Version 2026-09-30-v11
Privacy notice
This notice explains the information Velvet List uses and the choices available to visitors, members and creators.
Information we use
- Account identity and contact details supplied through sign-in.
- Saved creators and the private lists you organise them into, reviews, ratings, claims, corrections, reports and feedback you submit.
- Replies a creator profile owner posts to reviews, which stay with the creator profile and lose their author reference if the account is deleted.
- Inbox messages, your saved-creator offer and alert preferences with the wording you agreed to, and, if you opt in, alerts we write when a creator you save lowers a price, adds a free trial or offer, or publishes new gallery photos. Contributor-status alerts, sent when your approved submissions reach a new contributor tier, need no opt-in, and moderators see the contributor tier of pending submissions. Messages and alerts are kept for 12 months unless you delete them earlier; a deleted alert keeps only its type, creator and date for up to 7 days so the same alert is not repeated. Alerts are deleted with your account.
- Account-free safety reports, including the issue reference, details and an optional reply email.
- Creator profile, platform, location, category, commercial and verification information.
- The result of an age or identity check you choose to complete through Didit: whether you were verified as 18 or over, the method (age estimation or ID document), the check reference and its dates.
- Administrative and moderation audit records needed for security and accountability.
- Product-usage events only when your analytics setting permits them.
Why we use it
We use information to operate accounts, search and profiles; publish and moderate contributions; verify claims; prevent abuse; answer reports; maintain audit history; and improve the service. We do not use analytics permission to change organic ratings or secretly promote creators.
Analytics choices
Optional analytics are pseudonymous, not anonymous: they use a random browser and session identifier rather than your name, and may include routes viewed, search terms, selected categories and broad locations entered into search, result positions and creator profile interactions. We do not intentionally store IP addresses, exact device location or full user-agent strings in product analytics. Named activity is a separate optional setting available after sign-in. If you allow analytics and open a creator offer in your inbox, we record that the offer was opened and whether you followed its profile or external link, once per session. These records hold the offer reference and the random browser and session identifiers only, never the message, promo code, your account or the link destination; they are not read receipts and never decide who receives offers. Copying a code or marking a message read is not recorded. Withdrawing analytics immediately erases detailed events, search impressions and offer engagement for the current browser; withdrawing named activity also erases account-linked detail and rotates the browser identifier before pseudonymous collection can continue.
Sharing and retention
Information is handled by the services needed to host the site and provide sign-in. Public profile and approved review content is visible to site users; private account, report and moderation material is access-controlled. Resolved account-free safety report details, references, reply email and decision detail are redacted after 25 months. Abuse-prevention report hashes are erased after 24 hours. Detailed analytics events, search impressions and offer engagement are rolled up then erased after 90 days; aggregate rollups are erased after 25 months. Analytics-consent records and account-free policy acceptance records (linked to a random identifier) are erased 13 months after their last update, acceptance or withdrawal. Age verification results are kept until they expire after one year or you delete your account.
Age and identity verification
Gallery images may include nudity, so they are shown unblurred only to accounts verified as 18 or over, and creators complete an ID document and liveness check before claiming a profile. These checks are run by Didit, an identity-verification provider acting on our behalf. Didit processes your selfie, facial age estimate and, where needed, identity document under its own privacy notice and retention rules. Velvet List never receives or stores your photo, ID document, document number or date of birth: we keep only the outcome, the method used, the Didit check reference and when it was completed. A successful check does not expire, so you verify once. Verification is optional for members; without it, gallery images stay blurred.
Account export and deletion
Your export includes locally held provider identity and provider-deletion state, your account-linked named analytics detail and consent, plus current-browser consent, policy acceptance and offer engagement when that browser is available. It never includes single-use verification-code hashes or internal provider retry errors. Deletion immediately removes saves, feedback, account-linked analytics and offer engagement, the current browser’s analytics/policy records and revokes claims; it clears name/email, disables the local account and requests Clerk identity deletion. If Clerk is unavailable, the disabled account is retried daily. Trust/moderation integrity records remain on a non-public tombstone, with free text and URLs redacted after 25 months.
Your choices and rights
You can change analytics settings from your account, view an account-data export, correct profile information through the relevant workflow, and request deletion through the account page. Depending on applicable law, you may also have rights to access, correct, erase, restrict or object to processing.
Contact and complaints
Use the account-free safety, takedown and appeal form or, when signed in, the relevant profile or feedback route. A reply email is optional but required if you want a direct response. You may also complain to the UK Information Commissioner if you believe your data-protection rights have been infringed.