Privacy · plain-language data map

What we collect.
Why we need it.

This policy explains the information that may be processed when you visit petting.club, create an account, use Google Sign-In, place an order, join the waitlist, or contact us. The exact information depends on the features you choose to use.

Last updated .

The short version

Visiting the site may generate analytics and technical records. Accounts, purchases, waitlist signups, and support messages add only the information needed for those actions.

01 · Information

What information may be processed?

  • Site measurement. Petting uses Google Analytics. Its default web implementation may use a first-party _ga cookie and process user and session counts, page interactions, approximate location, and browser or device information. Read Google’s Analytics data-collection overview.
  • Email account. Registration uses an email address, display name, and password. The account record stores a password hash rather than the password itself, together with email-verification and account-creation information. An HTTP-only session cookie keeps track of a signed-in session.
  • Google Sign-In. If you choose this option, Petting verifies a Google credential and may receive a verified email address, Google account identifier, and display name. Petting does not receive your Google password. Google describes this flow in its Sign in with Google guide.
  • Bag and order. Petting may process product and variant identifiers, quantities, order status, amounts, currency, customer email and name, shipping address, and Stripe checkout or payment references. Stripe’s hosted checkout processes payment details; Petting’s order record does not contain a full card number.
  • Waitlist. A signup stores the email address, language or locale, signup source, and submission time so Petting can send product updates and purchasing news.
  • Messages. If you email Petting, the team receives the address, message, attachments, and any order or account details you choose to include. Never send a password.
  • Browser and service records. Browser storage may remember a language, guest bag, and selected product options. Site infrastructure may also receive request details such as a timestamp, requested page, IP address, and browser information for delivery, troubleshooting, and security.

02 · Purpose

How may Petting use this information?

  • Operate the website, account sessions, saved bag, email verification, and account support.
  • Create and maintain checkout and order records, calculate totals, confirm payment status, and help with delivery or refunds.
  • Send the product and purchasing updates requested through the waitlist.
  • Reply to product, privacy, editorial, account, order, press, or partnership messages.
  • Measure site use, diagnose failures, secure the service, prevent abuse, and maintain business or legal records where needed.

03 · Services

Which other services may handle information?

Petting currently integrates Google Analytics for measurement, Google Identity Services for optional account sign-in, Stripe for hosted checkout and payment processing, and service providers used to host the site, database, and operational email. Each provider processes information under its own terms and privacy practices.

For checkout details, read Stripe’s privacy policy. For Google services, read Google’s privacy policy.

04 · Cookies and storage

What stays in the browser?

Google Analytics may set a first-party identifier such as _ga. A Petting account session uses an HTTP-only session cookie so a signed-in account can be recognized. Local browser storage may keep language, guest-bag, and product-option choices. Signing out clears the account session cookie, but local choices may remain until you clear them in the browser.

You can remove or block cookies and local storage through browser controls. Doing so may reset preferences or prevent account and checkout features from working as expected.

05 · Retention and protection

How long is information kept?

Retention depends on why the information was collected. Account and order records may be kept while they are needed to provide the service, support a transaction, resolve a request, protect the service, or meet accounting and legal needs. Waitlist information may be kept while the signup remains active. Analytics and third-party services apply their own configured retention periods.

Petting uses measures visible in the current service design, including password hashing, email verification, HTTP-only account session cookies, and Stripe-hosted payment entry. No online service can promise absolute security.

06 · Choices

What can you ask Petting to do?

You may email hello@petting.club to ask about access, correction, deletion, a waitlist signup, or another privacy concern. Include enough context to locate the relevant account, order, signup, or message, but never include a password or full payment-card number.

Requests are reviewed based on the information involved and any verification, security, recordkeeping, or applicable-law requirements. Google and Stripe provide separate controls for information they process directly.

07 · Updates

How will this policy change?

Petting may update this page as the site, account, checkout, analytics, or support practices change. The date at the top shows the latest published version. Material changes should be read before continuing to use an affected feature.

08 · Petting Diary App

Petting Diary on iOS and iPadOS

This section applies to the Petting Diary iOS and iPadOS App and supplements the website disclosures above. The App processes data only for the features you choose to use.

Data the App handles and why

  • Account and pet profiles. The App processes your account name, email address, internal user ID, sign-in provider, and the pet profile information you enter. It uses this data to authenticate you, associate diaries and paired devices with the correct account, sync the content you choose, and provide support.
  • Photos, videos, and audio you choose. The App processes only photos and videos you actively choose to capture or upload, including audio contained in a selected video. It uses them to create, store, sync, display, and let you manage diary entries. A file is not uploaded until you choose it for upload.
  • Device location and Petting One GPS routes. With your iOS permission, the App may process device location for map and location features you request. If you pair Petting One, GPS coordinates, timestamps, and related pet or device identifiers may be processed to show recent positions and routes and support lost-pet recovery. You can revoke location permission in iOS Settings; affected features may stop working.

Uploads, security, and service providers

For a media upload, the App asks the Petting API for a short-lived presigned URL and then sends the file directly over HTTPS to Cloudflare R2. Your Petting authentication token is stored in the iOS Keychain and sent only to the Petting API when required to authorize a request. The token is never sent to R2 or embedded in an uploaded file.

If you choose Sign in with Apple or Google, that provider handles sign-in and may give Petting a provider user identifier, name, and email address according to your choices. Cloudflare handles media upload, storage, delivery, and associated network and security data. Petting also uses hosting, database, email, and security providers only as needed to operate the service. Those providers must protect data to the same or an equivalent standard under their agreements and applicable law. Read Apple’s privacy policy, Google’s privacy policy and Cloudflare’s privacy policy for their practices.

Petting does not sell App data, use it for cross-app advertising tracking, or use Petting Diary content, location, or GPS routes for targeted advertising. The App does not use Apple’s advertising identifier (IDFA).

Retention and deletion

  • While you keep the data. Account, pet profile, diary media, location, and Petting One GPS route data are kept while your account is active and the data is needed for requested features, or until you delete the item or account. A cloud media object in R2 is kept on the same basis as the diary item it supports.
  • Temporary and local data. Presigned upload URLs are temporary and expire automatically. Local copies and cached files remain only as managed by the App and iOS and can be removed by deleting the item or the App, as applicable. The Keychain token remains only until you sign out, it expires or is invalidated, or account deletion is completed.
  • Delete your account and cloud data. Use Settings > Account > Delete Account in the App, or email hello@petting.club from the address associated with your account. After identity verification, Petting completes deletion of the account, pet profiles, diary records, media in Cloudflare R2, location data, and GPS routes from active cloud systems within 30 days. Isolated backups are deleted or overwritten within 90 days. Petting may keep only records required by law or reasonably necessary for transaction records, fraud prevention, disputes, or security, and will explain an applicable exception.

For access, correction, consent withdrawal, deletion, or another App privacy request, email hello@petting.club.

Related pages