Skip to main content

Legal

Privacy Policy

What we collect, why, who sees it, and how to get it back or get rid of it. We do not sell your data and we do not share your profile with other dating sites.

Draft for review. These documents are a thorough starting point, not legal advice. A dating service handles special category personal data, so have a solicitor review this before taking real signups. Placeholders in square brackets still need filling in.

1. Who we are, and our promises

ImmigrantsDating (immigrantsdating.com) is run by Shpetim Braushaj, trading as ImmigrantsDating (a sole trader), [REGISTERED ADDRESS]. We are the "controller" of your personal data, which means we decide how it is used and are responsible for looking after it. Our registration number with the Information Commission (the ICO) is [ICO REGISTRATION NUMBER].

For anything about your data, email privacy@immigrantsdating.com.

Our promises, in plain terms: we do not sell your data; there are no adverts and no advertising trackers in the app; we do not share your profile with other dating services; and we do not build profiles of people who have not signed up.

If you have only joined our waitlist and have no account, section 14 is the part that applies to you.

2. What we collect

Your account: your email address and your password. We never store the password itself — only a one-way scrambled form of it (an Argon2id or bcrypt hash) that cannot be turned back into the password. We also record when you confirmed your email address, accepted our Terms and confirmed that you are 18 or over.

Your profile, which you fill in yourself: your name; your age (stored as your year of birth); your gender and who you are interested in; your sexuality; your height and eye colour; your ethnicity; your zodiac sign; the country you are from, your hometown, the city you live in and the year you arrived; the languages you speak; your work, job title and education; your religion; whether you have children and your family plans; whether you drink or smoke; whether you are here for dating or friendship, and the kind of relationship you are looking for; your interests, hobbies and music; and your bio. Many of these are optional — share only what you are comfortable with. Your sexuality, ethnicity and religion are stored only if you give your separate explicit consent (section 3), and are hidden from other members unless you choose to show each one. We never ask about your immigration status, and you do not need to share it.

Your approximate location, only if you choose to share it. We round it to about 1 km before storing it, and other members only ever see a distance, in 5 km steps.

Your photos — up to five. When you upload a photo we re-encode it, which strips out hidden details such as the camera model and the GPS location where it was taken.

Your verification selfie, which a member of our moderation team reviews. If it is approved we keep it while your account is verified, so a moderator can re-check you if you change your photos later; if it is not approved we delete it straight away. Either way it is deleted when you delete your account.

What you do on the Service: the likes you send and receive (including any note added to them), the profiles you pass on, your matches, and the messages, voice notes and date plans you exchange.

Calls: when you make or receive an audio or video call, we record who called whom, whether it was audio or video, and when it rang, was answered and ended (so how long it lasted). We never record, store or listen to the audio or video of a call, or to its live captions. While a call is being set up, your browser and the other person's exchange connection details through our server, including network (IP) addresses; we delete them as soon as the call ends, and always within an hour.

Safety records: the people you block, the reports you make, and any reports other members make about you. When a report is made, we also keep a copy of the conversation between the two members, including voice notes, and of the reported member's profile as it was at that moment.

Push notifications, only if you turn them on: for each browser or app where you do, the address and keys your browser's push service gives us (on the website) or the device token Firebase gives the app (on iPhone and Android), with the browser or device type and when it last received a notification; and your choices of which notifications you want (new matches, messages, calls).

Translations: when you tap "Translate" under a message you received, or switch on automatic translation in a conversation, we keep the translation with that message so it does not have to be translated again. We also count how many characters are translated each month across all members, as one total that is not linked to anyone.

Automatic check results: when a bio, like note or message matches our short list of words linked to scams, sexual solicitation or hate, we record the match so that a moderator can review it (section 5).

Technical information: your sign-in sessions (when each started and was last used, and the browser or device type your browser reports); short-lived rate-limit records, linked to your IP address or to a hashed form of your email address, which let us slow down repeated sign-in attempts and spam; and when you were last active. Our hosting provider also keeps standard web server logs — such as IP addresses, the pages requested and when — for security and troubleshooting.

Most of this comes from you. Some comes from other members — for example when someone likes you, messages you or reports you.

3. Special category data — please read this

Some information on a dating profile is especially sensitive. Your sexuality, ethnicity and religion are "special category" data under UK data protection law, and get extra protection. We do not ask about drug use.

