Last updated: 6 September 2026
1. Introduction
This privacy policy describes how we process your personal data in connection with your use of our dating platform, Celsius ("Platform"), available through our website ("Website") and mobile application ("App"). The Celsius dating platform is operated by Hexagons BV, a company registered under Belgian law with company/VAT number BE1009.785.044 ("Hexagons," "Celsius," "we," "us").
Protecting your privacy is of the utmost importance to us. This privacy policy explains how, why, and on what legal grounds we process your personal data. It also ensures that you retain control over your data while being informed about any data sharing practices.
Your data is processed in accordance with Belgian and European data protection regulations, including the General Data Protection Regulation 2016/679 ("GDPR"), as well as applicable national laws.
We encourage you to read this privacy policy carefully. It outlines your rights regarding your personal data, provides details about our data processing practices, and explains how you can exercise your rights.
Important notes:
- This privacy policy does not apply to the practices or conditions of third-party services.
- Our app is not intended for individuals under 18 years of age. We do not knowingly collect data from minors. If we discover that a user is under the age of 18, we will take appropriate steps to deactivate their account immediately.
- By using our Celsius Dating Platform, you agree to the terms of this privacy policy.
2. Data Controller Responsibilities
As a data controller, we determine the purposes and means of processing your personal data.
Important notes:
Hexagons BV is not responsible for how your personal data is handled once processed outside the App.
3. Data Collection and Purposes
| Purpose | Collected data | Legal basis |
|---|---|---|
| App functionality, including but not limited to: registration and user management; your use of the App; the provision of the App, the global Celsius platform and any related Celsius services. |
| Execution of a contract or actions related to a contract with the user. |
| Website analytics and marketing measurement, including but not limited to: measuring website traffic; understanding how visitors interact with our Website; improving website performance and user experience; and measuring the effectiveness of our campaigns. |
| Consent, where required by applicable law. |
| App performance analytics and crash analysis, including but not limited to: aggregated and pseudonymised app usage data; and the analysis of crash reports in order to diagnose and fix errors. |
| Legitimate interests to improve the performance and stability of the app. |
| Marketing attribution and advertising measurement in the App, including but not limited to: determining which advertising campaign or channel led to an app install; measuring the effectiveness of our advertising campaigns; deduplicating installs and conversions across advertising networks; and detecting attribution fraud. |
| Your consent (Article 6(1)(a) GDPR, and Article 5(3) of the ePrivacy Directive for the storing of and access to identifiers on your device). You can give or withdraw this consent at any time through the privacy settings in the App. |
| Fraud prevention, security and compliance. |
| Legal obligation and legitimate interests for fraud prevention, security and compliance. |
4. Third-party Processors and Data Sharing
Cloud Data Storage
All user data collected through the platform is securely stored on servers of Google Cloud Platform (GCP) and Supabase in the European Economic Area (EEA). Both providers ensure compliance with EU data protection standards and provide robust security and privacy measures for your personal data.
Supabase hosts part of our core platform database infrastructure. The personal data stored there is of the same nature as the data held in our Google Cloud databases and is described in section 3 of this privacy policy: account, profile and platform usage data. Supabase acts solely as a processor on our instructions and does not use your personal data for its own purposes.
For more information on how these providers process and protect your data, please refer to the Google Cloud Privacy Policy and the Supabase Privacy Policy.
Additional Third-Party Processing
We collaborate with carefully selected third-party service providers ("processors") who help us deliver our platform and services. We only share what is necessary for the processors to perform their specific services. We only work with processors who provide sufficient guarantees that they will protect your data in accordance with the GDPR and other applicable data protection laws.
List of third-party processors with whom your personal data may also be shared by Hexagons BV:
| Data Processor | Purpose & Activity | Shared Data | Location |
|---|---|---|---|
| Analytics & Monitoring |
| EEA | |
| Meta | Website analytics, advertising measurement and app attribution via Meta Pixel and the Meta SDK |
| USA |
| TikTok (TikTok Information Technologies UK Limited and TikTok Technology Limited) | Website analytics, advertising measurement and app attribution via the TikTok Pixel and the TikTok SDK |
| EEA and third countries (incl. USA) |
| Singular (Singular Labs, Inc.) | Mobile measurement partner (MMP): attribution of app installs and in-app events, advertising campaign measurement and attribution fraud detection |
| USA |
| HubSpot | CRM Platform |
| EEA |
| Postmark (AC PM LLC, part of ActiveCampaign) | Email delivery service (SMTP) used to send platform emails and bulk email |
| USA |
Website Analytics and Marketing Technologies
On our Website, we may use cookies, pixels and similar technologies, including Google Analytics, the Meta Pixel and the TikTok Pixel, to understand how visitors use the Website, measure the performance of our marketing campaigns and improve the user experience. These technologies may process data such as your IP address, browser and device information, pages visited, referring URLs, cookie identifiers and interactions with Website content.
Where required by applicable law, these technologies are only activated after you have provided your consent through our cookie banner or cookie settings.
