HEY BELLA

Hey Bella legal

Privacy Policy

JoinHeyBella.com
Last updated: 9 August 2026
Effective date: 9 August 2026

1. Who we are

Hey Bella operates an application-only online dating service for adults aged 18 years and over.

The Service is provided by:

Hey Bella Group
454 Collins St.
Melbourne VIC 3000
Australia

General support: support@joinheybella.com
Privacy enquiries and complaints: privacy@joinheybella.com

In this Privacy Policy, “Hey Bella,” “we,” “us” and “our” mean Hey Bella Group.

Hey Bella is based in Australia and the Service is currently designed primarily for Australian customers. The international sections of this Privacy Policy apply where the relevant overseas privacy law applies to our processing.

2. Scope of this Privacy Policy

This Privacy Policy explains how we collect, hold, use, disclose, protect, transfer and delete personal information when you:

  • visit JoinHeyBella.com;
  • join a waitlist;
  • submit an application;
  • complete selfie verification;
  • create, maintain or edit a profile;
  • use matching, messaging, safety or reporting features;
  • purchase or renew membership;
  • receive or respond to Hey Bella communications;
  • contact support or make a complaint; or
  • otherwise interact with the Service.

Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to Hey Bella, we will comply with them. We also adopt the privacy practices described in this Policy as our operating standard where a particular statutory provision may not technically apply.

Where applicable law requires consent, including for particular sensitive information or non-essential tracking technologies, we will request that consent separately and will not treat acceptance of the Terms and Conditions as a substitute for that consent.

3. Adults only

Hey Bella is intended only for adults aged 18 years and over.

We do not knowingly permit a person under 18 to create or use a dating account. If we reasonably believe that an applicant or member is under 18, we may suspend or close the application or account, remove the profile, delete verification material and retain only limited information where reasonably necessary for safety, fraud prevention or legal compliance.

4. Personal information we collect

4.1 Application and account information

We may collect:

  • full name;
  • approved display name;
  • email address;
  • date of birth;
  • age calculated from date of birth;
  • country or region of residence;
  • application date, status and review information;
  • login, authentication and account information;
  • records showing acceptance of Terms and privacy notices; and
  • records of consents or privacy choices.

Your full date of birth is used for eligibility and internal administration and is not ordinarily displayed to other members.

4.2 Relationship, preference and sensitive information

Because Hey Bella is a dating service, you may choose to provide information about:

  • relationship goals;
  • preferred relationship characteristics;
  • compatibility preferences;
  • lifestyle and interests;
  • cultural or religious preferences;
  • sexual orientation or dating preferences; and
  • other information you choose to include in your application or profile.

Some of this information may be sensitive information under Australian law or special-category/sensitive personal data under overseas privacy laws.

Where required, we obtain express or explicit consent before collecting or using sensitive information. We use sensitive relationship information only for purposes reasonably connected with providing the Service, application review, matching, profile display where chosen by you, safety and related functions described in this Policy.

4.3 Profile information and photographs

We may collect:

  • profile photographs;
  • profile descriptions and biographical information;
  • profile answers and preferences;
  • interests and lifestyle information;
  • information you choose to make visible to approved members; and
  • changes made to your profile.

Profile photographs may be manually reviewed by authorised Hey Bella personnel before approval.

4.4 Selfie-verification and verification images

Hey Bella may collect a verification selfie or still image as part of its trust and safety process.

The verification technology is proprietary Hey Bella software. At the date of this Policy, it is designed to:

  • perform a liveness check using simple movement instructions, such as asking you to turn your head left or right;
  • capture a verification image; and
  • allow authorised Hey Bella personnel to manually compare the verification image with your submitted profile photographs.

Hey Bella does not use the verification image to create or store a faceprint, facial-geometry template, facial embedding, reusable biometric template or other biometric identifier for automated identification. The profile-photo comparison is performed manually by authorised personnel.

The software may process visual information in real time as necessary to determine whether the requested movement or liveness step has been completed, but the system is not designed to uniquely identify you from a stored biometric template.

Further details appear in Section 9.

4.5 Messages, reports and safety information

We may collect:

  • direct messages sent through the Service;
  • message timestamps and delivery information;
  • matches, blocks and unmatches;
  • reports and complaints;
  • evidence submitted with a report;
  • moderation decisions and appeal records;
  • account restrictions; and
  • fraud, spam, impersonation and safety indicators.

