Privacy policy

How Between Us handles personal data on the website, contact form and interest list — controller identity, legal bases, special-category data, retention and your rights.

1. Controller and contact details

The controller responsible for the processing described in this notice is:

Between Us – LV. Ioan · Neideggweg 6 · 89134 Blaustein · Germany

Email: hello@between-us.app · Telephone: 0177 5984322 (+49 177 5984322)

2. Scope

This notice covers all processing of personal data through the website between-us.app: page delivery, technically necessary storage, the contact form, transactional email, the private-event interest list, and administrator sign-in. It does not describe third-party sites you may reach through outbound links.

3. Hosting and technical delivery

The website is delivered by our hosting provider. As with every website, each request necessarily transmits your IP address, the page you asked for, a timestamp and — if your browser sends them — the referring page and a short browser identifier. This information is used to deliver the page and to keep the site secure. It is not used to profile you.

Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is providing a functioning, secure and abuse-resistant website. IP addresses seen at the transport layer are not written to application logs and not correlated with your account or submissions.

4. Server logs and abuse prevention

Application logs and rate-limit records are kept only to the extent necessary to detect and defend against automated abuse (form flooding, credential stuffing, scraping).

  • To prevent misuse, we count how often the same email address submits a form on a given day using a one-way, keyed transformation of that address. The address itself cannot be recovered from that value.
  • Failed authentication attempts and unusual request patterns may be logged in short-lived security records.
  • Retention: 7 to 30 days by default; longer only where a specific investigation of abuse or a security incident is under way, and only for the material relevant to that investigation.

Legal basis: Article 6(1)(f) GDPR (legitimate interest in protecting the service and its users).

5. Technically necessary cookies, local storage and session storage

We do not use analytics cookies, advertising cookies, social-media tracking, or embedded third-party trackers. No cookie banner is required or shown because no consent-requiring technology is loaded.

Only the following technically necessary storage is used:

  • A language preference stored locally in your browser so the site remembers whether you chose English or German. It is not sent to us on its own.
  • For signed-in administrators only: authentication session tokens issued by our authentication provider. No such token exists for public visitors.
  • Short-lived form state kept in memory during a submission.

Legal basis: § 25(2) TDDDG in conjunction with Article 6(1)(f) GDPR, because these are strictly necessary to provide the requested functionality.

6. Account registration and authentication

Public account registration is not offered. Access to the editorial back-end is limited to a small group of administrators and uses email-based one-time sign-in links.

When accounts exist, the following applies: we process the email address you register with, a hashed authentication token, timestamps of sign-in events, and any profile information you voluntarily add. Legal basis: Article 6(1)(b) GDPR to provide the account you requested, together with Article 6(1)(f) GDPR for security, session integrity and abuse prevention.

7. Contact form

When you submit the contact form, we process the topic category you selected, an optional chosen name, the reply-email address you provide, the free-text message, your language preference, and a record of your explicit acknowledgement of this privacy notice.

Purpose: to receive, triage and answer your request. The message body is treated as the single source of truth so we do not create duplicate copies of the personal data in internal notes.

Legal basis: Article 6(1)(b) GDPR when the message is pre-contractual or a request-related enquiry, otherwise Article 6(1)(f) GDPR (legitimate interest in responding to inbound enquiries). If your message contains special-category data of your own accord, section 8 below applies.

8. Special-category data about sex life, sexual orientation or lifestyle affiliation

Between Us is an editorial site for adult consensual-non-monogamy topics (Hotwife and Stag–Vixen dynamics). Free-text fields on the contact form and on the private-event interest list can be used to voluntarily share information that reveals your sex life, sexual orientation or lifestyle affiliation. Under Article 9(1) GDPR this is a special category of personal data.

We do not require you to share such information. Standard, non-sensitive contact requests remain possible without it. Where a form field can reasonably be used to submit such data, a separate, unchecked explicit-consent checkbox is presented and must be actively ticked before the sensitive fields are transmitted.

9. Explicit consent under Article 9(2)(a) GDPR

For any voluntary submission of special-category data, the legal basis is Article 9(2)(a) GDPR (explicit consent) in combination with Article 6(1)(a) GDPR.

The consent statement names the sensitive nature of the data and the exact purpose (reviewing your enquiry or matching a private-event interest submission). Silence, pre-ticked boxes or the mere act of submitting the form are never treated as consent.

