Privacy Policy - CruiseHuddle - CruiseHuddle

Privacy Policy

Last Updated: March 30, 2026

Introduction

Welcome to CruiseHuddle, operated by CruiseConnect LLC ("we," "us," or "our"). We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at cruisehuddle.com, our mobile applications (iOS and Android), progressive web app (PWA), and related services (collectively, the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy.

As a platform that handles biometric age verification, sensitive personal data, and content filtering modes, we take extra precautions to protect your information and ensure user safety.

1. Information We Collect

1.1 Information You Provide

  • Account Registration: Username, email address, password, member type (male, female, couple), age, city, state, zip code
  • Profile Information: Profile picture, bio, seeking preferences
  • Cruise Listings: Cruise line, ship name, departure/return dates, embarkation port, photos, seeking preferences
  • Communications: Messages, Community Huddle posts, Ship Hub messages, support tickets
  • Payment Information: Subscription and one-time purchases are processed by Stripe and Square. CruiseHuddle does not directly store credit card numbers or bank account details. Payment processors retain payment data per their own privacy policies.

1.2 Biometric and Verification Data

  • Age Verification (Mandatory): A selfie image is captured and analyzed using AI facial age estimation provided by Didit. CruiseHuddle receives only a pass/fail result and estimated age bracket. The selfie image is processed by Didit and deleted within 7 days. CruiseHuddle does not store facial images or biometric data.
  • ID Verification (Optional): Government-issued identification documents submitted for premium verification are processed by Didit. CruiseHuddle receives verification status, document type, and name. Didit retains document images per their retention policy.

1.3 Information Collected Automatically

  • Device Information: IP address, browser type, device type, operating system
  • Usage Data: Pages visited, features used, interactions, time spent, search queries
  • Location Data: General location based on IP address (city/state level). We do not collect precise GPS location.
  • Online Status: When you are actively using the Service, your online status may be visible to other users
  • Cookies and Tracking: See Section 9

1.4 Third-Party Authentication

If you register via Google, Facebook, or Apple, we collect your name and email address as authorized. When using Apple's "Hide My Email," we receive a private relay address. We do not access your social media content, contacts, or OAuth provider passwords.

1.5 Sensitive Personal Data

In the course of providing the Service, we may process the following categories of data that qualify as sensitive personal data under certain privacy laws (GDPR, CCPA/CPRA):

  • Biometric Data: Facial geometry used for age estimation (processed by Didit, not stored by CruiseHuddle)
  • Lifestyle Preferences: Member type, seeking preferences, and content mode usage may reflect lifestyle information
  • Relationship Status: Member type (single male, single female, couple)

We process sensitive personal data only with your explicit consent and solely for the purpose of providing the Service. You may withdraw consent at any time by deleting your account.

2. How We Use Your Information

  • Provide the Service: Manage accounts, display profiles and listings, facilitate messaging, operate Ship Hubs and Community Huddles
  • Age and Identity Verification: Confirm minimum age requirements and optional identity verification
  • Payment Processing: Process subscriptions and purchases through Stripe and Square
  • Safety and Security: Monitor for prohibited content, prevent fraud, detect bots, enforce Terms, calculate KYC trust scores
  • Communications: Send verification emails, purchase confirmations, security alerts, notifications, and promotional communications (with opt-out)
  • Service Improvement: Analyze usage patterns, develop features, optimize experience
  • Legal Compliance: Respond to legal requests, protect our rights, comply with laws
  • Advertising Measurement: Measure advertising effectiveness through Google Analytics and Meta Pixel using anonymized/aggregated data

We will NEVER sell your personal information to third parties.

3. Legal Basis for Processing (GDPR)

For users in the EEA/UK, we process personal data on the following legal bases:

  • Consent: Biometric age verification, NSFW mode activation, optional ID verification, promotional emails, cookies
  • Contract Performance: Account creation, profile management, messaging, payment processing, subscription management
  • Legal Obligation: Compliance with applicable laws, responding to legal requests, age verification requirements
  • Legitimate Interest: Safety and fraud prevention, bot detection, KYC scoring, Service improvement, analytics. We conduct balancing tests to ensure our legitimate interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interest at any time by contacting [email protected].

