CS

Privacy Policy

Last updated: September 1, 2026|Effective date: October 1, 2026|v1.9.0

Recent Changes

Summary of updates to this policy

These changes will take effect on October 1, 2026. By continuing to use our service after this date, you agree to the updated terms.

  • Added the identity-document age-verification method: what is collected, that a person reviews it rather than facial recognition, and that it is deleted on the decision and within 7 days regardless

Summary

This summary provides a brief overview of our Privacy Policy. Please read the full policy below for complete details.

  • We collect your email, profile information, and location data to provide our service
  • Your location is used to show you nearby users but your exact location is never shared
  • We do not sell your personal information to third parties
  • You can request access to, correction of, or deletion of your data at any time
  • We use industry-standard security measures to protect your information
  • You must be 18 or older to use this service
  • We may review messages to enforce our Terms of Service and protect user safety
  • We apply the same strong privacy rights to all users worldwide, even when local laws require less

1. Introduction

ClubSilver.ORG, operated by All That Net Holdings, LLC ("CS," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our location-based social application and related services (collectively, the "Service").

We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Personal Information Protection and Electronic Documents Act (PIPEDA). This policy is designed to meet the requirements of these and other applicable privacy laws.

By using our Service, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with our practices, please do not use the Service.

We believe everyone deserves strong privacy protections. We apply privacy rights modeled on the world's most protective frameworks—including data access, correction, deletion, and portability—to all users worldwide, even when local laws require less.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, password, legal name (for account verification, never shown to other users), and date of birth (to verify you meet our age requirement)
  • Profile Information: Photos, biography, interests, and other details you add to your profile
  • Communications: Messages you send to other users, support requests, and feedback
  • Payment Information: Billing details processed by our payment providers (we do not store full payment card numbers)
  • Verification Data: Information provided for account verification purposes

2.2 Information Collected Automatically

  • Location Data: Geographic location when you use location-based features (with your permission)
  • Device Information: Device type, operating system, unique device identifiers, and mobile network information
  • Usage Data: Pages visited, features used, time spent, and interaction patterns
  • Log Data: IP address, browser type, access times, and referring URLs
  • Cookies and Tracking: Information collected through cookies, pixels, device identifiers, and similar technologies for authentication, security, and fraud prevention

2.3 Information from Third Parties

  • Social Login: If you sign in using Google or Apple, we receive basic profile information from those services
  • Analytics Partners: Aggregated analytics data about Service usage

2.4 Sensitive Personal Data (GDPR Art. 9 / LGPD)

Some profile fields — specifically HIV status and sexual orientation — constitute special category data under GDPR Article 9 and sensitive personal data under LGPD. This data is:

  • Collected only with your separate, explicit consent, which you may give or withhold at the profile-completion step without affecting your ability to create an account. You may revoke this consent at any time from Edit Profile > Sensitive Information, after which the data will be anonymised within 30 days.
  • Never shared with third parties for advertising purposes, never used for automated profiling unrelated to matching, and stored with additional access controls beyond our standard personal data handling. Your consent choice and timestamp are recorded in an auditable consent log per GDPR Art. 7(1).

2.5 Age Verification

Where age verification is required, you choose how to complete it: by registering a payment card (which is not charged), by submitting a photo of an identity document together with a short live capture, or, where we offer it, by a facial age check. In jurisdictions where age verification is legally required (currently the United Kingdom and the United States), users without an active payment method on file may be asked to complete a facial age check. During this process, your device camera captures a short liveness check. The image is transmitted to our own servers and processed by our private age estimation service; no raw image is retained in any storage system. All AI processing runs on our own privately-operated infrastructure - your image is never transmitted to any third-party service. The check estimates how old you appear; it does not identify you, and no facial template is created or kept. Only a derived result - whether your estimated age meets our threshold - is stored as proof of verification. We ask for your explicit, freely-given consent before any image is captured, and you may decline and use a payment card as an alternative verification method.

To withdraw biometric consent at any time, contact dpo@clubsilver.org. We will delete the stored age estimate record within 30 days and your account will require card-based age verification going forward. Withdrawal of consent does not affect your account status.

2.6 Photo Moderation — Automated Gender and Age Estimation

cs is a men-only membership service. To enforce this membership criterion, we apply automated image analysis to every profile photo you upload. Our private age estimation service analyses your photo to estimate the apparent age and gender of the person depicted. All processing runs on our own privately-operated servers — your photo is never transmitted to any third-party AI provider.

