Политика конфиденциальности
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
FruityPages
Tentstraat 86
6291 BJ Vaals
Netherlands
Email: datemyfoot@gmail.com
A data protection officer has not been appointed, as there is no legal obligation to do so. For any questions regarding data protection, you can reach us at the email address given above.
2. Overview of Processing Activities
We only process personal data of our users to the extent necessary to provide a functional platform, our content and our services, or where consent has been given. In particular, we process:
– Account data (e.g. username, email address, date of birth)
– Profile data (e.g. profile details, preferences, photos)
– Location data (positions you set yourself)
– Communication data (e.g. chat messages, shouts)
– Contract and payment data (e.g. booked memberships, transaction status)
– Usage data and metadata (e.g. IP addresses, access times, device information)
3. Relevant Legal Bases
Unless stated otherwise in this policy, the following legal bases apply: consent (Art. 6(1)(a) GDPR), performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR) and the protection of our legitimate interests (Art. 6(1)(f) GDPR).
Where you voluntarily provide information in your profile that constitutes special categories of personal data within the meaning of Art. 9(1) GDPR (e.g. information concerning your sex life or sexual orientation), such data is processed exclusively on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR (see section 8).
4. Hosting and Server Log Files
Our online service is operated by our hosting provider Leaseweb in a data centre within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider.
When you visit our website, server log files are collected automatically. These include: the page or file accessed, date and time of access, volume of data transferred, browser type and version, operating system, referrer URL and the IP address. This data is technically necessary to deliver the website and to ensure its stability and security (Art. 6(1)(f) GDPR).
Log files are stored only for a short period and then deleted, unless a specific security-relevant incident requires longer retention until it has been resolved.
5. Cookies and Consent
We use cookies. We use technically necessary cookies to provide basic functions such as login, session management, security (CSRF protection) and your language setting. These cookies are strictly necessary for the operation of the service and cannot be disabled (Art. 6(1)(f) and (b) GDPR).
Optional cookies (analytics via Google Analytics) are only set if you have given your consent via our cookie banner (Art. 6(1)(a) GDPR). You can change or withdraw your choice at any time via the "Cookie settings" link in the page footer. Withdrawal applies to the future; the lawfulness of processing carried out before the withdrawal remains unaffected.
The following cookies are used:
| Name | Purpose | Category | Retention |
|---|---|---|---|
| datemyfoot_session | Maintaining your session (e.g. login) | Necessary | Session (max. 2 hours) |
| XSRF-TOKEN | Protection against cross-site request forgery attacks | Necessary | Session |
| applocale | Storing your language preference | Necessary | 1 year |
| privacy_policy | Storing your cookie choice | Necessary | 1 year ("Only necessary") / 5 years ("Accept all") |
| a | Attributing a registration to an advertising partner (only set when arriving via a partner link) | Necessary (affiliate settlement) | up to 5 years |
| _ga, _ga_* | Google Analytics: reach measurement | Analytics — only with consent | up to 2 years |
6. Registration, User Account and Email Verification
A user account is required to use the platform. When you register, we process the mandatory data you provide (e.g. username, email address, password in encrypted form, account type) in order to provide the account (Art. 6(1)(b) GDPR). We confirm your email address via a verification link (double opt-in).
To prevent misuse and to protect our users, we log IP addresses and timestamps of security-relevant actions (e.g. registration, login). The legal basis is our legitimate interest in the secure operation of the platform (Art. 6(1)(f) GDPR). Data is only disclosed to third parties where this is necessary for the enforcement of legal claims or where a legal obligation exists.
7. Sign-in via Third-Party Providers (Social Login)
You may optionally sign in or register via a third-party provider (e.g. Google Ireland Limited, Meta Platforms Ireland Limited/Facebook, Apple Distribution International Ltd., X/Twitter International Unlimited Company). In this case, we receive from the respective provider the data required to create your account (usually name, email address and provider ID). The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Signing in with the third-party provider itself is subject to that provider's privacy policy. Further information is available from the respective provider: Google (https://policies.google.com/privacy), Meta (https://www.facebook.com/privacy/policy), Apple (https://www.apple.com/legal/privacy/), X (https://x.com/privacy). Using social login is voluntary; registration via email address is equally possible.
8. Profile Data and Special Categories of Personal Data
DateMyFoot is a dating platform. Information you provide in your profile (e.g. descriptions, preferences, interests, search criteria) may allow conclusions to be drawn about your sex life or sexual orientation and may therefore constitute special categories of personal data within the meaning of Art. 9(1) GDPR.
Providing this information is entirely voluntary. By actively entering and saving such information in your profile, you explicitly consent to its processing for the purpose of providing the service (Art. 9(2)(a) GDPR). Depending on the feature, your profile details are visible to other registered members; we do not pass them on to outside third parties and do not use them for advertising purposes.
You can withdraw your consent at any time with effect for the future by removing the relevant information from your profile or by deleting your account.
9. Photos, Verification and Content Review
Photos you upload are reviewed and approved by our team before publication. This review serves to protect all members from unlawful or abusive content (Art. 6(1)(b) and (f) GDPR). No automated decision-making within the meaning of Art. 22 GDPR takes place.
If you use the voluntary authenticity verification, we use the material you submit exclusively to verify your identity as a genuine member and do not publish it.
