PLUSH PRIVACY NOTICE

Effective Date: July 1, 2025

This Privacy Policy (the “Policy”) forms part of the Plush Terms of Service (the “Terms”). Any capitalized term not defined here has the meaning assigned to it in the Terms.
This Policy describes the personal data we collect when you use our mobile applications, websites, and related services (together, the “App” or the “Service”), as well as how and why we process that data.
By accessing or using the Service, you confirm that (i) you have read and understood this Policy and accept the processing described in it, and (ii) you are at least 18 years old, or the age of majority in your jurisdiction if that age is higher.
If you disagree with this Policy or cannot give that confirmation, you may not use the Service. In that event, you must:
Delete your account and contact us to request deletion of your data; and
Delete the App from your devices.

1. PERSONAL DATA WE COLLECT

1.1. Categories of Data Collected. Based on how you use and interact with the Service, we may collect the following categories of personal data:
Account and Registration Data: name, nickname, email address, profile photo, gender, date of birth, login credentials (including Apple ID, Google ID, or Facebook ID), and any optional profile details you choose to provide.


Communication Data: messages sent through the Service, communications with support, information connected with dispute resolution, and notification preferences. We may occasionally capture screenshots where needed for moderation or fraud prevention.


Device and Technical Data: IP address, time zone, device model, operating system, language settings, hardware identifiers (e.g., IDFA, AAID, IDFV), crash logs, network information, and performance data.


Usage Data: records showing how you use the Service (e.g., pages or features used, time spent, frequency of logins, in-app actions, search queries, and referral source such as the app store or ad that brought you to the Service).


Location Data: approximate location derived from your IP address or device settings. We do not collect precise GPS location unless you explicitly allow it.


Payment and Transaction Data: transaction IDs, purchase history, subscription or in-app purchase confirmations through Apple App Store or Google Play. We do not store full payment card details; payments are processed securely by Apple or Google.


Advertising and Analytics Data: advertising identifiers (IDFA, AAID), cookies, and tracking pixels (including Meta Pixel), which may collect data about your interactions with the Service, ads you see, and actions you take.


Verification Data (where required for compliance or fraud prevention): identity documents, selfies for age verification, and associated metadata.


1.2. Optional and Public Data. You may elect to submit additional information while using the Service, such as photos, stories, or other User Content visible to others. Information you choose to publish openly is treated as non-confidential.
1.3. Children’s Data. The Service is intended only for people aged 18 or older. We do not knowingly collect personal data from children. If we discover that a child has submitted data to us, we will delete it promptly.

2. WHY WE PROCESS DATA AND OUR LEGAL BASES

2.1. We primarily collect and use data to deliver the Service, maintain and improve the quality of the App, support safety and compliance, and develop our products. The details below explain these uses and provide practical examples.
2.2. We process personal data only where a valid legal basis exists under applicable data protection laws (including GDPR, CCPA/CPRA, and ePrivacy rules). Depending on the context, this may be:
 
(a) performance of our contract with you;
 
(b) compliance with legal obligations;
 
(c) your consent; or
 
(d) our legitimate interests, provided that your rights and freedoms do not override such interests.
2.3. The table below identifies each processing purpose, representative activities, the relevant data categories, and the lawful basis we rely on.

