Version 1.0 · Last updated: 10 August 2026
How we handle your personal information, and what you can do about it.
Chérie Social, Inc., a corporation incorporated in the State of Delaware, United States, with its principal place of business at 353 Lexington Avenue, 4th Floor, 534, New York, NY 10016, United States, is the controller of your personal data. That means we decide what is collected and why, and we are responsible for it.
Contact: hello@cherie.social
Our UK representative under Article 27 of the UK GDPR is [To be completed — UK Article 27 representative — name and postal address]. You can contact them instead of us about anything in this policy, and they will pass it on.
Data protection lead: [To be completed — name of the data protection lead], reachable at hello@cherie.social. We are not required to appoint a statutory Data Protection Officer, and we have not. If that changes we will say so here.
1.1This policy applies to everything we do with personal data through cherie.social, the Chérie app, and the Experiences we arrange. It applies whether or not you hold a paid Membership.
1.2It sits alongside our Terms of Service. Unlike the Terms, this policy is not a contract and you are not agreeing to it — it is us telling you what we do, which is a legal obligation on us under the UK GDPR.
1.3Where we say “UK GDPR” we mean the UK General Data Protection Regulation and the Data Protection Act 2018.
| What | Examples | When |
|---|---|---|
| Account details | First name, surname, email address, phone number, date of birth, password. | When you sign up. |
| Profile | Profile photo, city, neighbourhood, a short introduction. | Signup and any time you edit it. |
| Matching answers | Your season of life, interests, what you are looking for, energy and conversation preferences, availability, budget preference. | During the questionnaire. |
| Sensitive answers | Health conditions, access needs, dietary requirements, and anything you tell us that reveals a belief. See section 3. | Optional, during signup or later in settings. |
| Payment information | Billing name, billing address, the last four digits and expiry of your card, transaction history. | When you subscribe or pay for an Experience. |
| Messages | What you write in a group conversation, and anything you attach. | Whenever you use Messaging. |
| Reports and complaints | What you tell us when you report a member, report content, or complain. | When you contact us. |
| Filming consent | Whether you agreed to appear, and any signed consent form. | At an Experience we film. |
| Correspondence | Emails and support messages between us. | Whenever you contact us. |
3.1We ask because it makes the matching work. If you use a wheelchair we should not send you up three flights of stairs. If you are pregnant we should not put you at a wine tasting. If you do not drink, we should know before we book you onto a cocktail-making class.
3.2Every one of these questions is optional. You can skip all of them and still be matched.
3.3Our legal basis for this data is your explicit consent under Article 9(2)(a) of the UK GDPR. That is a higher standard than ordinary consent: we tell you exactly what we want and why, and you actively agree.
3.4You can withdraw consent at any time in Settings, or by emailing us. When you do, we delete the data, and we stop using it in matching. Withdrawing does not affect anything we did lawfully before.
3.5Who sees it. Other members never see it. Our team sees only what is needed to match you and to make a booking. Where a Venue needs to know — an allergy, a step-free requirement — we pass on the fact, not your name and not the underlying condition. See section 8.
3.6We do not use this data for marketing, ever.
We must have a lawful basis for everything we do with your data. Here is all of it.
| What we do | Data used | Legal basis | How long we keep it |
|---|---|---|---|
| Create and run your account | Account details, profile | Performance of our contract with you | While your account is open, then 30 days |
| Match you into a Group | Matching answers, profile, city, sensitive answers where given | Contract; explicit consent for sensitive answers | While your account is open |
| Book your place at an Experience | First name, dietary and access needs (as facts, not names) | Contract | While your account is open; booking records 6 years |
| Take payment and prevent fraud | Payment information, transaction history | Contract; legal obligation; our legitimate interest in preventing fraud | 6 years, for tax and accounting |
| Provide Messaging | Messages, attachments | Contract | While your account is open, then 30 days, unless retained under a report |
| Keep members safe and moderate content | Reports, messages, profile, usage, attendance | Our legitimate interest in protecting members; legal obligation under the Online Safety Act 2023 | Reports and their outcomes: 3 years. Records of a ban: indefinitely, so a banned member cannot rejoin |
| Handle complaints and appeals | Correspondence, account record | Legal obligation; our legitimate interest in running the service properly | 3 years from resolution |
| Improve the service and fix bugs | Usage and technical data, aggregated wherever possible | Our legitimate interest in improving what we build | 2 years |
| Send you service messages | Account details | Contract | While your account is open |
| Send you marketing | Account details, city | Your consent | Until you unsubscribe, then a suppression record indefinitely so we do not email you again |
| Use your image in marketing | Photographs, film, first name, voice | Your consent (separate, optional, revocable) | Membership plus 24 months, or until you withdraw |
| Meet our legal obligations | Whatever is required | Legal obligation | As required by the relevant law |
| Establish or defend a legal claim | Whatever is relevant | Our legitimate interest in defending ourselves | 6 years from the end of the relationship |
Where we rely on legitimate interests, we have weighed our interest against your rights and recorded the result. You can ask us for that assessment and we will send it to you.