These three answers — sexuality, ethnicity and religion — are optional, and we store them only if you give your separate, explicit consent. You give it by ticking a box of its own, which is never ticked for you and is separate from accepting our Terms, and we record the time you gave it. Without that consent, we do not store any of the three. Even with consent, each one stays hidden from other members unless you switch on "show on my profile" for it. Ethnicity is never used for matching.

We use these answers only to show them on your profile and to suggest people you may want to meet.

You can withdraw your consent at any time in Settings. Withdrawing it clears all five answers from your profile straight away. You can also remove any one of them by editing your profile. If your profile has been reported, the copy kept with that report as evidence is not changed (section 9). Withdrawing consent does not affect what we did with your answers before you withdrew it.

Your gender and who you are interested in can also reveal your sexual orientation. We need to know who you are interested in to suggest matches, so that answer is required; we use it only for matching and do not show it on your profile.

We do not run your selfie or photos through facial-recognition software. The verification check is done by a person, looking at the pictures. The one exception we are considering is the age check in section 4, which a separate provider would carry out and which we will explain fully before it starts.

4. Age checks

We may add an age check to verification, to make sure everyone on the Service is an adult. A specialist provider, [AGE ASSURANCE PROVIDER — to be confirmed], would carry it out using one of two methods: facial age estimation, where software estimates your age from a live image of your face (it estimates age only and does not work out who you are); or an ID check, where you photograph an identity document and the provider checks that it is genuine and that your face matches its photo.

Age checks have not started. Before they do, we will add the provider's name, where it processes your data and how long it keeps it to this policy, and tell you.

What it means for your data: the images, and any document, go to the provider for the check. We do not receive a copy of your identity document. We receive only the result (whether you passed, the method used and the date) and keep it with your account. [TO CONFIRM with the provider: what it keeps, and for how long.]

Our legal basis: for facial age estimation, our legitimate interest in keeping under-18s off the Service. Matching your face to an ID document uses biometric data, which is special category data, so we would do that only with your explicit consent. [TO CONFIRM in the DPIA.]

An identity document can show your nationality, and some show immigration status. We will never use an age check to find out about your immigration status, and where we can, we will let you choose facial age estimation, which needs no document. If the check cannot confirm that you are 18 or over, you can try the other method or contact us and a person will look at it, so no one is turned away by software alone.

5. Why we use it, and our legal basis

To create and run your account, show your profile to other members, suggest matches, and deliver your likes, messages, voice notes and date plans — because this is necessary to provide the Service you signed up for (our contract with you).

To connect audio and video calls between matches, and to keep a record of when calls happened and how long they lasted (never their content) — because this is necessary to provide the Service, and because of our legitimate interest in looking into reports about a call.

To translate a message you received when you ask us to (by tapping "Translate" or switching on automatic translation) — because it is part of the Service you asked for (our contract with you). The person who wrote the message is in a conversation where translation is a standard feature, and only the words of the message are sent, never who wrote it.

To store and use your sensitive answers (sexuality, ethnicity and religion) — only with your separate explicit consent (section 3); and your optional location — with your consent. You can withdraw either at any time.

To verify members, review reports, suspend accounts, stop suspended people from signing up again, and protect the Service from spam, fraud and attacks — because we have a legitimate interest in keeping members safe and the Service secure, and because a safe, verified community is part of the Service we promise you.

To send the emails the Service needs — confirming your email address, resetting your password, telling you the result of your verification, and warning you if someone tries to register with your email address — because they are necessary to provide the Service. Emails are sent through our hosting provider's mail system. We do not send marketing emails; if we ever want to, we will ask you first.

To keep a copy of a reported conversation (including voice notes) and of the reported profile as evidence, to let moderators read it, and to keep it after the match ends or either account is deleted — because of our legitimate interest in investigating reports fairly and protecting members, and to meet our legal obligations under the Online Safety Act 2023, such as acting on illegal content, handling complaints and appeals, and reporting child sexual exploitation and abuse to the National Crime Agency.

To check bios, like notes and messages automatically against a short list of words linked to scams, sexual solicitation and hate, show any match to a moderator, and show the person receiving a message a safety tip when it mentions money or moving to another app — because of our legitimate interest in protecting members from fraud and abuse, and our duties under the Online Safety Act 2023.

To keep records of reports and suspensions, to report child sexual exploitation and abuse to the National Crime Agency, and to respond to lawful requests from the police, courts or regulators — because of our legitimate interest in safety and in establishing or defending legal claims, and, for reports to the National Crime Agency and wherever else the law requires it, because we have a legal obligation to.

