Applicant Privacy

Privacy Policy

This policy explains how VelvetDolls handles applicant information, optional website analytics, A/B testing data, and privacy choices.

Cookie Policy

Application Data

When you apply, we collect the details needed to review your application and contact you about the next stage.

Privacy-First Setup

The public site does not expose webhook secrets, TDG application IDs, server configuration, or applicant records to the browser.

Your Choices

Optional analytics and A/B testing are controlled through the cookie settings and can be rejected without blocking the application form.

Information We Collect

The application form asks for full name, email address, WhatsApp or phone number, confirmation that you are 18 or over and have valid photo ID, Terms acceptance, an optional WhatsApp number if different, and up to three optional application images.

If optional analytics is accepted, the website records privacy-light events such as page views, application form opens, application submissions, referrer information, campaign tags, and A/B test assignments. Analytics events do not include application form fields.

How We Use Information

Application information is used to review enquiries, contact applicants, support onboarding, confirm eligibility, protect the service, and send the application securely into the configured Dolls Group applications system.

After a successful application, the website may offer a WhatsApp button so applicants can contact the applications team more quickly. If you choose to use WhatsApp, WhatsApp and its provider may process your message and related usage information under their own terms and privacy notice.

Analytics and A/B testing information is used to understand which pages, campaigns, and content variants help visitors find the right information and complete the application process.

Data Handling

Security, Sharing and Retention

VelvetDolls keeps applicant information separate from public website content and avoids storing unnecessary personal data in website analytics.

  • Secure form relay The browser submits to the same-origin website endpoint. The server then forwards approved applications to the configured TDG endpoint with the webhook secret kept server-side.
  • Image handling Optional application images are validated, re-encoded, stripped of metadata where supported, temporarily stored outside public uploads, forwarded securely to The Dolls Group applications system, and cleaned up after forwarding.
  • Limited logging The connector is designed not to log webhook secrets, full request bodies, application images, email addresses, mobile numbers, WhatsApp numbers, or other applicant personal information.
  • Service providers Application and security data may be processed by website hosting, Cloudflare Turnstile when enabled, The Dolls Group applications system, Microsoft 365 email when applicant emails are enabled, and WhatsApp if an applicant chooses to message the applications team.
  • Retention Application retention should follow the operational policy set inside the applications system. Rejected, withdrawn, or converted application images should not be kept longer than needed without a documented business reason.
  • Rights and contact Applicants can ask about their data, request corrections, or raise a privacy question by contacting the VelvetDolls team through the published contact route.