heysugardaddy
🔒 Legal Document · UK & EU GDPR

Privacy Policy

This Privacy Policy explains how Trusted Brokers Ltd, trading as HeySugarDaddy, collects, uses, shares, and protects your personal data when you use heysugardaddy.com and our associated mobile applications, wherever you are located across the UK, Ireland, and the wider EU/EEA.

Version 1.0
Effective date 9 July 2026
Last updated 9 July 2026
Governing law England & Wales
Data protection regimes UK GDPR, DPA 2018, EU GDPR & Irish DPA 2018
This Policy is designed to be read alongside our Terms and Conditions (effective 1 August 2025) and replaces the placeholder Privacy Policy previously published at this address.
01

Who We Are & Scope

The HeySugarDaddy service, accessible at heysugardaddy.com and via our mobile applications (the "Service"), is operated by:

Trusted Brokers Ltd, trading as HeySugarDaddy
Fitzroy Street, Fitzrovia, London, W1T, United Kingdom
Company registered in England and Wales

References to "we", "us", "our", or "the Operator" mean Trusted Brokers Ltd. We are the data controller for the personal data described in this Policy under both UK GDPR and, in respect of our Irish and other EU-resident Users, EU GDPR (see Section 10 for how the EU regime applies to us).

This Policy applies to all Users of the Service — Sugar Daddies and Sugar Babies — across the UK and Ireland, and to visitors to our website and blog (heysugardaddy.com/news). It should be read alongside our Terms and Conditions, Code of Conduct, and Data Deletion page, which form part of the same framework.

In plain terms: we collect only what we need to run a safe, verified sugar dating platform, we never sell your personal data, and — whether you're joining from the UK, Ireland, or elsewhere in the EU — you get the same standard of protection under UK GDPR and EU GDPR alike.
02

Information We Collect

We collect information in three ways: information you give us directly, information collected automatically as you use the Service, and information we receive from third parties (such as our verification and payment providers).

2.1 — Information you provide

CategoryExamples
Account & registrationName, date of birth, email address, password, gender, city/location, member type (Daddy or Baby)
Profile contentBio, interests, profile photos, private photo galleries, preferences
Verification documentsGovernment-issued photo ID (passport or driving licence) submitted for age and identity verification
Payment details (Daddies)Billing name and address; card details for Token bundle and subscription purchases are entered directly into Stripe's secure interface and are never stored by us
Payout details (Babies)PayPal email address or UK/Irish bank account details for Withdrawals
CommunicationsMessages exchanged with other Users, video call metadata, support enquiries, reports submitted
Marketing preferencesEmail/notification opt-ins and opt-outs
Social login dataIf you register or verify via Facebook or Instagram, we receive only your account name and a unique platform identifier — never your password, friends list, or posts

2.2 — Information collected automatically

CategoryExamples
Device & technical dataIP address, browser type, operating system, device identifiers, app version
Usage dataPages viewed, features used, Token spend and Earnings activity, login times, session duration
Approximate locationDerived from IP address or, where permitted, device GPS, used for city-matching and fraud prevention
Cookies & similar technologiesSee Section 7 below

2.3 — Information from third parties

We receive limited data from our identity verification provider (verification outcome, not the raw document itself, wherever this is achievable — see Section 5), our payment processors (transaction confirmation and fraud-risk signals), and, if you choose to register or log in via Facebook or Instagram, your name and a unique account identifier from that platform.

2.4 — Special category data

We do not ask Users to declare sexual orientation, health, religion, or similar special category data under Article 9 of UK GDPR / EU GDPR, and profile fields are limited to what is described above. Photographs may incidentally reveal characteristics such as ethnicity; we do not use photographs to infer or profile any special category attribute, and access to Private Content is controlled entirely by the Sugar Baby who uploads it.

03

How We Use Your Information

  • To create and administer your Account, and to operate core features (browsing, messaging, video calls, Token purchases, Earnings, and Withdrawals);
  • To verify your age and identity before granting access to the Service (see Section 5);
  • To process payments and payouts via our payment providers, and to maintain accurate financial and tax records;
  • To send transactional communications: account verification, receipts, Withdrawal confirmations, security alerts, and service notices;
  • To moderate content, investigate reports, and enforce our Code of Conduct and Terms and Conditions;
  • To detect, investigate, and prevent fraud, chargebacks, fake accounts, and other abuse of the Service;
  • To generate suggested profile copy and support internal admin tooling using AI (see Section 8.4);
  • To personalise your experience, such as city-based matching and relevant recommendations;
  • To analyse aggregate usage trends so we can improve the Service;
  • To send you marketing communications where you have opted in (see Section 15);
  • To comply with our legal, regulatory, and safeguarding obligations, including under the UK Online Safety Act 2023.
04

