Sign in

Privacy Policy

Last updated: September 7, 2026 · version 2026-09-07

This policy explains what personal data Allison Feet processes, why, on what legal basis, who receives it, how long we keep it, and what your rights are. It applies to visitors, buyers and sellers alike.

1. Who is responsible

The controller is the operator of Allison Feet, established in Belgium. Privacy questions and requests: info@allisonfeet.com. We have assessed that we are not required to appoint a data protection officer; the contact above handles all requests personally.

Allison Feet is in a testing phase while its business registration in Belgium is being completed. The operator’s legal name, address, enterprise number and VAT number will be published here as soon as the registration is final. Until then, every request, notice or question reaches the operator at info@allisonfeet.com.

2. What we process, why, and on what basis

DataPurposeLegal basis
Account: email address, username, name, profile picture, role (buyer/seller)Creating and running your account, sending service emailsContract (GDPR Art. 6(1)(b))
Identity and age verification: government ID document, selfie video, face geometry derived from them, verification outcomeConfirming that every member who interacts or sells is an adult and is the person on their document; preventing impersonation and stolen contentYour explicit consent for biometric data (Art. 9(2)(a)), given on the consent screen before the check; contract and our legitimate interest in a safe adult platform for the outcome (Art. 6(1)(b), (f)). Withdrawal: email info@allisonfeet.com; a manual review by a person is available on request
Profile you choose to fill in: city, country, date of birth, gender, feet size, height, weight, hair and eye colour, body type, bio and free-text sectionsPresenting your seller profile to visitors (only the age is shown publicly, never the date of birth); letting buyers describe themselves to sellersContract; consent for optional fields (you can leave them empty and clear them at any time). We do not ask for racial or ethnic origin, religion or health data; please do not put such information in free-text fields
Photos and videos you upload, captions, comments, hearts, followsPublishing your gallery and feed activity; the weekly leaderboardContract
Private messages and video-call metadataDelivering chat and calls between members. Calls are not recorded. Chat has no file attachmentsContract; legitimate interest in acting on reports of abuse (Art. 6(1)(f))
Consent records: which Terms, Privacy Policy, biometric notice and upload attestation you accepted, and whenProving what you agreed toLegal obligation and legitimate interest (Art. 6(1)(c), (f))
Reports you file or that concern you, moderation decisions and statements of reasonsHandling notices, keeping the Platform lawful, defending decisionsLegal obligation (Digital Services Act Arts 16–17); legitimate interest
Membership records: plan, period, activation date, price, withdrawal requestsProviding what you paid for; consumer-law and tax recordsContract; legal obligation
IP address and countrySecurity, rate limiting, applying regional access restrictions. The country is read at the edge and not stored with your accountLegitimate interest; legal obligation
Usage analytics (pages, clicks, errors), tied to your account idUnderstanding how the Platform is used and fixing bugsYour consent via the cookie banner (Art. 6(1)(a)); off until you accept

We do not sell personal data, we do not use it for advertising, and we do not train artificial-intelligence models on your content or messages.

3. Automated decisions

Access to interactive features depends on the outcome of the Didit check, which is largely automated. You can always ask for a review by a person, give your point of view and contest the outcome by emailing info@allisonfeet.com. No other decision about you is automated; content removals and suspensions are taken by a person.

4. Who receives your data

We use these service providers as processors under data-processing agreements. Where a provider is outside the European Economic Area, the transfer relies on the safeguard shown; you can ask us for a copy.