10. How consent is recorded and withdrawn

  • Every explicit consent is recorded with: an immutable consent version identifier, the locale in which the wording was shown, a timestamp, the purpose, and the form context.
  • Consent records are stored server-side; they do not contain your raw IP address. Rate-limit prevention uses a keyed hash instead of a raw IP.
  • Withdrawing consent is as easy as giving it: contact us via hello@between-us.app or, for the private-event interest list, use the one-click withdrawal link included in every confirmation email.
  • After withdrawal, the underlying entry is removed or anonymised within 30 days, subject to any statutory retention obligation. A minimal record that consent was validly given and then withdrawn may be retained to demonstrate lawful processing.

11. Resend (transactional email)

Transactional emails (verification, withdrawal confirmations, replies) are sent through Resend (Resend, Inc.), acting as our processor. To deliver a message, Resend receives at minimum the recipient email address, subject, message body and delivery metadata.

Legal basis: the same basis as the underlying request or account process (Article 6(1)(b) GDPR for request-related messages; Article 6(1)(a) GDPR for messages tied to an explicit consent). Where personal data is transferred outside the EU/EEA in the course of email delivery, appropriate safeguards under Chapter V GDPR (such as Standard Contractual Clauses) apply as offered by the processor.

12. Database and authentication

Website data (contact submissions, editorial content, administrator sessions and private-event interest submissions) is stored in a managed European database service, which also provides administrator sign-in.

Access is protected by database-level access controls so that anonymous visitors cannot read submissions, consent records or administrative data. Where personal data is processed outside the EU/EEA in the course of hosting, appropriate safeguards under Chapter V GDPR (such as Standard Contractual Clauses) apply as offered by the processor.

13. Processors, recipients and possible third-country transfers

We use the following categories of processors: hosting and content delivery, transactional email (Resend), and a managed database and sign-in service. We do not sell personal data, we do not share it with advertising networks, and we do not use it to build behavioural profiles. A processor may host or transit data outside the EU/EEA; in that case appropriate safeguards under Chapter V GDPR apply. A current list of subprocessors can be requested through the contact form.

14. Storage and deletion periods

  • Unverified private-event registrations: deleted within 30 days.
  • Withdrawn registrations: deleted or anonymised within 30 days.
  • Contact requests: up to 6 months after resolution, unless a statutory retention obligation applies.
  • Rejected submissions (once such a workflow is activated): up to 6 months.
  • Consent records: retained as long as reasonably necessary to demonstrate lawful consent and to handle related claims.
  • Security/server logs and rate-limit records: 7 to 30 days, unless a longer period is required to investigate specific abuse or security incidents.
  • Account data: until deletion of the account, subject to statutory retention obligations.

15. Your rights as a data subject

  • Right of access (Article 15 GDPR).
  • Right to rectification (Article 16 GDPR).
  • Right to erasure (Article 17 GDPR), within the limits of applicable law.
  • Right to restriction of processing (Article 18 GDPR).
  • Right to data portability where applicable (Article 20 GDPR).
  • Right to object under Article 21 GDPR, in particular against processing based on Article 6(1)(f) GDPR.

To exercise any of these rights, contact hello@between-us.app. We may need to confirm your identity before acting on the request.

16. Right to withdraw consent

Where processing is based on your consent (Articles 6(1)(a) and 9(2)(a) GDPR), you may withdraw that consent at any time with effect for the future. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

17. Right to object under Article 6(1)(f) GDPR

You have the right to object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. In that case we will no longer process the personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

18. Right to complain to a supervisory authority

You may lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work or the place of the alleged infringement. For the controller's registered address in Baden-Württemberg (Germany), the competent authority is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW).

19. Security measures

We apply appropriate technical and organisational measures to protect personal data. These include encrypted transport (HTTPS), database-level access controls, limited administrator permissions, protecting rate-limit counters so that raw email addresses or IP addresses are not stored, restrained logging, and administrator sign-in via short-lived one-time links. We deliberately do not describe further details that could help an attacker.

20. Adult-only service

Between Us is intended exclusively for adults aged 18 or older. We do not knowingly process personal data of persons under the age of 18. Please do not submit any form on this site if you are under 18.

21. No analytics or marketing tracking

We do not use web analytics, advertising trackers, social plugins, retargeting pixels, A/B-testing tools or session-replay tools. If any such technology is introduced later, this notice will be updated before it is activated and, where required, consent will be requested through an appropriate mechanism.

22. Changes to this privacy policy

We may update this privacy policy to reflect changes in the service, in processors or in applicable law. The current version is always available at /privacy. Material changes will be reflected in a new consent version so that consents given under a previous wording remain identifiable as such.