4. Third-Party Service Providers

We share information with trusted third-party providers who assist in operating the Service:

  • Didit — Age estimation (biometric) and identity verification. Processes selfie/ID images and deletes per their retention policy. CruiseHuddle receives only verification results.
  • Stripe — Subscription payment processing. Handles credit card data directly per PCI-DSS standards.
  • Square — One-time payment processing. Handles credit card data directly per PCI-DSS standards.
  • Postmark — Transactional and promotional email delivery.
  • Pusher — Real-time messaging infrastructure. Transmits message events; does not store content long-term.
  • Cloudflare — CDN, DDoS protection, SSL/TLS. May process IP addresses and request metadata.
  • Vultr — Server hosting and infrastructure (United States).
  • Google (OAuth, Analytics, Ads) — Authentication, anonymized usage analytics, advertising measurement.
  • Facebook/Meta (OAuth, Pixel) — Authentication and advertising measurement.
  • Apple (OAuth) — Authentication via Sign In with Apple.
  • OpenRouter — AI content generation. Processes anonymized prompts for content generation. User-identifying data is not sent to OpenRouter. AI-generated content is not used to train third-party models.

These providers are contractually obligated to protect your information and process it only as instructed by us.

5. Information Visible to Other Users

  • Username and profile picture (watermarked)
  • Bio, member type, and age
  • City and state (not zip code or precise location)
  • Cruise listings, photos, and seeking preferences
  • Online/offline status
  • Verification badges (age verified, ID verified, Fan Club member)
  • KYC trust score level
  • Community Huddle posts and Ship Hub messages

Your email address, payment information, IP address, exact zip code, and biometric data are NEVER publicly displayed.

6. Legal Disclosures

We may disclose your information when required by law or in good faith belief that disclosure is necessary to:

  • Comply with legal obligations, court orders, subpoenas, or government requests
  • Enforce our Terms of Service
  • Protect the rights, property, or safety of CruiseConnect LLC, our users, or the public
  • Investigate or prevent illegal activities, fraud, or security threats

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.

7. Data Security

  • Encryption: HTTPS/TLS encryption via Cloudflare for all data in transit
  • Password Protection: Passwords are cryptographically hashed (bcrypt) and cannot be viewed by staff
  • Access Controls: Limited employee access to personal data on a need-to-know basis
  • Photo Watermarking: All photos automatically watermarked to prevent misuse
  • Automated Backups: Regular encrypted database backups
  • Bot Detection: Automated systems detect and remove fraudulent accounts
  • Payment Security: All payment processing handled by PCI-DSS compliant processors (Stripe and Square)

No method of transmission over the internet is 100% secure. While we implement industry-standard security measures, we cannot guarantee absolute security.

Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify affected users within 72 hours of becoming aware of the breach via email and/or prominent notice on the Service, and will notify applicable regulatory authorities as required by law.

8. Data Retention

We retain personal information as follows:

  • Account Data: Retained while your account is active and for 90 days after deletion
  • Messages: Retained while both parties have active accounts. When you delete your account, your sent messages may remain visible to the other party but your username will be anonymized
  • Community Content: Huddle posts and Ship Hub messages may be retained after account deletion in anonymized form
  • Payment Records: Retained as required for tax and accounting purposes (typically 7 years)
  • Biometric Data (Didit): Processed and deleted by Didit within 7 days of the verification session
  • Backups: Account data may persist in encrypted backups for up to 30 days after deletion
  • Legal Requirements: Information required for legal compliance, dispute resolution, or fraud prevention may be retained as necessary

9. Cookies and Tracking Technologies

  • Essential Cookies: Required for authentication, CSRF protection, and session management. Cannot be disabled.
  • Preference Cookies: Remember your settings (SFW/NSFW mode, notification preferences)
  • Analytics (Google Analytics GA4): Anonymized usage data to understand how users interact with the Service. Tracking ID: G-TT23HJ0GJ7
  • Advertising (Google Ads): Conversion tracking for advertising measurement. Tag ID: AW-18043021788
  • Advertising (Meta Pixel): Conversion tracking for Facebook/Instagram advertising. Pixel ID: 795985589802264

These tools may use cookies, pixel tags, web beacons, or similar technologies to collect anonymized usage and conversion data. You can control non-essential cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.