We make no decisions about you by automated means alone that have legal or similarly significant effects on you. Our automatic checks only flag content for a person to look at, or show a safety tip. Verification and suspensions are always decided by a person, and if we introduce age checks, a person will review any result the software cannot confirm (section 4).

6. Who can see your information

Other members: once you are verified, other verified members can see your profile card — your name, your age (never your year of birth), the profile details you have filled in, and roughly how far away you are, in 5 km steps. They can see when you were last active, but only to within 15 minutes.

Your photos are shown only to signed-in, verified members who are allowed to see your profile. They are not published on the public website.

Your matches see the messages, voice notes and date plans you send them. People you have blocked, and people who have blocked you, cannot see you at all.

Calls are peer-to-peer: the audio and video go between your browser and the other person's, encrypted by the browsers themselves, and never through our server. When our call relay is set up, calls are relayed through Cloudflare's TURN service, so neither of you sees the other's IP address; Cloudflare carries the encrypted audio and video but cannot read it, and acts only on our instructions. If the relay is not available, the two devices connect directly and each can see the other's IP address, which can show roughly where someone is.

Live captions in a call are off unless the person speaking turns them on. They are made by that person's own browser, whose speech service may send their voice to the browser's maker (for example Google for Chrome, Microsoft for Edge, Apple for Safari) under that company's own terms. The captions go straight to the other person's browser; we never receive or store them.

Other members never see your email address, your password, your exact location or your verification selfie.

Our moderators see what they need to keep the Service safe: verification selfies, reports, the profile information needed to look into them, and any bio, like note or message our automatic checks have flagged.

Moderators can read a conversation only once one of the two people in it has reported it, and then they read the copy kept with the report. Each time a moderator opens a reported conversation, we log who opened it and when.

Our hosting provider, GoDaddy, runs the web server and the MariaDB database that store the Service, and delivers our emails. It acts only on our instructions, under its Data Processing Addendum (section 7).

Our translation provider, DeepL SE (Cologne, Germany, in the European Union): only when a member taps "Translate" (or has switched on automatic translation), the text of that one message, and the language to translate it into, are sent to DeepL to translate. Nothing else is sent: no names, no profile, no email address and nothing that says who wrote it or who is reading it. DeepL acts only on our instructions, under its data processing agreement. We use DeepL's paid service (DeepL API Pro), under which DeepL deletes the text once it has translated it and does not use it to train or improve its service. DeepL's free service, by contrast, may keep texts to improve its translations, which is why we do not use it for members' messages. If we ever change translation provider, we will name the new one here first.

Push notifications, if you turn them on, say only "You have a new match", "New message" or "Incoming call", in your language, with a link into the app: never a name, a photo or what anyone wrote. On the website they travel through your browser's own push service (Google for Chrome and Edge on Android, Mozilla for Firefox, Apple for Safari, Microsoft for Edge on Windows), encrypted so that the push service cannot read them; it learns only that a notification was sent to your browser, and when. In the iPhone and Android apps they are delivered through Google's Firebase Cloud Messaging (which passes iPhone notifications to Apple's push service), which handles them only to deliver them, as our processor under its data processing terms, and may do so outside the UK and EU under the UK–US data bridge or the UK International Data Transfer Addendum. You can turn notifications off in Settings, on each device, at any time; signing out on a device also stops them there.

If we introduce age checks, our age-check provider, [AGE ASSURANCE PROVIDER — to be confirmed], which will receive only what it needs to check your age and act only on our instructions (section 4).

The National Crime Agency, when we report child sexual exploitation or abuse, as the law requires (section 13).

The police, courts or regulators — only where the law requires it, or where it is necessary to protect someone from serious harm.

That is everyone. We do not sell your data, share it with advertisers, or pass it to other dating services.

7. Where your data is stored

Your data, including waitlist sign-ups, is stored on GoDaddy's servers in its data centre in Strasbourg, France, in the European Union, with daily backups kept by GoDaddy. UK law recognises the EU as giving personal data an adequate level of protection.

GoDaddy's contracting company, GoDaddy.com, LLC, is based in the United States, and it uses other companies to help run its service (for example, the maker of the server software and a backup provider). So some of your data may be accessed from outside the UK and EU — for example by GoDaddy's support staff. When that happens, your data is protected by GoDaddy's Data Processing Addendum, which we have with them: for the United States, by the UK–US "data bridge" (GoDaddy is certified under the UK Extension to the EU–US Data Privacy Framework); for other countries, by UK adequacy regulations or the UK International Data Transfer Addendum included in that agreement. You can read GoDaddy's Data Processing Addendum at godaddy.com/legal/agreements/data-processing-addendum, or ask us for a copy.

