Privacy Policy

Last updated: 19 August 2026

This policy covers the Sniff-it app, which opens in September 2026. If you signed up on this website before then, the privacy notice describes what happens to that data.

1 · Who is responsible for your data

Sniff-it, part of HappyPetSpace is the controller of the personal data described here. [Registered entity name, company number and registered address — still to be filled in.]

Write to us at support@sniff-it.app about anything on this page.

2 · The short version

If you read nothing else, read this.

  • Your pet is public. You are not. Their page, their photos, their name — not yours.
  • Your email address is your account. There are no passwords.
  • Everything lives in the EU.
  • You can take it all back, in a few taps, from the app.
  • We do not sell your data, to anyone, ever, and we do not run advertising.

3 · What we collect

When you create an account: your email address, and your first and last name if the way you signed in gave them to us. Later, in the app: your handle, your city and country, your language, and a photo if you add one. When you add a pet: their name, species, breed, date of birth, sex, and their photographs, and whether they are listed and searchable. When you turn on lost mode: the contact details you choose to publish, where they were last seen, and a reward if you offer one. When you use the app: who you connected with and the messages you sent them, what you reported, and how many times your pet’s public page has been scanned.

Automatically, we collect the basic technical information needed to run and protect the service — your device type and app version, and your IP address, which we use to apply rate limits and to detect abuse. We use no advertising trackers and no cross-site tracking, and the public website sets no tracking cookies.

4 · Why we use it, and on what legal basis

Different things, different reasons, and the reason is what decides what you can ask us to stop.

  • Your account and profile, your pet’s profile and photos, their public page — to provide the service you signed up for. Basis: contract, Art 6(1)(b). Discovery does not work without a profile to discover.
  • Listing your pet in the feed and allowing search engines to index their page — so people nearby can find them. You choose this, per pet, and can change it at any time.
  • Lost mode publishing your contact details — so a finder can reach you. It only happens when you switch it on.
  • Sending you a welcome email and lost-mode alerts — making the service work. There is no marketing email in this version.
  • Rate limiting, abuse detection, moderating reports, keeping the service secure — protecting users and the service. Basis: legitimate interests, Art 6(1)(f).
  • Product analytics, in aggregate — understanding what works so we can fix what does not. Basis: legitimate interests.
  • Keeping a record of what you accepted, and when — demonstrating we did this lawfully. Basis: legal obligation, Art 5(2).

We do not use consent as the basis for the core service, and that is deliberate. Consent has to be freely given and freely withdrawn. If you withdrew it, we would have to keep processing anyway — the service cannot run otherwise — and a basis that cannot be honoured when withdrawn was never really consent. Where consent genuinely is the basis, we say so and it is genuinely refusable.

5 · What becomes public

Your pet’s page — their name, photos, breed, and age — is visible to anyone with the link. That is what the QR code resolves to, and it is the reason the product exists. If you have them listed, that page also appears in the feed and can be indexed by search engines. In lost mode, the contact details you chose are published there until you turn it off.

You are not public. Your name, email address and photo are never published, never indexed, and never shown to people you have not connected with. Someone you have connected with sees your first name and photo.

6 · Who else sees it

Other people using Sniff-it, as described above. Companies that run parts of the service for us, listed in the next section — they act on our instructions under a data processing agreement, and none of them may use your data for their own purposes. The authorities, where the law requires it, or to protect someone from serious harm.

Nobody else. We do not sell personal data and we do not share it for advertising.

7 · Where your data is, and who processes it

Your data is stored in the European Union.

  • Supabase — sign-in and sessions. EU, Frankfurt.
  • Neon — the main database. EU.
  • Cloudflare R2 — photographs. EU.
  • Upstash — caching and queues. EU.
  • Render — runs the API. EU.
  • Vercel — runs the website. EU, though static delivery is global.
  • Resend — sends the emails. EU.
  • PostHog — product analytics. EU.
  • Sentry — error reporting. Region to be confirmed.

Where a supplier’s support or infrastructure reaches outside the EU, that transfer is covered by the European Commission’s standard contractual clauses.

8 · How long we keep it

While your account is open, we keep it. When you delete your account, your pet’s page goes dark immediately and your sessions are ended. Thirty days later we destroy the personal data — photographs are deleted, and name, contact details and city are erased. What remains is an anonymous skeleton with nothing in it that identifies you, which we keep so the system stays consistent. Signing in during those thirty days cancels the deletion, and we tell you it has been cancelled rather than quietly restoring it.

A profile created on the pre-launch site and never claimed is deleted 12 months after it was confirmed, and we write to you before that happens. The record of what you accepted survives the erasure, without your name attached — it is the evidence that we did this lawfully, and deleting it would defeat its purpose.

9 · Your rights

You can see your data, correct it, delete it, take it with you in a machine-readable file, restrict or object to how we use it, and withdraw consent where consent is the basis.

Most of it you can do yourself, in the app, without asking us — that is deliberate. For anything else, write to support@sniff-it.app, and we will answer within one month. If you think we have got it wrong, you can complain to a data protection authority — in Bulgaria, the Commission for Personal Data Protection; in Ukraine, the Verkhovna Rada Commissioner for Human Rights; or the authority where you live.

10 · Children

Sniff-it is not for children under 16. [Age to confirm.] If we learn that an account belongs to someone younger, we close it and delete the data.

11 · Decisions made about you

No automated decision-making, and no profiling that has legal or similarly significant effects. The feed orders pets by city, species and what you are looking for. It does not score you.

12 · How we protect it

Everything travels encrypted. There are no passwords to steal — sign-in is a one-time code or Google or Apple, and the session token is held in your device’s secure storage. Access to production data is limited to those who need it.

13 · Changes to this policy

If we change it in a way that matters, we will show you what changed the next time you sign in, and record that we did. We do not swap it silently — that is the whole reason each version has a name.

Version privacy-2026-08-19.