4.6 Payment information

Payments are processed through Stripe or another payment provider disclosed at checkout.

The payment provider may collect information such as your name, email address, billing information, payment method, transaction information, device information and fraud-prevention data.

Hey Bella does not intend to receive or store your complete payment-card number or card security code. We may receive limited transaction information such as:

  • amount paid;
  • transaction identifier;
  • payment status;
  • card brand; and
  • last four digits of a payment card where provided by the processor.

4.7 Technical, device and usage information

We and our infrastructure, security and analytics providers may collect:

  • IP address;
  • browser and device type;
  • operating system;
  • login and authentication activity;
  • approximate country or region;
  • referring page;
  • pages and features used;
  • timestamps;
  • cookie, consent or session identifiers;
  • error, security and performance logs; and
  • other technical information reasonably necessary to operate and protect the Service.

4.8 Support and legal communications

We collect information contained in support requests, privacy requests, complaints, refund requests, appeals, security reports and other communications sent to us.

5. How we collect personal information

We may collect personal information:

  • directly from you through applications, verification, profiles, messages, purchases and communications;
  • automatically through the website, application, security systems, cookies, consent tools and server logs;
  • from payment, hosting, email, analytics and other service providers acting for us;
  • from another member who reports an account or interaction; and
  • where lawful and reasonably necessary, from publicly available sources when investigating suspected impersonation, fraud or a serious safety concern.

We do not routinely collect information from public sources simply to enrich member profiles.

6. How we use personal information

We may use personal information to:

  • confirm age and application eligibility;
  • review and decide applications;
  • create, maintain and display profiles;
  • provide matching, discovery and direct messaging;
  • perform liveness and selfie verification;
  • manually compare verification images with profile photographs;
  • detect fake, duplicate, fraudulent or impersonating accounts;
  • approve and moderate profile photographs;
  • process membership payments and renewals;
  • send account, application, match, message, payment, renewal, safety and service communications;
  • investigate reports, scams, harassment and other misconduct;
  • allow members to block, report or unmatch;
  • provide customer support and complaint handling;
  • maintain security and prevent unauthorised access;
  • troubleshoot and improve the Service;
  • conduct analytics where permitted and subject to applicable cookie or consent choices;
  • comply with legal and regulatory obligations;
  • establish, exercise or defend legal claims; and
  • enforce our Terms and Conditions.

We may use appropriately aggregated or de-identified information to understand and improve the Service where that information is no longer reasonably capable of identifying an individual.

We do not sell or rent member profiles, private messages or verification images as a data product.

7. Lawful basis and consent

Depending on the law that applies, Hey Bella may process personal information because:

  • the processing is necessary to provide the Service or take steps at your request;
  • the processing is reasonably necessary for our legitimate interests, such as safety, security, fraud prevention, service improvement or protection of legal rights, where those interests are not overridden by applicable privacy rights;
  • you have provided consent for a specified purpose;
  • processing is required or authorised by law; or
  • another lawful basis applies.

Where Australian law requires consent for sensitive information, or European/UK law requires an additional condition for special-category data, we will obtain the consent or rely on another lawful condition permitted by the relevant law.

Where we rely on consent, you may withdraw it prospectively. Withdrawal does not make earlier lawful processing unlawful. If the information is necessary to provide a particular feature, withdrawing consent may mean we can no longer provide that feature or membership.

8. Manual application decisions and automated tools

The final decision to approve, waitlist, decline or request more information from an applicant is made by authorised Hey Bella personnel.

Technical systems may assist with security, fraud detection, liveness checks, spam detection and other indicators, but Hey Bella does not currently use a solely automated system to make the final membership admission decision.

If we introduce a computer program that makes, or is substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person’s rights or interests, we will update our disclosures and provide any information required by applicable law before or when those requirements apply.

9. Selfie Verification and Verification Images

9.1 Purpose

We use the verification image only for legitimate verification and safety purposes, including:

  • confirming that the person completing verification appears to be live and following the requested movement instructions;
  • manually comparing the verification image with submitted profile photographs;
  • detecting impersonation or fraudulent applications;
  • investigating a suspected verification failure; and
  • protecting the integrity and safety of the Service.

