Last updated: May 2026 ยท Compliant with UK GDPR and the Online Safety Act 2023
LoveLink UK is a dating platform for UK singles. We are the data controller for your personal information under UK GDPR.
Data controller contact: privacy@lovelink.uk
We collect the following categories of data:
Your dating preferences (including gender and who you are looking for) constitute special category data under UK GDPR Article 9. We process this data solely with your explicit consent, given when you create your profile, and use it only to match you with compatible people on the platform. You may withdraw this consent at any time by deleting your account.
| Data type | Legal basis | Why |
|---|---|---|
| Profile & preference data | Contract performance | Necessary to provide the matching service |
| Dating preferences (gender) | Explicit consent (Art. 9) | Special category โ you consent at sign-up |
| IP address & device data | Legitimate interest | Fraud prevention, UK-only enforcement, security |
| Device fingerprint | Legitimate interest | Ban evasion detection, fraud prevention (Online Safety Act 2023) |
| Postcode | Contract performance | Required to verify UK location and enable matching |
| Precise GPS location | Explicit consent | Asked via browser permission prompt โ you can decline |
| Push notification token | Explicit consent | Asked via browser permission prompt โ you can decline |
| Payment data | Contract performance | Necessary to process subscription and one-time purchases |
| Security logs | Legitimate interest | Fraud prevention, abuse detection, Online Safety Act 2023 |
| Message content scanning | Legitimate interest / Legal obligation | Romance scam and fraud detection; compliance with Online Safety Act 2023 |
We share your data only with the following third-party processors, all under data processing agreements:
| Processor | Purpose | Data shared |
|---|---|---|
| Supabase (EU-hosted) | Database, authentication, file storage | All profile, message, and account data |
| Anthropic (Claude AI) | AI icebreaker generation + photo moderation | Interests, city (icebreaker); photo hash (moderation). No name or contact data. |
| Groq | AI icebreaker fallback | Interests and city only |
| Stripe | Payment processing | Email, subscription status. Card data stays with Stripe. |
| Resend | Transactional email (match alerts, digest) | Email address and first name only |
| ProxyCheck.io | VPN/proxy and IP geolocation | IP address per request |
| FingerprintJS (client-side) | Device fingerprinting for fraud prevention | Browser characteristics. No personally identifiable data is sent to FingerprintJS servers โ processing is client-side only. |
| postcodes.io | Postcode validation and geocoding | Your postcode only (no name/email) |
We never sell your data, share it with advertisers, or use it for any purpose other than those listed above.
We use FingerprintJS (open-source, client-side library) to generate a device fingerprint. This is a hash derived from your browser's characteristics โ it does not capture your name, email, or any directly identifying information. The hash is stored in our database linked to your account and is used exclusively to:
This processing is carried out under our legitimate interest in protecting users from harassment and fraud, and in compliance with the Online Safety Act 2023. You may object to this processing by contacting us at privacy@lovelink.uk, though we may be unable to continue providing the service if this processing cannot be carried out.
We collect location data at three levels:
As required by the UK Online Safety Act 2023, we scan outgoing messages for signals associated with romance scams and financial fraud. This scanning is automated and looks for specific patterns such as requests for money, gift cards, cryptocurrency, or attempts to move conversations off-platform.
Messages flagged by this system are reviewed by our moderation team. We do not read your general conversations โ scanning is targeted and limited to fraud pattern detection. This processing is conducted under legitimate interest and our legal obligations under the Online Safety Act.
We send the following types of notifications with your consent:
To exercise any right, email privacy@lovelink.uk. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the ICO (UK data regulator) at ico.org.uk or by phone on 0303 123 1113.
We use only essential cookies required for authentication (Supabase session tokens). We do not use advertising, analytics, or third-party tracking cookies. Our service worker (used for push notifications) stores no personal data.
All data is transmitted over HTTPS. Passwords are hashed and never stored in plain text (managed by Supabase Auth). Our database uses row-level security policies to ensure users can only access their own data. We conduct regular reviews of our security practices.
To report a security vulnerability, email security@lovelink.uk.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes by email and by a notice on the platform at least 14 days before changes take effect. Continued use of LoveLink UK after that date constitutes acceptance of the updated policy.
LoveLink UK
Privacy: privacy@lovelink.uk
Security: security@lovelink.uk
Data regulator: ICO (ico.org.uk)