Privacy Policy

Privacy Policy
Soleae Feet — Privacy Policy

GDPR, UK GDPR, and US state privacy law require jurisdiction-specific review before
publication, and the disclosures below must be checked against what the product actually does
at launch. 
Last updated: [8/7/26] · Effective: [8/7/26] Applies alongside our [Terms of Service] and [Refund
Policy].
The short version
- We verify your age through a third party. Your ID is not visible to other members and
is not kept by us in a form we can browse.
- We do not collect your location. No GPS, no proximity matching, no distance filters.
- We never see or store your full card number.
- Your statement shows [DESCRIPTOR] — nothing that names this site.
- We do not sell your personal information, and we do not use it for cross-context
behavioural advertising.
- If you sell items, buyers never see your address and you never see theirs.

1. Who is responsible
Soleae Feet, Inc., a Delaware corporation, [800 North King Street Wilmington Delaware 19801], is the controller of your personal data.
Contact: [a1b4@soleaeinc.com] Data Protection Officer: [name / email] (appoint if required — see notes)
EU representative (Art. 27 GDPR): [name and address] UK representative: [name and address]

2. What we collect
You give us:
- Account details — email, username, password, display name
- Profile content — bio, photos, listings, session settings
- Age verification — see §3 Payment details — see §4
- Payout and tax details, if you are a Solet — see §4
- Shipping address, if you buy or sell items — see §6
- Messages and content you send through the Platform
- Support correspondence and reports you file
We collect automatically:
- Device and browser information, IP address, and session identifiers
- Pages viewed, features used, and timestamps
- Security and fraud signals, including device fingerprints used to detect banned accounts
returning
We do not collect:
- Location data. No GPS, no location permission, no proximity or distance features. We
derive approximate country from IP address only where we must — for tax, sanctions
screening, and applying the right age-verification standard.
- Contact lists, calendars, photo libraries, or microphone access outside a live session you
have started.

3. Age and identity verification
Verification is performed by [provider], acting as our processor. You submit your document and a
liveness capture to them.
- They return to us a pass/fail result, your verified age band or date of birth, and a
reference number
- We do not retain copies of your identity document for browsing or support purposes; the
provider holds it under contract for [X years] as required by law
- Your document is never shown to other members and never appears on your profile
- For Solets, we retain the records required by 18 U.S.C. §2257. The custodian is [name,
address]
Legal basis: compliance with a legal obligation, and performance of our contract with you. 

4. Payments and payouts
Payments are processed by [Segpay]. Card numbers are entered on their systems and
never touch ours. We receive a token, the last four digits, the card brand, and the result.
For Solets, our payout provider [name] collects the bank or wallet details and tax documentation
needed to pay you. We hold the payout status and amounts, not your full account credentials.
We retain transaction records for [7 years] for tax, accounting, and chargeback defence. This
retention applies even after you close your account.

5. Messages, sessions, and moderation
Messages are not end-to-end encrypted. They are encrypted in transit and at rest, and they
are subject to automated and human review for compliance with our Terms — in particular the
prohibition on soliciting or arranging paid in-person services.
- Automated systems scan message content for prohibited patterns
- Human moderators review flagged conversations and any conversation reported to us
- Live sessions are not recorded by us. Recording by either party is prohibited under our
Terms
- We retain moderation records — reports, reviews, decisions, and the content they relate
to — for [X years]. We need these to enforce our rules consistently, to defend decisions,
and to demonstrate our enforcement to regulators and processors
Legal basis: our legitimate interest in a safe and lawful platform, and compliance with legal
obligations.

6. Addresses and shipping
When an item is sold, our shipping integration generates the label.
- The buyer's address goes to the carrier, not to the seller
- The seller's address is used as the pickup or origin point, and does not appear on
anything the buyer receives
- Neither party sees the other's address through the Platform
- Carriers process addresses as independent controllers under their own policies 

7. Why we use your data
Purpose Legal basis (GDPR)
Providing the Platform and your account Contract
Age and identity verification Legal obligation
Processing payments and payouts Contract, legal obligation
Moderation, safety, fraud prevention,
enforcement
Legitimate interests, legal obligation
Support and communication about your
account
Contract
Tax, accounting, and record-keeping Legal obligation
Improving and securing the Platform Legitimate interests
Marketing email Consent (withdrawable at any time)
We do not use automated decision-making that produces legal or similarly significant effects
without human review. Account terminations under §6.4 of the Terms are reviewed by a person
before they take effect [confirm this matches the product].