9.2 No biometric template or automated identity matching

At the date of this Policy, Hey Bella does not create or store a biometric template, faceprint, reusable facial-geometry record, facial embedding or comparable biometric identifier from the verification image.

The verification image is not automatically matched against profile photographs, public databases, government databases or external facial-recognition databases. Authorised Hey Bella personnel perform the comparison with profile photographs manually.

We do not use the verification image for:

  • advertising or marketing;
  • general facial recognition;
  • government identity checks;
  • criminal-record checks;
  • employment or credit checks;
  • identification against public databases; or
  • training general-purpose artificial-intelligence models.

9.3 Storage and access

Verification images are stored only for the limited period described below and are accessible only to authorised personnel and systems that require access for verification, security, technical support or a related investigation.

Verification images are not shown to other members.

9.4 Seven-day deletion

The verification image will be deleted within seven days after collection.

Hey Bella designs its retention controls so that verification images are not intentionally placed into long-term backups, public content-delivery caches or general-purpose archives. Temporary files and derivative image copies created for the verification workflow are also deleted within the same period where technically applicable.

We may retain a non-image record showing that verification occurred, the date of verification, whether it passed or required review, and limited security information reasonably necessary to prevent misuse.

9.5 Future biometric functionality

If Hey Bella later introduces technology that creates, stores or compares biometric identifiers or templates for the purpose of uniquely identifying a person, we will update this Policy and provide any additional notice, consent, retention schedule or other protection required by applicable law before that functionality is used.

10. What other members can see

Approved members may see information that you choose or are told will form part of your visible profile, including:

  • approved name or display name;
  • age;
  • general location or country where displayed;
  • approved profile photographs;
  • selected profile answers;
  • selected relationship or preference information; and
  • other Content clearly identified as profile-visible.

Members do not ordinarily see your:

  • exact date of birth;
  • private email address;
  • verification image;
  • payment-card details;
  • internal application notes;
  • security logs;
  • private reports; or
  • internal moderation information.

11. Messaging and administrative access

Messages sent through Hey Bella are stored so they can be delivered and so we can operate safety, moderation, support and complaint processes.

Unless the Service expressly states otherwise, Hey Bella messages are not end-to-end encrypted.

Messages may be subject to proportionate technical checks for spam, scams, fraud indicators, security threats and policy violations.

Authorised Hey Bella personnel may access message content where reasonably necessary to:

  • investigate a report or complaint;
  • investigate fraud, harassment or serious misconduct;
  • respond to an immediate safety risk;
  • investigate a security or technical incident;
  • comply with a lawful request;
  • enforce our Terms and Conditions; or
  • conduct limited, documented safety or compliance reviews.

Personnel are not permitted to browse private messages for personal interest, entertainment, unrelated purposes or advertising profiling.

12. Emails, notifications and marketing

We may send service-related communications including:

  • login and authentication messages;
  • application-status communications;
  • profile or verification notices;
  • match and message notifications;
  • payment receipts and renewal reminders;
  • cancellation confirmations;
  • safety and security notices;
  • complaint responses; and
  • important Service or legal-document updates.

Marketing communications are sent only where permitted by applicable law. Where consent is required, marketing consent is separate from acceptance of the Terms and from verification consent.

Marketing emails will identify Hey Bella and include a functional unsubscribe method. In Australia, we will action unsubscribe requests within the period required by the Spam Act 2003 (Cth).

Opting out of marketing does not prevent us from sending necessary transactional, account, security or legal communications.

13. Cookies, Google Analytics 4 and site-wide consent

Hey Bella uses cookies and similar technologies for security, authentication, session management, preferences, fraud prevention, performance and analytics.

We use a site-wide cookie consent mechanism that allows users to manage non-essential cookies and similar technologies.

13.1 Essential technologies

Essential cookies or storage technologies may be used where necessary for:

  • authentication and session management;
  • security and fraud prevention;
  • load balancing and technical delivery;
  • storing privacy and cookie preferences; and
  • core Service functionality.

These technologies cannot always be disabled through our consent tool because the Service may not function securely without them.

13.2 Google Analytics 4

Hey Bella may use Google Analytics 4 (GA4) to understand website and Service usage, performance and engagement.

