Bridging Hearts Ltd ("Bridging Hearts", "we", "us") is a company registered in England and Wales and the data controller for the personal data described in this policy. It covers this website, our waitlist, and the Bridging Hearts app. We've tried to write it the way we build: plainly, and without surprises.
The short version
- We collect what the product needs to work — no more.
- We never sell your personal data.
- Messages are encrypted at rest; your exact location is never shown to other members.
- Deleting your account genuinely deletes your data, with narrow safety exceptions explained below.
- You can reach us any time at info@bridginghearts.world.
What we collect
On this website
If you join the waitlist, we collect your email address, handled for us by Clerk (our authentication provider). The live waitlist counter uses an aggregate number only. This site does not use advertising trackers.
In the app
- Account: your email address, stored in encrypted form, and a one-way password hash. If you recover a legacy account, we may check the phone number and date of birth previously associated with it. We convert the phone number to a one-way cryptographic fingerprint for matching rather than storing the number in our application database.
- Profile: the name you display, photos, prompts, interests, and optional details you choose to add (such as height, faith, or education).
- Location: approximate coordinates, used to show you people nearby. Other members only ever see a coarse distance — never your position.
- Messages: conversations with your bridges, stored encrypted at rest.
- Safety data: reports you make or that are made about you, including a snapshot of relevant content at the time of the report; verification selfies (deleted after review); blocks, including — if you choose contact blocking — an irreversible cryptographic fingerprint of phone numbers from your contacts (never the numbers themselves).
How we use it
To run the service: showing profiles to compatible people nearby, forming bridges, delivering messages. To keep it safe: verifying identity, reviewing photos and reports, enforcing our rules. To communicate: waitlist invitations and service messages, plus any notifications you switch on. We rely on the legal bases of contract (providing the service you asked for), legitimate interests (keeping the community safe), and consent where required (for example, location).
Who we share it with
Only with the processors that run the service under contract: Cloudflare (website hosting, photo storage, and transactional account email), Railway (application infrastructure), and Clerk during our transition for the website waitlist, staff access, and legacy account operations. We disclose data to authorities only where the law requires it. We never sell personal data, and there is no advertising ecosystem behind this product.
Cookies
We set only cookies that are strictly necessary for the service to work. The app uses secure, HttpOnly cookies for account access; they are not available to page scripts. Clerk may use necessary cookies on the waitlist or transitional staff surfaces, including for bot protection. There are no advertising or cross-site tracking cookies, and no analytics cookies.
International transfers
Our processors operate globally, so some data is processed outside the UK and EEA — notably by Cloudflare and Clerk in the United States. Where that happens, transfers are protected by recognised safeguards such as the UK Addendum to the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
How long we keep it
For as long as your account exists. When you delete your account (or ask us to), we erase your profile, photos, bridges, conversations and preferences, and we destroy the encryption keys protecting your messages so backups cannot restore them. Two narrow exceptions survive: safety records (reports and moderation actions), kept so that action against harmful behaviour can't be undone by deleting an account, and minimal records we're legally required to retain.
Your rights
Under UK and EU data protection law you can access, correct, export, restrict, object to, or delete your personal data. The app includes a full export of your data and self-serve deletion; for anything else, email info@bridginghearts.world and we'll respond within a month. You also have the right to complain to the Information Commissioner's Office (ICO) in the UK, or your local supervisory authority.
Age
Bridging Hearts is strictly for adults aged 18 and over. We do not knowingly collect data from anyone younger; accounts that misrepresent age are removed.
Changes
If this policy changes in a way that matters, we'll say so clearly — on this page and, where appropriate, by message — before the change takes effect.
Contact
Bridging Hearts Ltd · info@bridginghearts.world
