1. Introduction
This Privacy Policy ("Policy") describes how BunniesNextDoor, a service operated by BunniesNextDoor LLC ("Company," "we," "us," or "our"), collects, uses, discloses, and otherwise processes personal information in connection with our website located at bunniesnextdoor.com (the "Site"), our mobile applications, and all related services, features, and content (collectively, the "Services").
By accessing or using our Services, you ("User," "you," or "your") acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree to this Privacy Policy, you must not access or use the Services.
This Policy applies to all visitors, registered users, models, performers, content creators, and any other individuals who interact with our Services. Certain provisions of this Policy apply specifically to residents of particular jurisdictions, including California (CCPA/CPRA), the European Economic Area, the United Kingdom, and other regions with comprehensive privacy legislation.
BunniesNextDoor is an adult entertainment platform. As such, portions of this Policy address data handling practices specific to adult content services, including age verification, 18 U.S.C. § 2257 record-keeping obligations, and enhanced data protection measures for sensitive personal information.
2. Definitions
- "Personal Information"
- Any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. This includes but is not limited to name, email address, payment information, device identifiers, IP addresses, and browsing history.
- "Sensitive Personal Information"
- A subset of Personal Information that includes government-issued identification numbers, financial account credentials, precise geolocation data, biometric data used for identification, and data concerning an individual's sex life or sexual orientation.
- "Content Creator" or "Model"
- An individual who has registered with the Services to produce, upload, or distribute adult content through the platform, subject to identity verification under 18 U.S.C. § 2257.
- "Processing"
- Any operation performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.
- "Service Provider"
- A third party that processes Personal Information on behalf of the Company pursuant to a written contract that restricts the Service Provider from retaining, using, or disclosing the Personal Information for any purpose other than performing the contracted services.
- "Tokens"
- Virtual currency purchased through the platform and used for tipping, purchasing content, or other transactions within the Services.
3. Information We Collect
3.1 Information You Provide Directly
We collect Personal Information that you voluntarily provide when you register for an account, make purchases, communicate with us, or otherwise interact with the Services. This includes:
- Account Registration Data: Full legal name, email address, username, password (stored in hashed form), date of birth, and country of residence.
- Identity Verification Data: For content creators and where required for age verification: government-issued photo identification (driver's license, passport, or national ID card), selfie photographs for identity matching, date of birth, and legal name. Verification is processed through our third-party identity verification partners.
- Payment Information: Billing name, billing address, and payment method details. Payment card numbers are processed and stored exclusively by our payment processor, CCBill, and are never stored on our servers. We retain only a tokenized reference, the last four digits of the card, card type, and billing postal code for transaction records.
- Profile Information: Display name, profile photograph, bio, preferences, and any other information you choose to include in your public or private profile.
- Communications: Messages sent through the platform's messaging features, customer support inquiries, emails, and any other direct communications with us or other users through the Services.
- Content Creator Onboarding Data: W-9 or W-8BEN tax forms, Social Security Number or Tax Identification Number (for U.S.-based creators), banking information for payouts (bank name, routing number, account number), and 2257 compliance records including legal name, date of birth, and copies of government-issued photo identification.
- Survey and Feedback Data: Responses to surveys, questionnaires, or feedback forms you choose to complete.
3.2 Information Collected Automatically
When you access or use our Services, we automatically collect certain information about your device and usage patterns, including:
- Device Information: Hardware model, operating system and version, unique device identifiers (including advertising identifiers), browser type and version, screen resolution, and device language settings.
- Log Data: IP address, access dates and times, pages viewed, referring URL, clickstream data, search queries within the Services, and features used.
- Usage Analytics: Session duration, page interaction data (scrolls, clicks, mouse movements where applicable for fraud detection), content viewed, content engagement metrics, and feature usage patterns.
- Location Data: Approximate geographic location derived from your IP address. We do not collect precise GPS-based geolocation data unless you explicitly consent to share it.
