Privacy policy

1. Controller

Michael Temeschinko design&development
Poststrasse 1, 76669 Bad Schönborn, Deutschland
maschinenraum@amoremiau.de

2. Data we process

We process account and login data, profile details, birth year, location and city, uploaded photos, preferences, likes, matches, messages, reports, coin balances and marketplace transaction references. We also process necessary technical data such as IP address, device and browser information, timestamps and security events.

We embrace the principle of data minimization: we collect only data needed for the service. For example, we store the birth year instead of the complete date of birth.

3. Purposes and legal bases

We process data to create and secure your account, display profiles, provide search, matching and messaging, operate the coin and marketplace functions, handle reports and prevent abuse. The legal bases are performance of the contract (Article 6(1)(b) GDPR), legal obligations (Article 6(1)(c)), legitimate interests in secure and reliable operation (Article 6(1)(f)), and consent where requested (Article 6(1)(a)).

4. Sensitive profile information

Religion, gender and dating preferences may reveal special categories of personal data. Providing and publishing them is voluntary and is based on your explicit consent (Article 9(2)(a) GDPR). You may withdraw consent for the future by removing the information or deleting your account.

5. Location and distance

Location data is used for nearby search. Public distance information is deliberately imprecise and search is based on city or coarse location data to reduce the risk of determining an exact location.

6. Recipients and service providers

We use service providers for hosting and databases, Redis caching and sessions, object storage and image delivery, transactional email and affiliate attribution. Currently these may include Scalingo, MongoDB Atlas, Hetzner, Sweego and AWIN. They receive only the data required for their task.

7. Processing in the EU and EEA

The GDPR applies throughout the European Economic Area (EEA), which comprises the EU Member States as well as Iceland, Liechtenstein and Norway. Our core infrastructure is operated within the EU or EEA.

AWIN is an exception in connection with our affiliate marketplace. When you follow an affiliate link, AWIN may process a pseudonymous click reference as well as tracking and transaction data in the United Kingdom and through other AWIN group companies or service providers. The United Kingdom is outside the EEA, but the European Commission currently recognizes it as providing an adequate level of data protection. For transfers to other countries outside the EEA without an adequacy decision, AWIN states that it uses the European Commission's Standard Contractual Clauses. Further information is available in AWIN's privacy policy.

8. Cookies and local storage

We use only technically necessary first-party storage, including a secure session cookie for login and local settings such as display mode. We do not use marketing cookies. Affiliate shops and external payment or verification pages have their own privacy practices after you open them.

9. Retention and deletion

Messages are automatically deleted 14 days after they are sent. If a user reports a profile, the message history still available between the two profiles at that time is copied into the report so that the report can be reviewed even after the original messages expire. This evidence is retained only as long as necessary to investigate the report, prevent abuse, or establish, exercise or defend legal claims.

Account and profile data is stored while the account exists and deleted when the account is deleted, unless legal obligations or the establishment, exercise or defence of legal claims require longer retention. Payment and accounting records may be retained for statutory periods. Security logs, reports and backups are deleted or anonymized according to necessity and the applicable retention schedule.

10. Your rights

You may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interests. You may withdraw consent at any time for the future. You also have the right to lodge a complaint with a data protection supervisory authority.

11. Automated decisions and security

Search, matching and abuse-prevention functions use automated rules, but we do not make decisions producing legal or similarly significant effects solely by automated means. We use technical and organizational safeguards including encrypted transport, restricted access and security monitoring.

In addition to database encryption, particularly sensitive fields such as email addresses are encrypted by the application before storage. The encryption key is stored separately from the database on the infrastructure of an independent European hosting provider. The database provider does not have this key. A separate search hash permits login without storing the email address in searchable plain text.

12. Contact and changes

Contact us at the address above with privacy questions. We may update this policy when the service or legal requirements change; the current version is published here.