Privacy Policy
Effective: [EFFECTIVE DATE] · Marlow, Inc. [entity placeholder]
Marlow is a paid, private matchmaking service. Our business model is your membership fee — not
your data. This policy says plainly what we collect, why, who touches it, and how to delete it.
1. What we collect
You give us:
— Application & profile: name, date of birth, gender, orientation, profession, photos,
free-text answers (life goals, ideal date, relationship history, deal-breakers), voice notes,
cities and travel patterns, relationship intent.
— Private preferences (sensitive): income range and partner-income preference, financial
style, religion and practice, political leaning, monogamy and intimacy preferences, lifestyle
(alcohol, cannabis, other substances). These are **encrypted at rest, never shown on any
profile, never sold, never browsed by staff, and read only by the matching system**; every
programmatic access is logged. Providing them is optional (skipping may reduce match quality).
— Messages & coach conversations: chats with matches; conversations with Aria. Aria
conversations are private to you, are not shared with matches, are not used to train
third-party AI models, and are deletable by you at any time.
Generated or collected during use:
— Verification data: government ID images and extracted data, biometric identifiers
(face geometry from your liveness selfie — see the Biometric Consent for retention limits),
phone/email confirmation, optional LinkedIn verification.
— Background check results via our consumer-reporting partner (see the Background Check
Disclosure): criminal-record categories, registry status, marriage-status indicators. We
store the adjudication outcome, not the full report, past the verification decision.
— Matching signals: compatibility scores and internal pairing signals derived from your
application, photos, and in-app decisions (see AI & Automated Processing Disclosure).
— Usage & device data: first-party analytics events (allow-listed), IP-derived
city-level location, device type. Trip Mode, if you enable it, uses device location to
detect the *city* you are in; we store city names and dates only — never precise coordinates,
and matches never see live location.
2. What we never do
— Never sell or rent personal data. Not to advertisers, brokers, or affiliates.
— No third-party advertising trackers. No Meta pixel, no TikTok pixel, no ad SDKs.
— Never display private preferences — matches see at most derived compatibility statements
("open to interfaith"), never your answers.
— Never use your face data for anything except verification — no training, no marketing.
3. Why we process data (and legal bases where GDPR applies)
4. Who receives data
Processors under contract, only what each needs: Stripe (payments), Persona/[Onfido]
(ID + liveness), Checkr (background screening — acting as a consumer reporting agency),
Twilio (SMS), Resend (email), Vercel & Supabase (hosting; encrypted at rest), Mapbox (city
lookup), Anthropic (AI processing of the text needed for matching rationale, parsing, and Aria
— under a no-training data-processing agreement), Daily.co (video calls; not recorded by
default). Plus: authorities when legally compelled (we publish counts in a quarterly
transparency report), and successors in a merger (with notice).
5. Retention
— Account data: life of the account + [30] days after deletion completes.
— Deletion is real: Settings → Privacy Dashboard → Delete. 7-day recovery window, then
permanent erasure of profile, matches, conversations (including your side in counterparts'
threads), coach history, and matching signals. Legal/financial records (invoices, bond
transactions, safety reports) are retained as required by law.
— ID images and biometric templates: deleted on the schedule in the Biometric Consent
(verification decision + [12] months maximum, or upon account deletion, whichever is sooner).
— Background reports: adjudication outcome only; underlying report not retained past decision.
6. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar): access, portability
(one-tap "Download my data"), correction, deletion, restriction, objection to profiling, and
the right not to face fully-automated decisions with legal or similarly significant effects —
application rejections at Marlow always involve human review. Exercise any right in the
Privacy Dashboard or via privacy@marlowlove.com. We don't discriminate for exercising rights.
CPRA: we do not "sell" or "share" personal information as defined; sensitive-PI use is limited
to providing the service you requested.
7. Security
Encryption in transit and at rest; column-level encryption with managed keys for private
preferences and internal matching signals; row-level security on every table; access on
least-privilege with append-only audit logs; annual penetration testing; breach notification as
required by law. No system is perfect — see Section 6 rights and our transparency report.
8. International transfers
Data is processed in the United States. Where GDPR applies, transfers rely on Standard
Contractual Clauses with each processor. [Counsel: confirm EU representative + UK rep needs.]
9. Children
Marlow is 21+. We do not knowingly process data of anyone under 21, and age is verified
against government ID.
10. Changes & contact
Material changes: 30 days' notice. Questions: privacy@marlowlove.com · Marlow, Inc. [ADDRESS].
[Counsel: confirm whether a DPO is required.]
Draft — under legal review · legal@marlowlove.com