- Transaction Data: Records of Token purchases, tips sent and received, content purchases, subscription history, and payout records for content creators.
3.3 Information Collected via Cookies and Similar Technologies
We use cookies, pixel tags, web beacons, and similar tracking technologies to collect information about your interactions with the Services. See Section 10 ("Cookie Policy") for comprehensive details. Categories of cookies we deploy include:
- Strictly Necessary Cookies: Session authentication tokens, CSRF protection tokens, and load-balancing identifiers required for the Services to function.
- Analytics Cookies: PostHog analytics cookies for understanding user behavior, feature adoption, and platform performance. Datadog Real User Monitoring (RUM) cookies for performance monitoring and error tracking.
- Preference Cookies: Cookies storing your display preferences, language settings, and content filter configurations.
- Marketing Cookies: Where applicable and with your consent, cookies used to measure the effectiveness of advertising campaigns and deliver relevant promotional content.
3.4 Information from Third Parties
We may receive Personal Information about you from third-party sources, including:
- Identity Verification Providers: Results of identity and age verification checks.
- Payment Processors: Transaction confirmation data, chargeback notifications, and fraud alerts from CCBill.
- Social Media Platforms: If you link a social media account or use social login features, we may receive your name, email address, and profile information as permitted by your privacy settings on that platform.
- Law Enforcement and Regulatory Bodies: Information provided in connection with legal processes, compliance inquiries, or investigations.
4. How We Use Your Information
We process your Personal Information for the following purposes, each supported by a lawful basis under applicable privacy legislation:
4.1 Service Provision and Account Management
- Creating, maintaining, and securing your account.
- Processing Token purchases, subscriptions, tips, and content transactions.
- Facilitating payouts to content creators.
- Providing customer support and responding to inquiries.
- Enabling messaging and interactive features between users.
- Enforcing our Terms of Service and community guidelines.
4.2 Age and Identity Verification
- Verifying that all users accessing adult content are at least 18 years of age (or the age of majority in their jurisdiction, whichever is greater).
- Verifying the identity of content creators as required by 18 U.S.C. § 2257.
- Maintaining 2257 compliance records as mandated by federal law.
- Preventing the creation of duplicate or fraudulent accounts.
4.3 Personalization
- Recommending content based on your viewing history and preferences.
- Customizing the user interface and feature presentation.
- Tailoring notifications and communications to your interests.
4.4 Analytics and Platform Improvement
- Understanding how users interact with the Services to improve functionality, performance, and content discovery.
- Conducting A/B testing of features and interface elements.
- Monitoring platform performance, uptime, and error rates via Datadog and PostHog.
- Generating aggregated, de-identified statistical reports about platform usage.
4.5 Safety, Security, and Fraud Prevention
- Detecting, investigating, and preventing fraudulent transactions, unauthorized access, and other illegal activities.
- Monitoring for violations of our Terms of Service, including distribution of prohibited content.
- Implementing and maintaining technical security measures, including encryption, access controls, and intrusion detection.
- Conducting risk assessments and audit logging for compliance purposes.
4.6 Legal Compliance
- Complying with applicable laws, regulations, and legal processes, including 18 U.S.C. § 2257 record-keeping requirements.
- Responding to lawful requests from law enforcement agencies and regulatory bodies.
- Establishing, exercising, or defending legal claims.
- Maintaining records as required by tax laws in applicable jurisdictions.
4.7 Communications
- Sending transactional emails (account confirmations, purchase receipts, payout notifications, security alerts).
- With your consent, sending promotional communications about new features, content, and platform updates.
- Providing mandatory legal and regulatory notices.
5. How We Share Your Information
We do not sell your Personal Information. We share your information only in the following circumstances:
5.1 Service Providers
We engage trusted third-party service providers who process Personal Information on our behalf to support our operations. Each service provider is bound by contractual obligations to use your data only for the purposes we specify and to maintain appropriate security measures. Our key service providers include:
- CCBill: Payment processing, billing, subscription management, and chargeback resolution. CCBill receives your payment details, billing address, and transaction amounts. CCBill maintains its own privacy policy at ccbill.com.