Where consent is required, GA4 and other non-essential analytics technologies are not activated until analytics consent has been given through the site-wide cookie controls.

GA4 may receive technical and usage information associated with your browser or device. Hey Bella does not intend to send verification selfies, private message content or complete payment-card details to GA4.

13.3 Your cookie choices

Where our consent controls are available, you may:

  • accept non-essential cookies;
  • reject non-essential cookies;
  • choose categories of cookies; and
  • change or withdraw your preferences later through Cookie Settings.

Withdrawing consent affects future non-essential tracking and does not invalidate processing that was lawful before withdrawal.

Where applicable law requires us to recognise a browser-based opt-out preference signal, including a valid Global Privacy Control signal in jurisdictions where it has legal effect, we will treat that signal as required by the relevant law.

For further information about the cookies and similar technologies used by Hey Bella, please see our Cookie Policy.

14. When we disclose personal information

We may disclose personal information:

  • to approved members where you have chosen to make information visible in your profile or communications;
  • to service providers acting for us;
  • to authorised personnel and contractors subject to appropriate confidentiality obligations;
  • to professional advisers, accountants, insurers and legal representatives;
  • where reasonably necessary to investigate fraud, threats, abuse or serious safety concerns;
  • to police, courts, regulators, emergency services or other authorities where required or authorised by law;
  • where reasonably necessary to lessen or prevent a serious threat to life, health or safety where law permits;
  • in connection with a proposed or completed business sale, merger, financing, restructuring or transfer as described below; or
  • with your consent or at your direction.

We do not sell or rent private member profiles, messages or verification images as a commercial data product.

15. Business Transfers, Sale, Merger or Change of Ownership

If Hey Bella Group is involved in a proposed or completed merger, acquisition, financing, restructuring, sale of the business, sale of assets or transfer of the Service, personal information may be disclosed to professional advisers, prospective purchasers, investors, financiers or the new entity as reasonably necessary for the transaction.

Where appropriate, due-diligence access will be subject to confidentiality and data-security restrictions.

Following a completed transaction, the acquiring or successor entity may receive and continue to process personal information as part of the transferred business, subject to applicable privacy law and the privacy commitments that legally continue to apply.

If a new owner proposes a materially different use of personal information that requires additional notice or consent, the new owner or Hey Bella will provide that notice and obtain consent where required by law.

16. Service providers, AWS and international processing

Hey Bella uses cloud, network, database, payment, email, security, deployment and analytics providers to operate the Service.

Our providers and infrastructure may include:

Provider or serviceMain purposePossible processing locations
Amazon Web Services (AWS)Cloud infrastructure, storage, computing, security and supporting servicesAustralia (including Sydney), Singapore, United States, Canada, United Kingdom and European regions
SupabaseDatabase, authentication and secure application servicesAustralia, Singapore and other provider or subprocessor locations
CloudflareDomain, network delivery, bot protection, security and traffic filteringGlobal network, including Australia, Singapore, United States, Canada, United Kingdom and Europe
VercelWebsite and application deploymentUnited States and global infrastructure
Fly.ioApplication hosting and computingSelected regions and global infrastructure, including regions used by Hey Bella for operational services
ResendTransactional and service email deliveryUnited States and other provider or subprocessor locations
StripeMembership payments, fraud prevention and transaction processingAustralia, United States and other global locations
GitHubSource-code management and deployment workflowsUnited States and global infrastructure
Google Analytics 4Consent-controlled analytics and Service measurementGlobal Google infrastructure

Not every category of personal information is processed in every listed country. The location depends on the relevant service, configuration, network path and provider operations.

Hey Bella uses AWS services across regions including Sydney, Singapore, the United States, Canada, the United Kingdom and Europe. Personal information or technical data may therefore be stored, routed, backed up or otherwise processed in one or more of those locations where required for the relevant AWS service.

GitHub is not intended to be used as a production storage location for member profiles, private messages, verification images or payment-card information.

Where personal information is disclosed to an overseas recipient and Australian Privacy Principle 8 applies, we take reasonable steps required by applicable law concerning the overseas recipient’s handling of that information.

Where EU or UK transfer restrictions apply, we use a lawful transfer mechanism where required, which may include an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another legally recognised safeguard.

