Back to home

Privacy Policy

Version 1.0 · Last updated: 10 August 2026

How we handle your personal information, and what you can do about it.

The short version

We collect what we need to match you well and keep you safe, and not much else.

We never sell your personal data. We do not sell it to advertisers, data brokers, or anyone else.

Other members see your first name, your age range, and a little about you. They never see your surname, your contact details, your address, or your answers about health or money.

Some of what we ask — about health, access needs, or dietary requirements tied to a belief — is legally sensitive. We only collect it with your explicit consent, and you can change or delete it in your settings at any time.

You can get a copy of your data, correct it, or ask us to delete it. Email hello@cherie.social and we will do it within a month.

This summary is not the policy. The sections below are.

Who is responsible for your data

Chérie Social, Inc., a corporation incorporated in the State of Delaware, United States, with its principal place of business at 353 Lexington Avenue, 4th Floor, 534, New York, NY 10016, United States, is the controller of your personal data. That means we decide what is collected and why, and we are responsible for it.

Contact: hello@cherie.social

Our UK representative under Article 27 of the UK GDPR is [To be completed — UK Article 27 representative — name and postal address]. You can contact them instead of us about anything in this policy, and they will pass it on.

Data protection lead: [To be completed — name of the data protection lead], reachable at hello@cherie.social. We are not required to appoint a statutory Data Protection Officer, and we have not. If that changes we will say so here.

1. What this policy covers

1.1This policy applies to everything we do with personal data through cherie.social, the Chérie app, and the Experiences we arrange. It applies whether or not you hold a paid Membership.

1.2It sits alongside our Terms of Service. Unlike the Terms, this policy is not a contract and you are not agreeing to it — it is us telling you what we do, which is a legal obligation on us under the UK GDPR.

1.3Where we say “UK GDPR” we mean the UK General Data Protection Regulation and the Data Protection Act 2018.

2. What we collect

Information you give us

WhatExamplesWhen
Account detailsFirst name, surname, email address, phone number, date of birth, password.When you sign up.
ProfileProfile photo, city, neighbourhood, a short introduction.Signup and any time you edit it.
Matching answersYour season of life, interests, what you are looking for, energy and conversation preferences, availability, budget preference.During the questionnaire.
Sensitive answersHealth conditions, access needs, dietary requirements, and anything you tell us that reveals a belief. See section 3.Optional, during signup or later in settings.
Payment informationBilling name, billing address, the last four digits and expiry of your card, transaction history.When you subscribe or pay for an Experience.
MessagesWhat you write in a group conversation, and anything you attach.Whenever you use Messaging.
Reports and complaintsWhat you tell us when you report a member, report content, or complain.When you contact us.
Filming consentWhether you agreed to appear, and any signed consent form.At an Experience we film.
CorrespondenceEmails and support messages between us.Whenever you contact us.

Information we collect automatically

  • Device and technical data — device type, operating system, app version, browser, language, IP address, and a device identifier.
  • Usage data — which screens you open, what you tap, when you log in, which Experiences you view and book, and whether you attended.
  • Approximate location — derived from your IP address or the city you tell us, so we can show you Experiences near you. We do not collect precise or background location. We do not track where you are when you are not using the app.
  • Cookies and similar technologies — see section 14.

Information we get from other people

  • From our payment provider — confirmation that a payment succeeded or failed, and limited card details. We never receive your full card number.
  • From Apple and Google — subscription status, if you subscribed through an app store.
  • From Venues — occasionally, whether a booking was honoured, or a report about conduct at an Experience.
  • From other members — if someone reports you, what they told us forms part of your record.

3. Sensitive information, and why we ask

This section matters, so we have kept it separate

Some of what we ask is what the law calls special category data: information about your health, and information that could reveal a religious or philosophical belief. Dietary requirements often fall into the second group — telling us you eat halal or kosher reveals something about your beliefs.

It has stricter protection than ordinary data, and we treat it that way.