Legal basis: processing for membership eligibility assessment is carried out under GDPR Art. 6(1)(b) (performance of a contract — verifying you meet the membership criteria you agreed to in our Terms of Service) and GDPR Art. 6(1)(f) (legitimate interests — enforcing membership eligibility and community safety policies). No biometric data is collected: the photo is processed transiently to produce a derived conclusion (estimated age and apparent gender classification); no facial geometry or biometric templates are extracted or retained. This service operates as a men-only club and is accordingly exempt from gender-equality obligations under UK Equality Act 2010, Schedule 3 §27 and EU Directive 2004/113/EC Art. 4(5).

Separately, if you choose to earn an authenticity badge, you consent to biometric processing under GDPR Article 9(2)(a). To confirm that a photo shows the same person as your live check, and to compare photos you upload later against the photo a reviewer approved, we compute a mathematical representation of the face (a template) on our own private infrastructure. The template is derived for the comparison and is not shared with anyone. This is optional, applies only to accounts that request the badge, and you can withdraw at any time - which removes the badge and deletes the reference photo. We do not run this processing for users in Illinois or Texas.

Photos that do not depict a person (no detectable face), depict a person estimated to be under 25 years of age, depict explicit sexual content, or are classified as depicting a woman are flagged for moderator review or — when automated enforcement is enabled — immediately rejected. No raw photo or derived biometric estimate is shared with any third party. You may request human review of any automated moderation decision by contacting our support team.

3. How We Use Your Information

We use your information for the following purposes:

3.1 Service Provision

  • Create and manage your account
  • Enable location-based discovery and connections
  • Facilitate communication between users
  • Process transactions and premium purchases
  • Provide customer support

3.2 Service Improvement

  • Analyze usage patterns to improve features
  • Develop new products and services
  • Conduct research and analytics
  • Test and troubleshoot new features

3.3 Safety and Security

  • Detect and prevent fraud, abuse, and security threats
  • Enforce our Terms of Service and community guidelines
  • Verify user identity and prevent unauthorized access
  • Moderate content and investigate reports

3.4 Communications

  • Send service-related notifications
  • Provide updates about policy changes
  • Send marketing communications (with your consent)
  • Respond to your inquiries

3.5 Legal Basis for Processing (GDPR)

Under GDPR, we process your data based on:

  • Contract: Processing necessary to provide the Service you requested
  • Consent: Where you have given specific consent (e.g., marketing, location)
  • Legitimate Interests: For fraud prevention, security, and service improvement
  • Legal Obligation: To comply with applicable laws and regulations
  • Legitimate Interests (Content Moderation): We review user content, including messages, to protect users from harassment, illegal content, fraud, and Terms of Service violations. We have conducted a Legitimate Interest Assessment and determined that user safety interests outweigh the privacy impact, as users reasonably expect content moderation when agreeing to our Terms of Service

3.6 Content Moderation and Message Review

We scan all user-generated content — including messages, photos, and profile information — for policy violations. Moderation is assisted by automated systems. Human access to private content is limited and targeted in scope; all such access is logged with a stated purpose and restricted to authorised trust and safety personnel.

  • Automated Monitoring: We use automated tools to scan content for potential violations of our Terms of Service, including spam, harassment, illegal content, and fraud
  • Flagging for Review: Content may be flagged for human review when: (1) a user submits a report, or (2) our automated systems detect potential safety concerns
  • Human Review: Human access to content is limited and targeted. Trust and safety personnel may access content within the scope of their role; all access is logged with a stated purpose and restricted to authorised personnel.

Your private content — including messages, photos under review, and sensitive personal data — is not used to target you with advertising or to build commercial profiles based on that content. We do not share your data with third parties for any purpose not declared in this policy.

3.7 Automated Decision-Making

We use automated systems for moderation and to personalise your experience. This includes:

  • Detection of spam, bots, and fake accounts
  • Identification of potentially harmful content
  • Risk scoring for fraud prevention
  • Enforcement of rate limits and abuse prevention
  • Interest inference: we analyse the text in your profile bio using an automated classification system running on our own private servers to infer topic interests (e.g. music, fitness) that are used to improve discover ranking. Your profile text is never shared with any third-party AI service. This processing is based on your consent given at profile completion. You may view and remove inferred interests at any time from Edit Profile.
  • Age estimation: for users in age-assurance jurisdictions, we use our own private automated age estimation service to determine whether a user meets the 18+ age requirement. Processing uses a conservative threshold to minimise the risk of incorrectly admitting underage users. Your facial image is never shared with any third-party service. This processing is based on your explicit biometric consent. See Section 2.5 for full details.
  • Gender classification for membership eligibility: every profile photo is analysed by our private automated service to classify the apparent gender of the person depicted. cs is a men-only membership service and photos classified as depicting a woman are flagged for moderator review. All processing runs on our own privately-operated servers. See Section 2.6 for the legal basis and your right to request human review.
  • Explicit content detection and upload restrictions: profile photos are scanned by automated classifiers running on our own privately-operated servers to detect explicit sexual content (NSFW detection). Repeated moderation rejections accumulate an account-level violation score; if this score exceeds a threshold, new photo uploads may be temporarily restricted until an administrator reviews and resets the score. You may contact support to appeal any upload restriction or request human review of a moderation decision.

Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that significantly affect you. For moderation actions that result in account suspension or termination, you may request human review by contacting our support team. Under GDPR Article 21, you may object at any time to interest inference processing; to do so, remove your interests from Edit Profile or withdraw your consent there.

Premium albums: photos stored in your premium albums are held on our servers and undergo the same automated and, where flagged, human safety review as profile photos before they become visible to any recipient. This review checks for illegal content, non-consensual imagery, and content depicting minors. Photos that do not pass review are not shared. You can share an album with other logged-in members and revoke access at any time from the album settings.

4. Location Information

Location data is central to our Service. Here's how we handle it:

4.1 How We Use Location

  • Show you other users nearby
  • Calculate and display distances to other users
  • Provide location-based recommendations

4.2 What We Share

We never share your exact location with other users. Other users only see:

  • Approximate distance from their location (e.g., "2 km away")
  • General area at neighborhood or city level (optional)

4.3 Your Control

  • You can disable location sharing in your device settings
  • You can hide your distance from other users in privacy settings
  • Location history is not stored indefinitely. Precise GPS coordinates are cleared automatically after 90 days of account inactivity.

5. Information Sharing and Disclosure

5.1 With Other Users

Your profile information (photos, bio, age, approximate location) is visible to other users as part of the Service. You can control visibility through privacy settings.

5.2 With Service Providers

We share information with vendors who assist in providing the Service, including:

  • Cloud hosting and infrastructure providers
  • Payment processors
  • Email delivery services

All service providers are contractually bound to protect your information and may only use it for the specific services they provide to us.

5.3 For Legal Reasons

We may disclose information when required to:

  • Comply with legal obligations, court orders, or legal processes
  • Protect our rights, property, or safety
  • Protect the safety of our users or the public
  • Detect, prevent, or address fraud, security, or technical issues

5.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.

5.5 We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties. We do not share your data with third parties for any purpose not declared in this policy. Your private content and sensitive personal data are never shared with advertising networks or third-party data brokers.

6. Data Retention

We retain your information for as long as necessary to:

  • Provide the Service and maintain your account
  • Comply with legal obligations
  • Resolve disputes and enforce our agreements
  • Protect against fraud and abuse

6.1 Retention Periods

  • Account Data: Retained while your account is active and for 30 days following account deletion, after which your personal data is permanently deleted.
  • Messages: Archived after 365 days of inactivity; permanently deleted 1 year after archiving
  • Photos and Media: Retained while your account is active and permanently deleted within 30 days of account deletion.
  • Legal Records: May be retained longer as required by law
  • Precise Location (GPS): Cleared automatically after 90 days of account inactivity
  • IP-Based Location: Refreshed on each login; cleared after 12 months of inactivity
  • Audit Logs: Security and compliance audit records are retained as long as necessary for abuse investigation and legal compliance; permanently deleted after 7 years per regulatory requirements (GDPR Art. 5(1)(e)).
  • Payment Records: Stripe, our payment processor, is the system of record for transaction details and billing history. Stripe retains these records under its own regulatory obligations (including U.S. tax and anti-money-laundering rules). On our own systems we retain only the minimal premium-access metadata required to enforce premium access — checkout-session id, purchase status, and term end date — for as long as your account is active and for 30 days after deletion.

6.2 Account Deletion

You may delete your account at any time through your account settings. When you delete your account, your profile, messages, and activity are immediately hidden and your login is disabled. Your personal data will be permanently deleted within 30 days. Account deletion is not reversible. You may also submit a GDPR Art. 17 data erasure request separately if you require written confirmation or earlier action.

Backup systems may retain copies of your data for a limited period after deletion as part of our standard data protection procedures. These backups are eventually overwritten through normal backup rotation.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication mechanisms
  • Periodic security assessments
  • Access controls and employee training
  • Incident response procedures

While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

8. Your Rights and Choices

8.1 General Rights

All users have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and personal data
  • Opt-out of marketing communications via the unsubscribe link in any email (no login required)
  • Control location sharing through device settings
  • Adjust privacy settings within the app

8.2 European Union Rights (GDPR)

If you are in the EEA, UK, or Switzerland, you have additional rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

Data Protection Officer: You may contact our DPO at dpo@clubsilver.org

8.3 California Rights (CCPA/CPRA)

California residents have the following rights:

  • Right to Know: Request disclosure of personal information collected, used, and shared
  • Right to Delete: Request deletion of personal information
  • Right to Correct: Request correction of inaccurate information
  • Right to Opt-Out: Opt-out of the sale or sharing of personal information (we do not sell your data)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights
  • Right to Limit: Limit use of sensitive personal information

Categories of Information: We collect identifiers, commercial information, internet activity, geolocation data, and profile information as detailed in Section 2.

