KinkID.link

Privacy policy

This policy applies to kinkid.link and also to aresgearrubbergimp.de, mercurypup.de and puplaron.de.

In short: no tracking, no advertising, no user accounts with name or e-mail and only a single cookie – for the age check. Data is only processed when you open a page (technically necessary), write to me, create a card album or have a card of your own. The details are below.

1. Controller

Daniel Simon Rusch
Marktstraße 230
47798 Krefeld

E-mail: kontakt@kinkid.link · I am not required to appoint a data protection officer; please contact me directly with any questions.

2. Visiting the website and hosting

The website and all profile pages are delivered via Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). When a page is opened, Cloudflare processes technically necessary access data – in particular IP address, time, requested address, referrer and browser identifier – in order to deliver the pages and protect them against attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning service). A data processing agreement (Art. 28 GDPR) including the EU standard contractual clauses is in place with Cloudflare; Cloudflare is also certified under the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR). I do not store any access logs myself and do not analyse access data; server error messages do not contain IP addresses.

3. Cookies and storage in the browser

This website sets exactly one cookie: for the age check (see below). Apart from that, it stores nothing in your browser (no local storage, no pixels, no fingerprinting; for exceptions see below). There is no tracking, no analytics, no advertising and no embedded content from third parties: fonts, images and scripts all come from this website itself. That is why there is no cookie banner. The card album does not store anything in the browser either. Only if you create an album yourself does your device, on your instruction, save a passkey in your keychain or password manager. This is strictly necessary for the function you requested; I therefore base it on § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) (see Card album).

The only exceptions are the following entries in your browser's storage. Each one only serves the function you are using yourself; I consider them strictly necessary for it and base them on § 25(2) no. 2 TDDDG. Your browser deletes entries in session storage (sessionStorage) at the latest when you close the tab or window.

Age check (18+): The card deck and the card album show content from the fetish community and are intended for adults only. They are only displayed after you click “I am 18 or older”. For this, your browser stores the cookie kinkid_18 with the value 1 – nothing else: no date of birth, no identifier by which you could be recognised. It is only sent to the website on which you confirmed, and is only checked there for its presence; nothing is analysed or stored. The individual profile pages and cards – including those on their own domains – have no age check of their own and do not set this cookie.

How long: It is a session cookie without an expiry date and is deleted when you close your browser. Some browsers, especially on phones, restore sessions and then keep it longer. You can delete it at any time in your browser settings; the page will then ask again the next time you visit.

Legal basis: I consider the cookie strictly necessary for the page you requested and base storing it on § 25(2) no. 2 TDDDG; I base the processing on my legitimate interest in making this content accessible to adults only (Art. 6(1)(f) GDPR).

Only if Cloudflare detects an attack or an unusually high number of requests may Cloudflare briefly set a technically necessary security cookie for defence (e.g. “__cf_bm”, lifetime 30 minutes). I base this on § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. On Stripe's payment pages (separate address checkout.stripe.com), Stripe's cookie rules apply.

4. Contact form, e-mail and reports

If you write to me via the contact form or by e-mail, I process the information you provide (e-mail address, optionally name, your message) in order to answer your enquiry. The message is forwarded via Cloudflare (Email Routing) to my mailbox at Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); Google may also process data in the USA and is certified under the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry is aimed at a contract, otherwise Art. 6(1)(f) GDPR (answering enquiries). I delete the messages once the enquiry has been dealt with, at the latest after two years, unless retention obligations prevent this.

Photo or blueprint for your card: You can send a photo with the contact form; the “Design a card” page also sends a blueprint with your settings and texts. Depending on their content, the photo and blueprint may reveal a connection to the kink or pup scene and thus to your sex life or sexual orientation (special categories under Art. 9 GDPR). I therefore only process them with your explicit consent, which you give by ticking a box in the form (Art. 9(2)(a) and Art. 6(1)(a) GDPR); without the tick, the form with a photo or blueprint is not sent. The photo is reduced in size in your browser beforehand, sent to me as an attachment to the e-mail and not stored anywhere on the way. If no contract is concluded, I delete the photo and blueprint after the enquiry has been completed, at the latest after six months. Please only send me such information this way or together with your order – not in a general message without the tick.