3.1We ask because it makes the matching work. If you use a wheelchair we should not send you up three flights of stairs. If you are pregnant we should not put you at a wine tasting. If you do not drink, we should know before we book you onto a cocktail-making class.

3.2Every one of these questions is optional. You can skip all of them and still be matched.

3.3Our legal basis for this data is your explicit consent under Article 9(2)(a) of the UK GDPR. That is a higher standard than ordinary consent: we tell you exactly what we want and why, and you actively agree.

3.4You can withdraw consent at any time in Settings, or by emailing us. When you do, we delete the data, and we stop using it in matching. Withdrawing does not affect anything we did lawfully before.

3.5Who sees it. Other members never see it. Our team sees only what is needed to match you and to make a booking. Where a Venue needs to know — an allergy, a step-free requirement — we pass on the fact, not your name and not the underlying condition. See section 8.

3.6We do not use this data for marketing, ever.

4. Why we use your data, and our legal basis

We must have a lawful basis for everything we do with your data. Here is all of it.

What we doData usedLegal basisHow long we keep it
Create and run your accountAccount details, profilePerformance of our contract with youWhile your account is open, then 30 days
Match you into a GroupMatching answers, profile, city, sensitive answers where givenContract; explicit consent for sensitive answersWhile your account is open
Book your place at an ExperienceFirst name, dietary and access needs (as facts, not names)ContractWhile your account is open; booking records 6 years
Take payment and prevent fraudPayment information, transaction historyContract; legal obligation; our legitimate interest in preventing fraud6 years, for tax and accounting
Provide MessagingMessages, attachmentsContractWhile your account is open, then 30 days, unless retained under a report
Keep members safe and moderate contentReports, messages, profile, usage, attendanceOur legitimate interest in protecting members; legal obligation under the Online Safety Act 2023Reports and their outcomes: 3 years. Records of a ban: indefinitely, so a banned member cannot rejoin
Handle complaints and appealsCorrespondence, account recordLegal obligation; our legitimate interest in running the service properly3 years from resolution
Improve the service and fix bugsUsage and technical data, aggregated wherever possibleOur legitimate interest in improving what we build2 years
Send you service messagesAccount detailsContractWhile your account is open
Send you marketingAccount details, cityYour consentUntil you unsubscribe, then a suppression record indefinitely so we do not email you again
Use your image in marketingPhotographs, film, first name, voiceYour consent (separate, optional, revocable)Membership plus 24 months, or until you withdraw
Meet our legal obligationsWhatever is requiredLegal obligationAs required by the relevant law
Establish or defend a legal claimWhatever is relevantOur legitimate interest in defending ourselves6 years from the end of the relationship

Where we rely on legitimate interests, we have weighed our interest against your rights and recorded the result. You can ask us for that assessment and we will send it to you.

5. Matching, and how much of it is automatic

5.1Matching uses an algorithm. It looks at your answers, your city, your availability, and who else is available, and proposes a Group.

5.2This is profiling under the UK GDPR, so we should be straight about it. It does not produce a legal effect or anything similarly significant — the outcome is which four to five people you have dinner with. But you should know it happens.

5.3A person on our team reviews Groups before they are confirmed, and can override the algorithm.

5.4You can ask us why you were matched a particular way, ask for a human to look again, or tell us you do not want to be matched with a particular member. Email hello@cherie.social.

5.5Decisions about suspending or removing an account are never made by an algorithm alone. Automated systems may flag content or behaviour for review, but a person decides.

6. Who we share your data with

We share only what is needed, only with the organisations below, and only under a contract that requires them to protect it.