Calls relayed through Cloudflare (section 6) pass through the Cloudflare data centre nearest to each of you, which may be outside the UK and EU. The audio and video are encrypted and Cloudflare cannot read them.

8. Cookies and similar technologies

We use one cookie: a sign-in cookie that keeps you logged in. It holds a random code (we store only a scrambled form of it), it cannot be read by scripts on the page (it is "HttpOnly"), it is sent only over an encrypted connection, and it lasts at most 90 days, or until you sign out. The Service cannot work without it, so it does not need your consent.

That is the only cookie. We do not use analytics or advertising cookies.

We count how the site and app are used: for example, how many people visited the pricing page or finished their profile on a given day. We keep only daily totals: no cookie, no identifier, nothing that tells us who you are, and we never share them. We keep them for 25 months to improve the Service (the "statistical purposes" exception in the Privacy and Electronic Communications Regulations). You can switch this off at any time in Settings or on our Cookies page, and we also switch it off automatically if your browser sends a Global Privacy Control or Do Not Track signal.

Your browser also stores a few settings on your own device, in its local storage, so the app remembers them between visits: for example whether notifications are switched on, the currency you chose, and when the app last checked for new messages. They stay on your device and are not used to track you, and you can remove them by clearing your browser's data for our site.

Our fonts and images are served from our own server, so visiting the Service does not send your IP address to Google or any other outside company. The only one that receives it is our host, GoDaddy, which needs it to deliver the pages to you (section 7). If we introduce age checks, the age-check provider will also receive it while you take the check (section 4).

9. How long we keep it

Your account, profile and activity: for as long as you have an account.

Inactive accounts: if you do not sign in for 24 months, we email you, and if you still have not signed in 30 days later we delete your account.

Usage statistics (daily totals only, nothing about you): 25 months.

Your verification selfie: kept while your account is verified (so later photo changes can be re-checked against it), deleted at once if it is not approved, and deleted when you delete your account.

Sign-in sessions: at most 90 days, and ended when you sign out. One-time email links (to confirm your email address or reset your password) expire within days or hours and work only once.

Age-check result, if we introduce age checks: for as long as you have an account (section 4).

Rate-limit records: deleted after about a day.

Call records (who called whom, when, and for how long; never the audio, video or captions): 12 months, so a report about a call can be looked into, then deleted. Call connection details: deleted when the call ends, and always within an hour.

Push notifications: a device's push address or token is kept until you turn notifications off there, sign out there, or the push service tells us it no longer works, and is deleted with your account. The record that a notification was due (who, which kind, which screen; never any content) is deleted after 7 days.

Translations of messages: kept for as long as the message they translate is kept, and deleted with it (for example when either account is deleted). DeepL does not keep them (section 6).

Reported conversations: when a member is reported, we keep a copy of the conversation between the two members, including voice notes, and of the reported profile as it was at that moment, as evidence. The copy is kept even if the match ends or either person deletes their account, for up to 12 months after the report is closed, and is then deleted, unless the law requires us to keep it for longer.

Automatic check matches (a bio, like note or message our automatic checks flagged for a moderator): deleted 12 months after a moderator has reviewed them, or with the account if it is deleted first.

Waitlist sign-ups: see section 14.

Server logs kept by our hosting provider, GoDaddy (these record your IP address, the pages you request and your browser type): deleted after 7 days. Backups: GoDaddy keeps a daily backup copy of the Service, which is replaced every day, so information that has been deleted can remain in a backup for up to 2 days.

We also make our own daily backup of the database, kept on the same server outside the public part of the website, and keep the last 7, so deleted information can also remain in one of these for up to 8 days.

When you delete your account, it happens immediately. Your profile, photos, voice notes, likes, matches and conversations are deleted — including your conversations on the other person's side. The one exception is a conversation that has been reported: the copy kept as evidence is not deleted with your account (see "Reported conversations" above).

What we keep after deletion, and why: reports made about you (with the name on your profile at the time and a hashed copy of your email address), and reports you made (no longer linked to your account), because we may need them to protect other members or to deal with a legal claim. If your account was suspended, we also keep a hashed copy of your email address so it cannot be used to sign up again. We keep these records for [REPORT RETENTION PERIOD — to be confirmed]. Copies of reported conversations and profiles may be kept as evidence for up to 12 months after the report is closed, as described above.