Other people in your photo: Only send me photos in which all persons are adults and agree that the photo is used for your card and shown there – including in a kink context; you confirm this in the form. More on this under “Other people in photos”.

I process reports submitted via Report content in the same way in order to examine and answer them under the Digital Services Act (Art. 6(1)(c) GDPR in conjunction with Art. 16 DSA). Name and e-mail address are optional there; whoever posted the reported content does not learn them. I keep reports for up to three years as evidence.

The forms contain invisible spam protection (an empty field and the time at which the page was loaded). No further data is collected in the process.

5. Contact via Telegram

You can also write to me on Telegram (https://t.me/kinkid_link). I then process your Telegram name or username and your message in order to answer it. The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry is aimed at a contract, otherwise Art. 6(1)(f) GDPR (answering enquiries). I delete the chat once the enquiry has been dealt with, at the latest after two years, unless retention obligations prevent this.

Please do not send me photos of other people or sensitive information via Telegram – in particular nothing about your sex life, your preferences or your health. Please use the contact form for that: it asks for your explicit consent with a tick box (see “Contact form, e-mail and reports”).

Telegram processes your data under its own responsibility. For users in the European Economic Area, according to Telegram's privacy policy this is Telegram Messenger Inc., Commerce House, Wickhams Cay 1, Road Town, Tortola, British Virgin Islands. Regular Telegram chats are not end-to-end encrypted, and Telegram may transfer data to third countries within its group of companies (according to its own information based on EU standard contractual clauses). I have no influence over this; details are in Telegram's privacy policy. The link above only opens Telegram (t.me) when you click it. Using Telegram is voluntary – you can always write to me by e-mail or form instead.

6. Enquiries, orders, cancellations and withdrawals

If you enquire about or order a card via Get your card, I process the information from the form (name or nickname, e-mail address, chosen package, desired address or domain, your message and the confirmations you tick there; if you come from “Design a card”, also the blueprint with your settings and texts – without a photo) in order to handle your request and perform the contract. The same applies to information in the cancellation form and under Withdraw from contract. The information is sent to me by e-mail in the same way as with the contact form. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures and performance of the contract), for cancellation and withdrawal additionally Art. 6(1)(c) GDPR (statutory confirmation obligations under § 312k and § 356a BGB, German Civil Code). If no contract is concluded, I delete the information after the enquiry has been completed, at the latest after six months. I keep contract and invoice documents for as long as commercial and tax law requires (up to eight or ten years, § 257 HGB, § 147 AO).

Printed NFC card: If you order a printed card, I pass the print file (design of your card with name or nickname and photo as well as your chip link) to the print shop that produces the card on my behalf – currently Kartenstudio, Münchener Str. 8, 85643 Steinhöring, Germany (data processing on my behalf, Art. 28 GDPR). I only use your delivery address for shipping; it is on the letter carried by Deutsche Post AG. The legal basis is Art. 6(1)(b) GDPR. I delete the print file and delivery address once the card has arrived and no complaint is pending, at the latest after six months – unless they are part of the invoice that has to be retained.

Own domain with domain service: If I register a domain for you, I pass the holder details required by the registry (usually name, address, e-mail address and phone number) to a domain registrar and through it to the responsible registry (for .de: DENIC eG, Frankfurt am Main). You are registered there as the holder. The legal basis is Art. 6(1)(b) GDPR. The registrar and registry also process the data under their own responsibility according to their terms; which information they make publicly available (WHOIS) depends on their rules – for .de, data of private individuals is not displayed publicly.

7. Payment via Stripe

Payment is made via the payment service Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). After clicking the order button you are forwarded to a Stripe payment page; your e-mail address and an order number are passed on in the process. You enter your payment details (e.g. card number or IBAN) directly with Stripe – I do not receive them, only name, e-mail address, billing address, amount and payment status. Stripe also sends receipts and reminders before renewals on my behalf. The legal basis is Art. 6(1)(b) GDPR. Stripe also processes some of the data under its own responsibility, for example to prevent fraud and to comply with legal obligations; data may be transferred to Stripe, Inc. in the USA, which is certified under the EU-US Data Privacy Framework. More information: stripe.com/privacy ↗.

