Privacy Policy
1. Who we are (controller)
The controller responsible for processing your personal data under the EU General Data Protection Regulation (GDPR) is:
Luis Enrique Ramirez ChavezFürbringerstrasse 4, 10961 Berlin, GermanyEmail: [email protected]
We are a small team and are not legally required to appoint a Data Protection Officer. For any question about your data, write to the email above.
2. What this policy covers
This policy covers the Calupet mobile app (iOS and Android) and our website at app.calu.pet, including public pages such as shared walks and lost-pet alerts. Calupet is a pet-care app: you can keep a profile for your pet, record and review your walks, share walks or routes with people you choose, and raise or receive lost-pet alerts in your area.
Calupet is currently offered as a beta. Some features described here (marked coming in the safety release) are not yet live for all users.
3. The data we process, why, and our legal basis
We only process what a feature needs. The table below is the summary; the paragraphs after it add detail. "Legal basis" refers to the GDPR article that permits each use.
| What we process | Why | Legal basis |
|---|---|---|
| Email address, sign-in identifiers, sign-in metadata (IP, timestamps) | Create and secure your account; sign you in without a password | Art. 6(1)(b) contract; Art. 6(1)(f) security |
| Profile details you add (name, username, city, short bio, photo) | Show your profile and let others find you if you choose | Art. 6(1)(b) contract |
| Pet profile and pet health entries (weight, medications, vet notes, journal) | Let you track your pet's care | Art. 6(1)(b) contract |
| Walk GPS tracks and walk statistics | Record your walk and show your history and stats | Art. 6(1)(b) contract |
| Photos you upload (walk photos, pet and profile avatars) | Show your images in the app | Art. 6(1)(b) contract |
| Recorded-route sharing via an expiring link | Share a walk or route with people you pick | Art. 6(1)(b) contract |
| Lost-pet alerts and sightings; delivery to nearby users | Help find lost pets in the area | Creator: Art. 6(1)(b); nearby-recipient delivery: Art. 6(1)(f) legitimate interest |
| Community and social content (posts, comments, follows) | Run the community features you use | Art. 6(1)(b) contract |
| Which places you view on the map | Show popular places and improve discovery | Explicit tap: Art. 6(1)(b); walk-derived: Art. 6(1)(a) consent, off by default |
| App diagnostics and error reports | Keep the app working and fix crashes | Art. 6(1)(f) legitimate interest |
| Push notifications (coming in the safety release) | Alert you about lost pets, safety, and account events | Transactional/safety: Art. 6(1)(b)/(c)/(d); behavioural/marketing: Art. 6(1)(a) consent |
| Live location sharing and trusted contacts (coming in the safety release) | Let chosen people see where you are during a walk | Art. 6(1)(b) contract |
Accounts and sign-in. Calupet uses passwordless sign-in: we email you a one-time code (mobile) or a magic link (web), so we do not store a password. To do this we and our login provider process your email address, a login identifier, and technical sign-in metadata such as your IP address and timestamps.
Walks and location. When you record a walk, the app collects GPS points to draw your route and calculate distance and time. Location is collected only while a walk is active (with a background mode you control at the operating-system level). Your walk tracks are yours; we do not sell them or use them to advertise to you.
Sharing a walk or route. If you choose to share, we create a link containing a random, expiring token. Anyone with the link can view the shared route until the link expires or you revoke it. To protect your home, shared routes have their start and end automatically trimmed and shown only approximately.
Lost-pet alerts. If you report a pet as lost, we show an alert and can notify other users near the pet's last-seen area. We work out the delivery area from the current-area postal code, and we do not store precise coordinates for this matching beyond deriving that postal code. Public-facing flyers and link previews show only an approximate area (about a 500-metre zone), never the exact location, to protect against theft. Home-area matching and exact-radius matching are optional and off unless you turn them on.
Places you view. When you tap a place on the map, we count that view to show which places are popular. Counting views derived from your walk route (without a tap) is optional and off by default; you can turn it on in privacy settings. Analytics shown to businesses about their own listing are aggregated and suppressed below a minimum group size, so individuals are not identifiable.
Diagnostics. We use error tracking and performance monitoring to keep the app reliable. These tools are configured to scrub personal data: error reports do not carry your profile data, and monitoring identifiers are pseudonymised before they leave our systems.
4. Special-category data
We do not intend to collect special-category data under Art. 9 GDPR (such as data about your own health, race, or beliefs). Pet health entries are about your animal and are treated as ordinary personal data linked to you, not as your own health data. Please do not enter your own sensitive information in free-text fields such as journals or descriptions.