10. Your rights

Access and a copy: in Settings, choose "Download a copy of my data" to get a file (in JSON format) with your account, profile and activity. You can also ask us for anything it does not include.

Correction: you can edit your profile at any time. Tell us if anything else we hold about you is wrong.

Deletion: delete your account in Settings, after confirming your password. It takes effect immediately; section 9 explains the limited records we keep afterwards, including reported conversations kept as evidence.

Objection and restriction: you can object to our use of your data where we rely on legitimate interests, or ask us to limit its use while a concern is looked into.

Withdrawing consent: in Settings, withdraw your consent for your sensitive answers, which clears all five of them (section 3); ask us to remove your location by emailing us; or delete your account. You can do any of these at any time.

To use any of these rights, you can also email privacy@immigrantsdating.com. It is free, we may need to confirm it is really you, and we reply within one month.

If you are unhappy with how we have handled your data, section 11 explains how to complain.

11. Complaints about your data

If you are unhappy with how we have used your personal data, or with how we answered a request about it, please complain to us at privacy@immigrantsdating.com. Sending it to hello@immigrantsdating.com, or by post to [REGISTERED ADDRESS], is fine too. Tell us what happened and what you would like us to do; you do not need a form or any particular wording.

We acknowledge every complaint, normally within 7 days and always within 30, as the law requires. We then look into it properly, keep you updated, and tell you the outcome and our reasons without undue delay, normally within one month. It is the same process as for every complaint, set out in section 13 of our Terms.

You also have the right to complain to the UK data protection regulator, the Information Commission (still known as the ICO), at ico.org.uk or on 0303 123 1113. The ICO will usually expect you to have raised your concern with us first, but complaining to us never takes away your right to go to the ICO.

12. How we protect it

The site uses an encrypted connection (HTTPS). Passwords are stored only as Argon2id or bcrypt hashes, and sign-in codes only in scrambled form, so a copy of our database would not contain anything that could be used directly to sign in as you.

Photos, selfies and voice notes are kept outside the public part of the web server and are handed out only to people allowed to see them. Repeated sign-in attempts and bulk actions are rate-limited.

No system is perfectly secure. If a breach puts your data at risk, we will report it to the ICO within 72 hours where the law requires, and tell you without undue delay if it is likely to put your rights and freedoms at high risk.

13. Children

The Service is only for adults aged 18 and over, and everyone confirms they are 18 or over when they sign up; we may also ask for an age check (section 4). We do not knowingly collect data about anyone under 18. If we learn that an account belongs to a child, we suspend it at once and delete it, keeping only what we need to protect the child or others. Please report anyone you think is under 18.

If we find child sexual exploitation or abuse on the Service, we report it to the National Crime Agency, as UK law requires (section 66 of the Online Safety Act 2023, in force since 7 April 2026). The report includes the information the law requires, such as details of the account and the content concerned. Our legal basis for this is that the law requires it.

14. If you ask to be told when we launch

Asking to be told when we launch, on our Register page, does not create an account. We collect only your email address, and we record when you first asked and when you last gave your consent. Asking again with the same email updates your entry rather than adding a second one. (Entries made before 6 October 2026 may also hold a city and, if you gave them, where you are from and what you were looking for; we no longer use these and clear them when you next sign up or ask us.)

To stop the form being flooded, we also keep a scrambled (hashed) form of your IP address with the times of recent sign-ups from it, and clear these out after about an hour. Our hosting provider's standard server logs (section 2) apply here too.

Why we use it: to email you once, when sign-ups open. We use it for nothing else. It is not shown to members, and it is never sold or shared. Our legal basis is your consent, which you give by ticking the box on the form.

Where it is kept: in a file on our GoDaddy server, outside the public part of the website, so it cannot be downloaded through the site.

How long we keep it: until sign-ups open and we have told you, or until you ask us to remove it, whichever comes first.

Withdrawing your consent: email privacy@immigrantsdating.com (or hello@immigrantsdating.com), ideally from the address you signed up with, and ask to be removed. We will delete your entry promptly, and within one month at the latest. Every launch email we send will also tell you how to opt out. Withdrawing does not affect what we did before. You also have the other rights in section 10, such as asking for a copy of your entry or correcting it.

If you later create an account, the rest of this policy applies to it.

15. Changes to this policy

We will update this policy when the Service or the law changes, and tell you about important changes by email or in the app before they take effect. This version was last updated on 6 October 2026.

Last updated 6 October 2026.