Payment methods and discretion: You can pay by card, Apple Pay, Google Pay, Link or Amazon Pay. The payee shown on your bank statement is “KINKID.LINK”; people around you can tell from this that you have paid KinkID. If you do not want this, choose a payment method where you control this entry yourself, or talk to me before ordering. If you choose Amazon Pay, you log in to Amazon: Amazon (Amazon Payments Europe S.C.A., Luxembourg) then learns that you are paying KinkID, saves the payment in your Amazon account and passes the data needed for the payment (name, e-mail address, address) to Stripe. Amazon processes this data under its own responsibility according to its privacy terms. With Link, you can voluntarily save payment details with Stripe to pay faster next time; this is a separate Stripe service that you do not have to use.

8. If you have a card of your own

Which data: Everything you give me for your card and profile page – name or nickname, photos, texts, short info, links, if desired events from your calendar and contact details for “Save contact” – as well as the contract data (e-mail address, package, payments, correspondence).

For what purpose and on what basis: To design your card, to make it available publicly or under your random code as agreed, and to handle the contract (Art. 6(1)(b) GDPR). You decide what is on your page; it is published as you approve it.

Specially protected data – your whole profile: KinkID is a service for the kink and pup scene. Therefore, your photo (e.g. in pup gear), your tagline, your short info, your links and the fact that you have a card here may already allow conclusions about your sex life or sexual orientation. These are special categories of personal data (Art. 9 GDPR). I therefore only process and publish your profile with your explicit consent (Art. 9(2)(a) GDPR), which you give when enquiring or ordering. Without it, I cannot design a card for you, because publication is exactly what you order from me. You can withdraw your consent at any time by e-mail (Art. 7(3) GDPR); I will then take your page and card offline immediately, and our contract ends – what happens to amounts already paid is set out in § 13 of the terms and conditions. The lawfulness of the publication up to that point remains unaffected.

Kinks and preferences: I only show a list of your kinks, fetishes and sexual preferences with an additional, separate consent, which I obtain from you by e-mail if your page is to show such a list. It is voluntary; without it you still get your card, just without this list. If you withdraw only this consent, I remove the list immediately; the rest of your page remains.

Photos: When processing them, I remove camera data such as the location (GPS) and device. I cut out subjects on my own computer; the photos are not sent to any third-party service for this.

Where the data is stored: on my computer; as a backup and version history in a private, non-public repository at GitHub (GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA – certified under the EU-US Data Privacy Framework); the published page at Cloudflare (see above). I do not store the link to your calendar in the repository, but – transmitted in encrypted form – in Cloudflare's storage, so that the events can be displayed up to date. I handle correspondence via my mailbox at Google (see above).

How long: For the duration of the contract. After the contract ends, I delete your content within 30 days and from backups after 90 days at the latest. I keep contract and invoice documents for as long as the law requires (see above). I keep your chip code so that it is never assigned to anyone else – on its own it no longer refers to any person.

Card album: If your card is in the card deck, people who scan your chip or QR code can put it into their personal card album. Only a random identifier of your card and the day are stored there – not your name, not your contact details and not your chip code. The albums contain no names: I can see how often your card has been collected, but not by whom. The legal basis is Art. 6(1)(b) GDPR: collecting is part of the card deck, which you choose voluntarily. If you take your card out of the deck, it is automatically removed from all albums after the next publication – usually within a day.

9. Other people in photos

Photos for a card sometimes show other people, e.g. friends from the scene. For them too, the photo may allow conclusions about their sex life or sexual orientation (Art. 9 GDPR), and their right to their own image applies.

10. Visitors to collector cards and profile pages

Only cards whose owners have expressly agreed appear in the card deck. Events on profile pages are loaded on the server from the calendar of the respective person; no visitor data is transmitted to the calendar provider in the process. “Save contact” only downloads a file from this website. Links to social networks or other sites are simple links to third-party services; content is not embedded. Before you click such a link, no data is transferred to the third party; after the click, its privacy policy applies. Your browser does not tell the third party which page you are coming from (no “referrer”).

