Privacy Policy

Last updated: March 3, 2026

1. Introduction and Scope

Dreadful Damsels LLC ("we," "our," "us," or "Company") operates Haunted 365, a social networking platform for horror and oddities enthusiasts, and HR for Haunters, a comprehensive human resources management system for haunted attractions and seasonal businesses. This Privacy Policy ("Policy") describes how we collect, use, process, store, share, and protect your personal information across both services.

This Policy applies to all users of our services, including visitors, registered users, employees, contractors, and administrators. By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy and our Terms of Service.

Service Definitions:

  • Haunted 365: Social networking platform for industry enthusiasts, content sharing, community building, and entertainment discovery
  • HR for Haunters: HR management system providing employee data management, payroll processing, performance tracking, compliance monitoring, and workforce analytics

We are committed to transparency, data protection, and maintaining the highest standards of privacy and security in accordance with applicable laws including GDPR, CCPA, PIPEDA, and other international privacy regulations.

2. Information We Collect

2.1 Personal Information You Provide

We collect personal information that you voluntarily provide when creating accounts, using our services, or communicating with us:

Account and Profile Information:

  • Full name, username, email address, phone number
  • Profile photos, cover images, biographical information
  • Professional information (job title, company, industry, experience)
  • Social media links and website URLs
  • Location, timezone, and language preferences
  • Account credentials and security settings (passwords, 2FA settings)

HR-Specific Employee Data (HR invitation accepted):

  • Employment information (hire date, position, department, salary, benefits)
  • Personal identifiers (Social Security Number, tax ID, government-issued ID numbers)
  • Emergency contact information and beneficiary details
  • Performance reviews, disciplinary records, and training certifications
  • Attendance records, time tracking, and leave requests
  • Health and safety information, workers' compensation claims
  • Banking information for payroll processing
  • Background check results and employment eligibility verification

Content and Communications:

  • Posts, comments, messages, and other user-generated content
  • Photos, videos, documents, and files you upload
  • Communications with other users and customer support
  • Feedback, surveys, and contest entries

2.2 Information We Collect Automatically

Technical Information:

  • IP address, device identifiers, and browser fingerprints
  • Device type, operating system, browser type and version
  • Screen resolution, timezone, and language settings
  • Network connection type and internet service provider

Usage and Analytics Data:

  • Pages visited, features used, and time spent on platform
  • Click patterns, navigation paths, and interaction data
  • Search queries and content preferences
  • Performance metrics and error logs
  • Referral sources and campaign attribution

2.3 Information from Third Parties

  • Social media account information (when you connect accounts)
  • Listings (Google, Eventbrite, etc.)
  • Background check and verification services (HR only through CRCA)
  • Payment processors and financial institutions (HR only through Gusto)
  • Public records and commercially available information (HR only)

3. How We Use Your Information

We process your personal information for the following purposes, based on legitimate business interests, contractual necessity, legal obligations, and your consent:

3.1 Service Provision and Platform Operations

  • Create and maintain user accounts and profiles
  • Provide core platform functionality and features
  • Process transactions and manage subscriptions
  • Enable communication between users and communities
  • Deliver personalized content and recommendations
  • Provide customer support and technical assistance

3.2 HR Management Services

  • Process payroll, benefits, and compensation management
  • Maintain employment records and compliance documentation
  • Conduct performance evaluations and career development
  • Manage attendance, time tracking, and leave requests
  • Facilitate recruitment, onboarding, and offboarding processes
  • Generate HR analytics and workforce reporting
  • Ensure workplace safety and regulatory compliance

3.3 Security and Fraud Prevention

  • Verify user identity and prevent unauthorized access
  • Detect and prevent fraud, abuse, and security threats
  • Monitor for violations of our Terms of Service
  • Investigate and respond to security incidents
  • Maintain audit logs and access controls

3.4 Analytics and Improvement

  • Analyze usage patterns and user behavior
  • Improve platform performance and user experience
  • Develop new features and services
  • Conduct research and data analysis
  • Generate business intelligence and insights

3.5 Legal and Compliance

  • Comply with applicable laws and regulations
  • Respond to legal requests and court orders
  • Enforce our Terms of Service and policies
  • Protect our rights, property, and interests
  • Maintain records for audit and regulatory purposes

4. Legal Basis for Processing

We process your personal information based on the following legal grounds:

  • Contractual Necessity: Processing required to provide services under our Terms of Service
  • Legitimate Interests: Processing for business operations, security, and service improvement
  • Legal Obligation: Processing required to comply with applicable laws and regulations
  • Consent: Processing based on your explicit consent (which you may withdraw at any time)
  • Vital Interests: Processing necessary to protect health, safety, or life
  • Public Interest: Processing for tasks carried out in the public interest

5. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may share your information in the following limited circumstances:

5.1 With Your Consent

We may share your information when you provide explicit consent, such as connecting social media accounts or authorizing third-party integrations.

