Privacy Policy

Draft version 0.1-draft · Draft date: 16 July 2026 · Status: DRAFT — not yet legally reviewed

This draft explains what personal data Waggy processes, why, on which legal basis, who receives it, how long we keep it, and the rights you have under the GDPR. It is written to match what the Waggy platform actually does today (private beta).

How to read the highlights in this draft:

[PLACEHOLDER: …] — a company fact that does not exist yet (Waggy is not yet registered). Nothing here is invented.

[LEGAL REVIEW / PRODUCT DECISION: …] — an open question that Belgian legal counsel (or a product decision) must resolve.

1. Who is responsible (controller)

Controller: [PLACEHOLDER: registered legal entity name], [PLACEHOLDER: registered business address], company number [PLACEHOLDER: company number (KBO/BCE)].

Privacy contact: [PLACEHOLDER: privacy/GDPR email]. [LEGAL REVIEW: whether a DPO must or should be appointed given criminal-record data processing.]

Waggy is not yet formally incorporated; the controller identity must be completed before public launch.

2. Who this policy covers

  • Owners — people who book pet care
  • Providers — independent pet-care providers offering services
  • Administrators / staff accounts operating the platform
  • Visitors using public pages or the AI help assistant without an account

3. What data we process (actual processing map)

Account & profile: name, email, password (stored as a bcrypt hash — never in plain text), role, locale, phone (where provided), profile details and photos; Provider profiles additionally: services offered, prices, availability calendar, city/service area, bio.

Pet information: pet profiles (name, species/breed, age, care notes, vet information) and pet documents uploaded by Owners (e.g. vaccination records).

Provider verification (safety programme): email/phone confirmation status; identity document images (front/back); for safety-sensitive services a criminal-record extract. These files are encrypted (AES-256-GCM) before storage, are accessible only through authenticated, role-checked endpoints, and every access is written to an audit log. [LEGAL REVIEW: criminal-record extracts are Article 10 GDPR data — Belgian counsel must confirm the lawful basis, necessity, retention and whether processing by a private platform is permissible in this form. Real collection is currently DISABLED in production pending this review.]

Provider status & business details (marketplace transparency): the Provider’s declared status (private individual or professional/business provider (trader)), the declaration timestamp and accuracy confirmation, and — for traders — self-declared business details: legal/trading name, KBO/BCE company number, VAT number where applicable, business address, business contact email/phone and an optional self-certification. Status declarations, administrator corrections and business-details verification decisions (including the verification method used) are recorded in an audit history with redacted business summaries. During the private beta only the status, legal/trading name and KBO/BCE number are shown publicly; the business address and contact details are not publicly displayed. Self-declared business details are not presented as verified unless an administrator has completed an official-registry check or a documented manual verification. A wider pre-contract disclosure may be required after Belgian legal review. [LEGAL REVIEW: public vs pre-contract disclosure scope (LD-2) and retention of business details after a status change or account deletion (LD-7).]

Bookings & payments: booking details (service, times, price, status history, cancellation reasons), payment status, platform fee and payout amounts, tips. Card details are processed by Stripe — Waggy never stores full card numbers. Provider payout data (Stripe Connect account references, payout audit log).

Location data: live GPS location updates of the Provider during an active walk/booking (shared with the Owner for that booking), and walk routes in walk reports.

Communications: in-app chat messages per booking; audio/video call metadata (who called whom, when, duration) — calls are carried by Daily.co and are not recorded by Waggy; photo walk-report updates.

Safety & integrity: incident and safety reports (including free-text descriptions and any attachments), emergency contact details you choose to store, review content and moderation actions, and automated off-platform-payment signals (chat is scanned for patterns indicating attempts to move payment off-platform; flags are reviewed by admins).

Support: support tickets and their conversation history.

AI assistant: your messages to the in-app help assistant and its answers; an AI audit log; anonymous rate-limiting counters for guests. Assistant conversations are processed by our AI model providers (see Section 6).

Technical & security: authentication tokens (stored in your browser’s localStorage), server logs, security/operations alerts, document-access and admin-action audit logs, encrypted database backups.

4. Purposes and legal bases

  • Providing the marketplace (accounts, profiles, bookings, chat, calls, tracking, walk reports) — Art. 6(1)(b) GDPR (contract).
  • Payment processing, payouts, fee accounting — Art. 6(1)(b) and 6(1)(c) (bookkeeping/tax obligations).
  • Provider verification incl. identity checks — Art. 6(1)(f) (legitimate interest in marketplace safety) and/or 6(1)(c); criminal-record extracts — Art. 10 [LEGAL REVIEW: exact Belgian basis required].
  • Provider status declaration, business-details collection, verification decisions and the related audit history — Art. 6(1)(c) (consumer-transparency and, where applicable, platform-traceability obligations) and/or 6(1)(f). [LEGAL REVIEW: exact bases, and whether DSA Art. 30 applies to Waggy in full — checklist item LD-3.]
  • Safety monitoring (incident handling, off-platform-payment detection, review moderation) — Art. 6(1)(f) (fraud prevention and user safety).
  • AI help assistant — Art. 6(1)(b)/(f). No automated decision-making with legal or similarly significant effect is performed.
  • Security, audit logging, encrypted backups — Art. 6(1)(f)/(c).
  • Marketing: Waggy currently sends NO marketing emails; in-app notifications are functional only. If this changes, consent (Art. 6(1)(a)) will be requested.