- Supabase: Database hosting and authentication infrastructure. User account data, profile information, and platform data are stored in Supabase's hosted PostgreSQL instances in the US-East-1 (Virginia) region.
- PostHog: Product analytics and user behavior tracking. PostHog receives anonymized usage data, session recordings (where enabled), feature flag evaluations, and event tracking data.
- Datadog: Application performance monitoring, error tracking, and Real User Monitoring. Datadog receives performance telemetry, error logs, and anonymized session data.
- Content Delivery Networks (CDNs): We use CDN providers to deliver static assets and media content. CDN providers may process IP addresses and request metadata to serve content efficiently.
- Identity Verification Providers: Third-party services that process government-issued identification documents and biometric data for age and identity verification purposes.
- Email Service Providers: Services used to deliver transactional and, where consented, promotional email communications.
- Cloud Infrastructure: Amazon Web Services (AWS) provides compute, storage, and networking infrastructure for portions of the Services.
5.2 Content Creators
When you interact with a content creator (e.g., by tipping, subscribing, or messaging), the creator may see your username, display name, profile picture, and the content of your interactions. Content creators do not receive your real name, email address, payment information, or other account details unless you voluntarily share them.
5.3 Legal Obligations and Law Enforcement
We may disclose your Personal Information when we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, legal process, or enforceable governmental request.
- Enforce our Terms of Service, including investigation of potential violations.
- Detect, prevent, or address fraud, security, or technical issues.
- Protect against harm to the rights, property, or safety of the Company, our users, or the public as required or permitted by law.
- Respond to NCMEC (National Center for Missing & Exploited Children) reports or similar reporting obligations in other jurisdictions.
5.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your Personal Information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Services of any change in ownership or uses of your Personal Information, as well as any choices you may have regarding your Personal Information.
5.5 Aggregated and De-Identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for research, marketing, analytics, and other purposes.
6. Adult Content — Specific Provisions
6.1 Age Verification Data
Federal and state laws require us to verify that all individuals appearing in adult content distributed through our platform are at least 18 years of age. To comply with these requirements:
- We collect and retain copies of government-issued photo identification from all content creators.
- Age verification data is stored in encrypted form, separate from general account data, with strict access controls limiting access to authorized compliance personnel only.
- We do not use age verification data for any purpose other than legal compliance and identity verification.
- Retention of age verification records is governed by 18 U.S.C. § 2257 and 28 C.F.R. Part 75, which require records be maintained for a minimum of five (5) years after the last date content is published.
6.2 Section 2257 Record-Keeping
Pursuant to 18 U.S.C. § 2257 and the regulations promulgated thereunder (28 C.F.R. Part 75), we maintain records that document the identity and age of every performer depicted in visual content hosted on the Services. These records include:
- The performer's legal name and any aliases or stage names used.
- The performer's date of birth.
- A copy of the performer's government-issued photo identification.
- Cross-references linking each piece of visual content to the performer's 2257 records.
These records are maintained by our designated Custodian of Records and are available for inspection as required by law. See our 2257 Compliance Statement for details.
6.3 Content Moderation
We employ both automated systems and human reviewers to moderate content uploaded to the platform. In connection with content moderation, we may process the content of media files (images and videos) to detect prohibited content, including but not limited to content depicting minors, non-consensual activity, or other prohibited material. Automated scanning technologies are used solely for safety and compliance purposes.
7. Data Retention
We retain your Personal Information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements. Specific retention periods include:
- Active Account Data: Retained for the duration of your account's existence plus thirty (30) days following account deletion to allow for account recovery.
- Transaction Records: Retained for seven (7) years from the date of the transaction to comply with tax and financial reporting obligations.
- 2257 Compliance Records: Retained for a minimum of five (5) years following the last publication date of associated content, as required by federal law.
- Identity Verification Data: Retained for the duration of the creator's account plus five (5) years following account termination or the last publication date of their content, whichever is later.
