Privacy Policy

Last Updated: October 21, 2025

This Privacy Policy explains how PipelineGrid, LLC (a Delaware limited liability company) (“PipelineGrid”, “we”, “us”, or “our”) collects, uses, discloses, and protects information in connection with the Shiraz mobile application (the “App”) and the website shirazdate.com (the “Site”).

By using the App or Site, you acknowledge that you have read and understand this Privacy Policy.

1. Scope & Data Controller

This Policy applies to the App and Site operated by PipelineGrid, LLC, with business address at 8 The Green STE B, Dover, DE 19901, United States. For privacy requests, contact legal@pipelinegrid.com.

2. Information We Collect

2.1 Information You Provide

2.2 Information Collected Automatically

2.3 Information from Others

2.4 Location Data & Area Sharing

With your permission, Shiraz collects device location data to power an optional “Area Sharing” feature. For privacy, we never place your exact coordinates on the radar. Instead, the App computes a randomized point approximately 100 meters (about 330 feet) away from your actual location in a random direction and displays that obfuscated point (“dot”).

How the obfuscation works (plain English): imagine a circle centered on your true location. We pick a point on that circle that is ~100 meters/330 ft away, in a randomly chosen direction. This offset dot — not your true location — is what appears to others.

Refresh intervals: the obfuscated dot is periodically refreshed (e.g., at set intervals or when the app is reopened) by choosing a new randomized point ~100 m/330 ft away again. This helps prevent someone from inferring your exact location over time.

Who appears on your radar: you will see anonymized dots (no name/photo/profile) for nearby potential matches whom you have not acted on yet (not liked, passed, or reported) and who have Area Sharing enabled. Your own obfuscated dot may be visible to others if you match with them and keep Area Sharing enabled.

Sparse-area caution: in low-density areas, a single dot — even when offset by ~100 m/330 ft — could still be identifying (e.g., if you are the only user nearby). Consider turning Area Sharing off in such situations.

We do not display precise addresses, routes, or location history, and we store session tokens and in-app identifiers only to maintain your Area Sharing preference and protect the service. Location data used for this feature is retained for the period necessary to provide the feature and for a limited time thereafter for security and abuse prevention, after which it is deleted or aggregated.

2.5 Camera & Photos

With your permission, Shiraz may access your device camera and photo library so you can capture or upload images from your phone. When you add images as profile photos, they are public within Shiraz and may be shown across profile and discovery surfaces to other users.

What we use the camera/photos for

Do images leave your device? Where they’re stored; who can see them

When you submit a photo, it is transmitted from your device to our servers and stored by PipelineGrid, LLC and our service providers (see “International Transfers”). Profile photos are public to other Shiraz users. Authorized personnel and vetted processors may access images only as needed for operations, safety, moderation, and support.

Retention & deletion

Security measures

Photo uploads use transport encryption (e.g., TLS) and are stored with access controls and other technical and organizational safeguards designed to prevent unauthorized access, alteration, or disclosure. No system is perfectly secure; see “Security.”

Your choices

2.6 Google Sign-In (OAuth)

Google Sign-In (OAuth). When you authenticate with Google, we receive your basic account information from Google (such as your name, email address, Google user ID, and profile photo if available) to create and verify your account. We never receive or store your Google password.

2.7 Automated Moderation & AI Use

To keep Shiraz safe, we may use automated systems (including machine learning) to help detect policy violations and unsafe content (e.g., spam, suspected AI-generated images presented as real, or prohibited sexual content). Automated outputs may be reviewed by authorized personnel. These processes affect only in-app content and do not involve decisions producing legal or similarly significant effects without human review.

3. How We Use Information

4. Legal Bases for Processing (EEA/UK only)

5. How We Share Information

6. International Transfers

Information may be processed in countries other than your own. Where required, we use appropriate safeguards (e.g., standard contractual clauses) to protect personal data transferred from the EEA/UK.

7. Your Rights & Choices

EEA/UK: You may have additional rights (data portability, restriction, objection). You may lodge a complaint with your supervisory authority.

California: See §12 for your California privacy notice.

Deactivate your profile (hide without deleting)

Deactivating hides your profile and limits access to app features without deleting your account or data.

What happens when you deactivate

How to deactivate/reactivate

Note: Deactivation is not deletion. To delete specific data, see Delete specific data (keep your account). To permanently delete your account and all associated data, see Delete your account & data.

Delete specific data (keep your account)

Shiraz by PipelineGrid, LLC lets you remove certain data without closing your account.

How to delete data

What is deleted vs. kept

Retention

Deleted items are removed from active systems promptly and from backups during routine rotations (typically within 30 days). Limited fraud/safety logs may be retained for up to 24 months; legal/transactional records are kept as required by law.

To permanently remove your account and all associated data, see Delete your account & data.

Delete your account & data

You can delete your account any time in the App: Settings → Delete Profile. Deletion starts promptly and removes your profile, photos, messages, matches, and other in-app content from our production systems. We may retain limited records as required for fraud prevention, safety, or legal compliance.

If you need help with deletion, contact support@shirazdate.com.

Data access & portability

We don’t provide a self-service export in the app. If you are entitled to request access to or a copy of your personal data under applicable law, email support@shirazdate.com with the subject “Data Access/Portability – Shiraz.” We will verify your request and respond within the time required by law.

8. Children

Shiraz is intended for individuals aged 18 or older. We do not knowingly collect personal information from minors. If you believe a minor is using the service, please report it and contact us at legal@pipelinegrid.com.

9. Cookies, Local Storage & In-App Identifiers

We use cookies and similar technologies on the Site and in-app technologies in the App to operate, secure, and improve Shiraz. These include browser cookies, local storage, software development kits (“SDKs”), device and advertising identifiers, app instance IDs, and session tokens that persist your login and help us protect accounts.

9.1 Web Cookies (Site)

On the Site, we may use:

You can manage cookies through your browser settings. Disabling certain cookies may affect core features.

9.2 In-App Technologies (App)

In the App, we do not rely on browser cookies. Instead, we (and our service providers) may use:

9.3 Purposes

9.4 Your Choices & Controls

9.5 Retention

Session tokens are retained for the duration of the session and a limited period thereafter to support account security and continuity. Analytics and diagnostic data are retained for periods proportionate to the purposes described above. Where feasible, we apply aggregation or pseudonymization.

9.6 “Do Not Track”

Some browsers transmit “Do Not Track” signals. Because there is no common industry standard, Shiraz does not respond to these signals; we honor the controls described in this section and applicable consent mechanisms.

10. Security

We implement technical and organizational measures designed to protect information. No system is perfectly secure; we cannot guarantee absolute security.

11. Data Retention

We retain information for as long as necessary to provide the services, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods may vary by category and context (e.g., safety reports may be retained longer).

12. California Notice (CCPA/CPRA)

California residents have the right to request access to, deletion of, and information about personal information collected, used, or disclosed. We do not sell personal information as defined by California law. To exercise your rights, contact legal@pipelinegrid.com. You will not be discriminated against for exercising your rights.

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be indicated by updating the “Last Updated” date and, where required, by additional notice.

14. Contact

General support: support@shirazdate.com

Questions about this Policy or your privacy rights: legal@pipelinegrid.com
PipelineGrid, LLC, a Delaware limited liability company
8 The Green STE B, Dover, DE 19901, United States