Yiff Party

Privacy Policy

Last updated: 2026-05-05

This Privacy Policy describes how Yiff Party ("we", "us") collects, uses, and protects personal data when you use the Yiff Party website (yiff-party.com). We comply with the EU General Data Protection Regulation (GDPR / RGPD) and the California Consumer Privacy Act (CCPA).

1. Data Controller

The data controller is the operator of Yiff Party. For any privacy-related request, contact us via the contact formwith subject "GDPR request".

2. Data We Collect

4. Third-Party Processors

The following sub-processors handle data on our behalf:

Transfers to the United States are covered by Standard Contractual Clauses (SCCs) per the EU-US Data Privacy Framework.

5. Data Retention

6. Your Rights

Under RGPD, you have the right to:

7. Account Deletion

You can delete your account anytime from the account page. Deletion is immediate and removes:

Payment and subscription records are retained for the 7 years tax law requires, with personal identifiers (name, email) replaced by placeholders.

8. Children's Privacy

Yiff Party is an adults-only website. We do not knowingly collect data from anyone under 18. If you believe we have received data from a minor, contact us immediately and we will delete it.

9. Security

We use industry-standard measures: HTTPS everywhere, bcrypt for password hashing (cost factor 12), HSTS preload, X-Frame-Options DENY, rate limiting, antibot challenges on public forms, separate authentication tables for admin and customer accounts.

10. Breach Notification

In the event of a personal data breach likely to result in a high risk to your rights, we will notify affected users and the competent supervisory authority within 72 hours, as required by RGPD Art. 33-34.

11. Changes to This Policy

We may update this policy. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated via email to logged-in users.

12. Contact

For any privacy-related question or to exercise your rights, please use the contact formwith the subject "GDPR request". We respond within 30 days.