Privacy Policy and GDPR Information Notice — DoggyRadar
Effective Date: September 1, 2026
Document Version: 4.0.0
1. Data Controller
The data controller for personal data processed within the DoggyRadar website and mobile application (for Android, iOS, and Web platforms) is:
Krzysztof Wołosik – Javor
Sole Proprietorship
Address: ul. Anastazego Wika-Czarnowskiego 1A/7, 80-365 Gdańsk, Poland
Tax ID (NIP): PL5922047567
- General Contact: office@doggyradar.com
- Data Protection & GDPR Inquiries: rodo@doggyradar.com
- Official Website: https://doggyradar.com
The Data Controller has not appointed a Data Protection Officer. All inquiries concerning the exercise of rights under Regulation (EU) 2016/679 (GDPR) should be directed to rodo@doggyradar.com.
2. Scope and Nature of the Service
DoggyRadar is a social platform dedicated to dog owners and guardians, offering features including:
- creating and managing dog profiles;
- tracking and summarizing dog walks;
- displaying dog and user locations on an interactive real-time map;
- reporting local hazards (e.g., poisons, aggressive animals, lost dogs);
- community communication on a public forum and in private and group chat;
- gamification features, ranks, XP points, and optional digital subscriptions (DoggyRadar FULL).
3. Categories of Personal Data Processed
- Account and Authentication Data: email address, password hash (bcrypt/argon2), date of birth (required for age verification), first name / username, phone number (optional), MFA status (multi-factor authentication).
- Supervised Accounts (individuals under 16 years of age):
- guardian–child relationship linkage;
- scope and version of legal guardian consent;
- consent verification method (guardian MFA session or email double opt-in);
- technical consent evidence reference, timestamp, IP address, and User-Agent;
- internal technical domain identifier (`child-<uuid>@supervised.doggyradar.local`; children do not provide their own personal email address).
- Dog Data: name, breed, age, weight, gender, behavioral traits, microchip number, passport details, and health card.
- Geolocation and Spatial Data:
- GPS location obtained via operating system device permissions (Android / iOS);
- background location during active walks using a Foreground Service with an ongoing system notification;
- walk route coordinates, duration, and distance;
- coordinates of submitted hazard reports, dog-friendly places, and events.
- User Content: private and group chat messages, forum threads and replies, dog and profile photos (stripped of EXIF/GPS metadata prior to publication).
- Diagnostic and Technical Data: device identifiers, push notification tokens (FCM / APNs), IP addresses, error logs, and telemetry.
- Payment and Subscription Data: transaction identifiers, DoggyRadar FULL subscription status, expiration dates. The Data Controller does not process payment card numbers — billing is handled directly by Apple App Store, Google Play, or certified payment processors.
4. Purposes and Legal Bases for Processing (GDPR)
| Processing Purpose | Data Scope | Legal Basis (GDPR) |
|---|---|---|
| Registration and management of standard user account | Account data, email, password hash, birth date | Art. 6(1)(b) GDPR (contract performance) |
| Provision of Supervised Account services for minors | Child profile, dog data, walk records | Art. 6(1)(b) GDPR (contract performance) |
| Provision of map services, walk tracking, and patrol | GPS coordinates, dog data | Art. 6(1)(b) GDPR (contract performance) |
| Voluntary location sharing with other users on the map | Public map location data | Art. 6(1)(a) GDPR (GDPR consent) |
| Processing of minor's consent-based data (e.g., map visibility) | Child location data, dog profile | Art. 6(1)(a) in conjunction with Art. 8(1) GDPR (parental consent) |
| Recording and retaining legal guardian consent evidence | Guardian/child pseudonyms, scope, version, MFA, IP, User-Agent | Art. 6(1)(c) in conjunction with Art. 7(1) & Art. 8(2) GDPR (legal obligation to demonstrate consent) & Art. 6(1)(f) GDPR (defense of legal claims) |
| Chat and forum communication | Message contents, forum posts, attachments | Art. 6(1)(b) GDPR (service delivery) |
| Provision of DoggyRadar FULL subscriptions | App store purchase identifiers | Art. 6(1)(b) GDPR (contract) & Art. 6(1)(c) GDPR (tax and accounting obligations) |
| Sending push notifications regarding walks and hazards | Push token, device identifier | Art. 6(1)(a) GDPR (GDPR consent) |
| Displaying ads in free tier (Free Tier) | Advertising identifier (Google AdMob / UMP) | Art. 6(1)(a) GDPR (UMP consent; no profiling of children) |
| Ensuring security, abuse prevention | System logs, IP address, telemetry | Art. 6(1)(f) GDPR (legitimate interest) |
| Legal claims establishment and defense | Transaction records, correspondence, consent records | Art. 6(1)(f) GDPR (legitimate interest) |
*Note:* Device operating system location permissions (Android/iOS) represent hardware access permissions and are distinct from the legal bases for processing personal data under Article 6 GDPR.