- Analytics Data: Anonymized analytics data may be retained indefinitely. Personally identifiable analytics data is retained for no more than twenty-four (24) months.
- Communications and Support Records: Retained for three (3) years following the last interaction.
- Server Logs: Retained for ninety (90) days, after which they are either deleted or anonymized.
- Cookie Data: Session cookies expire when you close your browser. Persistent cookies have varying expiration periods as detailed in Section 10.
When Personal Information is no longer required for any purpose described in this Policy, we will securely delete or anonymize the data. Deletion may take up to thirty (30) days to propagate across all backup systems.
8. Security Measures
We implement and maintain commercially reasonable technical and organizational security measures designed to protect your Personal Information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption: All data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest (including identity documents and payment tokens) is encrypted using AES-256.
- Access Controls: Role-based access control (RBAC) limits access to Personal Information to authorized personnel who require access for their specific job functions. Multi-factor authentication is required for all administrative access.
- Infrastructure Security: Our infrastructure is hosted on secured cloud platforms with SOC 2 Type II certified providers. Network security includes firewalls, intrusion detection systems, and DDoS mitigation.
- Monitoring: Continuous security monitoring via Datadog and automated alerting for anomalous access patterns, failed authentication attempts, and potential data breaches.
- Employee Training: All personnel with access to Personal Information receive regular training on data protection obligations and security best practices.
- Incident Response: We maintain a documented incident response plan and will notify affected individuals and relevant authorities of any data breach in accordance with applicable law.
- Vendor Security: All third-party service providers are contractually required to maintain security measures at least as protective as our own.
9. International Data Transfers
The Services are operated from the United States. Our primary database infrastructure is hosted by Supabase in the US-East-1 (Northern Virginia) region. If you are accessing the Services from outside the United States, please be aware that your Personal Information will be transferred to, stored, and processed in the United States.
The data protection laws of the United States may differ from those of your country of residence. By using the Services, you consent to the transfer of your information to the United States and the processing of your information in accordance with this Policy.
For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on the following transfer mechanisms to ensure an adequate level of protection for your Personal Information:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Where applicable, adequacy decisions by the European Commission regarding the recipient country's data protection laws.
- Your explicit consent to the transfer, where required and where other mechanisms are not available.
You may request a copy of the applicable transfer mechanisms by contacting us at privacy@bunniesnextdoor.com.
10. Cookie Policy
This section describes the cookies and similar tracking technologies used by the Services.
10.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work more efficiently, to remember your preferences, and to provide information to the site operators. We also use similar technologies including pixel tags, web beacons, and local storage.
10.2 Cookies We Use
- Authentication Cookies (Strictly Necessary): Session tokens issued by Supabase Auth to maintain your logged-in state. These are HttpOnly, Secure, and SameSite=Lax. Expires: end of session or 7 days for "remember me" sessions.
- CSRF Tokens (Strictly Necessary): Tokens used to prevent cross-site request forgery attacks. Expires: end of session.
- PostHog Analytics (Analytics): PostHog deploys cookies to track anonymized user sessions, page views, feature usage, and conversion funnels. Cookie names include
ph_*identifiers. Expires: 1 year. - Datadog RUM (Analytics): Datadog Real User Monitoring cookies track page load performance, JavaScript errors, and user interaction latency for platform health monitoring. Expires: session.
- Preference Cookies (Functional): Cookies storing your content display preferences, theme settings, and locale. Expires: 1 year.
10.3 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, and set preferences for certain websites. Please note that disabling strictly necessary cookies may prevent you from using certain features of the Services.
For more information about managing cookies in your browser, please visit:
- Chrome: chrome://settings/cookies
- Firefox: about:preferences#privacy
- Safari: Preferences > Privacy
- Edge: edge://settings/privacy
11. Your Privacy Rights
11.1 Universal Rights
Regardless of your location, you have the following rights regarding your Personal Information:
- Access: You may request a copy of the Personal Information we hold about you.