Design a card: On the “Design a card” page you try out looks, texts and a photo of your own. This only happens in your browser: the photo and texts are not uploaded and not stored; cutting out the photo (removing the background) is also computed by your device itself – for this, after asking you, it loads a computation model from this website. Only when you choose to request these settings do your settings end up as a blueprint in the contact form and are sent to me when you submit it (see “Contact form, e-mail and reports”).

Profiles under their own domain have their own privacy policy unless they refer to this one.

11. Card album

In the card album you can collect cards that you have scanned via NFC chip or QR code. The album is voluntary and is only created when you explicitly consent and tap the button to agree and create the album.

Which data: a random album number, the public key of your passkey with its identifier, the identifiers of the collected cards and the day on which you collected them, the month in which you last opened the album, and the version, language and day of your consent (as evidence, Art. 7(1) GDPR). No name, no e-mail address, no IP address, no device name. When you open it, Cloudflare briefly processes the technical access data as with any page (see “Visiting the website and hosting”); it is not stored with the album.

Why consent: Which cards someone from the kink and pup community collects may allow conclusions about their sex life or sexual orientation – these are special categories of personal data (Art. 9 GDPR). The legal basis is therefore your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR). The album is intended for adults only. If the consent text changes, I will ask you again the next time you open it.

Passkey instead of an account: The album is opened with a passkey. Your device generates a key pair and protects it with Face ID, Touch ID, fingerprint or device code. Your face or fingerprint never leaves your device; I receive nothing of it, including no biometric data. The passkey is stored in your keychain or password manager (e.g. iCloud Keychain or Google Password Manager) and is synchronised between your devices by its provider according to its terms – I have no influence on this.

Where and how long: in Cloudflare's storage (processor, see above). The album remains stored until you delete it. If you have not opened it for 24 months, it is automatically deleted in the following month. If someone takes their card out of the card deck, it is automatically removed from all albums.

Withdrawal and deletion: You can withdraw your consent at any time with effect for the future (Art. 7(3) GDPR) by tapping “Delete album” in the album. The album, the record of consent and the key are then removed from the server immediately. You delete the passkey on your device in the Passwords app or your password manager.

No recovery, no attribution: Because I do not know who an album belongs to, I can neither recover an album without the matching passkey nor attribute it to anyone (Art. 11 GDPR). You can therefore obtain information about your album directly in the album under “What is stored about your album”; there you can also download the data as a file (Art. 15 and 20 GDPR). If your passkey is lost, the album remains inaccessible and is automatically deleted after the 24 months have passed.

Statistics: I do not open individual albums. Once a day, the server automatically counts only how often each card is in albums in total and stores only these totals. I do not analyse which cards are in which album (Art. 5(1)(c) GDPR, data minimisation).

12. Recipients and transfers to third countries

I only pass on personal data to the service providers named above (Cloudflare, Google, GitHub, Stripe; for a printed card the print shop and Deutsche Post) and only to the extent necessary for the respective purpose – and to authorities if I am legally obliged to do so. Insofar as data reaches the USA in the process, this is based on the adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR) and additionally on EU standard contractual clauses (Art. 46(2)(c) GDPR). I do not sell data and do not use it for advertising. If you write to me on Telegram, Telegram processes your data under its own responsibility (see “Contact via Telegram”).

13. Obligation to provide data, no automated decisions

You do not have to provide any data to visit the website. For a contract, I need your e-mail address, the information marked as mandatory in the order form and your consent for your profile (see “If you have a card of your own”); without them, I cannot conclude the contract. There is no automated decision-making or profiling (Art. 22 GDPR).

14. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), and you can withdraw consent at any time with effect for the future (Art. 7(3)).

Right to object: You can object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).

An informal message to kontakt@kinkid.link is sufficient. You can also lodge a complaint with a data protection supervisory authority, for example with the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, or with the supervisory authority in your country of residence.

As of: 10 October 2026