marlow. marlowlove.com

Privacy Policy

Draft · under legal review · effective date pending
Questions: privacy@marlowlove.com

Marlow is a paid, private matchmaking service. Our business model is your membership fee — not your data. This policy says plainly what we collect, why, who touches it, and how to delete it.

1. What we collect

You give us:

Generated or collected during use:

2. What we never do

3. Why we process data (and legal bases where GDPR applies)

PurposeDataBasis
Matching & introductionsapplication, photos, preferences, signalsContract; explicit consent for special-category data (Art. 9(2)(a))
Verification & safetyID, biometrics, background results, reportsContract; legal obligation; substantial-public-interest/safety; consent where required
Aria coachingyour coach conversationsContract; consent
Billingpayment tokens (held by Stripe)Contract
Service communicationsemail, phone, push (4 types only)Contract; consent for optional check-ins
Product analyticsfirst-party eventsLegitimate interest (no profiling for ads)

4. Who receives data

Processors under contract, only what each needs: Stripe (payments), Persona/[Onfido] (ID + liveness), Checkr (background screening — acting as a consumer reporting agency), Twilio (SMS), Resend (email), Vercel & Supabase (hosting; encrypted at rest), Mapbox (city lookup), Anthropic (AI processing of the text needed for matching rationale, parsing, and Aria — under a no-training data-processing agreement), Daily.co (video calls; not recorded by default). Plus: authorities when legally compelled (we publish counts in a quarterly transparency report), and successors in a merger (with notice).

5. Retention

6. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar): access, portability (one-tap "Download my data"), correction, deletion, restriction, objection to profiling, and the right not to face fully-automated decisions with legal or similarly significant effects — application rejections at Marlow always involve human review. Exercise any right in the Privacy Dashboard or via privacy@marlowlove.com. We don't discriminate for exercising rights. CPRA: we do not "sell" or "share" personal information as defined; sensitive-PI use is limited to providing the service you requested.

7. Security

Encryption in transit and at rest; column-level encryption with managed keys for private preferences and internal matching signals; row-level security on every table; access on least-privilege with append-only audit logs; annual penetration testing; breach notification as required by law. No system is perfect — see Section 6 rights and our transparency report.

8. International transfers

Data is processed in the United States. Where GDPR applies, transfers rely on Standard Contractual Clauses with each processor. [Counsel: confirm EU representative + UK rep needs.]

9. Children

Marlow is 21+. We do not knowingly process data of anyone under 21, and age is verified against government ID.

10. Changes & contact

Material changes: 30 days' notice. Questions: privacy@marlowlove.com · Marlow, Inc. [ADDRESS]. [Counsel: confirm whether a DPO is required.]