5.1Matching uses an algorithm. It looks at your answers, your city, your availability, and who else is available, and proposes a Group.
5.2This is profiling under the UK GDPR, so we should be straight about it. It does not produce a legal effect or anything similarly significant — the outcome is which four to five people you have dinner with. But you should know it happens.
5.3A person on our team reviews Groups before they are confirmed, and can override the algorithm.
5.4You can ask us why you were matched a particular way, ask for a human to look again, or tell us you do not want to be matched with a particular member. Email hello@cherie.social.
5.5Decisions about suspending or removing an account are never made by an algorithm alone. Automated systems may flag content or behaviour for review, but a person decides.
We share only what is needed, only with the organisations below, and only under a contract that requires them to protect it.
| Who | What they get | Why | Where |
|---|---|---|---|
| Stripe | Billing details, transaction data | To take payment | [To be completed — Stripe's contracting entity and its country — check which Stripe entity the account contracts with (Stripe, Inc. in the US, or Stripe Payments Europe in Ireland); it determines the transfer mechanism] |
| Google Firebase — authentication, the Firestore database, file storage, our Cloud Functions and push notifications | All platform data | To run the app and store data | United States (us-central1) |
| Supabase — the database behind Messaging, and storage for photos sent in a chat | Messages, attachments, and the account identifiers they belong to | To run Messaging | [To be completed — the country or region our Supabase database is hosted in] |
| Our transactional email service, which runs on Google Cloud, using [To be completed — name of the email delivery provider behind our email service] to deliver | Name, email, message content | To send transactional and marketing email | United States (us-central1) |
| Google Analytics for Firebase | Usage and technical data, pseudonymised | To understand how the app is used | United States (us-central1) |
| MapTiler | A place name or approximate location, so it can be turned into map coordinates | To show Experiences on a map and geocode Venue addresses | [To be completed — MapTiler’s corporate entity and the country its geocoding requests are processed in] |
| [To be completed — name of our customer support tool, if we use one beyond email] | Correspondence, account record | To answer you | [To be completed — country of our customer support tool] |
| Venues | Group size, first names, and the fact of an allergy or access need | To make and honour the booking | United Kingdom |
| Professional advisers | Only what is relevant | Legal, accounting and insurance advice | UK and US |
| Police and authorities | Only what is lawfully required or necessary to prevent harm | Legal obligation, or protecting someone | As applicable |
| A buyer of the business | Account and usage data | If Chérie is sold or merged. We would tell you first. | As applicable |
We do not sell your personal data, and we do not share it with advertisers or data brokers. We do not run behavioural advertising and we do not allow third parties to track you across other apps or websites through Chérie.
For a service built on meeting strangers, this is probably the section you care about most.
| Members of your Group see | They never see |
|---|---|
| Your first name | Your surname |
| Your profile photo | Your email address or phone number |
| Your age range, not your date of birth | Your exact address or home neighbourhood |
| Your general area, at city or borough level | Your payment details or what you paid |
| Your short introduction and interests | Your answers about health, access needs or money |
| What you choose to write in the group chat | Your questionnaire answers |
| That you have booked the same Experience | Whether you have reported anyone, or been reported |
7.1You choose what goes in your introduction. Do not put your surname, your employer, your street or your social handles in it if you would rather members did not have them.
7.2Anything you say in the group chat can be read by everyone in that Group, and could be screenshotted. Our Community Guidelines forbid sharing it outside Chérie, but we cannot make that technically impossible.
7.3When you block someone, she is not shown to you, you are not shown to her, and we make reasonable efforts to keep you out of the same Experience. We do not tell her you blocked her.