5.2 Service Providers and Business Partners

We work with trusted third-party service providers who assist in platform operations:

  • Payment processors and financial institutions (Stripe)
  • Email and communication service providers
  • Background check and verification services (CRCA)

All service providers are contractually bound to protect your information and use it only for specified purposes.

5.3 Legal Requirements and Protection

We may disclose your information when required by law or to protect our rights and safety:

  • In response to valid legal requests (subpoenas, court orders, search warrants)
  • To comply with applicable laws and regulations
  • To protect against fraud, security threats, or illegal activities
  • To enforce our Terms of Service and policies
  • To protect the rights, property, and safety of our users and the public

5.4 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will provide notice and ensure continued protection of your data.

5.5 Public Information

Information you choose to make public (profile information, posts, comments) may be visible to other users and search engines. You control the visibility of your content through privacy settings.

6. Data Security and Protection

We implement comprehensive security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

6.1 Technical Safeguards

  • End-to-end encryption for sensitive data transmission
  • Advanced encryption standards (AES-256) for data at rest
  • Secure Socket Layer (SSL/TLS) protocols for all communications
  • Multi-factor authentication and access controls
  • Regular security audits and penetration testing
  • Automated threat detection and response systems

6.2 Organizational Safeguards

  • Role-based access controls and principle of least privilege
  • Employee background checks and security training
  • Confidentiality agreements and data handling policies
  • Incident response procedures and breach notification protocols
  • Regular security awareness training and updates

6.3 HR Data Protection

Employee data in HR for Haunters receives additional protection:

  • Field-level encryption for sensitive information (SSN, salary, health data)
  • Segregated databases with enhanced access controls
  • Audit logging for all HR data access and modifications
  • Compliance with SOC 2 Type II and ISO 27001 standards
  • Regular compliance audits and certifications

Important: While we implement industry-leading security measures, no system is completely secure. We cannot guarantee absolute security, but we continuously monitor and improve our security posture to protect your information.

7. Your Privacy Rights and Choices

You have significant control over your personal information. Depending on your location, you may have the following rights:

7.1 Access and Portability

  • Request access to your personal information
  • Obtain a copy of your data in a portable format
  • Review how your information is being processed
  • Download your content and data

7.2 Correction and Updates

  • Update your profile and account information
  • Correct inaccurate or incomplete data
  • Modify privacy settings and preferences

7.3 Deletion and Erasure

  • Delete your account and associated data
  • Request erasure of specific information
  • Remove content you've posted or shared

Note: Some information may be retained for legal, security, or business purposes as outlined in our data retention policy.

7.4 Processing Restrictions

  • Limit how we process your information
  • Opt-out of marketing communications
  • Restrict data sharing with third parties
  • Object to processing based on legitimate interests

7.5 Consent Withdrawal

Where processing is based on consent, you may withdraw consent at any time. This will not affect the lawfulness of processing before withdrawal.

7.6 Exercising Your Rights

To exercise your privacy rights:

  • Use account settings and privacy controls
  • Contact us at [email protected]
  • Submit requests through our privacy portal
  • Contact our President, Kelly Hookham for complex requests

8. Cookies and Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to enhance your experience, analyze usage, and provide personalized content:

8.1 Types of Cookies We Use

  • Essential Cookies: Required for basic platform functionality and security
  • Performance Cookies: Help us analyze usage patterns and improve performance
  • Functional Cookies: Remember your preferences and settings
  • Marketing Cookies: Used for targeted advertising and campaign measurement

8.2 Third-Party Tracking

We may use third-party analytics and advertising services that place cookies on your device. These include Google Analytics, Facebook Pixel, and other marketing platforms.

8.3 Cookie Controls

You can control cookies through:

  • Browser settings and preferences
  • Our cookie consent manager
  • Account privacy settings
  • Opt-out tools provided by third-party services

Note: Disabling certain cookies may affect platform functionality and user experience.

9. Data Retention and Deletion

We retain your personal information only as long as necessary for the purposes outlined in this Policy:

9.1 Retention Periods

  • Account Data: Retained while your account is active and for 30 days after deletion
  • HR Employment Records: Retained for 7 years after employment termination (legal requirement)
  • Financial Records: Retained for 7 years for tax and audit purposes
  • Communication Logs: Retained for 2 years for customer support and security
  • Analytics Data: Aggregated data retained indefinitely; personal identifiers removed after 26 months

9.2 Automated Deletion

We implement automated data deletion processes to ensure compliance with retention policies. Data is securely deleted using industry-standard methods.

