FetishHaus
Legal / Privacy policy

Your business
stays your business.

How we collect, use, disclose, and protect personal information — and why, on an adult platform, we treat the very fact of your use as sensitive data.

Last updated August 27, 2026
01

Who we are and scope

This Privacy Policy explains how FetishHaus Ltd. (the "Company," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with fetish.haus. It also describes the privacy rights available to residents of certain U.S. states and how to exercise them. Because fetish.haus is an adult-content platform, the mere fact that a person uses the Service can reveal information about that person's sex life or sexual orientation — we treat that kind of information as sensitive and handle it with heightened care (Section 7).

This policy covers personal information collected through the Site, our checkout and billing flows, creator onboarding and payouts, support channels, and related online services that link to this policy. The Service includes three areas — Raw (free, ad-supported clips and previews), the Vault (recurring subscription), and Private Access (pay-per-clip purchases) — and all Content is reviewed before publication. The Service is offered from the United States and is presently directed to U.S. Users; it is strictly for adults (Section 13).

02

What we collect

  • Account & profile — username, display name, email, password (hashed), settings, profile details you choose to provide.
  • Payment & transactions — card and billing details are collected and processed directly by our third-party payment processors and acquiring banks; we do not store full card numbers. We retain transaction records (amount, date, product, tokenized card reference, descriptor, refund/chargeback history). Charges appear under the billing descriptor disclosed at checkout.
  • Government-ID & age-verification data — to enforce our adults-only rule and meet record-keeping obligations, we and our verification vendors may collect government-issued ID, date of birth, photographs or selfies used for identity/age checks, and check results. Biometric techniques used by vendors are covered in Section 7.
  • Device, usage & cookies — IP address, device/browser type, OS, identifiers, approximate location from IP, pages and Content viewed, search terms, referrers, interaction data, timestamps. See the Cookie Policy.
  • Communications — messages, support tickets, complaints, appeals, abuse or copyright reports, and related metadata.
  • Creator tax & payout information — legal name, business name, mailing address, tax forms, and payout account details needed to pay the creator revenue share.
  • Inferences — derived preferences which, on an adult platform, can imply sex life or sexual orientation; treated as sensitive (Section 7).
03

Where it comes from

  • Directly from you — account creation, profile, verification, purchases, uploads, support contact.
  • Automatically — cookies and similar technologies, and your use of the Service.
  • From service providers — payment processors, age-verification/KYC vendors, payout providers, hosting/CDN, and analytics, which return verification results, transaction outcomes, and usage measurements.
  • From other Users — for example, when a depicted person, rights-holder, or other party submits a report or consent record relating to Content.
04

How we use it

  • Provide and operate the Service — accounts, Raw, Vault subscriptions, Private Access purchases, creator uploads, and pre-publication review.
  • Process payments and payouts — billing, one-time purchases, refunds, and creator revenue-share payouts through our processors and payout providers.
  • Verify age and identity — 18+ checks, Creator KYC, and consumer age verification where required by law.
  • Safety, moderation, and legal compliance — the prohibited-keyword filter and moderation; investigating complaints, appeals, abuse, NCII and copyright reports; consent and record-keeping documentation; fraud and chargeback prevention; and meeting legal obligations.
  • Communicate with you — receipts, billing and renewal notices, security alerts, support responses, and (where permitted) service updates.
  • Improve and secure the Service — analytics, reliability, security, debugging, new features.
  • Tax and recordkeeping — creator tax documentation and business records.
05

How we disclose it

Service providers acting on our behalf — payment processors and acquiring banks; age-verification and KYC vendors; payout providers; hosting and content-delivery providers; analytics; and support and communications tools.

Legal, safety, and law enforcement — to comply with applicable law, subpoenas, warrants, court orders, or other valid legal process; to enforce our Terms and policies; to protect the rights, safety, and property of Users, the public, or the Company; and to report or preserve content as required by law, including reporting suspected CSAM to NCMEC. Legal process is handled through [email protected] — see the Law Enforcement Request Policy.

