Version 2026-09-07.2. Effective 7 September 2026.
1. Who is responsible
CHERRYCARE360 LTD (company number 17309946), at CHERRYCARE360, GLYNFELLIS, INSIDE TINA ROSE, GATESHEAD, NE10 8RH, United Kingdom, is the controller responsible for personal information processed for Cherry Kiss. For privacy questions or to exercise your rights, contact support@cherrykiss.co.uk and identify Cherry Kiss. Do not send passwords, verification codes, identity documents or intimate material in an initial email.
This notice explains the account, profile and review service and the gated Stripe Identity, discovery, connection, text and emoji chat, safety, moderation, profile-pause and account-deletion functions. Reading or acknowledging this notice is not blanket consent to biometric processing, marketing, sensitive-data matching or any new use of your information.
2. What the beta includes and how features are gated
The current invitation beta is free and limited to adults aged 18 to 39 in Newcastle upon Tyne and Gateshead. It supports account access, date-of-birth eligibility, profile and photo submission, policy choices, profile review and service notifications. A submitted or approved profile is not automatically visible to another member.
Software may be deployed for:
- a choice of Stripe-hosted identity-document check or document check with an optional matching selfie after human profile approval;
- a limited set of mutually eligible profile introductions;
- a connection request, with one optional introductory message;
- text and emoji chat after both members agree to connect;
- reporting, blocking and unmatching, with human moderation and an appeal route; and
- profile pause, leaving Cherry Kiss and full account deletion controls.
These functions are available only when the app presents them and the server confirms that their policy, provider, privacy, safety and operating gates are open. The server refuses access when a required gate or provider configuration is missing. Identity remains off and fail-closed until live Stripe activation is complete; after activation, it is available only while every required server gate remains open. Lounges, profile video, voice notes, chat attachments, audio or video calls and paid subscriptions are outside this beta.
3. Information we collect
Account and eligibility
We process your email address, authentication identifier, sign-in method, email-verification and disabled-account status, app membership, date of birth, and account creation or sign-in timestamps. If you choose Google or Apple sign-in, we receive the account information they make available, which may include a name, email address or Apple relay address. Those providers also process information under their own notices.
Firebase Authentication handles password-based access. Our application database does not need a readable copy of your password. Authorised account views expose selected account details, not password material or authentication tokens.
Profile, photos and matching setup
We process the profile information you choose to provide, such as your display name, broad area, biography, approved photos, relationship intention and public prompts or interests. We also process your private discovery preferences, rounded location, search radius and questionnaire answers. Private matching answers and coordinates are not public profile fields.
Do not put your home or workplace address, precise location, financial information, identity document, passwords, verification codes or another person's private information in your profile.
Stripe Identity
When the identity gate is available, our server creates an authenticated verification session and sends you to Stripe's hosted service. You choose a government-photo-document check or the same document check with an optional matching selfie. The document-only route does not use a selfie or biometric face comparison. Stripe may collect the document image, information read from it, device and browser information, network address and fraud-prevention signals. If you choose the selfie route, Stripe also collects a face image and uses it for face comparison. Stripe explains its processing in its Privacy Policy and the hosted verification flow.
Cherry Kiss receives and keeps only the result needed for access and audit: an opaque Stripe session reference, chosen method, status, safe failure code, attempt count, timestamps, consent record where applicable, and whether the verified date of birth matched the date already on the Cherry Kiss account and met the age rule. Cherry Kiss does not download or store raw Stripe document or selfie files, a document number, a biometric template or a separate copy of the legal name. Our server briefly retrieves the verified date of birth to compare it and then discards the provider response containing it.
Both routes can unlock the same core access after all checks selected for that route pass. Every route requires the document and date-of-birth checks; the selfie route also requires its configured face comparison to pass. Your choice does not change eligibility, recommendation order, price, badge, support or access to discovery and member chat. A completed Stripe result is not a background check, criminal-record check, guarantee of character or proof that meeting someone is safe. A successful profile review and a successful identity check are separate decisions.
