1. Controller and scope
BookMyDM.io is the service operator and controller for account, marketplace, safety, and support data processed through this service. Privacy requests are accepted through authenticated BookMyDM.io Support, which lets us verify the requester before disclosing account data.
2. Data we collect
- Account data: name, email, password hash, profile photo, age and terms confirmation, account status, and security sessions.
- Marketplace data: credit balance and ledger, purchases, paid turns, custom offers, reviews, reports, support tickets, and creator applications.
- Content: messages and files you choose to send, including information needed to investigate a report or refund case.
- Technical data: IP-derived country, security logs, device/request data, and limited first-party visit analytics where permitted or consented to.
- Payment data: Stripe processes payment credentials. BookMyDM.io receives identifiers, status, amount, and limited customer details needed to reconcile a purchase.
3. Why we process it
We process data to perform our contract (accounts, chats, credits, offers and support); comply with law (consumer, accounting and lawful requests); pursue legitimate interests (security, fraud prevention, service reliability and case handling); and, for optional EU/EEA analytics, with consent. We do not use sensitive message content for targeted advertising.
4. Who receives data
Data may be shared with the creator or customer participating in a conversation; infrastructure, storage, security and support providers acting under contract; Stripe and its managed-payment providers for checkout; professional advisers; and authorities when legally required. Private messages are not public. We do not sell personal information or share it for cross-context behavioral advertising.
5. International transfers
Providers may process data outside your country. Where EU/EEA data is transferred internationally, BookMyDM.io uses an approved transfer mechanism and supplementary safeguards where required. Contact Support for information relevant to your data.
6. Retention
Account and conversation data is kept while needed to provide the service. On closure, it is deleted or de-identified unless a limited period is required for chargebacks, disputes, abuse prevention, accounting, or legal obligations. Expired password-reset links stop working after 30 minutes, and expired token records are periodically deleted.
7. Your choices and rights
Depending on location, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent without affecting earlier processing; and appeal or complain to a regulator. California residents may request disclosure, correction, or deletion and may opt out of sale or sharing. BookMyDM.io does not sell or share data as those terms are used for cross-context advertising, so Global Privacy Control is honored by default.
8. Security
We use hashed passwords and session tokens, restricted server-side authorization, rate limits, same-origin checks, encrypted transport, private file authorization, audit records, and payment webhooks. No online service can promise absolute security. Report suspected compromise immediately through Support.
9. Children
BookMyDM.io is for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. Contact Support if you believe a minor created an account.
10. Automated decisions
Security signals may slow or block suspicious attempts, but BookMyDM.io does not make decisions producing legal or similarly significant effects solely through automated processing.
Questions or rights requests
Use BookMyDM.io Support for legal, privacy, accessibility, payment, or account questions. Privacy requests are verified before account data is disclosed or changed.
BookMyDM.io