We may replace, add or change providers as the Service develops. We will update this Policy where a change materially affects how personal information is handled.

17. Security

We use administrative, technical and organisational measures appropriate to the nature and sensitivity of the information we hold. Measures may include:

  • encryption in transit;
  • encryption at rest through configured infrastructure services;
  • private storage controls;
  • role-based permissions;
  • multi-factor authentication for privileged accounts where supported;
  • access and security logging;
  • rate limiting and bot protection;
  • secure software-development practices;
  • vulnerability and dependency management;
  • restricted access to verification information; and
  • incident-response and deletion controls.

No internet service can guarantee absolute security. Users should protect their email accounts and login methods and notify us promptly of suspected unauthorised access.

18. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including operation of the Service, safety, dispute resolution, fraud prevention, accounting, tax, legal compliance and protection of legal rights.

Our standard retention approach is:

  • Verification image: deleted within seven days after collection.
  • Verification result and date: retained while the account is active and ordinarily for up to 12 months after closure.
  • Incomplete, withdrawn, waitlisted or declined applications: ordinarily up to 12 months after the application is closed or decided, unless a shorter period is appropriate.
  • Active profile and account data: while the account is active and ordinarily for up to 12 months after closure.
  • Ordinary messages: while the account is active and ordinarily for up to 12 months after account closure.
  • Reported messages and serious safety evidence: ordinarily up to three years after the relevant report or investigation is finalised.
  • Moderation and appeal records: ordinarily up to three years after the final decision.
  • Limited serious-fraud, ban or re-registration prevention records: ordinarily up to five years where reasonably necessary and proportionate.
  • Technical and security logs: ordinarily up to 12 months.
  • Support, privacy and complaint records: ordinarily up to two years after the matter is finalised.
  • Payment, refund, invoice and tax records: ordinarily at least five years or longer where required by applicable law.
  • Marketing suppression records: minimal information may be retained for as long as reasonably necessary to ensure an unsubscribe request continues to be respected.
  • Ordinary encrypted system backups: routinely overwritten or deleted within 90 days, unless a longer period is required for a specific legal hold, security investigation or disaster-recovery event.

Verification images are excluded from ordinary long-term backups by design where technically practicable so that the seven-day deletion commitment can be honoured.

A closed profile is removed from active member display promptly even if limited records must temporarily be retained.

We may retain information longer where reasonably necessary for pending or anticipated legal proceedings, fraud or safety investigations, payment disputes, chargebacks, law-enforcement requests or another legal preservation requirement.

When information is no longer required, we take reasonable steps to delete or de-identify it.

19. Access, correction, deletion and privacy choices

You may contact us to request, as applicable:

  • access to personal information we hold about you;
  • correction of inaccurate or outdated personal information;
  • closure or deletion of your account;
  • withdrawal of a consent;
  • opt-out from marketing;
  • information about a privacy decision; or
  • exercise of another right available under applicable privacy law.

Send privacy requests to privacy@joinheybella.com.

We may take reasonable steps to verify your identity before providing access, deletion or other rights. We will not request more verification information than reasonably necessary.

Rights may be subject to legal exceptions, including where disclosure would unreasonably affect another person’s privacy, reveal confidential safety information, compromise security controls or conflict with legal proceedings or preservation duties.

20. Privacy complaints

To make a privacy complaint, contact:

privacy@joinheybella.com

Please provide enough information for us to understand what happened and the outcome you seek.

We aim to acknowledge privacy complaints within seven business days and provide a substantive response within 30 days where reasonably practicable, subject to any different timeframe required by applicable law.

21. Data breaches

We investigate suspected loss, unauthorised access, unauthorised disclosure or other compromise of personal information.

Where the Australian Notifiable Data Breaches scheme applies, we will assess suspected eligible data breaches and notify affected individuals and the Office of the Australian Information Commissioner where required.

We will also comply with applicable overseas breach-notification laws where they apply to the relevant incident and individuals.

22. Australian privacy rights

Where the Privacy Act 1988 (Cth) applies, you may have rights under the Australian Privacy Principles, including rights relating to access, correction, direct marketing, transparency, security and complaint handling.

If you are dissatisfied with our handling of a privacy complaint and the Privacy Act applies, you may be entitled to complain to the Office of the Australian Information Commissioner.