The matching-selfie route uses biometric face comparison and involves special-category biometric information. Before it starts, we show a separate explanation and ask for your explicit consent. We record the consent wording and version, your choice and when it was made. Accepting the Terms, Integrity Pledge or this notice is not selfie consent. You can decline or withdraw that consent and use the document-only route. After withdrawal, we stop relying on the selfie result, revoke any access based only on that result, queue eligible provider redaction and allow a new document-only check. Withdrawal does not make earlier processing unlawful.
You may make no more than two submitted verification attempts before support is required. The initial live beta is capped at 50 verification-session reservations or provider-linked sessions in total until the controller reviews and approves any expansion.
Discovery and member interactions
When enabled, we process which candidate set was prepared for you, the eligibility and recommendation reasons used, the profiles you opened, passed or restored, and the connection requests you sent, accepted or declined. We also process matches, optional introduction text, text and emoji messages, message timestamps and read state, and when a match was ended.
Safety, support and account controls
We process blocks, reports, the reason category and text you provide, the minimum relevant content or evidence, moderation notes, interim restrictions, decisions, appeals and audit records. A report is private and is not shown to the reported member as a public accusation. Blocking and unmatching do not require you to give the other person a reason.
We also process profile-pause state, last activity needed to manage inactive visibility, requests to leave Cherry Kiss, full account-deletion requests and the progress of deletion or provider-redaction jobs.
Notifications and technical information
We process in-app notices, notification choices, device-push registration tokens and delivery state. Lock-screen alerts should remain generic and must not reveal report details, private preferences or message text. Email is used for necessary account, policy, review, safety and recovery messages; it is not marketing consent.
Our hosting, authentication and delivery services also receive network and request details, security and error records, and technical delivery information. We process information you choose to include in support, privacy, safety or appeal correspondence.
4. Why we use information and our legal bases
- Account access, requested profile storage, discovery, connections and messaging: to take steps at your request and provide the service covered by our agreement with you.
- Document and age assurance: our legitimate interests under UK GDPR Article 6(1)(f) in protecting an adults-only dating service, reducing impersonation and fraud, and controlling access to discovery and messaging. We have assessed necessity, proportionality and the effect on members. You may object and request human review.
- Optional matching-selfie comparison: the same Article 6(1)(f) legitimate interests, together with your explicit consent under UK GDPR Article 9(2)(a) for the biometric comparison. You may decline or withdraw this consent and use the equal-access document-only route.
- Mutual eligibility and recommendations: to provide the requested introduction service and pursue our legitimate interest in relevant, privacy-conscious introductions. Hard eligibility rules are applied before any recommendation order.
- Security, blocking, abuse prevention, moderation, complaints and appeals: our legitimate interests in operating a safe and accountable service and, where applicable, compliance with a legal obligation. We must balance those purposes against the rights of affected people.
- Necessary service email, in-app and opted-in device notices: to provide account functions, keep you informed about requested interactions and protect access. Device permission can be withdrawn in the app or device settings. Marketing would need its own basis and choice.
- Meeting an applicable legal requirement, safeguarding a person or handling a legal claim: the relevant legal obligation, vital interest or legitimate interest, together with any extra condition required for sensitive information.
- An optional activity for which consent is required: the separate, informed consent presented for that activity. Accepting the Terms or this notice is not that consent.
You may object to processing based on legitimate interests. We will consider the circumstances and explain whether a compelling lawful reason requires it to continue. Where we rely on consent, you may withdraw it without changing the lawfulness of earlier processing.
5. What other members can see
An eligible member may see your approved display name, age, approved photos, broad area or distance band, relationship goal, biography, public prompts or interests and an accurately labelled 18+ age checked badge. The badge means Stripe's configured government-photo-document check passed, the verified date of birth matched the account and the member met the age rule at the time. If the member chose a selfie, the configured face comparison also passed. The badge does not disclose which route was used and does not mean that a background or criminal-record check took place. Other members do not see your full date of birth, exact or rounded coordinates, email address, authentication details, private questionnaire answers, people you passed, report history or moderation records.
