Privacy Policy
Last updated: February 2026
Paw Cities ("we," "our," or "the Company") is committed to protecting your privacy and ensuring you have a positive experience on our website and services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, password, and profile information. This information is necessary to create and maintain your account.
Dog Profile Information
If you choose to create dog profiles, we collect information about your dogs including their name, breed, age, size, personality traits, and photos. This information helps personalize your experience.
Usage Data
We automatically collect information about how you interact with our platform, including pages visited, establishments viewed, reviews written, check-ins recorded, and favorites saved. This helps us improve our services.
Location Data
If you enable location services, we may collect your approximate geographic location to show nearby dog-friendly establishments. Location data is only collected when explicitly authorized by you.
Device Information
We collect information about the devices you use to access our platform, including device type, operating system, browser type, and unique device identifiers.
Cookies and Tracking
We use cookies, web beacons, and similar tracking technologies to personalize your experience, remember your preferences, understand usage patterns, and prevent fraud. You can control cookie settings in your browser.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing and improving our services
- Creating and managing your account
- Personalizing your experience and showing relevant dog-friendly establishments
- Processing and managing your reviews, check-ins, and favorites
- Communicating with you about your account, updates, and new features
- Responding to your inquiries and customer support requests
- Conducting research and analytics to improve our platform
- Detecting and preventing fraud, abuse, and security incidents
- Complying with legal obligations and enforcing our Terms of Service
3. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Consent: When you have explicitly consented to the processing
- Contract Performance: To provide the services you have requested
- Legal Obligation: To comply with applicable laws and regulations
- Legitimate Interests: To improve our services, prevent fraud, and operate our business
- Vital Interests: To protect your health, safety, or vital interests
4. Third-Party Service Providers
Supabase
We use Supabase for authentication and database services. Supabase is certified as a GDPR-compliant data processor and handles user credentials securely.
Stripe
If applicable, we use Stripe for payment processing. Stripe is PCI-DSS compliant and processes payment information securely without us accessing your full payment details.
Cloudinary
We use Cloudinary to store, optimize, and deliver images of establishments and user-uploaded photos. Cloudinary maintains GDPR compliance.
Third-Party Analytics
We may use analytics services to understand usage patterns and improve our platform. These providers are GDPR-compliant and process data only on our behalf.
5. Data Retention
We retain your personal data for as long as necessary to provide our services and fulfill the purposes described in this policy. Specifically:
- Account data is retained while your account is active
- Usage data and analytics are retained for up to 12 months
- Dog profile information is retained until you delete it or your account
- Reviews and check-ins are retained indefinitely to maintain the integrity of our platform, unless you request deletion
- Location data is not stored permanently; it is processed only to show nearby establishments
- When your account is deleted, we anonymize personal data within 30 days
6. Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of all personal data we hold about you. You can request a data export through your account settings or by contacting us.
Right of Correction
You have the right to correct inaccurate or incomplete personal data. You can update most information directly in your account settings.
Right of Erasure
You have the right to request deletion of your personal data, subject to certain legal exceptions. We will delete your account and anonymize your data within 30 days of your request.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly-used, machine-readable format and to transmit that data to another service. We provide a data export feature for this purpose.
Right to Restrict Processing
You have the right to restrict how we process your personal data in certain circumstances. You can control marketing communications and data usage through your account settings.
Right to Object
You have the right to object to processing for legitimate interests, marketing communications, and automated decision-making. You can manage these preferences in your account.
Rights Related to Automated Decision-Making
We do not use your data for automated decision-making that produces legal or similarly significant effects without your consent.
7. Data Security
We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of sensitive data at rest
- Secure authentication mechanisms
- Regular security audits and penetration testing
- Access controls limiting data access to authorized personnel
- Secure backup and recovery procedures
- Incident response plan for data breaches
8. International Data Transfers
If we transfer personal data outside the European Economic Area (EEA), we implement appropriate safeguards such as Standard Contractual Clauses to ensure an adequate level of protection in compliance with GDPR.
9. Cookies and Tracking Technologies
Essential Cookies
These cookies are necessary for authentication and security. They cannot be disabled.
Functional Cookies
These cookies remember your preferences and personalization settings.
Analytics Cookies
These cookies help us understand how you use our platform to improve it. You can opt-out of analytics.
Marketing Cookies
We do not use marketing or advertising cookies at this time.
10. Children's Privacy
Paw Cities is not intended for children under 13 years of age, and we do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will delete it immediately. Parents or guardians who believe we have collected information about their child may contact us at the email below.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, regulations, or other factors. We will notify you of material changes by updating the "Last Updated" date and prominently displaying changes on our website. Your continued use of Paw Cities after changes constitutes your acceptance of the updated Privacy Policy.
12. Contact Information & Data Protection Officer
If you have questions about this Privacy Policy, wish to exercise your GDPR rights, or believe we have mishandled your personal data, please contact us:
Email: eric.silverstein@icloud.com
Reference: Data Protection Officer / Privacy Inquiry
13. Complaint Rights
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights. You can find contact information for your local authority at https://edpb.ec.europa.eu/about-edpb/board/members_en.
Have questions about your privacy? Contact our Data Protection Officer.
Contact DPO