Privacy Policy
Last updated: September 7, 2026 · version 2026-09-07
This policy explains what personal data Allison Feet processes, why, on what legal basis, who receives it, how long we keep it, and what your rights are. It applies to visitors, buyers and sellers alike.
1. Who is responsible
The controller is the operator of Allison Feet, established in Belgium. Privacy questions and requests: info@allisonfeet.com. We have assessed that we are not required to appoint a data protection officer; the contact above handles all requests personally.
Allison Feet is in a testing phase while its business registration in Belgium is being completed. The operator’s legal name, address, enterprise number and VAT number will be published here as soon as the registration is final. Until then, every request, notice or question reaches the operator at info@allisonfeet.com.
2. What we process, why, and on what basis
| Data | Purpose | Legal basis |
|---|---|---|
| Account: email address, username, name, profile picture, role (buyer/seller) | Creating and running your account, sending service emails | Contract (GDPR Art. 6(1)(b)) |
| Identity and age verification: government ID document, selfie video, face geometry derived from them, verification outcome | Confirming that every member who interacts or sells is an adult and is the person on their document; preventing impersonation and stolen content | Your explicit consent for biometric data (Art. 9(2)(a)), given on the consent screen before the check; contract and our legitimate interest in a safe adult platform for the outcome (Art. 6(1)(b), (f)). Withdrawal: email info@allisonfeet.com; a manual review by a person is available on request |
| Profile you choose to fill in: city, country, date of birth, gender, feet size, height, weight, hair and eye colour, body type, bio and free-text sections | Presenting your seller profile to visitors (only the age is shown publicly, never the date of birth); letting buyers describe themselves to sellers | Contract; consent for optional fields (you can leave them empty and clear them at any time). We do not ask for racial or ethnic origin, religion or health data; please do not put such information in free-text fields |
| Photos and videos you upload, captions, comments, hearts, follows | Publishing your gallery and feed activity; the weekly leaderboard | Contract |
| Private messages and video-call metadata | Delivering chat and calls between members. Calls are not recorded. Chat has no file attachments | Contract; legitimate interest in acting on reports of abuse (Art. 6(1)(f)) |
| Consent records: which Terms, Privacy Policy, biometric notice and upload attestation you accepted, and when | Proving what you agreed to | Legal obligation and legitimate interest (Art. 6(1)(c), (f)) |
| Reports you file or that concern you, moderation decisions and statements of reasons | Handling notices, keeping the Platform lawful, defending decisions | Legal obligation (Digital Services Act Arts 16–17); legitimate interest |
| Membership records: plan, period, activation date, price, withdrawal requests | Providing what you paid for; consumer-law and tax records | Contract; legal obligation |
| IP address and country | Security, rate limiting, applying regional access restrictions. The country is read at the edge and not stored with your account | Legitimate interest; legal obligation |
| Usage analytics (pages, clicks, errors), tied to your account id | Understanding how the Platform is used and fixing bugs | Your consent via the cookie banner (Art. 6(1)(a)); off until you accept |
We do not sell personal data, we do not use it for advertising, and we do not train artificial-intelligence models on your content or messages.
3. Automated decisions
Access to interactive features depends on the outcome of the Didit check, which is largely automated. You can always ask for a review by a person, give your point of view and contest the outcome by emailing info@allisonfeet.com. No other decision about you is automated; content removals and suspensions are taken by a person.
4. Who receives your data
We use these service providers as processors under data-processing agreements. Where a provider is outside the European Economic Area, the transfer relies on the safeguard shown; you can ask us for a copy.