[LEGAL REVIEW: legitimate-interest assessments (LIA) to be documented for verification, off-platform-signal scanning, and audit logging.]

5. Who receives data (recipients)

  • Other users, as needed for the service: Providers see booking-relevant Owner and pet details; Owners see Provider profiles, live walk location during their booking, walk reports and reviews.
  • Waggy administrators: role-restricted access for verification review, incident handling, refunds and support; document access is audit-logged.
  • Processors listed in Section 6.
  • Authorities, where legally required.

Waggy does not sell personal data.

6. Processors and international transfers (actually used)

  • Stripe (payments, payouts, subscriptions; Stripe Payments Europe / Stripe Inc.) — card processing, Connect payouts, fraud prevention. Transfers to the US covered by the EU–US Data Privacy Framework / SCCs. [LEGAL REVIEW: confirm current transfer mechanism + DPA]
  • Daily.co (audio/video calls; US) — call session routing; Waggy does not record calls. [LEGAL REVIEW: transfer mechanism + DPA]
  • Scaleway (object storage, region nl-ams, Netherlands/EU) — stores Waggy-encrypted (AES-256-GCM) verification documents and encrypted database backups; Scaleway cannot read the content (ciphertext only, keys remain with Waggy).
  • AI model providers via our AI integration layer (OpenAI / Anthropic; US) — process help-assistant conversations. Assistant messages should not include sensitive personal data. [LEGAL REVIEW: transfer mechanism, DPA, and whether provider-side training opt-outs are contractually ensured]
  • Hosting/infrastructure: the application and its MongoDB database run on Waggy’s managed container environment [PLACEHOLDER: hosting provider legal name + region]. [LEGAL REVIEW: hosting DPA]

A complete, current processor list will be maintained at [PLACEHOLDER: official domain]/privacy.

7. Retention (actual configured periods)

  • Verification documents: automatically deleted 30 days after the review decision (approval/rejection), and immediately on account deletion (GDPR cascade); replaced document versions are deleted on replacement. Deletions run daily and are guarded against mass-deletion errors.
  • Account data: deleted or anonymised on account deletion, except data we must keep (e.g. invoicing/booking records for tax law — [LEGAL REVIEW: Belgian retention periods, typically 7–10 years for accounting records]).
  • Bookings, payments, payout audit logs: retained for the legal accounting period. [PLACEHOLDER: exact period after counsel review]
  • Chat, walk reports, GPS traces: retained while the account/booking exists; removed with account deletion. [LEGAL REVIEW: whether shorter automatic expiry should be configured for GPS traces]
  • Document-access audit logs: retained after document deletion (with document content removed and subject references anonymised on GDPR deletion) for staff accountability. [LEGAL REVIEW: confirm audit-log retention period]
  • Encrypted database backups: 30 days rolling (minimum 7 backups always kept); deleted data disappears from backups as they rotate out.
  • AI assistant logs and support tickets: [PLACEHOLDER: retention period to be defined, proposal 24 months].

8. Security (actual measures)

  • Passwords hashed with bcrypt; role-based access control on every API endpoint.
  • Verification documents encrypted with AES-256-GCM before storage; stored in a private EU bucket with anonymous access denied; no public or pre-signed URLs — every access goes through authenticated, audited endpoints.
  • Encryption keys held only in server configuration, never in the database or code repository.
  • Daily encrypted off-machine database backups with restore testing; mass-deletion guards on automated deletion jobs; operational alerting on failures.

9. Your rights

You have the right of access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20) and objection (21, including to legitimate-interest processing), and the right to withdraw consent where processing is based on consent.

Exercise: in-app (account settings — account deletion triggers the full deletion cascade including verification documents) or by email to [PLACEHOLDER: privacy/GDPR email]. We respond within one month (extendable per Art. 12(3)).

You may lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, www.dataprotectionauthority.be) or the supervisory authority of your residence.

10. Children

Waggy is not directed at children and requires users to be 18+. We do not knowingly process children’s data; pet profiles are not children’s data.

11. Changes to this policy

Material changes will be announced in-app before they take effect. The current version and date are shown at the top of this page.

Reminder: this document is a DRAFT.

It requires Belgian legal review before public launch and is shown during the private beta for transparency only. The highlighted placeholders above are intentionally visible and unresolved.