Privacy Policy

Last updated: 27 August 2026

1. Introduction

Bonafide Xchange ("BFX") is committed to protecting the privacy and personal information of all users, including Companions, Clients, Agencies, and Establishments. This Privacy Policy explains how we handle personal information whenever you use BFX — how we collect, use, store, and protect personal data.

2. Information We Collect

  • Personal info (name, email, phone, DOB)
  • Verification documents (ID document and verification selfie)
  • Profile content (photos, text, rates, availability)
  • Live Feed posts you publish (text, images and links), including posts you have archived and posts we have removed
  • Reports you make about a post or other content, including the reason you select and any details you write
  • Booking and messaging activity
  • Reviews and ratings you give or receive
  • Interaction feedback from Companions about Clients (survey answers and private written notes)
  • Behaviour records (cancellations and the notice given, enquiry and booking outcomes, blocks, reports, disputes)
  • Payment details you save and choose to share in a chat (such as account name, bank name, BSB and account number, IBAN/SWIFT, PayID, PayPal or Beem identifiers)
  • Content offers and purchases, and payment receipts uploaded to a chat — a receipt may show your own banking details
  • Derived reliability information (scores, bands, and behavioural indicators computed from platform activity and feedback)
  • Private notes, labels, and tags Companions keep about Clients they have dealt with
  • Browsing activity (profiles viewed, favourites, category clicks)
  • Technical data (IP address, device info, cookies)
  • Business/licensing documents from Agencies/Establishments

3. How We Collect Information

  • Account creation
  • Verification uploads
  • Profile updates
  • Messages and bookings
  • Reviews and post-interaction feedback surveys
  • Automatic records of platform activity
  • Cookies and local device storage
  • Safety incident reports

4. Why We Collect Information

  • Operate the platform
  • Process verification
  • Ensure safety and prevent fraud
  • Provide reliability information that helps users assess interactions
  • Improve platform functionality
  • Meet legal obligations
  • Support dispute resolution

5. How We Store & Protect Data

We take reasonable steps to protect data, including secure servers, encryption, restricted access, and routine security reviews. Verification documents are never shared with other users.

6. Sharing Data

We do not sell data. We share personal information only with service providers that help us operate the platform, and otherwise only where the law requires:

  • Hosting and storage providers (Microsoft Azure; Vercel, whose global content delivery network caches public pages and images)
  • Email delivery provider (Postmark, located in the United States)
  • Real-time message and notification delivery (Pusher)
  • Sign-in providers you choose to use (Google, Apple, X)
  • Our support chat widget provider (Chatbase), which loads on our pages and processes any chats you send it
  • Our website analytics provider (Google Analytics, operated by Google in the United States), which receives the addresses and titles of the pages you visit — including public Companion profile pages, whose address carries the profile's public id and whose title is the Companion's display name — together with how you arrived and your device and browser type. It does not receive your email address, sign-in details or messages, and we strip private links and identifiers from the addresses it sees (see section 11)
  • Verification services
  • Fraud/security partners
  • Law enforcement (if required)
  • Payment processors — we do not use one. Clients and Companions pay each other directly, so payment details and receipts shared in a chat are stored by us and are not sent to a processor

7. Companion Privacy

We never display real names, ID details, or home addresses. Verification images are protected. Your public profile page can be opened by anyone with the link, including people who are not signed in, and search engines may list it in their results; we ask search engines not to show your profile photos in image search, but that is a request they may not honour and it does not make the photos private.

8. Client Privacy

We never publicly display a Client's private account or verification information. Your display name and the profile details you choose to provide appear on a limited client profile page. Anyone with the link can open that page, including people who are not signed in; we ask search engines not to index it, but it is not private. Other than reviews (see section 9), records of your platform conduct and derived reliability information are visible only to logged-in Companions and authorised BFX staff — a Companion can open them from your profile page, but they are never part of the page itself (see section 10). Companions can also keep private notes and labels about Clients they have dealt with; these are never shown to you or to other users, but are held by BFX and may be reviewed by staff for safety or dispute purposes. If either party reports a message in a chat, authorised BFX staff can read that message and the report in order to decide what to do about it; a report is recorded against the reported account and can affect a Client's reliability information, and if we find a report was baseless we void it and recalculate the score.

9. Reviews & Ratings

Reviews left by Clients after completed bookings are displayed publicly on the Companion's profile, together with category ratings and averages. Each review is linked to the reviewing Client's account, and the reviewed Companion can see the reviewer's display name. Companions may also review Clients after a booking both parties confirm took place. Those reviews are displayed publicly on the Client's profile with their category ratings and averages, and are readable by signed-out visitors. The reviewing Companion is not identified to the Client or to any other reader, and we do not notify a Client when a review of them is published. Only the newest review from each Companion is displayed. Ratings may feed automated listing categories (such as Highly Rated). Superseded reviews are retained internally for integrity and dispute purposes.

10. Interaction Feedback & Reliability Information

After an enquiry ends — it is cancelled by either side, either side stops replying for an extended period, the response window the Client set runs out, or a booking that came out of it takes place and both parties confirm it — the Companion may complete a short private feedback survey about how the enquiry was conducted. A booking being called off does not prompt a survey: an invitation withdrawn, or a confirmed booking cancelled, ends the booking, not the enquiry. Individual survey responses are not shown to the Client through the platform, and written notes are visible only to authorised BFX administrators. We never disclose which Companion provided feedback; if a Client exercises their right to access personal information we hold about them, we will withhold or de-identify feedback material to the extent the Privacy Act allows (see section 13). Responses raising a serious safety concern are routed to BFX staff for human review.

