Legal
Privacy policy
Last updated 12 August 2026
You're a sex worker or someone who books one. Your privacy isn't a compliance box for you - it's your housing, your family, your other job, sometimes your safety. We've built this site knowing that.
The rule we design to: don't collect it, and you can't lose it, leak it, or be made to hand it over. Everything below follows from that.
This policy describes what the site actually does, and it has been reviewed against detailed New Zealand legal advice (23 July 2026) covering the Privacy Act 2020 and the Biometric Processing Privacy Code, then rewritten to implement it. If anything on this page ever stops matching how the site behaves, tell us - that gap would be a bug we want fixed.
1. The short version
We never sell your data. Not to anyone, not ever, not "anonymised", not as part of a sale of the business.
We don't run advertising trackers. No Meta pixel, no Google Ads tag, no data brokers.
We don't store your IP address - only a salted one-way hash of it, which we can't reverse.
Identity checks run through an independent verification partner - we never see or store your ID or your selfie, only whether the check passed.
Your legal name never appears anywhere public on this site.
Nothing on your bank statement says Private Encounters. Pay in crypto and we never touch your bank at all; pay by bank transfer and the payee is our company name, not this site.
Ask us to delete you and we do it, quickly, without a retention conversation.
The rest of this page is the detail behind those seven lines. This policy covers privateencounters.co.nz and is written to the Privacy Act 2020.
2. What we collect
If you just read the site
- Whether you've passed the 18+ gate. One cookie, no identity attached.
- A hashed version of your IP address, if you report a listing or hit a rate limit. Salted and one-way - we can tell two reports came from the same connection, but we cannot work out where that connection is.
- Basic aggregate counts: how many people viewed a listing, how many tapped a phone number. Numbers, not people. We don't build a profile of you and we couldn't identify you from any of it.
No account, no name, no email. You can browse this entire site and leave nothing behind but a cookie you can clear.
If you save listings
Saved listings live in your browser, not on our server. No account, no email address, and nothing that ties the list to you. All we receive is a count: an advertiser can see that a number of people saved their listing, never who, and we hide the number entirely until enough people have saved it that it identifies nobody.
Clearing your browser data removes it, including from us, because we never had it.
If you have an account you can choose to keep the list on it, so it survives a new phone. That is off unless you turn it on, and it is the one thing here that means we hold a list of listings against your email address. Turning it off deletes our copy immediately, in that request, not on a schedule and not on request.
If you ask for alerts
We keep your email address, what you asked to hear about, the exact wording you agreed to, and when. You have to confirm the address before anything is sent, so nobody can sign you up. We do not track whether you open our emails or what you click, because a record of which listing you opened an email about would be more sensitive than the fact you subscribed.
Every alert carries a one-click stop link, which works immediately, and you can drop a single city or listing without losing the rest. No advertiser is ever told who follows them. If you never confirm the address, we delete it within a week.
If you advertise
- Your email address. Needed to run the account. It never appears on your listing and it doesn't need your real name in it.
- Your password - as an irreversible hash, never the password itself. We literally cannot see it.
- Your working name, and everything you choose to put in your listing: photos, bio, rates, city, availability, contact number.
- A hash of the IP you signed up from and the ones you log in from, for spotting account takeovers and ban evasion.
- Payment records: which plan, how much NZD, which coin, the invoice, the receiving address, the confirmation. Blockchain records are public by design and outside our control.
- Whether you're verified. Identity and phone checks run through an independent verification partner; we're told only the result - verified or not - with a reference id and timestamps. We never receive your ID document or your selfie.
- Your listing's stats - views, contacts, bumps - which we show you in your dashboard.
If you report something
What you wrote, which listing, and a hash of your IP. Your email only if you chose to give it, and only so we can ask a follow-up. We never show any of it to the person you reported - including your email, including if they ask, including if they're angry.
3. What we don't collect
Your real name. If you verify, an independent partner checks your ID - we never see the document or your legal name, only whether the check passed.
Your address. We ask for a suburb for the listing, and that's as precise as this site ever gets.
Your raw IP address. Hashed on arrival, and the original is never written down.
Your card or bank details. We have no way to take them and no interest in having one.
Your browsing history across other sites. There's no tracking pixel here to do it with.
Anything about your clients. We don't know who they are and we don't want to.
The content of a booking, a message, or a call. None of that touches our servers.
We also strip the metadata out of every photo on upload - the GPS coordinates, the device, the timestamp. Your camera writes that in without asking you and it has put people in danger on other sites. It never reaches our storage.
4. Identity verification
Verification is required before a listing is published. We engage Sumsub, an independent provider, to run it on our behalf. We're not sent your document or your selfie - Sumsub tells us pass or fail, and that is the whole of what reaches us. But because Sumsub does this for us, we stay responsible for it under New Zealand privacy law; it isn't simply "their problem".
The check includes a face-match, which is biometric processing under New Zealand's Biometric Processing Privacy Code 2025. We've written down why we use it, why we think it's proportionate, and the manual alternative for anyone it doesn't suit - on our biometrics page.
Who runs it
A specialist identity-verification provider - the same kind of service banks use. It opens a secure window over your dashboard, and everything to do with your document happens inside it, on the partner's systems.