5. Data Security and Communication Architecture
- Encryption in Transit: All communication between the app and server is protected using TLS (HTTPS / WSS).
- Server-Side Chat Encryption: Private and group chat messages are encrypted at rest on the server using AES-256-GCM. Chat is not end-to-end encrypted (E2EE) — the server processes and decrypts message content for standard delivery, history synchronization, and safety moderation.
- Photo Privacy: All photos uploaded to the service are automatically stripped of EXIF metadata, including GPS tags.
- Ghost Mode:
- Ghost Mode is a visibility filter that hides the dog's and guardian's position on the public map from other users;
- Ghost Mode does not stop server-side location logging and telemetry processing for walk tracking and does not provide total internet anonymity;
- For users under 16, Ghost Mode is activated based on registered birth date, except for authorized legal guardians with the `guardian_location_view` scope.
6. Data Recipients and Transfers Outside the EEA
Personal data is transferred only to trusted processors:
- EU-based cloud and hosting providers;
- push notification services (Google Firebase Cloud Messaging, Apple Push Notification service);
- app store platforms (Apple Inc., Google LLC) for subscription handling;
- Google AdMob advertising network (Free Tier only, subject to UMP consent).
Transfers outside the EEA rely on Standard Contractual Clauses (SCC) approved by the European Commission or the EU-US Data Privacy Framework.
7. Data Retention (Objective Criteria — Art. 13(2)(a) GDPR)
- Account and profile data: for the duration of the active account in the service.
- GPS coordinate history:
Raw GPS coordinates collected during walks are stored in the database only for the time necessary to compute the walk route and provide the service, after which they are automatically purged in daily retention batches (default software configuration: 90 days, configurable from 1 to 3650 days or disabled for technical diagnostics). Aggregated walk summaries (distance, duration) remain on the user profile until explicitly deleted by the user.
- Data handling upon account deletion:
- Forum posts and replies: unlinked from the user account and reassigned to a shared system account (`Użytkownik usunięty`). Post contents remain visible without original author identification (pseudonymization);
- Active hazard alerts: unlinked from the account and assigned to the system account with phone number, owner name, and email cleared;
- Inactive hazard alerts (resolved/expired): permanently deleted from the database along with the account via cascading deletion (`ON DELETE CASCADE`);
- Chat messages (private and group): direct messages where the user was sender or recipient (`chat`) and group messages sent by the user (`chat_group_messages`) are permanently deleted from the database via cascading deletion (`ON DELETE CASCADE`).
- Billing data: retained for statutory tax/accounting periods and until statutory limitation periods expire.
- Guardian consent evidence records after account deletion:
In the `guardian_consents` table, direct user foreign keys (`guardian_user_id`, `child_user_id`) are set to `NULL`, while profiles, dogs, chats, and routes are permanently purged. For statutory accountability (Art. 7(1) & Art. 8(2) GDPR) and legal defense (Art. 6(1)(c) & (f) GDPR), minimized pseudonymous audit trail records are retained:
- `guardian_pseudonym` and `child_pseudonym` — deterministic HMAC-SHA256 cryptographic hashes derived with a server secret key;
- `consent_scope` and `consent_version` — exact scope and version of granted authorizations;
- `granted_at` and `withdrawn_at` — authorization timestamps;
- `verification_method` and `verification_ref` — verification method (MFA session / email double opt-in) and request ID;
- `ip_address` and `user_agent` — network telemetry at the time of authorization.
These records are retained for the duration of statutory civil claim limitation or regulatory scrutiny periods, after which they are permanently purged. This process constitutes pseudonymization, not anonymization.
- Supervised Accounts upon consent withdrawal: retained in a locked state for 7 days (grace period), then permanently purged.
8. User Rights and Account Deletion Procedure
Users have the right to:
- access and receive a copy of their personal data (Art. 15 GDPR);
- rectify inaccurate data (Art. 16 GDPR);
- erase data — right to be forgotten (Art. 17 GDPR);
- restrict data processing (Art. 18 GDPR);
- data portability in a structured JSON format (Art. 20 GDPR — available in Profile tab);
- object to processing (Art. 21 GDPR);
- withdraw consent at any time without affecting prior lawful processing;
- lodge a complaint with a supervisory authority (in Poland: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw).
Account Deletion Procedure:
Accounts can be deleted directly in the mobile application (Profile → Settings → Your Data (GDPR) → Delete Account) or via the web form at https://doggyradar.com/delete-account. Deletion requires entering the account password, typing `USUWAM KONTO`, and MFA verification (if enabled).