Corporate transactions — in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred subject to this policy. We also share information with your direction or consent.

No sale for money. We do not sell personal information for monetary consideration. See Section 6 regarding "sharing" for cross-context behavioral advertising.

06

"Sale," "sharing" & opt-out

We do not sell personal information in exchange for money. Under California law, certain uses of cookies and similar technologies for cross-context behavioral advertising can be treated as "sharing" (and as a "sale" or "targeted advertising" under Virginia and Colorado law) even when no money changes hands.

Current status. We do not currently engage in any activity that constitutes a "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not deploy advertising, retargeting, or conversion-tracking technologies that disclose personal information to advertising networks; the promotions shown in the Raw area are served by us, first-party. Appendix A of our Cookie Policy lists every cookie and similar technology actually running on the Site.

How to opt out today. Email — send an opt-out request to [email protected]; we apply it to the account identified in your message and confirm when it is done, without requiring you to create an account or provide more information than we need. Opt-out preference signal — we are implementing support for recognized opt-out preference signals such as Global Privacy Control (GPC) and will honor them before any sale or sharing occurs. Browser and device controls — block or delete cookies through your browser settings, as described in the Cookie Policy.

Dedicated opt-out link (not yet available). We do not currently operate a "Do Not Sell or Share My Personal Information" link or preference center on the Site. Earlier versions of this policy referred to one; that reference was inaccurate and has been removed. We will implement a compliant opt-out mechanism, meeting the labeling and placement requirements of applicable state law, before we engage in any sale or sharing of personal information for cross-context behavioral advertising. Until then, the controls above are the operative ones. We do not use or disclose sensitive personal information beyond purposes permitted by law without offering any required limit-the-use or opt-in/opt-out choice (Section 7).

07

Sensitive personal information

Information about your use of the Service — Content you view, search, subscribe to, or purchase, and inferences drawn from that activity — can reveal or imply your sex life or sexual orientation. We treat such information as sensitive. We also treat government-ID, precise identifiers used for age verification, and any biometric information (for example, facial-age estimation processed by a verification vendor) as sensitive.

California (CPRA): we use sensitive personal information only for purposes permitted by law — providing the Service you request, verifying age, security, fraud prevention, and legal compliance — and not to infer characteristics for other purposes. Where the law gives you the right to limit its use, we honor that request. Because our use falls within the permitted purposes, we are not required to post a "Limit the Use of My Sensitive Personal Information" link; if our use changes, we will post one. You may make a limit request at any time by emailing [email protected]. Virginia (VCDPA) and Colorado (CPA): where these laws require opt-in consent before processing sensitive data, we obtain it or rely on a recognized exception. Biometric/ID data is used only to verify age/identity, meet record-keeping duties, and for fraud and safety, retained as described in Section 8.

08

Data retention

  • General — we retain personal information as long as needed to provide the Service, comply with legal obligations, resolve disputes, prevent fraud, and enforce agreements; then we delete, de-identify, or securely archive it.
  • Age and content records — identity and age records associated with Content are retained for the period required by law, including the 18 U.S.C. § 2257 period: seven years from production or five years after we cease to maintain the Content, whichever is longer. See the 2257 Compliance Statement for the Custodian of Records.
  • CSAM reporting preservation — where we report suspected CSAM, we preserve the associated report and material for at least the legally required period (one year of NCMEC-related preservation), or longer if required or requested by law enforcement.
  • Consumer age-verification data — we follow a data-minimizing approach and do not retain consumer government-ID data after verification is complete, except as strictly permitted or required by law; we rely on zero-retention/tokenized verification vendors where feasible.
  • Transactions and tax — billing, transaction, and creator tax/payout records are retained for the periods required by financial, tax, and card-network rules.
09

How we protect it

We maintain administrative, technical, and physical safeguards designed to protect personal information — encryption in transit (HTTPS sitewide), access controls, tokenization of payment data by our processors, and internal handling rules for sensitive data and verification records. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you and applicable authorities as required by law.