BFX may combine survey feedback with platform activity records (bookings, cancellations, enquiry and booking outcomes, blocks, and reports) to compute reliability indicators about Client accounts, such as a score, band, and behavioural signals. Indicators are shown only to logged-in Companions and authorised BFX staff, appear only once minimum thresholds are met (several closed interactions involving several independent Companions), and are never shown on public pages. Alongside the score and band, a Companion is shown counts and ratios drawn from the same records — how many enquiries you have sent, how many Companions you have contacted, how many bookings were confirmed and completed, how many you cancelled and how many of those were late, and how long you have been a member. Scoring uses a rolling 12-month window of activity and feedback, so indicators improve as reliable behaviour accumulates. Section 13 explains how to seek access or correction.

11. Cookies, Local Storage & Analytics

We use cookies and local device storage for login and session management, and to remember device preferences (such as age confirmation and discreet mode) and unsent form drafts.

We use Google Analytics to understand how the site is used — which pages are visited, how visitors arrive, and on what kinds of devices — so we can improve it. Google Analytics sets its own cookies to recognise a returning browser and receives technical data such as your browser and device type and an approximate location derived from your IP address (Google states that Google Analytics does not log or store the address itself). It receives the addresses and titles of the pages you visit. Public Companion profile pages are reported like any other public page, so a profile's address (which contains its public id) and title (the Companion's display name) are sent when someone views it. We do not send Google your email address, sign-in details or messages, and we strip private details from the page addresses it sees — Client profile ids, the other party in a conversation, password-reset and email-verification links, and the location you search from. You can opt out with Google's browser add-on at tools.google.com/dlpage/gaoptout.

We do not use third-party advertising cookies. Embedded third-party services — such as our support chat widget, which loads on our pages and may receive technical data like your IP address, and sign-in providers — may set their own cookies. You can control cookies through your browser settings.

12. Data Retention

We retain personal information only as long as needed for safety, legal compliance, or dispute resolution, then delete or de-identify it. In particular:

  • Reliability indicators are computed from a rolling 12-month window of platform activity and Companion feedback.
  • Interaction feedback survey responses are kept only while they remain relevant to safety and dispute resolution, and in any case no longer than 24 months. When we remove them, we delete the written notes and keep only aggregated numeric data. This removal is currently carried out on review by our staff rather than automatically.
  • Category click statistics are deleted after 90 days.
  • A Live Feed post stays on your public profile for 30 days, then moves to your archive automatically. Your archive holds 50 posts; when it is full, the oldest is deleted to make room.
  • If you delete one of your own posts and it has never been reported, we unpublish it immediately and delete it, together with its edit history and image, after a 7-day grace period.
  • If we remove a post, or if a post has ever been reported, we keep it in restricted storage for 12 months, together with its earlier versions and its image, so that we can answer a complaint, support an appeal, or respond to law enforcement or a regulator. We may keep it for longer where a matter is still with law enforcement or a regulator. It is not visible on your profile during this time.
  • Reports about content, including the details the reporter wrote, are kept for 12 months after the report is closed.
  • If you ask us to delete feedback about you, we review the underlying records, void any feedback that breaches our rules so it is excluded from every reliability calculation, and delete the written notes. We aim to complete this within 30 days of your request. Aggregated numeric counters may be retained where necessary to protect other users.
  • If your account is deleted, we may retain safety-related records (such as reports, blocks, and aggregated feedback counts) where necessary to protect other users or meet legal obligations.

13. User Rights & Complaints

You may request access to, correction of, or deletion of your personal information by emailing support@bfxchange.com.au. We aim to respond within 30 days. Where reliability information about you is derived from activity records and aggregated feedback, we correct it by reviewing the underlying records, voiding feedback that breaches our rules so it is excluded from any reliability calculation, and recomputing the affected indicators. Some information may be withheld or retained where the law allows — for example, where access would reveal another user's identity or endanger their safety, or where retention is required by law. If you make a privacy complaint, we will acknowledge it, investigate, and give you a written response within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (www.oaic.gov.au).

14. Where Data Is Processed

BFX is operated from Australia and handles personal information under the Privacy Act 1988 (Cth). Our application servers and uploaded media are hosted in Australian data centres. Some service providers process limited information overseas: email delivery and sign-in providers (United States), our support chat provider (United States), our website analytics provider (Google, United States), and global content delivery caching (worldwide edge locations operated by a US provider). Images you publish to your Live Feed are served through that caching layer, so copies may be held at edge locations outside Australia and may remain in those caches for a period after we remove a post.

15. Live Feed & Content Reports

Live Feed posts are part of your public profile. Anyone who can see your profile can see them, including people who are not signed in, and search engines may index the text. Treat a post as public from the moment you publish it.

Anyone signed in can report a post. Reports are readable by authorised BFX staff only. We never tell the person who published a post who reported it, and we do not disclose a reporter's identity on request. We may keep the details of a report after the report is closed — section 12 explains for how long.

When you write the details of a report, please do not include health, financial or identifying information about other people. We only need enough to review the post. Where a report contains sensitive information we did not need in order to decide it, we remove that information when we close the report.

16. Policy Updates

We may update this Policy to reflect legal or platform changes.

17. Contact

support@bfxchange.com.au