PurposeDescription and ExamplesCategories of DataLawful Basis
1. To provide the Service and administer your accountConfirming your identity, email, or device; securing sign-in; preventing fraud and misuse; tailoring your in-app experience; troubleshooting technical problems; and handling support requests. For example, we may adapt in-app recommendations to your preferences.Login details, identifiers, device data, support communicationsContract performance; Consent (if sensitive categories apply)
2. To communicate with you about the ServiceProviding service notices, password-reset messages, reminders such as push notifications, and requests for feedback. For example, we may send a notification inviting you to return to the App.Contact information, device identifiersContract performance; Legitimate interest (encouraging active and safe use of the Service)
3. To process in-app purchasesHandling one-time in-app purchases through the Apple App Store or Google Play. Transaction identifiers may be retained for accounting and fraud prevention; we do not keep complete payment-card details.Transaction IDs, purchase history, Apple/Google account dataContract performance; Legal obligation (fraud prevention, accounting)
4. To research and improve our ServiceApplying analytics tools such as Google Analytics, Firebase, AppsFlyer, Amplitude, and Meta Pixel to assess engagement, refine features, identify errors, test functionality, and tailor user experiences.Usage data, device data, cookies, advertising IDsLegitimate interest (improving and optimizing the Service); Consent (where required for tracking)
5. To personalize ads and marketingUsing advertising identifiers, cookies, and Meta Pixel to personalize advertising and evaluate campaign performance. For example, you may see a related Instagram ad after using the App.Device data, advertising IDs, cookies, interaction historyConsent (for personalized ads, where required); Legitimate interest (where permitted)
6. To enforce Terms, ensure safety, and combat fraudCombining automated tools and human review to identify harmful or prohibited conduct, investigate suspected abuse or fraud, and apply account restrictions or bans.Account data, communications, moderation logs, IP address, device identifiersLegitimate interest (ensuring safety, preventing fraud); Legal obligation (where applicable)
7. To comply with legal obligationsRetaining invoices, processing tax/accounting data, responding to law enforcement or regulatory requests.Payment records, account data, communication logsLegal obligation
8. To defend legal claims and rightsProcessing information to establish, pursue, or defend legal claims and disputes, including supplying evidence in arbitration or court proceedings.All categories, as relevantLegitimate interest (protection of legal rights)

3. WHEN AND WITH WHOM DATA IS SHARED

3.1. We disclose Personal Data to service providers only in the circumstances and for the purposes described in this Policy.
3.2. We will not:
 
3.2.1. Use data obtained through the Service for unrelated advertising, or sell it to ad platforms, data brokers, or information resellers.
 
3.2.2. Process your data in a way that is incompatible with the purposes described in Section 2.
 
3.2.3. Collect or process more data than is necessary for the purposes stated.
3.3. We require every third-party provider to safeguard personal data and process it lawfully. Providers may not use your data for their own purposes and may act only on our documented instructions.
3.4. We may disclose certain personal data internally (among employees, contractors, and affiliates) or externally (to authorized service providers) only where access is necessary, provided that such parties are bound by confidentiality and security obligations.

External Service Providers

We rely on third-party services to run, assess, and enhance the App. These providers support hosting, analytics, error tracking, advertising attribution, and specific App functionality. Below is a list of our current third-party providers, the purpose of their processing, and links to their respective privacy policies:

Third-Party ProviderServicePurpose of UsagePrivacy Materials
Google LLCGoogle AdsMarketing and advertisingPrivacy Policy
Meta Platforms, Inc.Facebook / Meta PixelMarketing, ad measurement, campaign personalizationPrivacy Policy
Apple Inc.App Store / APNsApp distribution, push notificationsPrivacy Policy
Amplitude Inc.AmplitudeProduct analytics and event trackingPrivacy Policy
AppsFlyer Inc.AppsFlyerMobile marketing analytics and attributionPrivacy Policy
Google LLCFirebaseDevelopment purposesPrivacy Policy
Agora Lab, Inc.Agora SDKReal-time audio/video streaming and quality monitoringPrivacy Policy
Applovin Corporation / AppLovin (Singapore) Pte. Ltd.AppLovinAnalytics and user engagement optimizationPrivacy Policy

5. HOW LONG WE KEEP DATA

5.1. We keep Personal Data only for the period reasonably necessary to achieve the purposes for which it was collected, including compliance with legal, accounting, or reporting obligations.
5.2. After you delete your account, we delete or anonymize data under the following schedule:
Account/profile data: deleted within 30 days of account deletion.


Communications (messages, correspondence, attachments): deleted within 30 days of account deletion.


Moderation and safety logs (e.g., flagged content, screenshots, abuse reports): retained for up to 60 days for fraud prevention and platform safety, then permanently deleted or anonymized.