- Correction: You may request correction of inaccurate or incomplete Personal Information.
- Deletion: You may request deletion of your Personal Information, subject to certain exceptions (e.g., data retained for legal compliance under 2257).
- Opt-Out of Marketing: You may opt out of promotional communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us directly.
- Account Deletion: You may request complete account deletion through your account settings or by emailing privacy@bunniesnextdoor.com.
11.2 CCPA/CPRA Rights (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights, including:
- Right to Know: You have the right to request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of sources from which it was collected, the business purposes for collection, and the categories of third parties with whom it was shared.
- Right to Delete: You have the right to request deletion of your Personal Information, subject to certain exceptions under the CCPA.
- Right to Correct: You have the right to request that we correct inaccurate Personal Information.
- Right to Opt-Out of Sale/Sharing: We do not sell your Personal Information. We do not share your Personal Information for cross-context behavioral advertising purposes.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of your Sensitive Personal Information to purposes necessary for performing the services you request.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise your CCPA/CPRA rights, contact us at privacy@bunniesnextdoor.com or call [toll-free number to be provided]. We will verify your identity before processing your request. You may also designate an authorized agent to make requests on your behalf.
Categories of Personal Information Collected (preceding 12 months): Identifiers; financial information; commercial information; Internet or other electronic network activity information; geolocation data; audio, electronic, visual, or similar information; professional or employment-related information (for content creators); and inferences drawn from the above.
11.3 GDPR Rights (EEA, UK, and Swiss Residents)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) or the UK GDPR:
- Right of Access: You have the right to obtain confirmation of whether we process your Personal Information and to receive a copy of that data.
- Right to Rectification: You have the right to have inaccurate Personal Information corrected and incomplete information completed.
- Right to Erasure ("Right to Be Forgotten"): You have the right to request deletion of your Personal Information where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
- Right to Restriction of Processing: You have the right to request restriction of processing in certain circumstances.
- Right to Data Portability: You have the right to receive your Personal Information in a structured, commonly used, machine-readable format and to transmit that data to another controller.
- Right to Object: You have the right to object to processing of your Personal Information based on legitimate interests, including profiling.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw consent at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in your country of residence.
Legal Bases for Processing: We process your Personal Information under the following legal bases: (a) performance of a contract (to provide you the Services you have requested); (b) compliance with legal obligations (2257 record-keeping, tax reporting); (c) your consent (marketing communications, non-essential cookies); and (d) legitimate interests (security, fraud prevention, platform improvement), balanced against your fundamental rights and freedoms.
12. Children's Privacy
The Services are intended exclusively for individuals who are at least 18 years of age. We do not knowingly collect Personal Information from individuals under the age of 18. If we become aware that we have inadvertently collected Personal Information from a minor, we will take immediate steps to delete that information from our records.
If you believe that a minor has provided us with Personal Information, please contact us immediately at privacy@bunniesnextdoor.com.
13. Do Not Track Signals
Some web browsers transmit "do not track" (DNT) signals to websites. Because there is no universally accepted standard for how to respond to DNT signals, we do not currently respond to DNT signals. However, you may manage your tracking preferences through the cookie management options described in Section 10.3.
14. Third-Party Links and Services
The Services may contain links to third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of any third-party services you access through our platform. We are not responsible for the privacy practices or content of third-party services.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy.
- Provide prominent notice on the Services (e.g., a banner or pop-up notification).
- Where required by law, send email notification to registered users.
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree with any changes, you must stop using the Services and may request deletion of your account and Personal Information.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Privacy Inquiries: privacy@bunniesnextdoor.com
- General Legal: legal@bunniesnextdoor.com
- Data Protection Officer: privacy@bunniesnextdoor.com (Attn: Data Protection Officer)
- Mailing Address:
BunniesNextDoor LLC
Attn: Privacy Department
[Physical Address to be provided]
United States
We will acknowledge your request within ten (10) business days and endeavor to respond substantively within thirty (30) days, or within the timeframe required by applicable law.