8.1We give a Venue the minimum it needs: the booking name, the number of people, the time, and any allergy or access requirement in the Group.
8.2We pass on the fact — “one guest is coeliac”, “one guest needs step-free access” — not your name attached to it, and never the underlying condition.
8.3We do not give Venues your contact details, and Venues are contractually prohibited from marketing to you using anything we give them.
9.1We are a US company, so your data is transferred to and stored in the United States. Some of our providers are also outside the UK.
9.2The UK does not consider the United States to provide equivalent protection generally. So we rely on [To be completed — which transfer safeguard we use — the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or certification under the UK Extension to the EU–US Data Privacy Framework], together with a transfer risk assessment we have carried out and recorded.
9.3You can ask us for a copy of the safeguards we use. Email hello@cherie.social.
10.1The table in section 4 gives the period for each purpose. The general rule is that we keep data while your account is open and delete it 30 days after you close it.
10.2Some things outlast your account, and you should know which:
10.3If your account is inactive for two years we will email you. If you do not respond within 30 days, we delete it.
11.1Data is encrypted in transit and at rest. Access is limited to team members who need it for their job, and access is logged.
11.2We use multi-factor authentication on our administrative systems, review permissions quarterly, and keep our dependencies patched.
11.3Please help: use a strong, unique password, and tell us straight away if you think someone has got into your account.
11.4If there is a breach that is likely to be a risk to you, we will report it to the Information Commissioner's Office within 72 hours of becoming aware, and if the risk to you is high, we will tell you directly and without undue delay. We will tell you what happened, what data was involved, and what to do about it.
Under the UK GDPR you have the following rights. They are free to use, and we will not treat you differently for using them.
| Right | What it means |
|---|---|
| Access | Get a copy of the personal data we hold about you, and an explanation of what we do with it. |
| Rectification | Have anything inaccurate corrected, or anything incomplete filled in. |
| Erasure | Have your data deleted, where there is no overriding reason for us to keep it. See section 10 for what we must retain. |
| Restriction | Have us pause using your data while a dispute about it is resolved. |
| Portability | Get the data you gave us in a structured, machine-readable file, or have us send it to someone else. |
| Object | Object to processing based on legitimate interests. You can object to direct marketing at any time and we must stop immediately, no reasons needed. |
| Withdraw consent | Withdraw consent for anything based on it — sensitive data, marketing, filming — at any time. |
| Complain | Complain to the Information Commissioner's Office. See below. |
12.1To use any of these, email hello@cherie.social or use Settings → Privacy in the app. We will respond within one month. If your request is complex we may extend by up to two further months, and we will tell you within the first month if we do.
12.2We may need to check who you are before we act, so that someone cannot get your data by pretending to be you. We will ask for the minimum necessary and delete it once you are verified.
12.3If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. But you can go straight to the regulator if you prefer.
13.1We only send marketing email if you have opted in, or if you are an existing member and it is about something similar to what you already have. Every email has an unsubscribe link that works in one click.
13.2Unsubscribing from marketing does not stop service messages — booking confirmations, renewal reminders, safety notices — because those are part of the service you have paid for.
13.3We do not use your sensitive data, your questionnaire answers or your Messaging content for marketing.
14.1On the website we use strictly necessary cookies, which keep you logged in and keep the site secure. These do not need your consent.
14.2We do not currently set any analytics or preference cookies on this website, so there is nothing here for you to consent to and no cookie banner to answer. If that changes we will ask you first, and we will say so here and in the Cookie Policy before we do it. [To be completed — revisit clause 14.2 the moment any analytics or marketing script is enabled on the website — this clause and the Cookie Policy must change together, and consent must be collected before the script loads]
14.3The full list of cookies, what each does and how long it lasts, is at cherie.social/cookies.
14.4In the app we use a device identifier for analytics and crash reporting. You can reset it in your device settings.
15.1Chérie is for adults. You must be 18 or over, and we do not knowingly collect data from anyone under 18.
15.2If we find out that someone under 18 has created an account, we close it and delete the data.
15.3If you believe a child has given us information, email hello@cherie.social and we will deal with it immediately. See also our Child Safety Standards Policy.
16.1We will update this policy when what we do changes. The date at the top tells you when it last changed, and previous versions are at cherie.social/legal/archive.
16.2If a change is significant — a new purpose, a new category of data, a new recipient — we will email you at least 30 days beforehand rather than quietly changing the page.