Legal Bases for Processing

Under UK GDPR and, for our Irish and other EU-resident Users, EU GDPR, we rely on the following legal bases depending on the purpose of processing — Article 6 of both regimes is identical in substance:

BasisWhen we rely on it
ContractCreating and managing your Account, processing Token purchases and Withdrawals, delivering the core Service you signed up for
Legal obligationAge verification under the Online Safety Act 2023, tax and accounting records, responding to lawful requests from authorities
Legitimate interestsFraud prevention, platform security, content moderation, service improvement, and direct marketing to existing Users about similar features — balanced against your rights and always subject to your right to object
ConsentOptional analytics cookies, marketing communications to prospective Users, use of Facebook/Instagram login

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

05

Identity & Age Verification

All Users must complete identity and age verification before their Account is activated, in line with our obligations under the Online Safety Act 2023. Verification is carried out by Veriff, an approved third-party identity verification provider.

  • You will be asked to submit a valid government-issued photo ID and, in some cases, a live selfie for comparison;
  • Documents are transmitted securely to Veriff for verification and are processed under Veriff's own data protection obligations as an independent processor acting on our instructions;
  • We store both the outcome of verification (pass/fail, verified age band) and the submitted verification record on your Account for as long as your Account remains open, so that we can respond to disputes, re-verify where required, and meet our Online Safety Act 2023 obligations; this record is permanently deleted when your Account is deleted (see Section 11);
  • If verification fails or is not completed, your Account will remain suspended and you will not be able to access member features;
  • Verification may be re-requested at any time, including where a Withdrawal is pending or we have reasonable grounds to suspect misuse of an Account.
We treat identity documents as highly sensitive data. Access is restricted to authorised personnel and our verification processor, and documents are never used for marketing or shared with other Users.
06

Payments & Financial Data

Sugar Daddies purchase access via a monthly subscription (Standard or Elite) which includes a bundle of Tokens, and/or additional standalone Token bundles. Both subscription and Token payments are processed by Stripe. We may also use a specialist high-risk payment processor (such as CCBill or Segpay) as a backup gateway. Card numbers, CVV codes, and full card data are entered directly into our payment processors' secure, PCI-DSS-compliant systems and are never transmitted to or stored on our own servers. Where you hold an active subscription, Stripe also retains a payment method on file to process automatic renewals, in accordance with Stripe's own privacy policy.

Withdrawals by Sugar Babies are paid out via PayPal or direct bank transfer. We store the payout account details you provide (PayPal email, or UK/Irish sort code and account number) for the purpose of processing your Withdrawals, and retain a record of completed transactions for tax and accounting compliance (see Section 11).

We do not store full payment card numbers under any circumstance. Transaction records we retain are limited to amount, date, Token bundle or Withdrawal type, and a payment reference — sufficient for receipts, refunds, tax reporting, and fraud investigation.

07

Cookies & Tracking Technologies

We use cookies and similar technologies to operate the Service and understand how it is used.

TypePurposeCan you opt out?
Strictly necessarySession management, login state, security (e.g. Cloudflare protection), load balancingNo — required for the Service to function
FunctionalRemembering your preferences, such as language selectionYes, via cookie settings
AnalyticsUnderstanding aggregate usage patterns to improve the ServiceYes, via the cookie banner or account settings

You can manage cookie preferences via the cookie banner shown on first visit, or at any time through your browser settings. Blocking strictly necessary cookies may prevent parts of the Service from working correctly.

08

Who We Share Data With

We do not sell your personal data to anyone, under any circumstances. We share data only with the categories of recipients below, each bound by a data processing agreement (where they act as our processor) or their own independent regulatory obligations.

8.1 — Service providers (processors)

Stripe
Payment processing for Token purchases
PayPal
Sugar Baby Withdrawal payouts
Veriff
Identity & age verification
Twilio
In-platform video calling infrastructure
Amazon Web Services (AWS)
Application hosting (EC2) and transactional email delivery (SES, eu-west-1)
DigitalOcean
Hosting for our news/blog content
Cloudflare
Content delivery, DDoS protection, and SSL
Anthropic
AI-assisted profile content suggestions and internal admin tooling

8.2 — Other Users

Your public profile information (name, photos, bio, city, interests) is visible to other verified Users of the Service as part of its core function. Private Content is visible only to those who have paid to unlock it. Your GBP Earnings, Token spend, payout details, and identity documents are never shown to other Users.

