Privacy Policy
Last updated: February 2025
Summary: PawTrust ("we", "us", or "our") is operated by VirtusNova SL. We are committed to protecting your personal data. This policy explains what data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable laws. If you have questions, contact us at [email protected].
1. Data Controller
The data controller responsible for your personal data is:
VirtusNova SL
Email: [email protected]
Website: pawtrust.app
For all data protection inquiries, you may contact our Data Protection contact at [email protected].
2. Data We Collect
We collect and process the following categories of personal data depending on your use of PawTrust:
2.1 Account Information
- Registration data: Full name, email address, phone number, password (stored hashed), date of birth, and chosen role (Dog Owner or Dog Walker).
- Profile data: Profile photo, bio/description, preferred language, and notification preferences.
2.2 Identity Verification Data (Walkers)
- Government-issued ID: Photo or scan of your national ID card, passport, or driver's license, used to verify your identity.
- Selfie verification: A live selfie photo used for facial comparison against your ID document.
- Background check consent: Your consent and any data provided to or received from third-party background check services.
- Verification status: The results and status of your verification process.
2.3 Dog Information (Owners)
- Dog profiles: Name, breed, age, weight, size, temperament, special needs, medical notes, and photos of your dog(s).
2.4 Location Data
- General location: Your approximate location used to match you with nearby walkers or walk requests.
- GPS tracking during walks: Real-time GPS coordinates recorded during active walks. This data is shared with the dog owner in real time and stored as a walk route history.
- Walk start and end locations: The pickup and drop-off locations specified for each walk booking.
2.5 Payment Information
- Payment method details: Credit/debit card information, billing address, and bank account details for payouts. Payment card data is processed and stored by our third-party payment processor and is never stored on our servers.
- Transaction history: Records of all payments, escrow holds, releases, refunds, and payouts.
2.6 Communication Data
- Messages: In-app messages between owners and walkers related to bookings.
- Support communications: Emails, chat logs, and other communications with our support team.
2.7 Usage and Device Data
- Device information: Device type, operating system, app version, unique device identifiers.
- Usage data: Features used, pages viewed, actions taken within the app, timestamps, and session duration.
- Log data: IP address, browser type (for web access), referral URLs, and crash reports.
2.8 Reviews and Ratings
- Reviews: Written reviews and star ratings you provide about other users, and reviews/ratings others provide about you.
- Trust scores: Calculated scores based on review history, verification status, and platform behavior.
3. How We Use Your Data
We process your personal data for the following purposes and legal bases:
3.1 Providing Our Services (Contract Performance)
- Creating and managing your account.
- Matching dog owners with suitable walkers based on location, availability, and preferences.
- Facilitating walk requests, applications, and bookings.
- Processing payments through our escrow system (holding funds, releasing to walkers upon walk completion, processing refunds).
- Enabling real-time GPS tracking during walks so owners can monitor their dog's location.
- Storing walk route history for reference and dispute resolution.
- Displaying reviews and trust scores to help users make informed decisions.
3.2 Verification and Safety (Legitimate Interest / Legal Obligation)
- Verifying walker identity through ID document checks and selfie comparison.
- Conducting or facilitating background checks on walkers.
- Calculating and maintaining trust scores to promote platform safety.
- Detecting and preventing fraud, abuse, and unauthorized access.
- Maintaining audit logs of critical account actions for security.
3.3 Communication (Contract Performance / Legitimate Interest)
- Sending booking confirmations, walk status updates, and payment notifications.
- Enabling in-app messaging between owners and walkers.
- Responding to your support requests and inquiries.
- Sending service-related announcements (e.g., policy changes, security alerts).
3.4 Improvement and Analytics (Legitimate Interest)
- Analyzing usage patterns to improve app features and user experience.
- Monitoring app performance and diagnosing technical issues.
- Conducting anonymized and aggregated statistical analysis.
3.5 Marketing (Consent)
- Sending promotional communications about PawTrust features and offers, only with your explicit consent.
- You may withdraw consent at any time through your account settings or by contacting us.
3.6 Legal Compliance (Legal Obligation)
- Complying with applicable laws, regulations, and legal processes.
