Privacy Policy

Effective on July 4, 2026

Billion Flower Moon Studios LLC ("we," "our," or "us") operates the informational landing page for Curtains Dating at curtainsdating.com (the "Website"). We value your privacy and believe in transparency. This Privacy Policy outlines the data processing practices applied to visitors of this Website.

This Policy applies only to the Website. It does not apply to the Curtains Dating mobile application. Once the Curtains Dating iOS application is available, use of the App will be governed by a separate, more detailed Privacy Policy, available within the App and linked from this site.


1. Scope and Age Limitations

This Privacy Policy applies solely to data processed through this informational landing page. The Website is directed exclusively to adults aged 18 and older. We do not knowingly collect personal information from individuals under the age of 18 through this Website. If we become aware that we have inadvertently collected information from a minor through the Website, we will delete it promptly. If you are a parent or guardian and believe your minor child has provided information through this Website, please contact us at the address in Section 11.

The Curtains Dating mobile application, once available, will be offered first to users located in the United States, with plans to expand to additional countries over time. This Website itself is accessible globally and is not geographically restricted; the phased rollout described above applies to the App, not to visiting this Website.


2. Who We Are (Controller Identity)

For the purposes of data protection law — including the EU General Data Protection Regulation (GDPR) to the extent it applies to Website visitors located in the EU — the data controller is:

Billion Flower Moon Studios LLC Wyoming Limited Liability Company Contact: privacy@curtainsdating.com

We do not currently have an EU establishment. For pre-launch Website processing, we rely on the Article 27(2)(a) GDPR exemption from the EU representative requirement, as our processing is occasional, does not involve special category data, and is unlikely to present a risk to the rights and freedoms of EU residents. This will be reviewed and updated when the App launches and EU users begin to be served, specifically, we will assess the representative requirement before the App is made available to EU residents.


3. Information We Do Not Collect

This Website is a static informational page with no interactive user features. We do not operate:

  • Account registration systems;
  • Waitlist forms, newsletter subscriptions, or contact submission fields;
  • Any feature that collects your name, email address, phone number, physical address, or financial data directly from you.

4. Website Analytics (PostHog — Cookieless Mode)

We use PostHog, a third-party product analytics service, to understand how visitors use the Website — for example, which pages are viewed, how visitors navigate the site, and aggregate traffic volume. This helps us improve the Website and understand audience growth ahead of the Curtains Dating App launch.

We have configured PostHog in cookieless mode. This means:

  • PostHog does not store any cookies on your device;
  • PostHog does not use browser localStorage or sessionStorage;
  • PostHog does not store any persistent identifier on your device of any kind;
  • No consent banner is required for this Website's analytics.

How cookieless tracking works. Instead of storing an identifier on your device, PostHog's servers generate a privacy-preserving daily hash using a combination of technical request data (such as user agent string and hostname) and a rotating daily salt. The salt is permanently deleted once that day's events are processed. The resulting hash cannot be reverse-engineered into your identity and does not persist across days. This means we can count approximate daily unique visitors without tracking any individual across sessions.

IP anonymization. We have enabled IP address anonymization at the project level in PostHog. IP addresses are stripped by PostHog's servers before any data is stored or enriched. We do not store, log, or retain raw IP addresses in our PostHog analytics data. We also do not use PostHog's GeoIP enrichment feature, meaning no location data is derived from your IP address in our analytics.

What we do collect via PostHog. Even in cookieless mode, PostHog may collect:

  • Page view events (which pages you visit and when);
  • On-site interaction events via autocapture (clicks, including the HTML element name, ID, and class attributes of the element you clicked, but not the content of any text you type);
  • Browser type, device type, operating system, screen size, and referring URL or UTM campaign parameters, all treated as non-identifying metadata.
  • Web performance metrics (Core Web Vitals: Largest Contentful Paint, First Contentful Paint, Cumulative Layout Shift, Interaction to Next Paint, and Time to First Byte), measured from your browser to understand real-world page load experience. These are performance timing numbers only and contain no personally identifying information.

What we do not do. We do not use PostHog to build advertising profiles, retarget you on other websites, run session replays, or engage in any form of cross-site behavioral tracking.

Data hosting. Our PostHog instance stores and processes data on PostHog Cloud EU servers located in Frankfurt, Germany. Event traffic is routed to PostHog via a managed reverse proxy that transits Cloudflare's global edge network before reaching PostHog's EU infrastructure, in accordance with PostHog's Data Processing Agreement in which Cloudflare is listed as a subprocessor. Data is stored and retained only within PostHog's EU region.

Retention. Analytics event data is retained by PostHog for up to 1 year, in accordance with PostHog Cloud's standard data retention policy for event data. Session recording data (if enabled) is retained for 30 days. We do not currently enable session recordings on this Website.


5. Infrastructure & Security Data (Cloudflare)

Separately from analytics, the infrastructure used to deliver this Website — including our deployment and content delivery network provider, Cloudflare — automatically processes limited technical network data for every request. This may include your IP address and request headers, used exclusively to route traffic, maintain uptime, and defend against malicious bot activity, distributed denial-of-service attacks, and other security threats.

