Privacy Policy

Version 3.1  ·  Effective 29 August 2026  ·  Operated by Conesworth Limited (New Zealand)

This Privacy Policy explains what information JoyR1der collects, how we use and share it, how long we keep it, and — importantly — the technical measures we take to verify age and keep minors off the Service (JoyR1der's 18+ account requirement). Please read it alongside our Terms & Conditions.

Who we are. JoyR1der is owned and operated by Conesworth Limited, a company incorporated in New Zealand (company number 1862936), registered office 16 Rautawhiri Road, Helensville 0800, New Zealand, trading as “JoyR1der” (“JoyR1der”, “we”, “us”, “our”). We are the “agency” responsible for your personal information under the New Zealand Privacy Act 2020, and the data controller for users in the EU/UK.

Contents

1. Information we collect
2. How we use your information
3. Our lawful bases
4. How we share information
5. We do not sell your data
6. Where your data is held
7. Age assurance — the 18+ account requirement
8. Safety & our moderation model
9. How we protect your information
10. How long we keep information
11. Your rights & choices
12. Cookies & local storage
13. Changes to this policy
14. How to contact us

1. Information we collect

We collect only what we need to run the Service, keep it safe, and meet our legal obligations. The main categories are:

CategoryExamplesSource
Account & profileDisplay name, username, avatar and gallery images, date of birth (stored encrypted), derived age band, gender (optional), your chosen privacy and notification preferences, and your acceptance of these terms.You, at sign-up and in Profile settings
Contact detailsEmail address and (if provided) phone number. These are held in a restricted, access-controlled store separate from your public profile.You
Content you createLive video/audio streams, event recordings, chat and direct messages, posts, comments, images you upload, tips and reactions.You, as you use the Service
Financial & transactionYour Click balances and a double-entry ledger of purchases, earnings, payouts, refunds and gifts. We do not collect or store your card number. Card entry and identity checks are handled by Stripe; host bank and payout details are handled directly by our licensed payout provider.You (via Stripe and our payout provider); the Service’s ledger
Age & identity verificationA “liveness” selfie used for automated age-estimation (the selfie is deleted immediately after processing — we keep only the result), and/or a government-ID identity check handled by Stripe. We retain the verification result (e.g. verified / estimated age band), not the underlying image or document.You, and our verification providers
Device & technicalA push-notification token, IP address, device/browser type, and anti-abuse signals (e.g. from Google App Check / reCAPTCHA). We do not embed third-party advertising or analytics trackers.Your device
Approximate locationOnly if you turn location sharing on. It is deliberately imprecise (fuzzed on your device).Your device (opt-in)
Safety & moderationReports you make or that are made about you, moderation decisions, appeals, and evidence attached to a report.You and other users; our moderators

We do not knowingly collect more sensitive categories of data except where you provide it for age/identity verification. This may include a facial image (biometric data) used to estimate your age; that image is deleted immediately after processing and is never used for advertising, profiling or identification (see section 7). The face scan is optional — you can always choose a government-ID check instead, anywhere.

2. How we use your information

Advertisements are targeted using content categories, interests and coarse location you provide — never using your identity documents, biometric data or messages.

3. Our lawful bases

Under the New Zealand Privacy Act 2020 we collect, use and disclose personal information in accordance with the Information Privacy Principles. If you are in the EU/UK, we rely on: performance of our contract with you (to provide the Service); your consent (e.g. optional location sharing, marketing); our legitimate interests (safety, fraud prevention, running our business); and legal obligation (financial records, child-safety reporting). Where we rely on consent you may withdraw it at any time.

4. How we share information

We share personal information only with the service providers (“sub-processors”) that help us run JoyR1der, and only as needed. Our current sub-processors are:

ProviderPurposeWhat is shared
StripePayments (web card purchases) and age/identity verification (Stripe Identity)Your user ID, purchase amounts, and — direct to Stripe — your card and identity details (we never receive your card number)
TrolleyHost/creator payouts and payout tax forms (W-8/W-9)Your name, email and country, and — direct to Trolley — your bank and tax details (we never receive your bank details)
Google / Firebase (Google Cloud)Sign-in, database, file storage, push notifications, bot/abuse protection, and hostingAccount data, content, device push token, and abuse-protection signals
LiveKitReal-time video/audio streaming transportYour user ID and the live media of streams you take part in
SendGrid (Twilio)Sending transactional and notification emailYour email address and the message content
AppleiOS call notifications (APNs) and validating in-app purchasesA device push token and purchase receipts (purchase receipts are validated offline; no data is sent to Apple)
Automated age-estimation provider (e.g. AWS Rekognition)Estimating age from a liveness selfieThe selfie image, sent for analysis and deleted immediately after processing — not retained by the provider or by us (only the age result is kept)
OpenStreetMap / NominatimDisplaying maps and looking up place names, from your deviceMap view area and any place name you type

We may also disclose information: (a) to law enforcement, regulators or child-safety bodies (including New Zealand’s Department of Internal Affairs and, where a report has a US nexus, the US National Center for Missing & Exploited Children) where we are required to or where it is necessary to protect a child or prevent serious harm; (b) to professional advisors; and (c) as part of a business sale or reorganisation, subject to this policy. We require our sub-processors to protect your information and use it only for the purposes above.