An approved profile is shown only through authenticated, app-scoped discovery after both members' current rules are checked. It is not intended to be published as an open web directory. A connection recipient can see the sender's eligible profile and optional introduction. Only matched members can exchange messages.
Shared sign-in infrastructure with Truly Yours does not automatically create another membership or share your Cherry Kiss profile, preferences, matches, messages, reports or subscriptions. A serious person-level safety finding may be considered across communities only through a separate, recorded and authorised process where this is necessary and lawful.
6. How introductions are selected
When discovery is available, the service first applies reciprocal requirements such as active membership, age, current policy choices, approved profile and photos, identity status, chosen audience, age range, distance and relationship-intention lane. A block, pause, suspension or safety restriction prevents an introduction. Payment cannot bypass these requirements or buy a higher place.
Eligible profiles may then be ordered using compatible private answers, shared interests and recent presentation history. We may show a few plain-language reasons, but do not publish private answers or claim a scientifically proven compatibility percentage. We do not rank people by wealth, race or perceived attractiveness.
If an automated eligibility result appears wrong, you can request correction or human help. An automated risk signal may prioritise a case but must not by itself impose a permanent disciplinary ban.
7. Who receives information
- Other eligible Cherry Kiss members receive only the profile and interaction information described above.
- Authorised operator, moderation and technical-support personnel receive the minimum information needed for their role, support, security, review or administration. App-scoped access is required for app-scoped member information.
- Google/Firebase provides authentication and device-notification services. Google or Apple also processes information under its own terms when you choose its sign-in service. Apple Push Notification service may deliver iOS alerts through Firebase.
- Amazon Web Services hosts the application API, operator portal and self-hosted PostgreSQL, Redis and private media storage on the existing server.
- Mailtrap delivers branded account, policy, review, safety and recovery email, including recipient details, message content and delivery information.
- Stripe processes identity-document, device and verification information for the gated identity check, and selfie information only if you choose that route. We do not ask Stripe to use a payment card as identity evidence.
- Professional advisers, emergency services, regulators, courts, law enforcement or another recipient may receive limited information where reasonably necessary and lawful for safety, a legal obligation, legal claim or business transfer.
We do not sell member information or provide a public member directory. Installing an SDK does not mean a feature is active. RevenueCat subscriptions and real-time calling are not active processing covered by this release.
8. International processing
The existing application server is hosted in AWS region ap-south-1, Mumbai, India. Firebase states that Firebase Authentication processes data in the United States. Mailtrap lists US-based infrastructure subprocessors. Stripe may process verification information in the United States and other locations described in its terms and privacy information. We do not promise UK-only storage.
For AWS hosting, the standard AWS service terms incorporate its UK GDPR Addendum and the European Commission's Standard Contractual Clauses as adapted for relevant UK transfers. This is a contractual protection, not a claim that India has UK adequacy status. For Firebase Authentication, Google's Cloud Data Processing Addendum provides for recognised transfer arrangements, including the UK Extension to the EU-US Data Privacy Framework for covered US transfers, and contractual clauses where applicable. Mailtrap's Data Processing Addendum provides for the Data Privacy Framework for covered UK-to-US transfers and UK contractual clauses as a fallback if that framework no longer applies. These arrangements include obligations concerning the protection of personal data and onward processing; they do not make overseas laws identical to UK law. You may ask support@cherrykiss.co.uk for a copy of the relevant safeguards or more information about the arrangements affecting your information. Provider details are available in the AWS UK GDPR guidance, Google Cloud Data Processing Addendum, Google transfer arrangements and Mailtrap Data Processing Addendum.
For processing where Stripe acts for us, Stripe's Data Processing Agreement forms part of the Stripe Services Agreement. Stripe's Data Transfers Addendum provides transfer mechanisms, including the UK Addendum to the standard contractual clauses and an applicable Data Privacy Framework route where their conditions are met. Stripe publishes a service-provider and subprocessor list. These documents are contractual safeguards; they do not mean all Stripe processing stays in the UK, make overseas laws identical to UK law or establish that every destination has a UK adequacy decision.