8.3 — Legal & safety disclosures

We may disclose personal data to law enforcement, regulators, or courts where required by law, or where necessary to protect the safety of our Users or the public — including mandatory reporting of suspected child sexual abuse material to the Internet Watch Foundation (IWF) and National Crime Agency (NCA) under the Online Safety Act 2023.

8.4 — AI-assisted features

We use the Anthropic API to help generate suggested profile copy and to power internal admin tools. Where User-submitted profile text is sent to this service to generate suggestions, it is processed solely for that purpose and is not used by the AI provider to train models on our behalf.

8.5 — Business transfers

If Trusted Brokers Ltd is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to the same protections described in this Policy.

09

International Data Transfers

Our core infrastructure is hosted in the United Kingdom and Ireland. Where a service provider processes data outside the UK or European Economic Area (EEA) — for example, a global payment or cloud provider — we ensure appropriate safeguards are in place, such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses themselves, an adequacy decision, or another lawful transfer mechanism recognised under UK GDPR and/or EU GDPR.

The UK currently benefits from an EU adequacy decision (and the EU benefits from corresponding recognition under UK law), meaning personal data can generally flow between the UK and the EU/EEA — including Ireland — without additional safeguards. We monitor the status of this adequacy arrangement and will implement Standard Contractual Clauses or another approved mechanism if it is ever withdrawn or lapses.

10

EU & Irish Data Protection (GDPR)

HeySugarDaddy is built for the UK and Ireland market, and we recognise that Irish and other EU-resident Users are protected by EU GDPR (Regulation (EU) 2016/679) in addition to, or instead of, UK GDPR, depending on your circumstances. This section sets out how that applies to you.

10.1 — When EU GDPR applies

Although Trusted Brokers Ltd is established in the United Kingdom, EU GDPR applies to our processing of your personal data under its extraterritorial scope (Article 3(2)) wherever we offer the Service to, or monitor the behaviour of, individuals located in the EU/EEA — which includes our Irish User base. In practice, this means Irish and other EU-resident Users benefit from the same substantive rights and protections under EU GDPR as UK Users receive under UK GDPR, and we apply a single, consistent set of data protection standards across both regimes rather than a lesser standard for either.

10.2 — EU representative

Where required under Article 27 of EU GDPR, we will appoint and publish the contact details of a representative established in the European Union (which may be based in Ireland, given our Irish User base) to act as your point of contact for EU GDPR matters, alongside our UK contact details in Section 21. If you cannot locate a published EU representative at the time you read this Policy, you may contact us directly at [email protected] and we will route your request appropriately.

10.3 — Irish Data Protection Act 2018

For Users in the Republic of Ireland, our processing is also subject to the Irish Data Protection Act 2018, which gives further effect to EU GDPR in Irish law. Where Irish law provides any additional or more specific protection relevant to your data (for example, around children's consent thresholds or direct marketing), we comply with that standard for Users located in Ireland.

10.4 — Your supervisory authority

If you are located in Ireland or elsewhere in the EU/EEA, you have the right to lodge a complaint with your local supervisory authority in addition to, or instead of, the UK ICO. For Irish Users, this is the Data Protection Commission (DPC) — full contact details are in Section 20, immediately below.

In plain terms: whether you're in London or Dublin, you get the same rights, the same standard of protection, and the same commitment not to sell your data — we've simply documented both legal frameworks so it's clear which regulator and which specific legal provisions apply to you.
11

Data Retention

Data typeRetention period
Account & profile dataFor as long as your Account is active; permanently deleted immediately on account deletion
Verification records & identity documentsRetained for as long as your Account is open; permanently deleted immediately on account deletion
Messages & contentPermanently deleted immediately on account deletion, except where retained under a legal hold
Social login data (Facebook/Instagram)Deleted with your Account; you can also revoke access directly from your Facebook/Instagram settings
Financial transaction recordsRetained for up to 7 years after account deletion, for tax and accounting compliance
Fraud & abuse logsAnonymised records may be retained after account deletion to prevent re-registration by banned Users
Aggregated analyticsDe-identified statistical data that cannot be linked back to you may be retained indefinitely
Legal hold dataRetained for as long as required by an active legal proceeding or law enforcement request

Deleting your Account — whether via Settings → Danger Zone in the app, or by emailing [email protected] — permanently removes your profile, messages, verification records, and social login data immediately. Only the limited categories above are retained afterwards, exactly as described on our Data Deletion page, which also covers the process if you signed up via Facebook or Instagram.

