Privacy Policy
Last updated: December 28, 2025
#1. Introduction
Welcome to Offairy ("Company," "we," "us," or "our"). Offairy is a comprehensive agency management platform designed specifically for OnlyFans agencies and content creators. We are committed to protecting your personal information and your right to privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, including our website, applications, and related services (collectively, the "Platform"). Please read this Privacy Policy carefully. By accessing or using our Platform, you agree to the collection and use of information in accordance with this policy.
Scope of This Policy
This Privacy Policy applies to all information collected through our Platform, as well as any related services, sales, marketing, or events. It does not apply to information collected by third parties, including OnlyFans or any other platforms you may interact with through our services.
#2. Information We Collect
Personal Information
We collect personal information that you voluntarily provide to us when you:
- Register for an account on our Platform
- Complete agency or creator onboarding
- Participate in activities on the Platform
- Contact us with inquiries or support requests
This information may include:
- Identity Information: Full legal name, stage name or alias, date of birth
- Contact Information: Email address, phone number, mailing address
- Account Credentials: Username, password, security questions
- Professional Information: Agency name, business registration details, role and permissions
Age Verification Data (18 U.S.C. 2257 Compliance)
In compliance with 18 U.S.C. 2257 and related regulations concerning record-keeping requirements for content producers, we collect and maintain:
- Government-issued photo identification (passport, driver's license, or national ID)
- Proof of age documentation
- Legal name as it appears on official documents
- Date of birth verification
- Photo verification to confirm identity matches documentation
- Records of when verification was completed and by whom
Important: All age verification records are maintained for a minimum of 7 years as required by federal law, even after account termination.
Financial Information
To process commissions and payments, we collect:
- Bank account details for payout processing
- Tax identification numbers (SSN, EIN, or VAT number)
- Commission rates and earning records
- Payment history and transaction records
- Billing addresses
Usage Data
We automatically collect certain information when you access our Platform:
- IP address and geographic location
- Browser type and version
- Device type and operating system
- Pages visited and features used
- Time and date of visits
- Referring URLs
- Click patterns and interaction data
Cookies and Tracking Technologies
We use cookies, web beacons, and similar tracking technologies to collect information about your browsing activities. See Section 9 for detailed information about our cookie practices.
#3. How We Collect Information
Directly From You
We collect information directly when you:
- Create an account or complete registration
- Submit identity verification documents
- Complete your agency or creator profile
- Enter financial information for payouts
- Contact our support team
- Respond to surveys or promotional communications
- Sign contracts or agreements through our Platform
Automatically Through Technology
Information is automatically collected through:
- Cookies and similar tracking technologies
- Server logs and analytics tools
- Session recording and heatmap tools (for UX improvement)
- Security monitoring systems
From Third Parties
We may receive information from:
- OnlyFans Platform: Performance metrics, subscriber counts, and earnings data (with your authorization)
- Payment Processors: Transaction verification and fraud prevention data
- Identity Verification Services: Document authentication results
- Analytics Providers: Aggregated usage statistics
#4. How We Use Information
Provide and Maintain Our Services
- Create and manage your account
- Facilitate agency-creator relationships
- Enable content scheduling and management features
- Provide analytics and performance insights
- Deliver messaging and communication tools
Process Commissions and Payments
- Calculate commission splits and earnings
- Process payouts to agencies and creators
- Generate invoices and financial reports
- Handle tax documentation (1099s, VAT reports)
Communicate With Users
- Send service-related notifications
- Respond to support inquiries
- Provide product updates and announcements
- Send marketing communications (with consent)
Improve Our Platform
- Analyze usage patterns to enhance features
- Conduct research and development
- Test new features and functionalities
- Personalize user experience
Legal Compliance
- Maintain 2257 compliance records
- Respond to legal requests and court orders
- Prevent fraud and illegal activities
- Enforce our Terms of Service
- Protect the rights and safety of our users
#5. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases for processing your personal data:
Consent
Where you have given us explicit consent to process your personal data for specific purposes, such as:
- Marketing communications
- Non-essential cookies and tracking
- Third-party integrations
You may withdraw your consent at any time by contacting us or adjusting your account settings.
Contract Performance
Processing necessary for the performance of a contract with you, including:
- Providing our Platform and services
- Processing payments and commissions
- Account management and authentication
- Customer support
Legal Obligations
Processing required to comply with legal obligations, such as:
- 18 U.S.C. 2257 record-keeping requirements
- Tax reporting obligations
- Anti-money laundering (AML) regulations
- Responding to lawful government requests
Legitimate Interests
Processing based on our legitimate business interests, balanced against your rights:
- Fraud prevention and security
- Platform improvement and analytics
- Business operations and administration
- Protecting our legal rights
#6. Information Sharing
We do not sell your personal information. We may share your information in the following circumstances:
Service Providers
We share information with trusted third-party service providers who assist us in:
- Payment Processing: Stripe, PayPal, or similar payment processors
- Identity Verification: Document verification services
- Cloud Hosting: AWS, Google Cloud, or similar infrastructure providers
- Analytics: Usage analysis and reporting tools
- Customer Support: Help desk and support ticket systems
All service providers are contractually bound to protect your information and use it only for specified purposes.
