Privacy Policy
Effective date: August 11, 2026
This Privacy Policy explains how Starbiss LTD., the company that operates Heveny (the “Operator,” “we,” “us,” or “our”), collects, uses, discloses, stores, and otherwise processes personal data when you use the Heveny website, progressive web application, accounts, profiles, discovery features, communities, stories, posts, messaging, payments, rewards, partner features, and related services (collectively, the “Service”).
The Operator is the controller of personal data processed for its own purposes. Some service providers process personal data for us under our instructions, while payment providers and other independent services may act as separate controllers for their own purposes.
By using the Service, you acknowledge the practices described in this Policy. Where consent is the lawful basis for processing, we will ask for consent separately and you may withdraw it at any time without affecting processing that occurred before withdrawal.
1. Scope
This Policy applies to personal data processed through the Service and in related support, safety, payment, marketing, and business operations. It does not govern a third party’s service, website, or application merely because it is linked from or integrated with Heveny. Third parties have their own privacy notices and terms.
The Service is intended only for people aged 18 or older. It is not directed to children.
2. Personal data we collect
The data we collect depends on the features you use, the information you choose to provide, your settings, and the permissions you grant.
2.1 Account and identity data
We may collect:
- email address, password authentication records, email-verification status, login method, authentication tokens, and account identifiers;
- display name, first and last name, username, date of birth, age, gender, country, state, city, and profile photo;
- account creation and update dates, role, onboarding status, account status, restrictions, and security events;
- referral or invitation codes, referring partner or member, and registration source; and
- information received from an authentication provider, such as Google, when you choose that sign-in method. We do not receive your Google password.
Passwords are handled through our authentication service and are not displayed to other members. You are responsible for keeping your credentials confidential.
2.2 Profile, preference, and discovery data
You may provide information for your relationship or social profile, including:
- connection intent, the genders you are interested in meeting, preferred age range, maximum discovery distance, and other discovery preferences;
- tagline, biography, photos, relationship status, religion, education, occupation, employment, lifestyle, family and children preferences, personality, horoscope, pets, relocation preferences, living situation, body type, and similar optional profile fields;
- fields you choose to hide or show; and
- profile completion status and timestamps.
Some profile and preference information may reveal or permit inferences about sensitive characteristics, including religious beliefs, sexual orientation or sex life, relationship preferences, or other information treated as sensitive or special-category data under applicable law. You choose whether to provide optional fields. We process sensitive profile data to provide the features you request and, where required, on the basis of your explicit consent.
2.3 Location data
We process the country, state, city, and coordinates associated with a selected city to provide nearby discovery and distance estimates. We may also infer your country from your IP address for signup, security, localization, fraud prevention, or compliance. If the Service later requests device-location permission, your device will provide location only after you grant that permission.
Other members generally see a city or approximate distance—not your underlying coordinates. Do not include a home address or other precise location in public profile text or content.
2.4 Photos, posts, stories, communities, and other content
We collect content you create, upload, publish, repost, react to, or otherwise submit, including profile photos, avatars, posts, replies, stories, series, community content, captions, links, polls, reactions, likes, and related metadata. Content may include personal data about you or another person.
You must have the right to share any content you upload. Do not post another person’s private information, image, or communications without appropriate permission.
2.5 Connections, messages, and social activity
We process:
- connection requests, acceptances, declines, revocations, disconnects, and related status;
- messages and message metadata, including sender, recipient, conversation, timestamps, delivery and read status;
- short-lived typing indicators and presence or activity status;
- likes, reactions, profile views, blocks, notification activity, and social-interaction counts; and
- settings and templates used for connection requests and responses.
Messages are visible to conversation participants and may be reviewed by authorized personnel when reasonably necessary to investigate a report, protect users, enforce our rules, comply with law, or maintain the Service.
2.6 Safety, reporting, and moderation data
We collect reports, report categories, descriptions, evidence, appeals, enforcement history, blocked accounts, suspected abuse signals, and records of moderation decisions. A report may contain information supplied by another member about you. We may preserve relevant content and account records when needed to investigate abuse, prevent repeat violations, respond to emergencies, establish or defend legal claims, or comply with law.