5. We do not sell your data

We do not sell your personal information, and we do not share it with data brokers or third-party advertising networks for their own use. JoyR1der contains no third-party analytics, telemetry or ad-tracking SDKs. We earn money from Click purchases, platform fees and advertisers who buy space on our own system — not from selling your data.

6. Where your data is held

JoyR1der runs on Google Cloud infrastructure located in the United States, and several of our providers (Stripe, LiveKit, SendGrid, Apple) are US-based. By using the Service you understand that your information is transferred to and processed in the United States and other countries, which may have different data-protection laws than your own. We take reasonable steps, and use providers with recognised safeguards, to protect information that is transferred internationally.

7. Age assurance — the 18+ account requirement

Our promise. You must be 18 or older to hold a JoyR1der account. We do not knowingly allow anyone under 18 on the Service, there are no child or guardian-managed accounts, and we verify age with technical checks that are enforced in our server code and “fail closed” — if we cannot confirm you are an adult, interactive features stay locked.

Minimum age

You must be at least 18 years old to create an account or use the Service. Our sign-up screens will not accept a date of birth under 18, and there is no mechanism for anyone under 18 to hold or be given an account.

How we verify age

Age is not taken on trust. Verification is layered:

How we handle your face data — Biometric Data Policy

This is our published policy for the biometric identifier a liveness selfie collects — a scan of your facial geometry. It is sensitive data and we handle it strictly:

Reports that someone is under 18

Any user can report another user who appears to be under 18. We review the report and may require the reported user to complete a government-ID check (which is free to them). A user who is confirmed to be under 18, or who refuses or fails the required check within the time we specify, is removed from the Service. Verification checks you start for yourself carry a fee, described in our Terms; a fee owed for an ID check can be paid either by buying Clicks or as a one-time card payment through Stripe, and Stripe (not JoyR1der) handles the card details.

Minors depicted in content

Even though every account holder is an adult, a real child could appear on camera (for example, a bystander). Child sexual abuse material and any sexualisation of a minor are strictly prohibited and are removed. We also run automated age-estimation across event recordings to help detect a suspected minor appearing in content. Where we become aware of child sexual abuse material we preserve the relevant evidence and escalate to the appropriate authorities, including New Zealand’s Department of Internal Affairs and, for reports with a US nexus, the US National Center for Missing & Exploited Children (NCMEC).

8. Safety & our moderation model

Keeping the community safe is central to how the Service works:

9. How we protect your information

No system is perfectly secure, but we work continuously to protect your information and to fix issues we find.

10. How long we keep information

InformationRetention
Event recordingsAutomatically deleted 24 hours after the stream, unless a host has a paid storage plan, or the recording is preserved under a legal hold for a serious safety case.
Live event chatDeleted when the event ends — unless it is subject to an open safety report, in which case it is kept until that report is resolved.
Chat / direct-message imagesAutomatically deleted approximately 24 hours after they are sent; you can also delete them immediately.
Age-verification selfie (biometric)Deleted immediately after processing. We keep only the verification result (estimated age band / pass-refer outcome), never the image.
Government-ID checkHandled by Stripe under Stripe’s own retention; JoyR1der keeps only the outcome (verified / not verified).
Bonus ClicksExpire 30 days after they are granted.
Account & profile dataKept while your account is open; removed or de-identified when you delete your account, except where we must retain it (below).
Transaction, tax & moderation recordsRetained as long as we are legally required to, and to resolve disputes and prevent fraud, even after account closure.

11. Your rights & choices

You can, at any time:

If you are in the EU/UK you also have rights to portability, restriction and objection, and to lodge a complaint with your data-protection authority. If you are in California you have rights under the CCPA/CPRA, including to know and to delete — and note that we do not sell or “share” your data as those terms are defined. If you are in New Zealand and are not satisfied with our response, you can contact the Office of the Privacy Commissioner (privacy.org.nz).

12. Cookies & local storage

Our web app uses only the local storage and cookies needed to keep you signed in, remember your preferences, and run our bot-abuse protection (App Check / reCAPTCHA). We do not use advertising or cross-site tracking cookies.

13. Changes to this policy

We may update this policy from time to time. If we make a material change we will update the “Effective” date above and, where appropriate, notify you in the app or by email. Continuing to use the Service after a change means you accept the updated policy.

14. How to contact us

Conesworth Limited (trading as JoyR1der)
Privacy Officer: Tim Schliebs
16 Rautawhiri Road, Helensville 0800, New Zealand
NZ company number 1862936
Email: legal@joyr1der.com