Hey Bella’s Privacy Officer can be contacted at privacy@joinheybella.com.

23. European Economic Area and United Kingdom

This section applies only to the extent that the EU GDPR, UK GDPR, or another applicable European data-protection law applies to Hey Bella’s processing of your personal data.

23.1 Lawful grounds for processing

Where the EU GDPR or UK GDPR applies, we process personal data only where a lawful basis applies. Depending on the activity, the basis may include:

  • performing a contract with you or taking steps at your request before entering into a contract;
  • our legitimate interests in operating, securing and improving Hey Bella, preventing fraud and protecting our legal rights, where those interests are not overridden by your rights and interests;
  • your consent for a specified purpose;
  • compliance with a legal obligation; or
  • another lawful basis permitted by applicable law.

23.2 Special-category information

Dating-service information may reveal sexual orientation, religious or philosophical beliefs, health information or other special-category data.

Where Article 9 of the EU GDPR or equivalent UK provisions apply, we process special-category data only where an additional lawful condition applies, which may include your explicit consent.

A photograph or verification image is not automatically biometric data under the GDPR. Hey Bella’s current verification process does not create or store a biometric template for uniquely identifying you. If we later introduce that type of processing, we will implement the additional protections required by applicable law before doing so.

23.3 Your rights

Subject to applicable conditions and exceptions, you may have rights to:

  • access your personal data;
  • correct inaccurate personal data;
  • request erasure;
  • restrict processing;
  • object to particular processing, including direct marketing;
  • receive or transfer certain data in a portable format;
  • withdraw consent where processing relies on consent; and
  • exercise rights concerning qualifying automated decisions.

Requests may be sent to privacy@joinheybella.com.

We may verify identity before acting on a request and will respond within the period required by applicable law.

23.4 Marketing

Where European or UK law requires consent for marketing, we will obtain the required consent. You can withdraw from marketing at any time using the unsubscribe method in the message or by contacting us.

23.5 International transfers

Hey Bella is based in Australia and uses service providers in multiple countries. Where EU or UK restricted-transfer rules apply, we use a recognised transfer mechanism where required, as described in Section 16.

23.6 Complaints

If EU GDPR applies, you may have the right to lodge a complaint with the competent supervisory authority in the EEA, including an authority in the country of your habitual residence, place of work or alleged infringement.

If UK GDPR applies, you may have the right to complain to the UK Information Commissioner’s Office.

23.7 EU or UK representative

Hey Bella currently targets its Service primarily to Australian customers. If Hey Bella becomes legally required to appoint an EU or UK representative because it actively offers services to or monitors individuals in those jurisdictions and no applicable exception applies, we will appoint the required representative and publish the representative’s contact details before or when that obligation arises.

24. United States residents

This section applies only to the extent that a United States federal or state privacy law applies to Hey Bella and our processing of your personal information.

Depending on your state of residence and the law that applies, you may have rights including:

  • access or confirmation of personal information processed about you;
  • correction of inaccurate information;
  • deletion, subject to exceptions;
  • portability of certain information;
  • opt-out from sale, sharing, targeted advertising or certain profiling where applicable;
  • withdrawal of consent where provided by law;
  • limits on certain uses of sensitive information;
  • an appeal of particular privacy-request decisions where state law provides that right; and
  • non-discrimination for exercising statutory privacy rights.

Requests may be sent to privacy@joinheybella.com.

We may verify identity and, where allowed, verify the authority of an authorised agent before completing certain requests.

Hey Bella does not sell private member profiles, messages or verification images for monetary consideration. If an online analytics or advertising disclosure is treated as a “sale,” “sharing,” targeted advertising or similar regulated activity under an applicable state law, Hey Bella will provide the consent, opt-out or preference-signal treatment required by that law.

25. California residents

This section applies if the California Consumer Privacy Act, as amended (CCPA) applies to Hey Bella.

Depending on the CCPA’s applicability and exceptions, California residents may have rights to:

  • know the categories and specific pieces of personal information collected;
  • know categories of sources, purposes and recipients;
  • request deletion;
  • request correction;
  • opt out of sale or sharing;
  • limit certain uses or disclosures of sensitive personal information where applicable; and
  • receive equal service and treatment when exercising CCPA rights.