2.7 Payments, wallet, rewards, and partner data
If you purchase a membership, pay for a feature, receive rewards, participate in a partner program, or request a payout, we may process:
- product, plan, order, subscription, transaction, currency, amount, status, and payment-reference data;
- wallet balances, credits, debits, holds, rewards, commissions, payout requests, and transaction history;
- billing details and limited payment-method information returned by a payment provider, such as payment type, card brand, and last four digits; and
- payout identity, bank-account, mobile-money, or connected-account details needed by the applicable payout provider.
Stripe or Flutterwave processes payment-card, bank, or payout credentials. We do not intend to store complete payment-card numbers or card security codes on Heveny systems.
2.8 Device, network, cookie, and usage data
We and our providers may automatically collect:
- IP address, device and browser type, operating system, language, user agent, network information, and approximate country;
- page paths, referring page, page views, feature interactions, login and signup events, checkout and purchase events, app-install events, timestamps, and diagnostic data;
- a first-party visitor identifier, account identifier, session identifiers, and similar persistent identifiers;
- push-notification endpoint and encryption keys, permission state, delivery status, and failure information; and
- fraud, abuse, bot, rate-limit, and security signals, which may include a browser-generated device fingerprint.
We use the open-source FingerprintJS library to generate device/browser signals used for visitor continuity, security, abuse prevention, and aggregate analytics. A first-party visitor identifier may be stored in a cookie and local storage for up to 12 months unless you clear it sooner.
2.9 Data from other sources
We may receive personal data from:
- other members who interact with, mention, invite, block, or report you;
- authentication, payment, payout, email, push, analytics, advertising, anti-fraud, hosting, and location providers;
- partners and referral sources;
- public sources where permitted by law; and
- authorities or other parties involved in safety, fraud, dispute, or legal matters.
3. How we use personal data
We use personal data to:
- Provide and perform the Service. Create and secure accounts; operate profiles, discovery, connections, messaging, communities, content, notifications, memberships, purchases, wallets, rewards, and payouts; remember settings; and provide support.
- Personalize discovery and content. Apply your age, gender-interest, intent, distance, and profile preferences; calculate approximate distance; rank eligible profiles; and present relevant communities, content, and features.
- Maintain safety and integrity. Verify eligibility, enforce the 18+ requirement, detect spam or fraud, prevent unauthorized access, investigate reports, block harmful interactions, moderate content, apply restrictions, process appeals, and protect users and the public.
- Communicate with you. Send verification codes, security and transactional messages, connection and activity notifications, support responses, service announcements, and marketing communications where permitted.
- Process payments and administer financial records. Complete purchases, subscriptions, refunds, wallet transactions, partner commissions, and payouts; reconcile accounts; prevent payment fraud; and meet tax, accounting, and financial obligations.
- Operate, measure, and improve the Service. Diagnose errors, monitor performance, understand aggregate usage, test improvements, develop features, and conduct internal research and analytics.
- Comply with law and protect rights. Respond to lawful requests, preserve records, enforce agreements, resolve disputes, and establish, exercise, or defend legal claims.
- Complete business transactions. Evaluate or complete a financing, reorganization, merger, acquisition, sale, or transfer involving all or part of the Service, subject to appropriate safeguards.
We do not use the contents of private messages or sensitive profile fields for third-party targeted advertising.
4. Lawful bases
Where applicable law requires a lawful basis, we rely on one or more of the following:
- Contract: processing necessary to create your account, provide requested features, deliver memberships or purchases, and administer our relationship with you.
- Consent: processing optional sensitive profile information where explicit consent is required; sending certain marketing or push communications; accessing device permissions; or using non-essential tracking where consent is legally required.
- Legitimate interests: operating and improving the Service; recommending relevant profiles; securing accounts; preventing fraud and abuse; moderating content; protecting users; measuring performance; and communicating about the Service. We balance these interests against your rights and expectations.
- Legal obligation: processing necessary for tax, accounting, consumer-protection, sanctions, law-enforcement, regulatory, recordkeeping, or other legal duties.
- Vital interests or substantial public interest: limited processing needed to protect someone’s life, safety, or fundamental rights, or for another basis recognized by applicable law.
- Legal claims: preserving and using information to establish, exercise, or defend legal rights.
If we ask for data that is required to provide the Service, failure to provide it may prevent you from creating or completing an account, using a feature, making a payment, or receiving a payout. Optional profile fields may be left blank unless the interface identifies them as required.