ProviderWhat forWhereSafeguard
Didit (Didit Identity Spain, S.L., Barcelona, Spain)Identity and age verification: document check, liveness, face matchEUProcessor agreement; EU establishment
Clerk, Inc. (USA)Sign-in, account and session management, email addressUSAEU–US Data Privacy Framework; standard contractual clauses
Convex, Inc. (USA)Application database (profiles, gallery metadata, reports, consent records)Data stored in the EU (eu-west-1)Standard contractual clauses
Cloudflare, Inc. (USA)Storage and delivery of photos and videos (R2, CDN), child-abuse-material hash scanningEU storage; global edge cacheEU–US Data Privacy Framework; standard contractual clauses
Stream.io, Inc. (USA)Private messaging and video callsUSA / EU regionEU–US Data Privacy Framework; standard contractual clauses
Vercel, Inc. (USA)Web hosting; reads your IP country to apply regional restrictionsEU edge (Frankfurt) and USAStandard contractual clauses
Resend, Inc. (USA)Transactional email (welcome, confirmations, report outcomes)USAEU–US Data Privacy Framework; standard contractual clauses
PostHog, Inc. (EU Cloud, Frankfurt)Product analytics and error tracking, only with your cookie consentEUProcessor agreement; EU hosting

Other members. Seller profiles, galleries and feed activity are public to anyone on the internet. Buyer profiles are visible only to verified sellers. Members you message see your display name and profile picture, never your email or legal name.

Authorities. We disclose data when a court or competent authority orders it, when the law obliges us to report (child sexual abuse material to NCMEC and Child Focus / the Belgian Federal Police), and when someone’s life or safety is at risk.

5. How long we keep data

DataKept
Account, profile, gallery, comments, follows, notificationsUntil you delete your account (notifications: 90 days)
ID document images, selfie, face geometry (at Didit)Deleted by Didit after the retention period configured in our account, which we keep to the minimum needed to resolve disputes about a decision; never longer than while your account exists
Verification outcomeWhile your account exists. After deletion, only the fact, date and outcome of the decision, without any document data, for 5 years to defend legal claims (Art. 17(3)(e))
Private messagesUntil either participant deletes the conversation or you delete your account
Reports, moderation decisions, statements of reasons5 years
Consent records5 years after your account is deleted
Membership and payment records7 years (Belgian accounting and tax law)
Analytics events12 months
Server and security logs30 days

When you delete your account we delete your profile, gallery (including edge-cached copies), comments, hearts, follows, notifications, entitlements and your Stream chat history. Data we are legally required to keep, or that we need to defend a claim, is kept for the periods above and then deleted.

6. Your rights

You can ask us to access, correct, delete or restrict your data, to receive the data you gave us in a portable format, to object to processing based on legitimate interest, and to withdraw consent at any time (this does not affect processing before withdrawal). Email info@allisonfeet.com; we answer within one month. You can also complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, https://www.dataprotectionauthority.be, Drukpersstraat 35, 1000 Brussels, Belgium) or to the authority of the EU country where you live.

Providing an email address and completing verification are requirements of the contract for interactive features; without them you can still browse public pages but cannot chat, call, comment or sell.

7. Biometric data: retention and destruction policy

This section is our written policy for biometric identifiers (face geometry) processed on our behalf, published for the benefit of users in jurisdictions that require one (including the Illinois Biometric Information Privacy Act). Biometric data is collected only after a written notice and your express release on the consent screen; it is used only to verify identity and age; it is never sold, leased or traded; and it is permanently destroyed by our processor when the purpose is fulfilled or within three years of your last interaction with us, whichever comes first, and in any case when you delete your account. Allison Feet itself never stores biometric data.

8. Cookies

See the Cookie Policy. Analytics run only after you accept them in the banner; strictly necessary cookies keep you signed in.

9. Security

Data is encrypted in transit and at rest with our providers; access to verification outcomes and reports is limited to the operator and is logged; media files have unguessable addresses and are removed from the edge cache when deleted. If a breach is likely to put you at risk we notify you and the Data Protection Authority within 72 hours. Choose a strong, unique password and keep your login private.

10. Children

The Platform is for adults only. We do not knowingly collect data from anyone under 18; if you believe a minor has an account or appears in content, report it immediately.

11. Changes

This policy is versioned. Material changes are announced by email and in the app and require your fresh acknowledgement before you continue using interactive features.