5. Who we share your data with
We do not sell your personal data. We use a small number of carefully chosen service providers ("processors") who process data only on our instructions under a data-processing agreement.
| Provider | What they do for us | Where |
|---|---|---|
| Auth0 (Okta, Inc.) | Passwordless authentication | EU tenant |
| Google Workspace (Google LLC) | Sends your sign-in one-time codes | EU/US |
| Hetzner Online GmbH | Hosts our servers and database | Falkenstein, Germany |
| Cloudfleet | Manages our server cluster (no user data) | EU-scoped |
| Cloudflare, Inc. (incl. R2 storage) | Delivers and protects the site; stores uploaded media | EU edge; R2 EU (Frankfurt) |
| Mapbox, Inc. | Map tiles and geocoding (map-tile coordinates only) | EU CDN |
| Sentry (Functional Software, Inc.) | Error tracking (personal data scrubbed) | EU region |
| Grafana Labs | Performance monitoring (identifiers pseudonymised) | EU (Grafana Cloud) |
| Apple (APNs) / Google (FCM) | Deliver push notifications (safety release) | US; device token only |
We may also disclose data where the law requires it (for example, a valid legal request), or to establish or defend legal claims.
6. International transfers
Our core systems and your data at rest are hosted in the European Union (Germany). Some providers listed above are part of groups with a US parent. Where personal data is transferred outside the EU/EEA, we rely on an appropriate safeguard under Chapter V GDPR — typically the European Commission's Standard Contractual Clauses and, where applicable, additional measures — set out in our agreement with each provider. You can request more detail using the contact in Section 1.
7. How long we keep your data
We keep personal data only as long as needed for the purpose, then delete or anonymise it. Key periods:
| Data | Retention |
|---|---|
| Account and profile | For the life of your account; erased when you delete your account |
| Pet profiles and pet health entries | For the life of your account; erased on account deletion |
| Walk GPS tracks and statistics | For the life of your account (no fixed expiry); erased on account deletion |
| Walk photos | 90 days |
| Pet and profile avatars | For the life of your account |
| Temporary uploads | 24 hours |
| Place-view records (individual) | 90 days |
| Shared-route links | 30 days, or until you revoke |
| Live-share position (safety release) | Only while the share is active; the last point is cleared on stop, and the record is purged within 24 hours |
| Lost-pet alerts and sightings | For the life of the alert; finder contact details are removed when the alert ends |
| Lost-pet public flyer image | 7 days |
| Notification delivery receipts | 90 days |
| Consent records | Kept for 3 years after account deletion, in pseudonymised form, as proof of consent (Art. 7 GDPR) |
| Security/audit logs | 1–7 years depending on the record, to meet security and legal duties |
| Error tracking | Up to 90 days, personal data scrubbed |
| Performance monitoring | 14 days, pseudonymised |
| Edge/access and email delivery logs | Up to 30–90 days (provider policy) |
Some records must be kept longer where the law requires it (for example, certain safety-moderation records for up to 7 years). Where we keep such records, we minimise them.
8. Your rights
Under the GDPR you have the right to:
- Access — get a copy of your data. You can export your data yourself in the app, or ask us.
- Rectification — correct data that is wrong; you can edit most of it directly.
- Erasure — delete your account and data. Deleting your account in the app removes your data and your sign-in identity; some minimised records are kept only where the law allows (Section 7).
- Restriction — ask us to pause processing while a concern is resolved.
- Portability — receive your data in a portable, machine-readable format.
- Objection — object to processing based on legitimate interest, including nearby lost-pet alerts (you can opt out with a single toggle).
Where processing is based on your consent (for example, walk-derived place views, or behavioural/marketing notifications), you can withdraw consent at any time, as easily as you gave it, without affecting past processing.
To exercise any right, use the in-app controls or contact [email protected]. You also have the right to lodge a complaint with your data-protection authority. Our lead authority is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)Alt-Moabit 59-61, 10555 Berlin, Germany
9. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you using only automated processing (Art. 22 GDPR). Features such as popular-place ranking and content feeds order information for convenience only.
10. Children
Calupet is not intended for people under 16. We do not knowingly collect data from children under 16. If you believe a child has given us data, contact us and we will delete it.
11. Security
Your data is hosted in the EU and protected with encryption in transit, access controls, and security logging. Sign-in is passwordless, so there is no password to steal. No system is perfectly secure, but we work to protect your data and will notify you and the authority of a qualifying data breach as required by law.
12. Cookies and the website
The mobile app does not use advertising cookies. Our website uses only what is necessary to serve pages securely; where any non-essential storage or analytics is used, we will ask for your consent first, as required by the German TDDDG.
13. Changes to this policy
If we make a material change, we will update the date above and, where appropriate, notify you in the app. Continued use after an update means the current version applies.
14. Contact
Questions about your data or this policy: [email protected], Luis Enrique Ramirez Chavez, Berlin, Germany.