5. Discovery ranking, profiling, and automated systems
Heveny uses automated processing to determine which profiles are eligible for discovery and how they are ordered. The system may use:
- mutual gender-interest and age eligibility;
- connection intent and preference compatibility;
- approximate distance, with closer eligible profiles generally prioritized;
- profile status, recency, and availability;
- blocks, existing relationship state, account restrictions, and safety rules; and
- the discovery mode and filters you select.
Discovery ranking affects the order in which profiles appear; it does not determine whether you may form a relationship or make another legally significant decision. You can change available discovery preferences in your account.
We may also use automated rules or signals to detect abuse, prioritize reports, identify suspicious activity, rate-limit actions, or temporarily quarantine content. Authorized personnel may review reports and enforcement decisions. Where applicable law gives you a right not to be subject to a solely automated decision producing legal or similarly significant effects, you may request human review and contest the decision through the appeal or contact process.
6. When personal data is disclosed
We may disclose personal data as follows.
6.1 To other members and the public
- Your profile and the fields you choose to show are visible to eligible members through discovery and profile pages.
- Your public posts, stories, replies, reactions, community activity, username, display name, avatar, and related content may be visible to members or the public, depending on the feature and privacy setting.
- Content in a private community is visible to authorized community participants, subject to that community’s settings.
- Connection requests and messages are disclosed to their recipients.
- Other members may see limited activity such as likes, connection state, or presence where the product displays it.
Search engines or third parties may copy public content. Changing a setting or deleting content may not remove copies already indexed, cached, quoted, or independently retained by others.
6.2 To service providers
We use providers that support hosting, database and file storage, authentication, email, payments, payouts, analytics, advertising, location lookup, image delivery, push notifications, security, and customer support. Depending on the features enabled, these may include:
- Convex for application hosting, database, authentication components, real-time services, and file storage;
- Amazon Web Services, including Amazon SES, for email delivery;
- Google for optional sign-in and, if enabled, analytics;
- Stripe and Flutterwave for payments, connected payout accounts, bank or mobile-money transfers, refunds, and fraud controls;
- Meta and TikTok if their analytics or advertising pixels are enabled;
- IP2Location, IPGeolocation, ip-api, IPWhois, or MaxMind for IP-based country lookup, depending on availability and configuration;
- browser and operating-system push services for web notifications; and
- content delivery, image, monitoring, security, professional-adviser, and support providers used to operate the Service.
Providers receive only the data reasonably necessary for their function and are subject to contractual or legal duties appropriate to their role. A provider acting as an independent controller processes data under its own privacy notice.
6.3 For legal, safety, and compliance purposes
We may disclose data when we reasonably believe disclosure is necessary to comply with law or legal process; respond to a valid request from a court, regulator, or authority; detect or investigate fraud or abuse; protect a person from harm; enforce our agreements; or protect the rights, property, and safety of the Operator, users, or others.
We review government and law-enforcement requests for apparent validity and scope. Where legally permitted and appropriate, we may notify the affected user.
6.4 Business transfers
Personal data may be disclosed to advisers, counterparties, and successors in connection with a proposed or completed investment, financing, merger, acquisition, restructuring, insolvency, or sale of assets. Any successor that becomes a controller will remain subject to this Policy until it provides another legally valid notice.
7. Cookies, local storage, and similar technologies
The Service uses cookies, local storage, session storage, pixels, and similar technologies for the following purposes:
- Strictly necessary: authentication, security, fraud prevention, load handling, checkout continuity, and core Service operation.
- Preferences: theme and other choices remembered on your device.
- Visitor and product analytics: a first-party visitor identifier, page-view counts, feature events, app-install activity, and aggregate performance measurement.
- Referral attribution: an encrypted referral or partner identifier that may remain for the referral period configured by the applicable program.
- Third-party analytics or advertising: Google Analytics, Meta Pixel, or TikTok Pixel when enabled.
The first-party visitor identifier may persist for up to 12 months. Checkout data stored in session storage generally lasts until the browser session ends or the data is cleared. Authentication-cookie duration is determined by the session and security configuration. Other technologies remain for the duration set by the applicable provider or until you clear or block them.
You can use browser or device settings to delete or block cookies and local storage. Blocking strictly necessary storage may prevent sign-in, payments, preferences, or other features from working. Where applicable law requires consent for non-essential technologies, we rely on consent and honor an effective withdrawal through the controls made available for that technology or through a verified privacy request.
