Effective 16 September 2026 · Version 2026-09-16
Privacy Policy
Karan Gandhi operates PawRelay. This policy explains the information we process for the app and companion website, why it is needed, and the choices available to you. Privacy and data requests can be sent to maxsinner@gmail.com.
Information and purposes
We process account and profile details, consent records, settings, pet and care records, care-circle permissions, uploaded media, community content, Relay and lost-and-found reports, directory submissions, reviews, business claim evidence, reports and audit records to provide the functions you choose and keep them secure.
We process city and locality for relevant local content, and device tokens, timezone and recent app activity for notification delivery. Optional engagement check-ins use recent device activity, pet membership and the presence of eligible local posts. They do not use private medical text for targeting. Security and service diagnostics help investigate failures and abuse.
Visibility and sharing
Public posts, reviews, directory listings and public help reports are visible according to their audience and workflow. Directory suggestions remain restricted to the submitter and authorized reviewers until approved. Approval publishes the listing's business information, not private claim evidence.
Medical details, microchip identifiers, private documents and claim evidence require authorized access. Owners choose care-circle permissions. Exact home locations are not public by default and must not be included in public content. A Pet Passport or document shared outside PawRelay can be retained by its recipients; review its contents before exporting.
Device permissions and files
Camera, photo, location and notification permissions are requested in context and can be changed in operating-system settings. We do not continuously track background location. State and city can be selected without GPS.
Supported photos are compressed and embedded metadata is removed before upload. User uploads are limited to 2 MB after compression. Private document previews use authenticated access and memory while the preview is open. Keep original records separately. Operating-system backups, screenshots and files that you explicitly save or share remain subject to your device and recipient choices.
Processors and international services
We use Supabase for authentication, database, storage and server functions, Google Firebase for push delivery, Google for optional sign-in, and operating-system services for file and notification features. They process necessary data for those functions under their applicable terms. Infrastructure and service processing may involve locations outside India, subject to applicable restrictions and safeguards.
We do not sell personal information. We disclose information only as needed for service delivery, your chosen publication or sharing, authorized support, safety, legal compliance and protection of rights. We do not use private pet medical records or private documents in advertising.
Optional first-party usage analytics
For signed-in accounts that allow optional analytics, PawRelay also collects sanitised app errors in its own backend: a fixed error category, app version and platform, a screen template without record identifiers, and up to 12 application source-code locations. Exception messages, form input, credentials, private documents and medical text are excluded. These error records are retained for up to 90 days. The encrypted device retry queue holds at most 20 errors for 24 hours and is cleared when the account changes or collection is disabled. This does not capture every native crash or app exit.
PawRelay records screen views, foreground engagement, feature actions and business views or contact taps in its own Supabase backend to understand usage and improve the product. This uses a random installation identifier, short-lived sessions, pseudonymised account counts, app platform and version, and your selected account city. It does not collect search text, pet names, health information, document contents, contact details, exact location, advertising identifiers or recordings of your screen. A contact tap does not prove a completed call, booking or sale.
You can disable optional usage analytics in Profile, Privacy or on this Privacy Policy page. The choice takes effect on this device immediately; account changes made offline are retried when connected. This also disables optional analytics of completed product actions once your account preference syncs. Necessary business records, security and moderation logs, and notification delivery records remain separate from optional analytics.
Detailed analytics events and sessions are retained for up to 90 days, then removed by scheduled cleanup. Daily aggregate counts without account or installation identifiers can remain for up to two years. Account deletion removes linked detailed analytics, while aggregate totals may remain. Queued events on your device are limited to 200 and discarded after 24 hours. Administrators can see aggregated reports and a limited activity feed, without private content or identity details.
When connected by the operator, official Google Play and App Store reports provide aggregated downloads and stability or usage metrics. Store reports are delayed and may cover only users sharing diagnostics or satisfy store privacy thresholds. They are kept separate from PawRelay usage events. PawRelay does not install an external analytics or advertising tracking SDK.
Support requests and account security
In-app support tickets and their replies are private to the requesting account and authorised support administrators. If you choose to attach app information, the attachment contains only the app version, build and platform. Please do not send passwords, one-time codes or unnecessary medical information. Resolved tickets are removed one year after their last update; account deletion removes linked tickets and app diagnostics. Your data export includes your support conversations and retained diagnostics.
Authenticator setup uses Supabase Auth. Staff operations require a verified second factor and a live sign-in session. Session review displays a broad device category and sign-in times; PawRelay does not display raw session tokens, IP addresses or full device-identification strings in that screen. Ending another session immediately removes its privileged staff access and refresh capability, while already-issued ordinary access tokens can remain valid until expiry.
Notification choices
Care and activity notification categories can be managed in Profile, Notifications. Helpful check-ins and the local digest are optional and off until you enable them. They are limited to two in a rolling seven-day period, separated by at least 48 hours, and are not sent between 9 pm and 9 am in the device timezone. A return reminder is limited to once in 30 days and optional engagement messages stop after 30 days of inactivity.
Turning optional messages off prevents future engagement sends. We retain a minimal queue history to enforce these limits. Required security, legal and moderation information may still appear in the app or be sent by an appropriate contact method. Notification delivery may be delayed or unavailable.
Retention and security
We retain account and workflow information while needed to provide the service and meet proportionate legal, fraud-prevention, dispute, moderation and backup obligations. Data export and account deletion can be requested in the app. Some limited audit records may remain without an account identifier; information already independently saved by others cannot be withdrawn by deleting it here.
We use transport encryption, access control, database authorization, private storage, signed access where required, audit trails and restricted server credentials. These measures reduce risk but do not guarantee that every incident can be prevented. We will handle incidents and required notices according to applicable law.
Your rights and complaints
Use Profile to update your information, manage visibility, block users, control permissions, request an export and request deletion. Contact maxsinner@gmail.com for access, correction, erasure, consent withdrawal or other applicable rights. We may proportionately verify identity and authority before releasing or changing private information.
Indian privacy and consumer laws apply according to their commencement dates and requirements. These choices do not waive additional rights as they come into force. Grievances may be addressed to Karan Gandhi at the same contact with the subject PawRelay privacy grievance. Applicable court, regulator and grievance-appellate remedies remain available.
Adults only and policy changes
PawRelay accounts are for people aged 18 or older. Do not provide children's personal information. If you believe a child has submitted personal information, contact us so we can investigate and take appropriate action.
We publish the version and effective date of updates and request renewed acceptance when appropriate. Material privacy changes will not be treated as permission for unrelated advertising. Questions about this policy can be sent to maxsinner@gmail.com.