You may request information about relevant recipients, safeguards and how to obtain a copy at our privacy contact. We may redact security-sensitive or unrelated commercial information without removing information you are entitled to receive.
9. Retention, pause and deletion
We keep information only while needed for its stated purpose, account operation, safety, a legal duty, an unresolved complaint or claim, and the protected backup lifecycle. Indefinite retention is not the default. Feature gates remain closed where the corresponding deletion or minimisation control is not ready.
Stripe's standard processor copy can otherwise remain available for three years. When Identity is active, Cherry Kiss requests irreversible Stripe redaction no later than 30 days after an eligible terminal verification result, and sooner following withdrawal of selfie consent or an eligible account-erasure request, unless a documented legal or safeguarding hold applies. If Stripe cannot accept redaction in the session's current state, the request remains queued for retry or support escalation. Stripe says redaction can take up to four days and may retain information separately where it acts as an independent controller. Cherry Kiss does not describe the provider information as redacted until Stripe confirms it.
Pausing hides your profile from new discovery but keeps your account, existing matches and messages. Unmatching ends direct contact; limited message or safety records may remain where needed for a report, appeal, abuse prevention or legal duty. Blocking keeps the minimum relationship needed to enforce the block without exposing it to the other member.
Leaving Cherry Kiss starts removal of the Cherry Kiss membership and app-scoped content through the applicable deletion process. Full account deletion covers the shared sign-in identity and every joined brand after a separate clear confirmation. An accepted request hides the account and revokes ordinary access promptly, then records the remaining deletion and provider-redaction work. The request screen is a progress record, not proof that every database row, private file, provider copy or protected backup has already been removed. We confirm completion only after the applicable work and retention checks have finished. If an in-app deletion control is unavailable, you may make the same request through our privacy contact. Store billing, if introduced later, would require a separate cancellation step and is not currently active.
Limited records may remain where necessary to document a request or agreement, prevent ban evasion or serious abuse, meet a legal duty or resolve a dispute. They must not be reused for ordinary matching. Protected backups must expire through their lifecycle and must not be restored into ordinary use without reapplying valid deletion records.
10. Your choices and rights
Depending on the law and circumstances, you may ask for access, correction, erasure, restriction, portability, or object to particular processing. You may withdraw consent where we rely on it and ask for information or human involvement where rights concerning automated decisions apply.
You can edit your profile and matching setup, pause discovery, withdraw notification permission or selfie consent, block or unmatch another member, and start an account-deletion request through the available controls. Use our contact email if a control is unavailable, to challenge an identity or moderation outcome, or to request the document-only route. We aim to acknowledge identity-support requests within two business days and provide an identity appeal decision or clear next evidence step within five business days. These are operating targets. We may need proportionate information to confirm that a request is yours; do not email an identity document unless we first provide a secure, explained method.
You can complain to the UK Information Commissioner's Office, or the appropriate regulator where you live. You do not have to contact us first, although we welcome the chance to address your concern. We will not penalise you for making a privacy request or complaint.
11. Security and responsible use
We use protected connections, server-side access checks, private media delivery and role-limited operator controls. Stripe URLs are created only for an authenticated member, are short-lived and are not intended to be logged or shared. Signed provider events, current server state and audit records are used instead of trusting a browser return alone. No system is risk-free.
Keep your account secure and tell us promptly about suspected compromise. Do not send passwords, verification codes, identity documents or unlawful material through ordinary support email. When reporting harmful content, use the in-app report route where available and provide only the evidence needed.
12. Changes
We will update this notice when relevant processing changes and bring material changes to your attention. Each published version is identifiable. An unpublished policy source or code deployment is not publication, and publication is not consent to a separate biometric check. We must obtain any activity-specific choice or consent that the law requires before carrying out that activity.