8. Advertising, sale, and sharing
We do not sell personal data in exchange for money. We do not knowingly sell or share the personal data of anyone under 18.
If third-party advertising pixels are enabled, those providers may receive identifiers and internet or network activity for measurement or advertising. Some privacy laws may define those disclosures as a “sale,” “sharing,” or targeted advertising even when no money changes hands. Where such laws apply, you may request to opt out through our Contact page. We will not discriminate against you for exercising a privacy right.
We do not disclose private messages or sensitive profile fields to third parties for cross-context behavioral advertising.
9. International data transfers
The Operator and its providers may process personal data in Nigeria and other countries where they or their infrastructure operate. Those countries may have privacy laws different from the laws where you live.
When required, we use a legally recognized transfer mechanism, such as an adequacy decision, approved contractual clauses, binding rules, an approved certification or code, or a lawful statutory exception. We also assess the circumstances of transfers and apply supplementary contractual, organizational, or technical safeguards where appropriate. You may request information about the transfer mechanism relevant to your data through our Contact page.
10. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, protect users, satisfy legal and accounting obligations, resolve disputes, and enforce agreements.
Our general retention approach is:
- Account and profile data: for the life of the account and for a limited period after closure or a verified deletion request, subject to legal, safety, fraud, backup, and dispute exceptions.
- Public content: until you delete it, the associated feature removes it, or the account is closed, subject to copies retained for safety, legal claims, backups, or by other users and search engines.
- Connections and messages: while needed to provide conversations and connection history, and afterward where reasonably necessary for user safety, abuse investigations, disputes, or legal compliance.
- Discovery snapshots and typing indicators: short-lived operational data. Discovery snapshots normally expire after approximately 15 minutes, and typing indicators expire within seconds unless refreshed.
- Notifications: read in-app notifications are ordinarily eligible for deletion after 120 days; push-delivery logs are ordinarily eligible for deletion after 30 days.
- Safety and moderation records: ordinarily up to 730 days after the relevant activity or case, and longer when reasonably necessary for an active restriction, repeat-abuse prevention, legal claim, regulatory matter, or safety risk.
- Payment, wallet, commission, and payout records: for the period required by applicable tax, accounting, anti-fraud, financial, and dispute-resolution obligations.
- Visitor identifiers and analytics: the first-party visitor identifier may remain on your device for up to 12 months. Aggregate statistics that no longer identify a person may be retained longer.
- Security and technical records: for a period proportionate to the security, fraud-prevention, troubleshooting, and legal purpose for which they were created.
- Backups: until overwritten through the ordinary backup cycle, unless preservation is required by law.
When retention is no longer justified, we delete, anonymize, aggregate, or securely isolate the data. Anonymized or aggregated information that can no longer reasonably identify you is not treated as personal data under this Policy.
11. Security
We use administrative, technical, and organizational measures designed to protect personal data, including access controls, authentication, authorization checks, encrypted network transport, restricted administrative access, provider due diligence, data minimization, validation, rate limits, monitoring, backups, and incident-response procedures.
No service can guarantee absolute security. You should use a unique password, protect your devices and email account, sign out of shared devices, avoid sharing financial or identity information with other members, and report suspected compromise promptly.
If a personal-data breach occurs, we will investigate and notify affected people and regulators when required by applicable law.
12. Your choices and controls
Depending on the feature, you may:
- edit account, profile, discovery, and notification settings;
- hide eligible profile fields or remove profile photos and content;
- change discovery age, distance, interest, and intent preferences;
- leave communities or adjust content visibility where the feature permits;
- block members, disconnect, decline requests, and report content or conduct;
- withdraw push-notification permission through your browser or device;
- unsubscribe from non-essential email using the method provided in the message;
- clear cookies, local storage, and app data through browser controls; and
- request access, correction, deletion, restriction, objection, portability, consent withdrawal, or human review where applicable.
Some transactional, security, safety, payment, and account messages are necessary to provide the Service and cannot be disabled while the relevant account or transaction remains active.