OnlyFans Platform
With your authorization, we may exchange data with OnlyFans to:
- Retrieve performance metrics and analytics
- Access subscriber and earnings data
- Facilitate content management features
Legal Requirements
We may disclose your information when required by law, including:
- Compliance with legal obligations or court orders
- Response to valid government requests
- Protection of our rights, privacy, safety, or property
- Prevention of fraud or illegal activities
- 2257 compliance inspections by authorized authorities
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections outlined in this policy.
#7. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.
Age Verification Records (2257 Compliance)
7-Year Minimum Retention: In compliance with 18 U.S.C. 2257 and related regulations, we are legally required to maintain age verification records for a minimum of 7 years from the date of last publication or use of any content associated with the verified individual. This requirement persists even after account deletion.
Contract and Financial Records
We retain contract and financial information for:
- The duration of your contract with us
- Plus the applicable statute of limitations for legal claims (typically 6-10 years)
- As required for tax compliance (generally 7 years)
Account Information
If you request account deletion, we will delete or anonymize your account information within 30 days, except for data we are legally required to retain (such as 2257 records).
Usage Data
Aggregated and anonymized usage data may be retained indefinitely for analytics and platform improvement purposes.
#8. Your Rights
GDPR Rights (EEA, UK, Switzerland)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data, subject to legal retention requirements
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Restrict Processing: Request limitation of how we use your data
- Right to Withdraw Consent: Withdraw previously given consent at any time
- Right to Lodge a Complaint: File a complaint with your local data protection authority
CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we collect
- Right to Delete: Request deletion of your personal information, subject to exceptions
- Right to Opt-Out: Opt-out of the sale of your personal information (we do not sell personal information)
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
See Section 13 for detailed information about California privacy rights.
Exercising Your Rights
To exercise any of these rights, please contact us at privacy@offairy.com or use the contact methods listed in Section 14. We will respond to your request within 30 days (or as required by applicable law).
We may need to verify your identity before processing your request. In some cases, we may not be able to fulfill your request due to legal obligations (e.g., 2257 record retention requirements).
#10. Data Security
We implement industry-standard security measures to protect your personal information from unauthorized access, use, or disclosure.
Technical Safeguards
- TLS/SSL encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Multi-factor authentication (MFA) options
- Regular security audits and penetration testing
- Intrusion detection and prevention systems
- Automated security monitoring and alerting
Organizational Safeguards
- Role-based access controls with least privilege principles
- Employee security training and awareness programs
- Background checks for employees with data access
- Confidentiality agreements and security policies
- Incident response procedures
Compliance
- SOC 2 Type II compliance
- GDPR-compliant data processing
- Regular third-party security assessments
Important: While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.
#11. International Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your country.
Transfer Safeguards
When we transfer personal data internationally, we ensure appropriate safeguards are in place:
- Adequacy Decisions: Transfers to countries with adequate data protection laws as determined by applicable authorities
- Standard Contractual Clauses: EU-approved contractual terms for data transfers
- Binding Corporate Rules: Internal policies approved by data protection authorities
- Consent: In some cases, with your explicit consent
Data Processing Locations
Our primary data processing facilities are located in the United States. We may also use service providers located in other jurisdictions. All international transfers are subject to appropriate safeguards as described above.
#12. Children's Privacy
Important: Our Platform is intended solely for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under the age of 18.
Given the nature of our Platform and the industry we serve, we have strict policies against the participation of minors:
- All users must verify they are at least 18 years old
- Age verification is required for all creators and content participants
- We immediately delete any information we discover belongs to a minor
- Accounts found to be operated by or on behalf of minors will be terminated
If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@offairy.com.
#13. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information. This section describes your CCPA rights and explains how to exercise them.
Categories of Personal Information Collected
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (name, email, phone number, IP address)
- Personal information under California Civil Code Section 1798.80(e)
- Commercial information (transaction history, services purchased)
- Internet or network activity (browsing history, interactions with our Platform)
- Geolocation data (general location based on IP address)
- Professional or employment-related information
- Sensitive personal information (government ID for verification, financial account information)
Do Not Sell or Share My Personal Information
We do not sell your personal information. We do not share personal information for cross-context behavioral advertising purposes. Therefore, we do not offer an opt-out for the sale or sharing of personal information.
Sensitive Personal Information
We collect certain sensitive personal information (such as government ID and financial information) solely for purposes permitted under CCPA, including:
- Performing services requested by you
- Detecting security incidents and fraud prevention
- Complying with legal obligations
We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA Section 1798.121.
How to Submit a Request
You may submit a verifiable consumer request by:
- Emailing us at privacy@offairy.com
- Using the privacy request form in your account settings
- Calling our privacy hotline (if available)
You may designate an authorized agent to make a request on your behalf. We will require verification of your identity and confirmation that you authorized the agent to act on your behalf.
Response Timing
We will respond to verifiable consumer requests within 45 days. If we require more time, we will inform you of the reason and extension period (up to an additional 45 days).
#14. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Mailing Address
Offairy Inc.
Privacy Team
[Address to be added]
United States
Response Time
We aim to respond to all privacy-related inquiries within 30 days. For urgent matters, please indicate "URGENT" in the subject line.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify you via email (for registered users)
- Display a prominent notice on our Platform
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
By using the Offairy Platform, you acknowledge that you have read and understood this Privacy Policy.