Mobile App Analytics and Attribution
Within our App, we use analytics and measurement tools, including Google services (Firebase Analytics and Crashlytics), the Meta SDK, the TikTok SDK and the Singular SDK, to understand how the App is used, measure campaign effectiveness, attribute installs or other app events, and improve app performance and stability. These tools may process data such as device and advertising identifiers, operating system information, IP address and the approximate location derived from it, install referrer and campaign data, app events and other interaction data.
The tools we use for advertising measurement and attribution - the Meta SDK, the TikTok SDK and the Singular SDK - are only started after you have given your consent through the consent form the App shows you, and no advertising identifier is read from your device before that. On iOS we additionally ask for your permission through Apple's App Tracking Transparency framework; if you decline there, your IDFA is not read and attribution falls back to Apple's privacy-preserving SKAdNetwork. You can change or withdraw your choice at any time through the privacy settings in the App, which stops any further collection by these tools.
Mobile Measurement and Attribution (Singular)
We use Singular, a service of Singular Labs, Inc. (181 South Park Street, Unit 2, San Francisco, CA 94107, United States), as our mobile measurement partner ("MMP"). Singular is the single service that tells us which advertising campaign led to an App install or to a later action in the App. This allows us to see how our advertising budget performs, to avoid counting the same install twice across different advertising networks, and to detect attribution fraud.
What Singular receives. The Singular SDK in our App processes your IP address and the approximate location derived from it, your advertising identifier (Apple's IDFA on iOS, the Google Advertising ID on Android), other device identifiers such as the Singular Device ID that Singular generates for your device, the Apple IDFV, the Android ID and the App Set ID, information about your device and operating system, install referrer and campaign information from the app stores and the advertising networks, Apple SKAdNetwork postbacks, and a limited set of app events: registration, login, profile created, profile completed, profile verified, phone number exchanged, and subscription purchases with their amount and currency.
What Singular does not receive. We do not send Singular your name, email address, date of birth, photos, school or field of study, chat messages, matches, swipes, or your dating preferences or sexual orientation. We also do not link your Celsius account identifier to the data Singular holds about your device. Singular's published data processing terms also prohibit us from providing special categories of personal data within the meaning of Article 9 GDPR.
Legal basis. We rely on your consent (Article 6(1)(a) GDPR, and Article 5(3) of the ePrivacy Directive for the storing of and access to identifiers on your device). The Singular SDK is not started at all before you have given that consent through the consent form the App shows you. If you withdraw your consent through the privacy settings in the App, we instruct Singular to stop all collection and to stop sharing your data with advertising partners.
Role and safeguards. Singular acts solely as a processor on our instructions and does not use your personal data for its own purposes. Singular's published data processing terms, which apply to our use of the service and are referred to in its privacy policy, incorporate the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914, Module Two, controller to processor) as the mechanism for the transfer of personal data to the United States. Singular is additionally self-certified under the EU-U.S. Data Privacy Framework, and names Amazon Web Services and Snowflake as its sub-processors, both located in the United States and both covered by Standard Contractual Clauses.
Retention and your rights. Singular retains attribution records at the level of an individual device only for a limited period after collection, after which only aggregated reporting data remains that can no longer be linked to your device. If you ask us to delete your personal data, we also pass that request on to Singular so that the records it holds about your device are erased.
For more information, please refer to the Singular Privacy Policy.
Email Delivery
We use Postmark, a service of AC PM LLC (part of ActiveCampaign), as our SMTP provider to send platform emails and bulk email such as newsletters and other announcements. To deliver these messages, Postmark temporarily processes and stores the recipient's email address and the content of the email, together with delivery metadata such as timestamps and delivery status.
Postmark retains this content and metadata for a maximum of 45 days, so that we can consult the message history to resolve delivery problems and prevent abuse, after which it is removed from their systems. Postmark's servers are located in the United States. This transfer outside the EEA takes place on the basis of the Standard Contractual Clauses approved by the European Commission, as included in our data processing agreement with Postmark.
For more information, please refer to the Postmark GDPR information and the ActiveCampaign Privacy Policy, which covers Postmark.
Data Sharing
Hexagons BV only shares personal data that is relevant and necessary for your use of the platform and to operate our services. When we transfer your personal data to third parties or processors, we ensure that appropriate safeguards and security measures are in place to protect your information.
In addition, we may disclose your personal data if required by law or when we in good faith determine that such disclosure is necessary to:
- Comply with a request from a supervisory authority, a legal investigation, court order, or legal proceedings related to the Celsius Platform.
- Address claims against Hexagons BV regarding personal data that may infringe the rights of third parties.
- Protect the rights, property, or safety of Hexagons BV, our employees, contractors, users, or the general public.
Access to Your Data
Your personal data will only be accessed by processors, employees, or contractors of Hexagons BV, and by third parties on a strict "need-to-know" basis. Access is limited to the extent necessary to perform their specific tasks or services.