- Responding to lawful requests from public authorities.
- Establishing, exercising, or defending legal claims.
4. Data Sharing
We share your personal data only in the following circumstances:
4.1 Between Users
- During booking: When a walk is booked, owners can see the walker's name, profile photo, ratings, trust score, and verification status. Walkers can see the owner's name, profile photo, ratings, dog details, and walk location.
- During active walks: Owners receive real-time GPS location data of the walker.
- Reviews: Reviews and ratings are visible to other users on the platform.
4.2 Service Providers
- Payment processors: We share necessary payment and transaction data with our payment processor to facilitate escrow payments, releases, and refunds.
- Identity verification providers: ID documents and selfie images may be shared with third-party verification services to confirm walker identities.
- Background check providers: With walker consent, relevant personal data is shared with background check services.
- Cloud hosting providers: Your data is stored on secure cloud infrastructure provided by trusted hosting services.
- Analytics providers: Anonymized usage data may be shared with analytics services.
4.3 Legal Requirements
We may disclose your data if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections described in this policy.
4.5 No Sale of Data
We do not sell your personal data to third parties. We do not share your data with advertisers or data brokers.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days after deletion |
| ID documents & selfies | Deleted within 90 days of successful verification |
| GPS walk tracking data | 12 months from walk date |
| Transaction records | 7 years (legal/tax obligation) |
| Messages | Duration of account + 30 days after deletion |
| Reviews & ratings | Duration of reviewed user's account |
| Support communications | 3 years from last interaction |
| Usage/analytics data | 24 months (anonymized thereafter) |
| Audit logs | 5 years |
When data is no longer needed, it is securely deleted or anonymized so that it can no longer be associated with you.
6. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): You may request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction: You may request that we restrict the processing of your data in certain circumstances.
- Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format and transfer it to another service.
- Right to Object: You may object to processing based on legitimate interests, including profiling.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to file a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.
You can also manage much of your data directly within the app, including editing your profile, deleting your dogs, and requesting account deletion from your account settings.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When such transfers occur, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions for countries deemed to provide an adequate level of data protection.
- Other legally recognized transfer mechanisms under the GDPR.
8. Cookies and Tracking
Our website and web-based services use cookies and similar technologies. For detailed information about what cookies we use and how to manage them, please see our Cookie Policy.
The PawTrust mobile app does not use cookies but may use similar local storage technologies for session management and preferences.
9. Children's Privacy
PawTrust is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children under 18. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected], and we will promptly delete such data.
Users must be at least 18 years old to create an account. We verify age during registration and may request additional proof of age if there is reason to believe a user is underage.
10. Security Measures
We implement robust technical and organizational measures to protect your personal data, including:
- Encryption: All data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest is encrypted using industry-standard algorithms.
- Password security: Passwords are hashed using bcrypt with appropriate salt rounds and are never stored in plain text.
- Authentication: JWT-based authentication with short-lived access tokens (15 minutes) and refresh tokens (30 days).
- Access control: Role-based access control limits data access to authorized personnel only. Staff access is logged and audited.
- Infrastructure: Our servers are hosted in secure data centers with physical security controls, firewalls, and intrusion detection systems.
- Payment security: Payment card data is processed by PCI DSS-compliant payment processors. We do not store full card numbers on our servers.
- ID document handling: Verification documents are encrypted, access-restricted, and deleted within 90 days of successful verification.
- Audit logging: Critical security events are logged for monitoring and incident response.
- Regular updates: We regularly update our security practices and conduct periodic security reviews.
While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use strong passwords and keep your login credentials confidential.
11. Third-Party Links and Services
PawTrust may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through PawTrust.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify you via the app (push notification or in-app banner) or by email for significant changes.
- Where required by law, obtain your consent before applying material changes.
We recommend reviewing this policy periodically. Your continued use of PawTrust after changes are published constitutes your acceptance of the updated policy.
13. Contact Us
VirtusNova SL (operating as PawTrust)
Email: [email protected]
Website: pawtrust.app
For data protection requests, please include "Privacy Request" in your email subject line. We aim to respond to all requests within 30 days.