10. Location Data and Proximity Features
For the proximity search and the map view (radar), we process location information that you set yourself — for example by selecting a position on the map or by sharing your device location. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Other members are never shown your exact address, only approximate positions or distances. In addition, our map deliberately uses an abstracted display without street details and is served from our own servers; no third-party map services are embedded.
11. Chat, Shouts and Real-Time Features
Messages, shouts and other communication content that you exchange via the platform are stored on our servers and displayed to the authorised recipients (Art. 6(1)(b) GDPR). For real-time features (e.g. notifications, online status) we operate our own WebSocket server; no third party is involved.
Communication content is deleted when you or your conversation partner delete it or when the associated account is deleted, unless statutory retention obligations require otherwise.
12. Payment Processing and Subscriptions
Paid memberships and feature packages are processed via our payment service provider inet-cash GmbH (Germany). Your full payment details (e.g. credit card number, bank account details) are collected and processed directly by the payment service provider; we essentially only receive the transaction status and the information required for allocation.
The legal bases are the performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR). We retain billing-related data within the scope of commercial and tax retention periods of up to ten years. Information about data processing by inet-cash is available at https://www.inet-cash.com.
13. Email Communication and Newsletter
We send system-related emails (e.g. verification links, notifications about new messages or account events) in order to perform the user agreement (Art. 6(1)(b) GDPR). You can manage notifications in your account settings.
You will only receive our newsletter with your consent (Art. 6(1)(a) GDPR). Subscription uses a double opt-in procedure and is logged in order to be able to prove consent. You can unsubscribe from the newsletter at any time via the unsubscribe link at the end of each email or in your account settings. Emails are sent via our own infrastructure; no external newsletter service provider is used.
14. Google Analytics (only with consent)
Only if you have selected "Accept all" in our cookie banner do we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Art. 6(1)(a) GDPR). Google Analytics uses cookies (see the table in section 5) and processes pseudonymised usage data for reach measurement; IP addresses are processed in truncated form and are not stored.
Data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework, which ensures an adequate level of data protection (Art. 45 GDPR).
You can withdraw your consent at any time with effect for the future via the "Cookie settings" link in the page footer. Further information: https://policies.google.com/privacy.
15. Adobe Fonts
To display our brand typeface consistently, we embed a font via Adobe Fonts, provided by Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. When you visit a page, your browser loads the font file from Adobe servers (use.typekit.net); for technical reasons your IP address is transmitted in the process. According to Adobe, no cookies are set for the delivery of the fonts.
The legal basis is our legitimate interest in a consistent and appealing presentation of our service (Art. 6(1)(f) GDPR). Where data is transferred to the USA, Adobe Inc. is certified under the EU-US Data Privacy Framework. Further information: https://www.adobe.com/privacy/policies/adobe-fonts.html.
16. External Content
With the exception of the font embedding described in section 15, we serve scripts, stylesheets, map material and libraries from our own servers; no external content delivery networks are embedded.
On our imprint page, the provider identification is embedded via a service of inet-cash GmbH. When you visit this page, your IP address is transmitted to inet-cash for technical reasons. The legal basis is compliance with our statutory imprint obligation and our legitimate interest in a secure provision of this information (Art. 6(1)(c) and (f) GDPR).
17. Affiliate Programme
If you reach us via a link from an advertising partner, we store a cookie ("a", see section 5) in order to attribute a subsequent registration to that partner and to settle the remuneration. The legal basis is our legitimate interest in the settlement of our affiliate programme (Art. 6(1)(f) GDPR).
Advertising partners only receive aggregated statistics (e.g. number of registrations and payouts); your profile or communication data is not passed on to partners.
18. Transfers to Third Countries
As a rule, your data is processed on servers within the European Union. Transfers to third countries (in particular the USA) only take place in the cases described in this policy (Google, Adobe and, where applicable, the social login provider you have chosen) and only where an adequacy decision pursuant to Art. 45 GDPR (e.g. the EU-US Data Privacy Framework) or appropriate safeguards pursuant to Art. 46 GDPR (e.g. standard contractual clauses) are in place.
19. Retention Periods and Deletion
We only store personal data for as long as is necessary for the respective purposes or as required by statutory retention obligations. You can delete your account at any time in your settings or by emailing us. After deletion, your profile data is made inaccessible to other members and is subsequently permanently deleted.
Billing-related data is subject to commercial and tax retention periods of up to ten years and is only deleted after these have expired. Security logs (e.g. IP logs) are only retained for a short period, unless a specific incident requires longer storage.
20. Rights of Data Subjects
You have the following rights vis-à-vis us with regard to your personal data: the right of access (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR) and to data portability (Art. 20 GDPR). You may withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR).
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in particular with the supervisory authority of your habitual residence or with the Dutch supervisory authority responsible for us (Autoriteit Persoonsgegevens, www.autoriteitpersoonsgegevens.nl).
You are neither legally nor contractually obliged to provide your data; however, without the information required at registration, the user account cannot be provided.
21. Right to Object (Art. 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR. We will then no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Where your personal data is processed for direct marketing purposes, you have the right to object at any time to such processing; this also applies to any profiling to the extent that it is related to such direct marketing. If you object, the data will no longer be processed for direct marketing purposes.
An objection can be made without any formal requirements, e.g. by email to datemyfoot@gmail.com.
22. Version and Changes to this Policy
This privacy policy is dated 25 July 2026. We will update it whenever changes to our data processing or to the legal situation make this necessary. The current version is always available on this page.