WhoWhat they getWhyWhere
StripeBilling details, transaction dataTo take payment[To be completed — Stripe's contracting entity and its country — check which Stripe entity the account contracts with (Stripe, Inc. in the US, or Stripe Payments Europe in Ireland); it determines the transfer mechanism]
Google Firebase — authentication, the Firestore database, file storage, our Cloud Functions and push notificationsAll platform dataTo run the app and store dataUnited States (us-central1)
Supabase — the database behind Messaging, and storage for photos sent in a chatMessages, attachments, and the account identifiers they belong toTo run Messaging[To be completed — the country or region our Supabase database is hosted in]
Our transactional email service, which runs on Google Cloud, using [To be completed — name of the email delivery provider behind our email service] to deliverName, email, message contentTo send transactional and marketing emailUnited States (us-central1)
Google Analytics for FirebaseUsage and technical data, pseudonymisedTo understand how the app is usedUnited States (us-central1)
MapTilerA place name or approximate location, so it can be turned into map coordinatesTo show Experiences on a map and geocode Venue addresses[To be completed — MapTiler’s corporate entity and the country its geocoding requests are processed in]
[To be completed — name of our customer support tool, if we use one beyond email]Correspondence, account recordTo answer you[To be completed — country of our customer support tool]
VenuesGroup size, first names, and the fact of an allergy or access needTo make and honour the bookingUnited Kingdom
Professional advisersOnly what is relevantLegal, accounting and insurance adviceUK and US
Police and authoritiesOnly what is lawfully required or necessary to prevent harmLegal obligation, or protecting someoneAs applicable
A buyer of the businessAccount and usage dataIf Chérie is sold or merged. We would tell you first.As applicable

We do not sell your personal data, and we do not share it with advertisers or data brokers. We do not run behavioural advertising and we do not allow third parties to track you across other apps or websites through Chérie.

7. What other members can see

For a service built on meeting strangers, this is probably the section you care about most.

Members of your Group seeThey never see
Your first nameYour surname
Your profile photoYour email address or phone number
Your age range, not your date of birthYour exact address or home neighbourhood
Your general area, at city or borough levelYour payment details or what you paid
Your short introduction and interestsYour answers about health, access needs or money
What you choose to write in the group chatYour questionnaire answers
That you have booked the same ExperienceWhether you have reported anyone, or been reported

7.1You choose what goes in your introduction. Do not put your surname, your employer, your street or your social handles in it if you would rather members did not have them.

7.2Anything you say in the group chat can be read by everyone in that Group, and could be screenshotted. Our Community Guidelines forbid sharing it outside Chérie, but we cannot make that technically impossible.

7.3When you block someone, she is not shown to you, you are not shown to her, and we make reasonable efforts to keep you out of the same Experience. We do not tell her you blocked her.

8. What we tell Venues

8.1We give a Venue the minimum it needs: the booking name, the number of people, the time, and any allergy or access requirement in the Group.

8.2We pass on the fact — “one guest is coeliac”, “one guest needs step-free access” — not your name attached to it, and never the underlying condition.

8.3We do not give Venues your contact details, and Venues are contractually prohibited from marketing to you using anything we give them.

9. Sending your data outside the UK

9.1We are a US company, so your data is transferred to and stored in the United States. Some of our providers are also outside the UK.

9.2The UK does not consider the United States to provide equivalent protection generally. So we rely on [To be completed — which transfer safeguard we use — the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or certification under the UK Extension to the EU–US Data Privacy Framework], together with a transfer risk assessment we have carried out and recorded.

9.3You can ask us for a copy of the safeguards we use. Email hello@cherie.social.

10. How long we keep things

10.1The table in section 4 gives the period for each purpose. The general rule is that we keep data while your account is open and delete it 30 days after you close it.

10.2Some things outlast your account, and you should know which:

  • Financial records — 6 years, because tax law requires it.
  • Safety reports and their outcomes — 3 years, so that a pattern of behaviour is visible even if accounts are closed and reopened.
  • A record that an account was banned — kept indefinitely, so that someone removed for harming a member cannot simply sign up again. This is the minimum needed to enforce the ban and nothing more.
  • Marketing suppression records — kept indefinitely, so that unsubscribing actually works.

10.3If your account is inactive for two years we will email you. If you do not respond within 30 days, we delete it.

11. Keeping it secure

11.1Data is encrypted in transit and at rest. Access is limited to team members who need it for their job, and access is logged.

11.2We use multi-factor authentication on our administrative systems, review permissions quarterly, and keep our dependencies patched.