25.1 Categories of California personal information

The categories we may collect include identifiers; customer records; commercial and transaction information; internet or electronic-network activity; approximate geolocation; photographs and other visual information; inferences and preferences; communications; and sensitive personal information where you choose to provide it or where it is necessary for the Service.

Sensitive information may include account credentials, relationship or sexual-orientation information, religious or philosophical information you choose to provide, and other information treated as sensitive under California law.

We use these categories for the purposes described in Sections 6 and 9 and disclose them to the categories of recipients described in Sections 14 to 16.

25.2 Sale, sharing and analytics

Hey Bella does not sell private profiles, messages or verification images for monetary consideration.

Where consented analytics technologies such as GA4 involve a disclosure that is legally treated as “sharing” or another opt-out activity under the CCPA, you may use the site-wide cookie controls or another legally required opt-out method. Where applicable, we will honour a valid Global Privacy Control signal as required by California law.

25.3 Sensitive personal information

Hey Bella uses sensitive personal information for purposes reasonably necessary to provide, secure and administer the dating Service and for other purposes permitted by law. We do not use verification images or sensitive dating information to build third-party advertising profiles.

25.4 California requests

California privacy requests may be sent to privacy@joinheybella.com. We will process requests, verification and authorised-agent requests in accordance with applicable CCPA requirements.

26. Canadian residents

This section applies to Canadian residents to the extent that the Personal Information Protection and Electronic Documents Act (PIPEDA) or applicable provincial privacy legislation applies to Hey Bella.

Depending on the circumstances, provincial privacy legislation in Quebec, Alberta or British Columbia may apply instead of, or together with, PIPEDA.

26.1 Accountability and Privacy Officer

Hey Bella is responsible for personal information under its control and has designated responsibility for privacy compliance.

The Hey Bella Privacy Officer can be contacted at privacy@joinheybella.com.

26.2 Consent and purposes

Where Canadian law requires consent, we seek consent that is meaningful and appropriate to the sensitivity of the information and the purpose for which it is collected, used or disclosed.

For sensitive information, express consent may be required. You may withdraw consent subject to legal or contractual restrictions and reasonable notice, although withdrawal may mean we cannot continue providing a feature that depends on the information.

26.3 Limiting collection, use and retention

We seek to collect only information reasonably necessary for identified purposes and do not use or disclose it for a materially different purpose unless authorised by law or supported by additional consent where required.

Retention is governed by Section 18.

26.4 Accuracy, safeguards and access

We take reasonable steps to keep personal information sufficiently accurate for the purposes for which it is used and to protect it with safeguards appropriate to its sensitivity.

Subject to applicable law and exceptions, Canadian residents may request access to personal information held about them and correction of inaccurate or incomplete information.

26.5 Cross-border processing

Hey Bella is based in Australia and uses providers and infrastructure in multiple countries, including the locations described in Section 16. Canadian personal information may therefore be processed outside Canada and may be subject to the laws of the jurisdiction where it is processed.

We use contractual, technical and organisational measures appropriate to the circumstances and provide transparency or seek consent for cross-border processing where required by applicable Canadian law.

26.6 Canadian complaints

Privacy complaints should first be sent to privacy@joinheybella.com.

Where applicable, you may also have the right to complain to the Office of the Privacy Commissioner of Canada or the relevant provincial privacy regulator.

Residents of Quebec, Alberta and British Columbia may have additional rights or protections under applicable provincial legislation, including rights or requirements relating to consent, access, correction, portability, governance and cross-border processing.

27. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, providers, security practices, features or our information-handling practices.

For material changes, we will provide reasonable notice through the Service, email or another appropriate method where required.

If a change introduces a new use of sensitive information, biometric identifiers or another processing activity that requires new consent, we will obtain that consent before beginning the new processing where required by law.

28. Contact Us

For general Service questions:

Hey Bella Group
454 Collins St.
Melbourne VIC 3000
Australia
support@joinheybella.com

For privacy enquiries, privacy rights or privacy complaints:

Hey Bella Privacy Officer
Hey Bella Group
454 Collins St.
Melbourne VIC 3000
Australia
privacy@joinheybella.com

Privacy PolicyTerms and ConditionsCookie Policy