13. Privacy rights and requests
Subject to applicable law and exceptions, you may have the right to:
- be informed about how your personal data is processed;
- obtain confirmation and a copy of personal data we hold about you;
- correct inaccurate or incomplete data;
- request deletion of data;
- restrict or object to processing, including direct marketing and certain processing based on legitimate interests;
- receive certain data in a portable, machine-readable format;
- withdraw consent at any time;
- opt out of sale, sharing, or targeted advertising where applicable;
- limit certain uses or disclosures of sensitive personal data;
- request information about international-transfer safeguards;
- contest certain automated decisions and request human review; and
- lodge a complaint with a competent data-protection authority.
To submit a request, email support@heveny.com or use our Contact page, and identify the request as a “Privacy Request.” Provide the email address associated with your account and enough detail for us to understand the request. Do not send your password, complete payment-card number, or unnecessary identity documents.
We may verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct verification with the account holder. We will respond within the period required by applicable law. If we deny a request in whole or in part, we will explain the basis when legally required and provide any available appeal method.
Rights are not absolute. We may retain or withhold information where permitted or required for another person’s privacy, freedom of expression, fraud prevention, safety, legal compliance, privileged communications, or the establishment, exercise, or defense of legal claims.
Direct-marketing objection
You may object at any time to the use of your personal data for direct marketing. Use the unsubscribe method in the communication or submit a Privacy Request. This does not stop service, security, or transactional communications.
14. Nigeria privacy notice
The Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission’s General Application and Implementation Directive 2025 may provide rights concerning access, correction, erasure, restriction, objection, portability, consent withdrawal, automated decision-making, and complaints.
We ask that you contact us first so we can address your concern. You may also lodge a complaint with the Nigeria Data Protection Commission (NDPC) through its official website at ndpc.gov.ng.
15. EEA and United Kingdom notice
If the EU GDPR or UK GDPR applies, the lawful bases in Section 4 apply to our processing. You may contact the supervisory authority where you live, work, or believe an infringement occurred. EEA authority details are available through the European Data Protection Board, and UK residents may contact the Information Commissioner’s Office.
If the Operator is required to appoint an EEA or UK representative or a Data Protection Officer, the applicable contact details will be made available through this Policy or our Contact page.
16. United States and California notice
Residents of certain U.S. states may have rights to know, access, correct, delete, or obtain a portable copy of personal data; opt out of sale, sharing, targeted advertising, or certain profiling; limit use of sensitive data; appeal a denied request; and receive equal service when exercising a right.
For purposes of California law, the categories of personal information described in Section 2 may include identifiers; customer-record information; protected-class or demographic information; commercial and payment information; internet or network activity; approximate geolocation; audio, electronic, visual, or similar information; professional or employment information; sensitive personal information; and inferences drawn from profile and activity data. We collect these categories from the sources in Section 2.9, use them for the purposes in Section 3, and disclose them to the recipients in Section 6.
We do not use or disclose sensitive personal information for purposes other than providing requested features, safety and security, payment and legal compliance, and other purposes permitted without a right to limit under applicable law, unless we first provide the required notice and choice.
To exercise a state privacy right or appeal a decision, submit a Privacy Request through our Contact page. You may also state in that request that you are exercising an opt-out preference communicated through your browser or device.
17. Children and age eligibility
The Service is for adults aged 18 and older. We do not knowingly collect personal data through the Service from anyone under 18. If you believe a minor has created an account or provided personal data, contact us promptly. We may request limited information needed to investigate and will delete or restrict the account and associated data as appropriate, subject to safety and legal-preservation requirements.
18. Third-party links and embedded services
The Service may link to or embed content from third parties, such as payment pages, social platforms, videos, image hosts, partner sites, or external articles. Your interaction with a third party may allow it to collect identifiers, device data, and activity under its own privacy policy. Review the third party’s terms and privacy notice before providing information.
19. Changes to this Policy
We may update this Policy to reflect changes in the Service, data practices, providers, or law. We will post the revised Policy with a new “Last updated” date. If a change is material, we will provide additional notice when required, such as through the Service or by email. Where required, we will obtain consent before applying a materially different use to data already collected.
20. Contact us
Questions, complaints, privacy requests, and requests for transfer safeguards may be submitted to Starbiss LTD. at support@heveny.com or through our Contact page. Use the subject “Privacy Request” and include the email address associated with your account.
For your protection, do not include passwords, complete payment-card numbers, private keys, or unnecessary government identification in an initial request.
Last updated: 2026-08-11