What we collect
The information depends on how you use girlsbook.
- Visitors: limited request, security and privacy-preserving analytics information needed to serve and protect the site. If you choose Near me, your browser uses your coordinates only to select the closest supported city; the site receives that city search, not your coordinates.
- Customer members: administrator-managed onboarding information, email address, display name, password hash, account status, favourites, review submissions, changes and moderation history.
- Enquirers: the name, contact details, reply preference and message you choose to send.
- Contact and complaint submissions: the topic, optional name and phone number, email address, private message, adult confirmation, consent, review state and operational timestamps.
- Providers: administrator-managed onboarding, account, contact, profile, image, availability, enquiry and review-reply information.
- Touring submissions: the linked provider and profile, approximate city and region, future start and end times, an optional encrypted private review note, moderation decisions and audit history.
- Community notices: a private source alias and message, approximate city, adult-entry confirmation, publication consent, moderation decisions, a separately written public alias and message, and expiry dates. We do not collect a phone number or email for a notice.
- Organizations and rooms: names, descriptions, approximate locations, images, amenities, indicative rates, web or booking links, profile associations, and encrypted phone or email details where an administrator has recorded authorization for public display.
- Managed migrations: source references, review status, publication permission, approved profile attributes and an encrypted contact number where supplied. Sensitive source-only attributes are not automatically published.
- Provider advertising: Advertising Credit balance and ledger, funding requests and references, plan subscriptions, add-on campaigns and profile performance totals.
- Reports: the concern, supporting detail and optional follow-up address you provide.
How information is used
We use information to operate and secure the directory, authenticate accounts, review profiles and content, maintain favourites, pass an enquiry to the selected provider, moderate reviews and replies, administer provider advertising, investigate reports, prevent abuse, communicate account matters and meet legal obligations. We do not sell personal information.
Favourites and age confirmation
Your selected interface language is remembered on this device.
When a customer is signed in, favourites are stored with that member account so they can be accessed across signed-in devices. Guest favourites remain in that browser and can be removed by clearing site data. The R18 entry flow uses a signed age-confirmation cookie; a browser-only flag cannot grant access to directory records.
Privacy-preserving analytics
Profile views, unique visitor estimates, contact clicks, enquiries and favourites are counted to give providers and administrators useful performance reporting. Raw IP addresses and raw User-Agent values are not written to the analytics event table. Instead, it stores a secret-keyed pseudonymous visitor token with per-day event counts so 7-day, 30-day and all-time estimates can be calculated. Providers see aggregated totals, not the token or raw request data. Known provider, administrator and automated traffic is excluded where practicable.
Sharing and visibility
Approved profile fields, sponsored-placement disclosures, approved reviews and approved provider replies are public. Approved tours may show the linked profile, approximate place, dates and a separately written public note; the encrypted source note is not copied into the public listing. Approved community notices show only the moderator-written public alias and message, approximate city and dates; private source material is never published.
For an eligible administrator-managed profile, an encrypted contact number is decrypted for the individual profile page only when its public display was explicitly authorised; it is not placed in directory cards, sitemaps, page descriptions or logs. Organization and room contact details are shown only on the individual listing where an administrator has recorded public-display authorization. When direct call and text options are shown, the site does not also accept an enquiry that the managed account cannot receive. Private onboarding, customer and commercial account details are limited to authorised operations. Other enquiries are shared with the provider selected by the enquirer. Funding-request details are available only to the approved provider and authorised accounts staff. Information may also be disclosed to service suppliers under safeguards, to address safety or fraud, or where law requires it.
Retention
- Private enquiry contact details and message content are automatically erased from the live service at the 30-day expiry. The expired status and operational timestamps may remain for accountability.
- Pending provider applications are kept in the live service for no more than 30 days. The application source, including personal details and its password hash, is erased at expiry or immediately after an approval or rejection; only non-personal decision, linkage and timing records remain.
- Profile-report evidence and optional follow-up email are encrypted at rest and erased from the live service when the report is archived or reaches its 90-day expiry. Non-content status and timestamps may remain for accountability.
- Contact and complaint names, contact details and private messages are encrypted at rest and erased from the live service when the record is archived or reaches its 90-day expiry. Non-content operational status and timestamps may remain where needed for accountability.
- Community notices expire 30 days after submission. The encrypted private source is erased during scheduled cleanup after expiry; the public copy and moderation note are erased 30 days later.
- A tour's encrypted private note is erased when the tour ends. Notes attached to rejected, cancelled or archived tours are removed under the 30-day cleanup schedule; public and reviewer notes are also cleared after the terminal retention period.
- Encrypted organization and room phone or email details, together with their public-display authorization flag, are erased 30 days after archiving.
- Protected operational backups may retain an earlier encrypted snapshot until their scheduled 30-day manual retention review. They are not served by the live site; a restored copy must run the current fail-closed retention cleanup before any content access.
- Account, favourites and review records are kept while the account is active and then archived or removed in line with account closure, moderation, safety and legal needs.
- Advertising Credit ledgers, funding-request decisions and campaign records may be kept for accounting, fraud prevention, dispute and legal requirements.
- Analytics event records may be retained to provide all-time reporting; they contain a keyed pseudonymous token and daily counts rather than raw IP addresses or raw User-Agent values. Providers see only aggregate results.
- Audit and security records are retained according to operational, protection and legal needs.
Security and your choices
Reasonable access controls, password hashing, session protection, encryption for sensitive settings and operational safeguards are used, but no online service can promise absolute security. Changing a member password requires the current password and invalidates every existing member session, including the current session. Entered passwords are not written to audit records.
You may ask for access to or correction of personal information held about you, and may request account closure, subject to applicable New Zealand privacy law and records that must be retained. Providers can submit profile corrections through their dashboard. Use the private contact form, an authenticated dashboard, or the relevant profile-report channel, and do not include unnecessary sensitive information.
Last updated: 26 September 2026.