Technical logs and device information: deleted or anonymized within 60 days, unless longer retention is required for security or legal investigations.


Payment and transaction data: retained as required by applicable tax and accounting laws (typically 5–7 years).


5.3. Where an exact retention period cannot be set in advance, we use the shortest period consistent with the purposes stated in this Policy.
5.4. Once the applicable retention period ends, we securely erase or anonymize Personal Data so it can no longer be linked to you.

6. YOUR DATA-PROTECTION RIGHTS

6.1. Depending on applicable law, including the GDPR and CCPA, you may exercise the following rights:
Right of access: to request confirmation of whether we process your data and obtain a copy.


Right to rectification: to have inaccurate or incomplete data corrected.


Right to erasure (“right to be forgotten”): to request deletion of your data, subject to legal obligations.


Right to object: to object to processing based on legitimate interests, including direct marketing.


Right to restrict processing: to request suspension of processing under certain conditions.


Right to data portability: to obtain your data in a structured, machine-readable format and transfer it to another controller.


Right to withdraw consent: where processing is based on your consent, you may withdraw it at any time.


Right to lodge a complaint: with your local data protection authority if you believe we unlawfully process your data.


6.2. To submit a rights request, contact [email protected]. We may verify your identity before responding in order to protect your data.
6.3. We respond to verified requests within 30 days, or within up to 60 days where the law permits an extension.
6.4. Access rights under California’s Shine the Light California also provides its residents with additional access rights. Under Shine the Light law, the residents may ask companies once a year what personal information they share with third parties for those third parties' direct marketing purposes. Learn more about what is considered to be personal information under the statute.

To obtain this information from us, please send an email message to [email protected], which includes “Request for California Shine the Light Privacy Information” on the subject line and your state of residence and email address in the body of your message. Please be aware that not all information sharing is covered by the “Shine the Light” requirements and only information on covered sharing will be included in our response.

7. AGE RESTRICTION AND CHILDREN’S DATA

7.1. The Service is designed for adults aged 18 and above. We do not knowingly collect or process Personal Data of children.
7.2. If we learn that a person under 18 has provided data, we will promptly remove that information. Parents or guardians who believe their child may have provided us with Personal Data should contact us at [email protected].

8. CROSS-BORDER DATA TRANSFERS


8.1. Because we operate internationally, Personal Data may be transferred beyond the country in which it was collected.
8.2. If you are located in the EEA or UK, transfers outside these regions will only occur where:
The European Commission has issued an adequacy decision for the destination country; or


We have implemented Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring equivalent safeguards.


8.3. You acknowledge that data may be transferred, stored, or processed in jurisdictions with different privacy protections, subject in every case to appropriate safeguards.

9. HOW WE PROTECT YOUR DATA

9.1. We maintain suitable technical and organizational safeguards against unauthorized access, loss, misuse, alteration, or disclosure of Personal Data. These include encryption of data in transit, access controls, regular monitoring, and staff confidentiality obligations.
9.2. We also require our service providers to apply security measures consistent with applicable data protection laws, including the GDPR and CCPA/CPRA.
9.3. No online system or Internet transmission can be guaranteed completely secure. While we use commercially reasonable safeguards, we cannot guarantee absolute security of your information.
9.4. You are responsible for maintaining the confidentiality of your account details and must notify us promptly at [email protected] of any suspected unauthorized use of your account.
9.5. In case of a data breach that may affect your rights, we will notify you and, where applicable, the competent supervisory authorities, in accordance with the law.

10. UPDATES TO THIS NOTICE

10.1. We may revise this Policy periodically to reflect legal, technical, or operational developments.
10.2. Where an update is material, we will provide notice by email or within the App. The “Effective Date” will be updated accordingly.

11. PRIVACY CONTACT

11.1. For questions about this Policy or our handling of personal data, contact:
Controller: DESTRIA INVESTMENTS LIMITED
Email: [email protected]
Address: THE LEVENTIS GALLERY TOWER, Floor 13, Flat 1301, 5 A.g. Leventis, Nicosia 1097, Cyprus