10

Your privacy rights

Depending on your state of residence, you may have some or all of the following rights:

  • Know / access — learn what we collect, use, and disclose, and obtain a portable copy.
  • Delete — request deletion, subject to legal exceptions (age/2257 records, tax, fraud prevention, legal compliance).
  • Correct — request correction of inaccurate personal information.
  • Opt out — of any "sale"/"sharing" for cross-context behavioral advertising and certain targeted advertising or profiling.
  • Limit sensitive-data use — where provided by law.
  • Non-discrimination — we will not discriminate against you for exercising your rights.
  • Appeal — if we deny your request, you may appeal (Section 11).
11

Exercising your rights

You (or an authorized agent acting on your behalf) may submit any privacy request — access, deletion, correction, opt-out, and limit requests — by emailing [email protected]. Email is currently our single intake channel for all privacy requests. We may need to verify your identity before acting and will not require more information than necessary. We respond within legally required timeframes and will tell you if we need a permitted extension. If we decline a request, our response explains why and how to appeal — reply to the decision or email [email protected]; where applicable you may also contact your state Attorney General.

Opt-out and limit controls. To opt out of any "sale" or "sharing" for cross-context behavioral advertising, use the controls in Section 6: email [email protected], or adjust your cookie and browser settings (see the Cookie Policy); recognized opt-out preference signals such as GPC will be honored before any sale or sharing occurs. To limit the use of sensitive personal information where that right applies, email [email protected]. As stated in Section 6, we do not yet operate a "Do Not Sell or Share My Personal Information" link or a cookie preference center; we will add a compliant mechanism before any sale or sharing occurs and update this policy at the same time.

California Notice at Collection. This Privacy Policy serves as our Notice at Collection: the categories we collect (Section 2), purposes (Section 4), disclosure practices (Sections 5–6), sensitive-data treatment (Section 7), and retention (Section 8). It is made available before payment information is requested.

12

Cookies

We use cookies and similar technologies to operate the Site, remember preferences, and secure accounts. We do not currently run third-party analytics or advertising cookies. The Cookie Policy explains the categories, the controls available to you, and — in its Appendix A — every cookie and storage key actually in use.

13

No users under 18

The Service is intended only for adults. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete it. If you believe a minor has provided us information, contact [email protected].

14

State-law mechanics & thresholds

This policy is built to a multistate baseline drawing on the California CCPA/CPRA, the Virginia VCDPA, and the Colorado CPA. Several of these laws apply only to businesses that cross defined thresholds. Under the CCPA as amended, a business is covered if it exceeds $26,625,000 in annual gross revenue (the inflation-adjusted figure for 2026), buys, sells, or shares the personal information of 100,000 or more California consumers or households annually, or derives 50% or more of annual revenue from selling or sharing personal information. The Virginia and Colorado statutes use comparable volume-based tests.

We have not confirmed that we currently meet any of these thresholds. We nevertheless honor the rights described in this policy as a voluntary baseline from launch. Certain statutory mechanics — a dedicated opt-out link, a preference center, and formal appeal workflows — will be implemented as we cross the relevant thresholds or begin any activity that triggers them, whichever comes first. Where a control is not yet in place, this policy says so rather than describing it as if it were. Residents of other states with comparable privacy laws may have similar rights, which we will extend as those laws require.

15

Changes & EU/UK note

We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date and, where required, additional notice. Continued use after an update takes effect means you accept the revised policy.

The Service is currently directed to U.S. Users. If and when we serve EU/UK users, additional requirements will apply — including the EU/UK GDPR (which treats data revealing sex life or sexual orientation as a special category requiring explicit consent) and EU/UK cookie-consent rules. We will provide a supplemental EU/UK privacy notice before directing the Service to those users.