| Provider | What for | Where | Safeguard |
|---|---|---|---|
| Didit (Didit Identity Spain, S.L., Barcelona, Spain) | Identity and age verification: document check, liveness, face match | EU | Processor agreement; EU establishment |
| Clerk, Inc. (USA) | Sign-in, account and session management, email address | USA | EU–US Data Privacy Framework; standard contractual clauses |
| Convex, Inc. (USA) | Application database (profiles, gallery metadata, reports, consent records) | Data stored in the EU (eu-west-1) | Standard contractual clauses |
| Cloudflare, Inc. (USA) | Storage and delivery of photos and videos (R2, CDN), child-abuse-material hash scanning | EU storage; global edge cache | EU–US Data Privacy Framework; standard contractual clauses |
| Stream.io, Inc. (USA) | Private messaging and video calls | USA / EU region | EU–US Data Privacy Framework; standard contractual clauses |
| Vercel, Inc. (USA) | Web hosting; reads your IP country to apply regional restrictions | EU edge (Frankfurt) and USA | Standard contractual clauses |
| Resend, Inc. (USA) | Transactional email (welcome, confirmations, report outcomes) | USA | EU–US Data Privacy Framework; standard contractual clauses |
| PostHog, Inc. (EU Cloud, Frankfurt) | Product analytics and error tracking, only with your cookie consent | EU | Processor agreement; EU hosting |
Other members. Seller profiles, galleries and feed activity are public to anyone on the internet. Buyer profiles are visible only to verified sellers. Members you message see your display name and profile picture, never your email or legal name.
Authorities. We disclose data when a court or competent authority orders it, when the law obliges us to report (child sexual abuse material to NCMEC and Child Focus / the Belgian Federal Police), and when someone’s life or safety is at risk.
5. How long we keep data
| Data | Kept |
|---|---|
| Account, profile, gallery, comments, follows, notifications | Until you delete your account (notifications: 90 days) |
| ID document images, selfie, face geometry (at Didit) | Deleted by Didit after the retention period configured in our account, which we keep to the minimum needed to resolve disputes about a decision; never longer than while your account exists |
| Verification outcome | While your account exists. After deletion, only the fact, date and outcome of the decision, without any document data, for 5 years to defend legal claims (Art. 17(3)(e)) |
| Private messages | Until either participant deletes the conversation or you delete your account |
| Reports, moderation decisions, statements of reasons | 5 years |
| Consent records | 5 years after your account is deleted |
| Membership and payment records | 7 years (Belgian accounting and tax law) |
| Analytics events | 12 months |
| Server and security logs | 30 days |
When you delete your account we delete your profile, gallery (including edge-cached copies), comments, hearts, follows, notifications, entitlements and your Stream chat history. Data we are legally required to keep, or that we need to defend a claim, is kept for the periods above and then deleted.
6. Your rights
You can ask us to access, correct, delete or restrict your data, to receive the data you gave us in a portable format, to object to processing based on legitimate interest, and to withdraw consent at any time (this does not affect processing before withdrawal). Email info@allisonfeet.com; we answer within one month. You can also complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, https://www.dataprotectionauthority.be, Drukpersstraat 35, 1000 Brussels, Belgium) or to the authority of the EU country where you live.
Providing an email address and completing verification are requirements of the contract for interactive features; without them you can still browse public pages but cannot chat, call, comment or sell.
7. Biometric data: retention and destruction policy
This section is our written policy for biometric identifiers (face geometry) processed on our behalf, published for the benefit of users in jurisdictions that require one (including the Illinois Biometric Information Privacy Act). Biometric data is collected only after a written notice and your express release on the consent screen; it is used only to verify identity and age; it is never sold, leased or traded; and it is permanently destroyed by our processor when the purpose is fulfilled or within three years of your last interaction with us, whichever comes first, and in any case when you delete your account. Allison Feet itself never stores biometric data.
8. Cookies
See the Cookie Policy. Analytics run only after you accept them in the banner; strictly necessary cookies keep you signed in.
9. Security
Data is encrypted in transit and at rest with our providers; access to verification outcomes and reports is limited to the operator and is logged; media files have unguessable addresses and are removed from the edge cache when deleted. If a breach is likely to put you at risk we notify you and the Data Protection Authority within 72 hours. Choose a strong, unique password and keep your login private.
10. Children
The Platform is for adults only. We do not knowingly collect data from anyone under 18; if you believe a minor has an account or appears in content, report it immediately.
11. Changes
This policy is versioned. Material changes are announced by email and in the app and require your fresh acknowledgement before you continue using interactive features.

