Privacy Policy
Last updated: August 2026
1. Data Controller
Aquila Global Ltd trading as MyShrine (shrine.io), registered in England & Wales, is the data controller responsible for your personal data processed in connection with your use of the Platform.
- Contact: support@myshrine.io
- ICO Registration: Aquila Global Ltd is registered as a data controller with the Information Commissioner's Office (ICO) in the United Kingdom.
- EU Representative: For EU residents, our representative can be contacted via support@myshrine.io.
This Privacy Policy applies to all personal data we process in connection with your use of MyShrine and is compliant with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU 2016/679), and the Data Protection Act 2018.
2. Personal Data We Collect
We collect and process the following categories of personal data:
2.1 Identity Data
- Name and display name
- Username
- Date of birth (for age verification purposes)
2.2 Contact Data
- Email address
2.3 Verification Data (Creators)
- Government-issued photo identification (processed by Didit — see Section 5)
- Selfie / biometric data (processed by Didit — see Section 5)
- Verification status (verified / not verified) and timestamp — retained by MyShrine
MyShrine does not store your identity documents or biometric data directly. These are processed by Didit under their own Data Processing Agreement.
2.4 Financial Data
- Transaction amounts and references
- Cryptocurrency wallet addresses (Creator payouts)
We do not store card details. Payment processing is conducted via NOWPayments (cryptocurrency). We do not have access to your full payment credentials.
2.5 Technical Data
- IP address
- Browser type and version
- Device information and operating system
- Session cookies and authentication tokens
2.6 Usage Data
- Pages visited and features used
- Content purchased or accessed
- Follows, interactions, and messaging activity on the Platform
3. Legal Basis for Processing (GDPR Article 6)
We process your personal data on the following legal bases:
- Contract (Article 6(1)(b)): Processing necessary to perform the contract for the provision of the Services you have entered into by creating an account on the Platform.
- Legal Obligation (Article 6(1)(c)): Processing necessary to comply with applicable legal obligations, including age verification under the UK Online Safety Act 2023, 18 U.S.C. § 2257 record-keeping requirements, fraud prevention obligations, and tax and financial record-keeping requirements.
- Legitimate Interests (Article 6(1)(f)): Processing necessary for our legitimate interests in maintaining platform security, detecting and preventing fraud and abuse, improving the Services, and operating the Platform effectively — where those interests are not overridden by your rights and interests.
- Consent (Article 6(1)(a)): Where you have given explicit consent, including for the receipt of marketing communications. You may withdraw consent at any time by contacting support@myshrine.io.
Where we process special category data (such as biometric data for age verification, processed by Didit), we rely on Article 9(2)(b) (employment, social security, and social protection law), Article 9(2)(g) (substantial public interest), and, where applicable, explicit consent under Article 9(2)(a).
4. Age Verification Data
Age verification is conducted by Didit (didit.me), an independent KYC and identity verification processor. Biometric data and identity documents submitted for age verification purposes are processed by Didit under their own privacy policy and data processing agreement.
MyShrine retains only the verification outcome (verified / not verified) and the timestamp of verification. We do not retain copies of your identity documents or biometric data.
Age verification session data is stored in a cookie (age_verified) which expires after 60 minutes, in compliance with the requirements of the UK Online Safety Act 2023.
5. How We Use Your Personal Data
We use your personal data for the following purposes:
- To create and maintain your account and provide the Services;
- To process payments and maintain transaction records;
- To conduct age verification and, for Creators, identity verification;
- To send transactional emails (receipts, notifications, account updates) via Resend;
- To comply with our legal obligations, including 2257 record-keeping, anti-fraud measures, and tax obligations;
- To protect the Platform from abuse, fraud, and illegal activity;
- To communicate with you regarding your account or the Services;
- Where you have consented, to send marketing communications.
6. Third-Party Data Processors
We share your personal data with the following third-party processors, each operating under a Data Processing Agreement with Aquila Global Ltd:
Supabase
Database and authentication infrastructure. Servers located in EU and USA. Transfers to USA are protected by Standard Contractual Clauses (SCCs) and Supabase's adequacy compliance framework.
Resend
Transactional email delivery. Based in the USA. Transfers protected by Standard Contractual Clauses (SCCs).
NOWPayments
Cryptocurrency payment processing. Based in Estonia (EU). Subject to EU GDPR in its own right.
Didit (didit.me)
KYC / identity and age verification. Processes identity documents and biometric data under their own privacy policy and Data Processing Agreement with Aquila Global Ltd.
Vercel
Hosting and infrastructure. Servers located in USA and EU. Transfers to USA are protected by Standard Contractual Clauses (SCCs).
We do not sell your personal data to third parties.
7. Data Retention
We retain personal data for the following periods:
- Account data: Retained while your account is active and for 7 years following account closure (to comply with legal and tax obligations).
- Age verification records: Retained for 7 years in accordance with 18 U.S.C. § 2257 compliance requirements.
- Transaction records: Retained for 7 years in accordance with UK HMRC requirements and EU VAT obligations.
- Marketing data: Retained until you withdraw your consent.
- Technical and log data: Retained for 90 days.
Following expiry of the applicable retention period, personal data will be securely deleted or anonymised.
8. Your Rights Under UK GDPR / EU GDPR
Subject to applicable law, you have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may request correction of inaccurate or incomplete personal data.
- Right to erasure: You may request deletion of your personal data, subject to any overriding legal retention obligations (for example, transaction records required for tax compliance).
- Right to restrict processing: You may request that we restrict processing of your personal data in certain circumstances.
- Right to data portability: You may request your personal data in a structured, commonly used, machine-readable format.
- Right to object: You may object to processing based on legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds.
- Rights related to automated decision-making: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, subject to limited exceptions.
To exercise any of these rights, please email support@myshrine.io with the subject line "Data Rights Request". We will respond within 30 days of receipt of your request.
9. Supervisory Authority Complaints
If you are not satisfied with how we handle your personal data or your rights request, you have the right to lodge a complaint with the relevant supervisory authority:
- UK residents: Information Commissioner's Office (ICO) — ico.org.uk
- EU residents: Your local data protection supervisory authority (the relevant authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement).
10. Cookies
We use the following cookies on the Platform:
- age_verified — Session cookie confirming age verification status. Expires after 60 minutes in compliance with the UK Online Safety Act 2023. Essential for use of the Platform.
- Authentication session cookie — Manages your login session. Essential for use of the Platform.
We do not use advertising, tracking, or third-party analytics cookies. Cookie preferences can be managed via your browser settings; however, disabling essential cookies will prevent you from using the Platform.
11. International Transfers of Personal Data
Some of our third-party processors are based outside the UK and EU, in particular in the United States. Where we transfer personal data outside the UK or EU, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the relevant supervisory authorities, or adequacy decisions where applicable.
12. Children's Privacy
Our Platform is strictly for persons aged 18 and over. We do not knowingly collect personal data from persons under 18 years of age. If you believe that a minor has registered on the Platform or that we have inadvertently collected personal data from a minor, please contact us immediately at support@myshrine.io. We will take immediate steps to delete such data.
This policy is consistent with the requirements of the Children's Online Privacy Protection Act (COPPA) in the United States and the UK Age Appropriate Design Code (Children's Code).
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via email. The "Last updated" date at the top of this page indicates when this policy was most recently revised. Continued use of the Platform following notification of changes constitutes acceptance.
Related policies:
© 2026 Aquila Global Ltd trading as MyShrine (shrine.io). All rights reserved. Registered in England & Wales.