What they check
That you are a real person, over 18, that the face on your government ID matches a short liveness selfie, and that the public phone number on your listing is real and yours.
What we receive
One result - verified, or not - plus a reference id from the partner and the time it happened. That is the whole message. We are never sent your ID image, your selfie, your date of birth, or your document number.
What we store
Only that result and reference: that your identity and phone were confirmed, the partner's reference id, and timestamps. No documents, no selfie, no date of birth, no document number - we have no copy of any of it to hold.
Your public number
Verification also confirms the number on your listing. If you change your public number, its verified tick drops until the new one is confirmed - the identity badge itself stays.
Verification uses a specialist provider that operates internationally, so your identity data is processed by them, overseas, under their own security and retention terms rather than ours. We're being straight about that because it matters - and the trade-off is that the most sensitive document you own never lands on our servers at all. Your legal name is used only for the check, with the partner, and is never shown to clients or anywhere public on this site.
More detail on the verification page.
5. What we use it for
Only these things. Nothing else, and no quiet expansion later - if we ever want to use your information for something new, we'll ask first.
- Running your account and publishing your listing.
- Taking payment and keeping the invoice records the law requires.
- Moderation - checking listings before they go live and acting on reports.
- Keeping people safe: verifying age, spotting coercion patterns, catching scammers and ban evasion.
- Emailing you about your account. Your listing is about to expire, your listing was rejected and here is why, we replied to your report. Never marketing - we have no newsletter and no plans for one.
- Aggregate stats, so we know which cities need more listings and which pages are broken.
- Meeting a legal obligation when we genuinely have one.
7. How long we keep it
| What | How long |
|---|---|
| Verification result and partner reference id | While your account exists |
| Your account and listing | Until you delete it, or 24 months after you last log in |
| Deleted listing photos | Gone immediately; backups age out within 30 days |
| IP hashes | 90 days |
| Reports | 24 months, or longer if it went to Police |
| Payment and invoice records | 7 years - tax law, not our choice |
| Sessions | Until they expire or you log out |
| Aggregate stats | Indefinitely, but they have no identity attached |
When the clock runs out, deletion is automatic - a scheduled job, not a person remembering. That's the only kind of retention promise worth making.
9. How we protect it
- HTTPS everywhere, encryption at rest, no exceptions.
- Passwords hashed with a slow, salted algorithm designed for the job. A stolen database still doesn't give anyone your password.
- We hold no identity documents at all. Your ID and selfie go to the verification partner, never to us, so there is nothing here to leak.
- Photo metadata stripped on upload, before it is ever written to disk.
- Payment keys aren't here to steal. The system holds public key material only - it cannot derive a private key, by design. There is no wallet on this server to drain.
- Moderator access is logged and least-privilege.
- Rate limits and lockouts on login, so a leaked password from another site isn't enough on its own.
No site is unbreakable and anyone who tells you otherwise is lying. What we can promise is that we hold as little as possible - so there's less to take - and that if we ever have a breach that could hurt you, we'll tell you and the Privacy Commissioner promptly, as the Privacy Act requires. We won't sit on it while we work out the PR.
Found a security hole? Email support@privateencounters.co.nz. We'll thank you, we'll fix it, and we won't come after you for looking.
10. Your rights
Under the Privacy Act 2020 you have real rights here, and we're not going to make you fight for them.
See what we hold
Ask and we'll send you everything we have about you. Free, within 20 working days, usually a lot sooner.
Correct it
Most of it you can edit yourself in the dashboard. For the rest, ask.
Delete it
Ask us to close your account and erase what we hold, and we do. The only things that survive are payment records we're legally required to keep for 7 years, and anything tied to an active Police matter.
Take it with you
Ask and we'll export your listing content and photos in a usable format.
Complain
Email us first - we'd rather fix it. If we don't, the Office of the Privacy Commissioner takes complaints for free at privacy.org.nz or 0800 803 909, and you don't need our permission to go to them.
11. Asking us things
Privacy questions, access requests, deletion requests: support@privateencounters.co.nz. Every email to that address is read by a person, and a privacy request - seeing, correcting, or deleting what we hold - has the Privacy Act's timeframes applying to it. You'll get a real answer, not a template, and we won't try to talk you out of it.
You don't have to use your account email to ask, and you don't have to explain why.
Our privacy officer
The Privacy Act 2020 requires us to have a named person responsible for how we handle your information. We do - they are named on our operator details page - and you can reach them directly at privacy@privateencounters.co.nz. If you've asked us something about your privacy and feel we haven't dealt with it properly, you can also complain to the Office of the Privacy Commissioner at privacy.org.nz.
If something goes wrong
If personal information is ever exposed in a way that could cause you serious harm, the Privacy Act requires us to tell you and to notify the Privacy Commissioner, and we will - promptly, in plain language, and with what you can do about it. For the people who use this site that is not a formality, so we treat it as the most serious thing that can happen here.
We'll update this page as the site changes. If a change matters to you, we'll email you about it rather than quietly bumping the date at the top.
See also: terms, cookies, how verification works.
