database dump. It does not protect against an attacker who obtains full access to the server itself.
Photographs
Every image is re-encoded when you upload it. That removes the EXIF metadata a camera writes into a file, including GPS coordinates — which for a photograph taken at home is your home address.
Orientation is read before the metadata is discarded, so this does not rotate your photographs.
Who can see what
- Albums are private by default. You grant access to named members one at a time, and you can withdraw it at any moment.
- Your email address and date of birth are never shown to another member.
- Moderators reviewing photographs see only images awaiting a decision, and every such view is recorded against the reviewer's name.
- Nothing on this platform is visible to search engines.
Staff access to your account
We would rather tell you this plainly than have you discover it.
A member of staff can sign in to your account to help with a support problem. While they are signed in as you, they see what you see — including your private albums and the contents of your messages. There is no technical barrier that stops this, and we are not going to pretend otherwise.
What we do instead is make it accountable and limited:
- The ability is a separate permission, held by as few people as possible, and never by default.
- Every session is recorded against the name of the individual who started it, with the time it began, the time it ended, and how long it lasted. That record is kept whether or not anything went wrong.
- The session ends by itself after an hour, so a forgotten one closes.
- While signed in as you, staff cannot act as you: they cannot send a message from your account, change your password or email address, delete your account, or download your data. Looking is support; acting in your name is not.
If you want to know whether anyone has ever signed in to your account, ask us and we will tell you. The record exists precisely so that the question has an answer.
Nothing is sent to third parties
We load no external fonts, no analytics, no advertising networks, no social widgets, no embedded video. Every third-party request would be a record, held by somebody else, that your browser was on an adult site. There are none.
Advertisers see only aggregate impression and click counts. They are never told who you are, and outbound clicks carry no referrer.
We do not sell your data, and we do not share it for anyone else's marketing. Ever.
Who handles data on our behalf
- Our hosting provider, which operates the server the platform runs on.
- Our email provider, which carries the messages we send you.
- A payment provider, if and when payments are enabled. They will hold your card details under their own terms; we will not.
Each acts on our instructions under a written agreement. We will disclose your data to anyone else only where the law requires it, and we will tell you unless we are forbidden to.
Where your data is
The server is in London, in the United Kingdom. Everything is held there and nowhere else: the database, your photographs, and the encrypted identity documents.
We do not hand your data to anybody. There is no analytics service, no advertising network, no font or script loaded from someone else's server, and no third party with a copy of the database. The platform makes a handful of outgoing requests — an exchange-rate lookup, and public blockchain explorers to see whether a payment has arrived — and those carry only our own wallet addresses and public market data. Nothing about you is in any of them.
[TRANSFER MECHANISM — the United Kingdom is outside the EEA. A reviewer must confirm what covers members in the EU and state it plainly here.]
Cookies
One cookie, for your session, so the site knows you are signed in. It is deleted when you close your browser. There is also a record of your age-gate confirmation so you are not asked repeatedly.
We use no tracking or advertising cookies, which is why you are not asked to consent to any.
How long we keep it
- Identity documents — destroyed the moment a decision is recorded, whether you are accepted or refused. We keep the decision, never the document. (This is a setting. If it is ever changed to keep documents for a period, this line must be changed to say so on the same day.)
- Your recent searches — 30 days, and no more than the last dozen. Cleared instantly if you ask.
- Confirmation and password-reset tokens — 30 days, then deleted automatically.
- Failed sign-in attempts — 7 days.
- Age-gate confirmations — 12 months, as a record that the check was carried out.
- Your account and its content — until you delete it.
- Messages — until either party deletes their account.
- Orders, tickets and payment records — [RETENTION PERIOD REQUIRED BY TAX AND ACCOUNTING LAW — commonly six or seven years].
- Administrative audit records — 24 months. These record staff actions, not member browsing, and survive the deletion of a staff account by design.
- Backups — a rolling 7 days. Deleted data disappears from backups within that window.
Decisions about you
Applications are decided by a person, not by an automated system, and so is every moderation decision. You are not subject to automated decision-making or profiling that produces legal or similarly significant effects.
Your rights
You can download everything we hold about you as a file from your account settings, at any time, without asking and without explaining why.
You can delete your account from the same page. Deletion is immediate and real: rows are removed, and photograph files are erased from disk. It is not a flag that hides you.
What deletion does not remove. Records of money are kept, because tax and accounting law requires them, and consent is not what we rely on to hold them. Your orders and tickets are deleted along with the rest of your account, but the accounting entry behind anything you paid for stays: what was paid, when, its reference, and the display name the account had at the time — an invoice has to say who it was for. Where you paid in cryptocurrency we also keep the record of that payment, including the wallet address it came from and the transaction identifier. Everything else goes: your profile, photographs, messages, album permissions, blocks, reports and searches. How long we keep it gives the period.
You also have the right to:
- ask what we hold and why, and get a copy;
- have inaccurate information corrected — most of it you can edit yourself;
- ask us to restrict or stop certain processing;
- object to processing we carry out on the basis of legitimate interest;
- withdraw consent at any time, which for special category data means deleting your account;
- receive your data in a portable form, which is what the download gives you.
We answer within one month. If a request is complex we may take longer, and we will tell you why within that first month.
Complaining
If you are unhappy with how we have handled your data, tell us first at info@myswinghub.com — we would rather fix it.
You also have the right to complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to the supervisory authority in the EU country where you live or work.
Security incidents
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the supervisory authority within 72 hours of becoming aware of it, and tell affected members without undue delay where the risk to them is high.
We will tell you what happened, what data was involved, what we have done, and what you should do — in plain language, not a press release.
Children
This platform is for adults. Nobody under 18 may use it, and every account is age-verified by a person before it is opened. If you believe a minor has an account here, tell us immediately at info@myswinghub.com and we will act at once.
Changes
Material changes will be notified to the address on your account before they take effect. We record which version of this policy applied when you joined.