10. Automated Decision-Making and Profiling

CruiseHuddle uses automated systems that may affect your experience:

  • Age Estimation: AI analyzes facial features to estimate age. A "decline" result prevents access until resolved. You may request manual review or use ID Verification as an alternative.
  • KYC Trust Score: An automated score based on verification status, account behavior, and community engagement. This score is visible to other users and may affect how your profile is perceived. The score does not restrict access to features.
  • Bot Detection: Automated systems may flag or restrict accounts exhibiting bot-like behavior. Affected users may contact support for manual review.

Under GDPR and similar laws, you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. If you believe an automated decision has adversely affected you, contact [email protected] to request human review.

11. Your Privacy Rights

  • Access: Request a copy of the personal information we hold about you
  • Correction: Update or correct inaccurate information through your account settings
  • Deletion: Request deletion of your account and personal information
  • Opt-Out: Unsubscribe from promotional emails (transactional emails cannot be disabled while your account is active)
  • Data Portability: Request your data in a structured, machine-readable format
  • Object/Restrict: Object to or restrict certain processing of your information
  • Withdraw Consent: Withdraw consent for optional data processing at any time without affecting prior processing
  • Contest Automated Decisions: Request human review of automated decisions (age verification, KYC scoring, bot detection)

To exercise these rights, contact [email protected]. We will respond within 30 days (45 days for complex requests).

12. Children's Privacy

CruiseHuddle is intended exclusively for adults 18 years and older. We do not knowingly collect information from individuals under 18.

All users must complete AI-powered age verification before accessing the platform. If we discover a user is under 18, their account will be immediately terminated and all associated data deleted.

If you believe a minor has accessed our Service, contact us immediately at [email protected]

13. California Privacy Rights (CCPA/CPRA)

California residents have additional rights:

  • Right to Know: Request disclosure of categories and specific personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Correct: Request correction of inaccurate information
  • Right to Opt-Out of Sale/Sharing: We do NOT sell or share personal information for cross-context behavioral advertising
  • Right to Non-Discrimination: You will not be discriminated against for exercising rights
  • Right to Limit Sensitive Data Use: You may request we limit use of sensitive data to what is necessary

Email [email protected] with "California Privacy Rights" in the subject line.

14. European Privacy Rights (GDPR/UK GDPR)

EEA and UK residents have rights including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.

You may lodge a complaint with your local data protection authority. Our legal bases for processing are detailed in Section 3.

15. Illinois Biometric Information Privacy (BIPA)

Illinois residents: We provide the following disclosures regarding biometric data:

  • Purpose: Biometric data (facial geometry) is collected solely for age estimation to comply with our 18+ age requirement
  • Processor: Biometric data is processed exclusively by Didit, our third-party verification provider
  • Retention: Didit deletes biometric data within 7 days of the verification session. CruiseHuddle never stores biometric data.
  • No Sale or Trade: Biometric data is never sold, leased, traded, or otherwise profited from
  • Consent: By completing age verification, you provide informed written consent to this biometric data collection and processing
  • Third-Party Liability: CruiseHuddle relies on Didit's representations regarding biometric data handling. We are not liable for Didit's independent processing of biometric data beyond our contractual agreements.

16. International Data Transfers

CruiseHuddle is based in the United States. All data is stored on servers located in the United States (Vultr). If you access the Service from outside the United States, your information is transferred to and processed in the United States.

For EEA/UK users: We rely on your explicit consent as the legal mechanism for transferring data to the United States. We acknowledge that the United States may not provide the same level of data protection as the EEA/UK. By using the Service, you explicitly consent to this transfer and acknowledge the associated risks.

Our third-party providers (including Didit, Stripe, Cloudflare) may process data in various jurisdictions per their own privacy policies and data transfer mechanisms.

17. Do Not Track Signals

We do not currently respond to "Do Not Track" browser signals as there is no universally accepted standard.

18. Third-Party Links

The Service may contain links to third-party websites (cruise line websites, merchandise stores, etc.). We are not responsible for their privacy practices. Review their policies before providing personal information.

19. Data Deletion Requests (Facebook)

Per Facebook platform requirements, you may request deletion of data received from Facebook by emailing [email protected] with "Facebook Data Deletion" in the subject line. We will confirm deletion within 30 days.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you by posting the updated policy with a new "Last Updated" date. For material changes, we will also notify by email.

Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

21. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy:

CruiseConnect LLC — Privacy

Privacy: [email protected]

Support: [email protected]

1500 N Grant St, Ste R, Denver, CO 80203

Website: https://cruisehuddle.com

By using CruiseHuddle, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.