Marlow is a paid, private matchmaking service. Our business model is your membership fee — not your data. This policy says plainly what we collect, why, who touches it, and how to delete it.
1. What we collect
You give us:
- Application & profile: name, date of birth, gender, orientation, profession, photos, free-text answers (life goals, ideal date, relationship history, deal-breakers), voice notes, cities and travel patterns, relationship intent.
- Private preferences (sensitive): income range and partner-income preference, financial style, religion and practice, political leaning, monogamy and intimacy preferences, lifestyle (alcohol, cannabis, other substances). These are encrypted at rest, never shown on any profile, never sold, never browsed by staff, and read only by the matching system; every programmatic access is logged. Providing them is optional (skipping may reduce match quality).
- Messages & coach conversations: chats with matches; conversations with Aria. Aria conversations are private to you, are not shared with matches, are not used to train third-party AI models, and are deletable by you at any time.
Generated or collected during use:
- Verification data: government ID images and extracted data, biometric identifiers (face geometry from your liveness selfie — see the Biometric Consent for retention limits), phone/email confirmation, optional LinkedIn verification.
- Background check results via our consumer-reporting partner (see the Background Check Disclosure): criminal-record categories, registry status, marriage-status indicators. We store the adjudication outcome, not the full report, past the verification decision.
- Matching signals: compatibility scores and internal pairing signals derived from your application, photos, and in-app decisions (see AI & Automated Processing Disclosure).
- Usage & device data: first-party analytics events (allow-listed), IP-derived city-level location, device type. Trip Mode, if you enable it, uses device location to detect the city you are in; we store city names and dates only — never precise coordinates, and matches never see live location.
2. What we never do
- Never sell or rent personal data. Not to advertisers, brokers, or affiliates.
- No third-party advertising trackers. No Meta pixel, no TikTok pixel, no ad SDKs.
- Never display private preferences — matches see at most derived compatibility statements ("open to interfaith"), never your answers.
- Never use your face data for anything except verification — no training, no marketing.
3. Why we process data (and legal bases where GDPR applies)
| Purpose | Data | Basis |
|---|---|---|
| Matching & introductions | application, photos, preferences, signals | Contract; explicit consent for special-category data (Art. 9(2)(a)) |
| Verification & safety | ID, biometrics, background results, reports | Contract; legal obligation; substantial-public-interest/safety; consent where required |
| Aria coaching | your coach conversations | Contract; consent |
| Billing | payment tokens (held by Stripe) | Contract |
| Service communications | email, phone, push (4 types only) | Contract; consent for optional check-ins |
| Product analytics | first-party events | Legitimate interest (no profiling for ads) |
4. Who receives data
Processors under contract, only what each needs: Stripe (payments), Persona/[Onfido] (ID + liveness), Checkr (background screening — acting as a consumer reporting agency), Twilio (SMS), Resend (email), Vercel & Supabase (hosting; encrypted at rest), Mapbox (city lookup), Anthropic (AI processing of the text needed for matching rationale, parsing, and Aria — under a no-training data-processing agreement), Daily.co (video calls; not recorded by default). Plus: authorities when legally compelled (we publish counts in a quarterly transparency report), and successors in a merger (with notice).
5. Retention
- Account data: life of the account + [30] days after deletion completes.
- Deletion is real: Settings → Privacy Dashboard → Delete. 7-day recovery window, then permanent erasure of profile, matches, conversations (including your side in counterparts' threads), coach history, and matching signals. Legal/financial records (invoices, bond transactions, safety reports) are retained as required by law.
- ID images and biometric templates: deleted on the schedule in the Biometric Consent (verification decision + [12] months maximum, or upon account deletion, whichever is sooner).
- Background reports: adjudication outcome only; underlying report not retained past decision.
6. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar): access, portability (one-tap "Download my data"), correction, deletion, restriction, objection to profiling, and the right not to face fully-automated decisions with legal or similarly significant effects — application rejections at Marlow always involve human review. Exercise any right in the Privacy Dashboard or via privacy@marlowlove.com. We don't discriminate for exercising rights. CPRA: we do not "sell" or "share" personal information as defined; sensitive-PI use is limited to providing the service you requested.
7. Security
Encryption in transit and at rest; column-level encryption with managed keys for private preferences and internal matching signals; row-level security on every table; access on least-privilege with append-only audit logs; annual penetration testing; breach notification as required by law. No system is perfect — see Section 6 rights and our transparency report.
8. International transfers
Data is processed in the United States. Where GDPR applies, transfers rely on Standard Contractual Clauses with each processor. [Counsel: confirm EU representative + UK rep needs.]
9. Children
Marlow is 21+. We do not knowingly process data of anyone under 21, and age is verified against government ID.
10. Changes & contact
Material changes: 30 days' notice. Questions: privacy@marlowlove.com · Marlow, Inc. [ADDRESS]. [Counsel: confirm whether a DPO is required.]