No Unauthorized Sale or Sharing
Hexagons BV will never sell or lend your personal data to third parties without your explicit consent. In the event of a significant change in the business structure—such as a merger, acquisition, reorganization, asset sale, or bankruptcy—Hexagons BV may transfer your personal data as part of the transaction. In such cases, we will make reasonable efforts to ensure the recipient adheres to this privacy statement.
5. Data Location and Transfer
Your personal data is stored on servers within the European Economic Area (EEA). A limited number of our processors, listed in the table in section 4, process personal data outside the EEA: currently Meta (advertising measurement and app attribution), Singular (mobile measurement and attribution for the App) and Postmark (email delivery), all three in the United States, and TikTok (advertising measurement and app attribution), which stores personal data of European users within the EEA but may allow access from and transfers to third countries outside the EEA.
Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place to comply with applicable data protection laws. These safeguards may include, but are not limited to:
- Use of Standard Contractual Clauses approved by the European Commission.
- Implementation of additional measures to adequately protect your data.
You will be informed of any new transfers and the applicable safeguards in accordance with legal requirements.
6. Data Protection
At Celsius, we take appropriate technical and organizational measures to ensure a level of security appropriate to the risks associated with processing your personal data. These measures include, but are not limited to:
- Technical controls and protections such as encryption, authentication, and authorization to secure your data.
- Data recovery and backup systems to minimize the impact of potential incidents.
- Incident response plans to efficiently address data breaches.
- Regular testing and evaluation of our security measures to ensure effectiveness.
Important note:
While we strive to protect your personal data, it is important to understand that data transmission over the internet inherently carries risks. Despite taking all precautions to secure your information, we cannot guarantee absolute security.
7. Data Retention
We will only process, store, or retain your personal data as long as necessary to fulfill the purposes described in section 3 of this privacy policy, including compliance with legal, regulatory, tax, accounting, or reporting obligations.
We may retain your personal data for a longer period if legally required, or in case of a complaint, or if we reasonably believe there is a dispute or potential legal action regarding our relationship with you or your company or organization. After that, data may remain in our backups or archives but will no longer be actively processed.
Retention periods may vary depending on the purposes of processing and our legal obligations.
The Celsius Dating Platform applies the following retention periods:
- All data will be deleted 24 hours after account closure. Student accounts must complete an annual email verification to confirm that the user is still a student. If this verification fails or is ignored, the account will be automatically closed.
- Marketing attribution records held by our mobile measurement partner at the level of an individual device are retained only for a limited period after collection, as described in section 4. The aggregated reporting data derived from them can no longer be linked to your device.
All technical data that is (pseudo-)anonymized or aggregated will be deleted 12 months after collection.
8. Your Rights and How to Exercise Them
Your Rights
Under Articles 15–22 of the GDPR, you have the following rights regarding the processing of your personal data via the Celsius Dating Platform:
- Right of Access : You have the right to request confirmation of whether we process your personal data. If so, you may access the data, understand how and why it is processed, and request a copy.
- Right to Rectification : You may request correction of inaccurate personal data or completion of incomplete data we process about you. As a user, you may exercise this right by submitting a data change request in the app for fields not editable via self-service, such as first or last name. This can be done via email.
- Right to Erasure ("Right to be Forgotten") : You may request the deletion of your personal data under certain conditions. As a user, you can exercise this right by submitting a profile deletion request via the app.
- Right to Restrict Processing : You may request restriction of processing in specific cases, such as when data accuracy is contested or processing is unlawful.
- Right to Data Portability : You may receive the personal data you provided to us in a structured, commonly used format (e.g., JSON).
- Right to Object : You may object to the processing of your personal data when it is based on our legitimate interest. You may also object at any time, free of charge, to the processing of your data for direct marketing purposes.
Exercising Your Rights
The Celsius Dating Platform offers self-service access to view, update, or delete data linked to your account—either directly or through a request submission.
To exercise any rights not supported by self-service, you can contact us via: privacy@celsiusdating.com
Exercising these rights is generally free of charge. However, we may charge an administrative fee for repeated or excessive requests.
To verify your identity, we may request proof such as a copy of your ID. Please ensure non-essential information (e.g., photo, ID number) is hidden before submission.
Complaints
If you believe your rights have been violated, you have the right to lodge a complaint with the appropriate data protection authority.
In Belgium, you can contact:
Data Protection Authority
Email: contact@apd-gba.be
Address: Drukpersstraat 35, 1000 Brussels
We recommend contacting us first at privacy@celsiusdating.com so we can address your concerns directly before involving the authority.
9. Governing Law and Jurisdiction
This privacy policy is governed by and interpreted in accordance with Belgian law. Any disputes arising from this privacy policy fall under the exclusive jurisdiction of the courts of Ghent.
We encourage you to contact us first via privacy@celsiusdating.com so we can address your concerns directly before pursuing legal action.
10. Changes to This Privacy Policy
Hexagons BV reserves the right to update this privacy policy at any time. The date of the last revision is indicated at the top of this document.
Notice of Changes: We will notify you explicitly of significant updates through the platform and, if necessary, request your consent for major changes.
Effective Date: Updates take effect 7 days after publication unless required to comply with legal obligations, in which case they take effect immediately.