12

How We Protect Your Data

  • Encryption of data in transit (TLS) and at rest (AES-256);
  • Network protection via Cloudflare, including DDoS mitigation and web application firewall rules;
  • Access to production systems and identity documents restricted to authorised personnel on a need-to-know basis;
  • Server-level firewalling restricting infrastructure access to trusted networks only;
  • Regular security review of our infrastructure and third-party processors;
  • Secure, PCI-DSS-compliant handling of all payment data by our payment processors.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If you believe your Account has been compromised, contact us immediately (see Section 21).

13

Your Rights Under UK & EU GDPR

Whether you are protected under UK GDPR, EU GDPR, or both, you have the following rights in relation to your personal data — the substance of these rights is materially identical under both regimes:

  • Access — request a copy of the personal data we hold about you;
  • Rectification — ask us to correct inaccurate or incomplete data;
  • Erasure ("right to be forgotten") — request deletion of your personal data, subject to the retention exceptions in Section 11;
  • Restriction — ask us to limit how we use your data in certain circumstances;
  • Portability — receive your data in a structured, commonly used, machine-readable format;
  • Objection — object to processing based on legitimate interests, including direct marketing;
  • Withdraw consent — where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email [email protected] or use the in-app deletion tool described on our Data Deletion page. We will respond within 30 days. We may ask you to verify your identity before actioning a request, to protect your data from unauthorised access.

14

Automated Decision-Making

We use automated checks to support (not replace) key decisions — for example, flagging potentially fraudulent payments, screening for duplicate or fake accounts, and triaging reported content for our 24/7 human moderation team. We do not make any decision with a legal or similarly significant effect on you (such as permanent account termination or withholding a Withdrawal) using fully automated means without human review. If you wish to contest an automated flag, contact us at the details in Section 21.

15

Marketing Communications

We may send you marketing communications about new features, promotions, or platform updates where you have opted in, or, for existing Users, on the basis of our legitimate interest in keeping you informed about a service you already use. You can opt out at any time by clicking "unsubscribe" in any marketing email or adjusting your notification preferences in Account Settings. Transactional and security communications (such as verification, receipts, and account alerts) are not marketing and cannot be opted out of while your Account remains active.

16

Children's Privacy

The Service is strictly for individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18, and mandatory identity verification is designed to prevent minors from accessing the Service. If we discover that an Account belongs to a person under 18, we will suspend it immediately, permanently delete the associated data (subject to any legal reporting obligation), and, where CSAM or grooming is suspected, report the matter to the IWF and NCA as required under the Online Safety Act 2023. If you believe a minor has registered or been targeted on the Service, contact us immediately at [email protected].

17

Third-Party Links

The Service may contain links to third-party websites or integrate third-party tools (such as our payment, verification, and video-call providers). This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their privacy policies before providing them with personal data.

18

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) and, where the breach affects Irish or other EU-resident Users, the Data Protection Commission (DPC), within 72 hours of becoming aware of it, in accordance with UK GDPR and EU GDPR, and will notify affected Users without undue delay where the breach is likely to result in a high risk to them.

19

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Where changes are material, we will notify you by email and/or an in-app notice at least 30 days before they take effect. The "Last updated" date at the top of this page always reflects the current version. Continued use of the Service after a change takes effect constitutes your acceptance of the revised Policy.

20

Complaints, the ICO & DPC

If you have concerns about how we handle your personal data, please contact us first at [email protected] so we can try to resolve the issue directly. You also have the right to lodge a complaint with the relevant independent data protection regulator for your location — you do not need to raise it with us first, and doing so does not affect your right to complain to a regulator.

Information Commissioner's Office (ICO) — UK regulator
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: ico.org.uk · Helpline: 0303 123 1113

Data Protection Commission (DPC) — Irish & EU regulator
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: dataprotection.ie · Phone: +353 (0)57 868 4800

If you are resident in Ireland or elsewhere in the EU/EEA, you may complain to the DPC or to your own country's supervisory authority instead of, or in addition to, the ICO. If you are resident in the UK, the ICO is your primary regulator.

21

Contact Us

For any question about this Privacy Policy or how we handle your personal data:

Trusted Brokers Ltd (trading as HeySugarDaddy)
Fitzroy Street, Fitzrovia, London, W1T, United Kingdom

Privacy & data requests: [email protected]
General support: [email protected]
Legal & compliance: [email protected]
Safety & safeguarding: [email protected]

We aim to respond to all privacy-related enquiries within 5 business days, and to complete formal data requests within 30 days as required by UK GDPR and EU GDPR. You can also delete your Account directly at any time via Settings → Danger Zone — see our Data Deletion page for details.