8. Who we share it with
- Service providers acting on our instructions: hosting, payments, verification, payouts,
email, shipping, moderation tooling, analytics
- Other members, but only what you choose to show: your profile, listings, and what you
send in chat. Never your ID, email, address, or payment details
- Authorities, where legally required or where we consider it warranted — including
mandatory reporting of child sexual abuse material to NCMEC
- A buyer or successor, if the business is sold, subject to this policy
- Advisers, under confidentiality
We do not sell personal information and do not share it for cross-context behavioural
advertising, as those terms are defined under US state privacy law. 

9. International transfers
We are US-based and our infrastructure is in [region]. If you are in the EEA or UK, your data is
transferred to the US under [Standard Contractual Clauses / Data Privacy Framework], with a
transfer risk assessment on file. Ask us at [privacy email] for details.

10. How long we keep it
Data Retention
Account and profile Life of the account, then [30 days]
Verification result and reference [X years] after closure (legal requirement)
§2257 records (Solets) As required by law
Transaction and payout records [7 years]
Messages [X months] after sending, or longer if part of a
report
Moderation and enforcement records [X years]
Ban-evasion signals (email, payment, device) [Indefinitely], to keep removed accounts off
the Platform
Support correspondence [2 years]
Some records survive account deletion because we are legally required to keep them, or
because deleting them would let a banned account return. We tell you which when you ask.

11. Your rights
Depending on where you live, you can request: access, correction, deletion, a portable copy,
restriction of processing, objection to processing based on legitimate interests, and withdrawal
of consent. EEA/UK: you may also complain to your supervisory authority. California and other US states:
you may request access, deletion, and correction, and appeal a refusal. We do not sell or share
your data as defined by those laws, and we do not discriminate against you for exercising a
right.
To exercise a right, email [privacy email]. We verify who you are before acting — usually through
your registered account — and respond within [30 days].
Note: deleting your account does not delete records we must keep under §10.

12. Security
Encryption in transit and at rest, access controls limited to staff who need it, logging of
administrative access, and [MFA] on internal systems. Verification documents and card data are
held by specialist providers rather than by us, which is the single largest reduction in risk we can
make.
No system is perfectly secure. If a breach affects you, we notify you and the relevant regulator
as required by law.

13. Cookies
We use cookies that are strictly necessary for login, security, and billing, and [analytics] cookies
with your consent where required. You can manage non-essential cookies at [cookie settings].
Details in our [Cookie Policy].

14. Children
The Platform is for adults only. We do not knowingly collect data from anyone under 18. If we
discover an underage account we close it immediately, delete the data except what we must
retain for reporting, and report as legally required. 

15. Changes
We will post any change here and, if it is material, notify you by email at least [30] days before it
takes effect.

16. Contact
[A1b4@soleaeinc.com] · [800 North King Street Wilmington Delaware 19801] EU representative: [details] · UK representative: [details]
Notes for counsel
1. A DPIA is almost certainly mandatory — large-scale processing of adult-content
activity plus identity documents plus systematic monitoring of communications. It should
be completed before the September 2026 release, not after.
2. Art. 27 EU and UK representatives must be appointed and published if you serve
those markets from the US. These are named roles with real contact details, not
boilerplate.
3. A DPO is likely required on the systematic-monitoring limb, given §5.
4. §5 is the sensitive one. Message scanning is necessary to your enforcement posture
and to your FOSTA position, but it must be disclosed plainly and justified by a legitimate
interests assessment. Do not soften it — undisclosed scanning is the worse outcome.
5. §2 "we do not collect location" is a genuine design commitment, not marketing. It
needs to stay true in the schema; PostGIS and any location column should be removed
from the data model before build.
6. Special category data. Sexual-preference inferences may be argued to fall under Art. 9.
Worth a considered position on whether membership itself reveals sexual orientation,
and if so what the Art. 9 condition is.
7. Retention table must match what the systems actually do at launch. A published
schedule the product doesn't honour is worse than a vaguer one.
8. US state coverage — the "we do not sell or share" statement needs verifying against
every analytics and advertising tag you deploy, including anything a marketing team
adds later.