9.3 Legal Hold

We may retain data longer when required by law, legal proceedings, or to protect our legitimate interests, even after account deletion or retention period expiration.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with equivalent privacy protections
  • Binding Corporate Rules and certification programs
  • Explicit consent for transfers where required

We primarily process data in the United States and European Union, with appropriate safeguards in place for all international transfers.

11. Children's Privacy, COPPA Compliance, and Minor Safety

Haunted 365 takes the privacy and safety of minors extremely seriously. We comply with the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation provisions for children (GDPR-K), and the UK Age Appropriate Design Code (AADC).

11.1 Age Requirements

Under 13: Users under 13 years of age are not permitted to create accounts on Haunted 365. We do not knowingly collect any personal information from children under 13. If a user indicates they are under 13 during registration, the process is immediately stopped and no data is collected or stored. Users under 13 may browse public attraction listings without an account.

Ages 13–17: Users between 13 and 17 may create accounts with verified parental consent. During registration, minors must provide their birth year and a parent/guardian email address. A consent request is sent to the parent/guardian, who must approve the account within 48 hours. If consent is not received within this window, the account and all associated data are automatically and permanently deleted.

18 and older: Adults may create accounts through the standard registration process with full platform access.

11.2 Data We Collect From Minors

We practice data minimization for minor accounts. We collect only:

  • Birth year (not full date of birth) — to determine age bracket
  • Email address — for account authentication only
  • Parent/guardian email — for consent verification
  • Display name — chosen by the minor or parent

We do not collect from minors: location data, phone numbers, photos, social media profiles, or any additional personal information beyond what is listed above. Location sharing is disabled for all minor accounts unless explicitly enabled by a parent/guardian.

11.3 Family Accounts

Parents and guardians may create Family Accounts to manage their children's access to Haunted 365. Through a Family Account, parents can:

  • Control their child's permission level (browse-only, community, or expanded access)
  • Review their child's activity on the platform
  • Modify or revoke access at any time
  • Request complete deletion of their child's data
  • Receive notifications about safety-related events

11.4 Feature Restrictions for Minors

Minor accounts have age-appropriate safety restrictions including:

  • Adults cannot initiate direct messages with minor accounts
  • All messages involving minors are subject to content moderation
  • Location sharing is disabled by default
  • Profile visibility is restricted
  • Age-appropriate content advisories on attraction pages
  • Employment features (Souls for Hire) require expanded parental permission for ages 16–17

11.5 Parental Rights Under COPPA

Parents and guardians have the right to:

  • Review the personal information we have collected from their child
  • Request deletion of their child's personal information
  • Refuse to allow further collection of their child's information
  • Revoke consent at any time, which will result in account deactivation

To exercise these rights, contact us at [email protected] or use the Family Account dashboard. We will respond to all parental requests within 48 hours.

11.6 Data Retention for Minors

We retain minor account data only for as long as the account is active and parental consent is maintained. When a minor's account is deleted (by parent request, consent expiry, or the minor turning 18 and choosing to delete), all personal data is permanently purged within 24 hours. When a minor turns 18, they are automatically transitioned to an adult account with full access and standard data retention policies apply.

11.7 Employment of Minors (HR for Haunters)

When processing employment data for workers under 18, we require employers to maintain proper documentation including work permits, parental consent, and compliance with applicable federal and state labor laws.

11.8 Child Safety Standards

Our standard against child sexual abuse and exploitation, the protections that apply to teen accounts, and how to report a concern are published in full on our Child Safety Standards page.

12. California Privacy Rights (CCPA/CPRA)

California residents have additional privacy rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request information about personal information collection, use, and sharing
  • Right to Delete: Request deletion of personal information (subject to exceptions)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt-out of the sale or sharing of personal information
  • Right to Limit: Limit use of sensitive personal information
  • Non-Discrimination: We will not discriminate against you for exercising your rights

To exercise these rights, use "Data Security" under "Settings". If you need additional support, contact [email protected]

13. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

  • Lawful Basis: We process your data based on contract, legitimate interests, consent, or legal obligation
  • Data Protection: Contact [email protected]
  • Supervisory Authority: You may lodge complaints with your local data protection authority
  • Cross-Border Transfers: We use appropriate safeguards for international data transfers

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

  • We will post the updated policy on this page with a new "Last updated" date
  • We will notify you of material changes via email or platform notification
  • We may require re-acceptance of the policy for significant changes
  • Changes will take effect 30 days after posting unless otherwise specified

We encourage you to review this Policy periodically to stay informed about how we protect your information.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Dreadful Damsels
General Privacy Inquiries: [email protected]
Data Protection Officer: [email protected]
HR Data Inquiries: [email protected]
Legal Department: [email protected]

For general questions about our services, please visit our contact page.

We will respond to privacy requests within 30 days (or as required by applicable law). For complex requests, we may extend this period and will notify you of any delays.