Cloudflare's security mechanisms and load-balancing cookies are strictly necessary to deliver the Website and are not used for analytics, advertising, or cross-site tracking. Cloudflare does not set advertising or marketing cookies. Infrastructure log data is retained by Cloudflare for approximately 30 days on a rolling basis, after which it is deleted or anonymized.


6. Cookies and Local Storage

This Website does not set any analytics, tracking, or marketing cookies. The only cookies that may be present are strictly necessary technical cookies set by Cloudflare for security and traffic routing, as described in Section 5. These cookies cannot be used to identify you personally and are exempt from cookie consent requirements under the EU ePrivacy Directive and equivalent laws.

Because this Website uses PostHog in full cookieless mode and does not deploy any other analytics, advertising, or non-essential cookies, no cookie consent banner is required or displayed.


7. No Sale or Sharing of Personal Data

We do not sell or share personal information with third parties for advertising or marketing purposes, as those terms are defined under the CCPA/CPRA and equivalent state laws. PostHog and Cloudflare act solely as our processors / service providers, operating under data processing agreements that prohibit them from using data they collect on our behalf for their own independent advertising or marketing purposes.

Global Privacy Control (GPC) and Do Not Track (DNT). Because this Website sets no non-essential cookies and stores nothing on your device through PostHog's cookieless mode, your GPC or DNT browser signal has no device-side data to act on. At the infrastructure level, Cloudflare's strictly necessary cookies are exempt from opt-out requirements. If we ever change our analytics approach to one that places cookies or uses persistent identifiers, we will update this Policy and implement the appropriate GPC/DNT honor mechanisms before doing so.


8. Third-Party Sub-Processors

ProviderRoleData ProcessedLocation
CloudflareCDN, deployment, securityIP address, request headers, technical metadataGlobal CDN; US HQ
PostHog Inc. (Cloud EU)Cookieless product analytics, via managed reverse proxyAnonymized daily-hash visitor count, page view events, interaction events, browser/device metadataFrankfurt, Germany (EU) for storage and processing; event traffic is routed via Cloudflare edge infrastructure globally before reaching PostHog EU servers, in accordance with PostHog's DPA

Both providers operate under data processing agreements with us and are contractually restricted from using your data for their own independent commercial purposes.


9. Your Data Rights

US residents (CCPA/CPRA and state equivalents). You have the right to know what personal information we have collected, to request deletion, to request correction, to opt out of sale (we do not sell your data), and to non-discrimination for exercising these rights. To submit a request, contact privacy@curtainsdating.com. We will respond within 45 calendar days (extendable by a further 45 days where permitted by law).

EU/EEA and UK residents (GDPR / UK GDPR). To the extent GDPR applies to your data, you have the following rights:

  • Right of access (Article 15): obtain confirmation of whether we process data about you and a copy of it;
  • Right to rectification (Article 16): request correction of inaccurate data;
  • Right to erasure (Article 17): request deletion of your data ("right to be forgotten");
  • Right to restriction of processing (Article 18): request that we limit how we process your data;
  • Right to data portability (Article 20): receive your data in a machine-readable format;
  • Right to object (Article 21): object to processing based on legitimate interests;
  • Rights related to automated decision-making (Article 22): we do not use automated individual decision-making or profiling on this Website;
  • Right to withdraw consent: where we rely on consent (we currently do not for this Website), you may withdraw it at any time.

Lawful basis for processing (GDPR). Our analytics processing (Section 4) is carried out on the basis of legitimate interests (Article 6(1)(f) GDPR): specifically, our legitimate interest in understanding Website traffic patterns and improving the Website ahead of App launch, balanced against the minimal privacy impact of cookieless, IP-anonymized analytics that store nothing on your device. Our infrastructure processing (Section 5) is carried out on the basis of legitimate interests in maintaining secure, stable service delivery.

GDPR response window. For EU/UK data subject requests, we will respond within 30 calendar days (extendable by a further 2 months for complex requests, with notification to you within the first 30 days).

Right to complain. If you are located in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en. UK residents may complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Practical note on identification. Because our cookieless analytics do not store any persistent identifier on your device, and IP addresses are anonymized before storage, we may not be able to identify which analytics records correspond to you. In such cases, and consistent with GDPR Article 11, we are not required to collect additional personal information solely to verify your identity for the purposes of fulfilling a data rights request — but we will make reasonable efforts to locate relevant records using the information you provide. If you submit a deletion or access request, it would be most helpful to include the approximate date and time of your visit and your general location to assist us in locating any records.


10. Data Security

We rely on Cloudflare (SOC 2, ISO 27001 certified) and PostHog (SOC 2 certified) as infrastructure providers. Their certifications cover their internal platforms and the services they provide to customers. No method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach affecting data we control, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, where required by GDPR Article 33. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay, as required by GDPR Article 34.


11. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, our Website, or applicable law. When we make a material change — including any change to our analytics approach, cookie usage, or data retention — we will update the "Effective Date" at the top of this Policy and post a notice on the Website. Your continued use of the Website after a revised Policy takes effect constitutes your acceptance of the revised Policy.


12. Contact Us

Billion Flower Moon Studios LLC Email: privacy@curtainsdating.com

2106 House Ave, Cheyenne, WY 82001, USA