11.3Please help: use a strong, unique password, and tell us straight away if you think someone has got into your account.

11.4If there is a breach that is likely to be a risk to you, we will report it to the Information Commissioner's Office within 72 hours of becoming aware, and if the risk to you is high, we will tell you directly and without undue delay. We will tell you what happened, what data was involved, and what to do about it.

12. Your rights

Under the UK GDPR you have the following rights. They are free to use, and we will not treat you differently for using them.

RightWhat it means
AccessGet a copy of the personal data we hold about you, and an explanation of what we do with it.
RectificationHave anything inaccurate corrected, or anything incomplete filled in.
ErasureHave your data deleted, where there is no overriding reason for us to keep it. See section 10 for what we must retain.
RestrictionHave us pause using your data while a dispute about it is resolved.
PortabilityGet the data you gave us in a structured, machine-readable file, or have us send it to someone else.
ObjectObject to processing based on legitimate interests. You can object to direct marketing at any time and we must stop immediately, no reasons needed.
Withdraw consentWithdraw consent for anything based on it — sensitive data, marketing, filming — at any time.
ComplainComplain to the Information Commissioner's Office. See below.

12.1To use any of these, email hello@cherie.social or use Settings → Privacy in the app. We will respond within one month. If your request is complex we may extend by up to two further months, and we will tell you within the first month if we do.

12.2We may need to check who you are before we act, so that someone cannot get your data by pretending to be you. We will ask for the minimum necessary and delete it once you are verified.

12.3If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. But you can go straight to the regulator if you prefer.

The Information Commissioner’s Office

Website: ico.org.uk/make-a-complaint

Helpline: 0303 123 1113

Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

You do not need our permission and you do not have to come to us first.

13. Marketing

13.1We only send marketing email if you have opted in, or if you are an existing member and it is about something similar to what you already have. Every email has an unsubscribe link that works in one click.

13.2Unsubscribing from marketing does not stop service messages — booking confirmations, renewal reminders, safety notices — because those are part of the service you have paid for.

13.3We do not use your sensitive data, your questionnaire answers or your Messaging content for marketing.

14. Cookies and similar technologies

14.1On the website we use strictly necessary cookies, which keep you logged in and keep the site secure. These do not need your consent.

14.2We do not currently set any analytics or preference cookies on this website, so there is nothing here for you to consent to and no cookie banner to answer. If that changes we will ask you first, and we will say so here and in the Cookie Policy before we do it. [To be completed — revisit clause 14.2 the moment any analytics or marketing script is enabled on the website — this clause and the Cookie Policy must change together, and consent must be collected before the script loads]

14.3The full list of cookies, what each does and how long it lasts, is at cherie.social/cookies.

14.4In the app we use a device identifier for analytics and crash reporting. You can reset it in your device settings.

15. Children

15.1Chérie is for adults. You must be 18 or over, and we do not knowingly collect data from anyone under 18.

15.2If we find out that someone under 18 has created an account, we close it and delete the data.

15.3If you believe a child has given us information, email hello@cherie.social and we will deal with it immediately. See also our Child Safety Standards Policy.

16. Changes to this policy

16.1We will update this policy when what we do changes. The date at the top tells you when it last changed, and previous versions are at cherie.social/legal/archive.

16.2If a change is significant — a new purpose, a new category of data, a new recipient — we will email you at least 30 days beforehand rather than quietly changing the page.

17. Contact us

  • Email: hello@cherie.social
  • Post: Chérie Social, Inc., 353 Lexington Avenue, 4th Floor, 534, New York, NY 10016, United States
  • UK representative: [To be completed — UK Article 27 representative — name and postal address]
  • In the app: Settings → Privacy
TermsPrivacyCommunitySafetyComplaintsChild safetyCookiesVerificationSupportArchive

Chérie Social, Inc., a corporation incorporated in the State of Delaware, United States
353 Lexington Avenue, 4th Floor, 534, New York, NY 10016, United States
hello@cherie.social