8.4 Canadian Rights (PIPEDA)

Canadian residents have rights under PIPEDA:

  • Right to Access: Request access to your personal information
  • Right to Correction: Challenge the accuracy of your information and request corrections
  • Right to Withdraw Consent: Withdraw consent to collection, use, or disclosure (subject to legal or contractual restrictions)
  • Right to Complain: File a complaint with the Office of the Privacy Commissioner of Canada

Consent: We obtain meaningful consent for the collection, use, and disclosure of your personal information. You may withdraw consent at any time, subject to legal or contractual restrictions.

Accountability: We are responsible for personal information under our control and have designated a Privacy Officer to ensure compliance.

CASL (Canada's Anti-Spam Legislation): Before sending you any commercial electronic message (CEM), we obtain your express consent, which includes identification of the sender, a mailing address, and clear withdrawal instructions. If we relied on implied consent (e.g., an existing business relationship), that consent expires after 2 years from your last transaction. You may withdraw consent at any time via Settings > Notifications or by following the unsubscribe link in any email we send.

8.5 Brazilian Users (LGPD)

If you are located in Brazil, you have the following rights under the LGPD:

  • Confirmation of whether we process your personal data
  • Access to, correction of, or anonymisation of incomplete, inaccurate, or unnecessary data
  • Data portability and deletion of data processed on the basis of consent
  • Information about third parties with whom your data is shared, and the right to withdraw consent at any time without detriment

9. International Data Transfers

Our infrastructure is hosted in the United States. If you are located in the EU/EEA, United Kingdom, Brazil, Canada, or Australia, your personal data will be transferred to and processed in the US.

We transfer personal data internationally under the following legal bases:

EU / EEA (GDPR Art. 44–46)

We intend to rely on Standard Contractual Clauses (SCCs) adopted by the European Commission under Decision 2021/914 as the lawful mechanism for transfers from the EU/EEA to the US. We are also in the process of conducting a Transfer Impact Assessment (TIA) to document risks of US data access laws and applicable mitigations. Until these instruments are in place, we process EU/EEA data on the basis of contract necessity under Art. 49(1)(b) GDPR where required to perform the service you requested.

United Kingdom (UK GDPR)

We intend to rely on the UK International Data Transfer Agreement (IDTA) as the lawful mechanism for transfers of UK personal data to the US. We are in the process of executing this instrument. Until it is in place, we process UK personal data on the basis of contract necessity under UK GDPR Art. 49(1)(b) where required to perform the service you requested.

Brazil (LGPD Art. 33)

We intend to rely on ANPD Standard Contractual Clauses adopted under Resolution CD/ANPD No. 19/2023 as the lawful mechanism for transfers of Brazilian personal data to the US. We are in the process of executing these instruments. Until they are in place, we process Brazilian data on the basis of contract necessity under Art. 33(VI) LGPD where required to perform the service you requested.

Canada (PIPEDA)

Under PIPEDA Schedule 1, Principle 4.1.3, we are accountable for personal information we transfer to US-based processors. We use contractual means (data processing agreements) to require processors to provide protections comparable to PIPEDA.

Australia (Privacy Act 1988)

Under APP 8.1, before disclosing your personal information to US-based processors, we take reasonable steps to ensure those recipients do not breach the Australian Privacy Principles, including through data processing agreements requiring APP-equivalent protections.

A list of our current sub-processors is available on request at privacy@clubsilver.org.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Essential Cookies: Required for the Service to function properly, including authentication and security
  • Preference Cookies: Remember your settings, preferences, and language choices

You can control cookies through your browser settings. Note that disabling essential cookies may prevent the Service from functioning correctly.

11. Age Requirements

The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a user under 18, we will delete it promptly.

If you believe we have collected information from someone under 18, please contact us immediately.

UK Online Safety Act (Ofcom): CS has conducted a Children's Code risk assessment as required under the UK Age Appropriate Design Code. While CS is an 18+ service with eligibility verification at account creation, we acknowledge that self-declared date of birth alone may be insufficient per ICO guidance. Users registering from UK IP addresses are required to complete additional age verification — either by adding a payment card or by completing a facial age estimation scan — before they can send messages. Our risk assessment is maintained and reviewed annually.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting a notice on the Service at least 30 days before changes take effect
  • Sending an email to your registered address
  • Updating the "Recent Changes" section at the top of this page

Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Data Controller: ClubSilver.ORG, operated by All That Net Holdings, LLC

We will respond to your request within 30 days (or sooner as required by applicable law).