Privacy
PackStack privacy notice
Version 1.0-draft.3. This public route is technically available, while the notice itself remains subject to named product and legal approval.
Product owner and qualified legal/privacy reviewer approval against the exact production release.
- Effective date
- Pending legal approval
- Last updated
Scope and approval status
PackStack is used by pet-business operators, staff, and clients. This review draft summarizes data handling identified in the version 1 app and its first-party services.
The responsible legal entity, applicable legal bases, jurisdiction-specific rights, and final representations about sale, sharing, or tracking have not been approved. This draft must not be treated as the final App Store privacy policy until its status is changed to approved.
Information the product is designed to handle
The release inventory identifies the following categories. Availability depends on a user's role, the business configuration, and the features enabled for the submitted build.
- Account and identity data, including names, email addresses, phone numbers, authentication identifiers, roles, and business memberships.
- Pet-care and business records, including client and pet profiles, bookings, visits, service notes, contacts, invoices, and financial or operational records.
- User content, including messages, intake responses, photos, files, reports, and credential documents.
- Audio data, transcripts, and derived voice-command results when an authorized operator explicitly starts the opt-in Voice feature.
- Precise foreground location used for enabled pickup, drop-off, and visit-route workflows.
- Device and notification data, including push tokens, notification preferences, delivery receipts, and app or device context needed to deliver notifications.
- Integration data from services a business chooses to connect, including calendar and other provider records within the scopes that are enabled.
- Security, audit, diagnostic, and product-interaction records such as request identifiers, bounded error codes, and delivery or sync status.
Evidence-derived purposes
The reviewed product uses these categories to authenticate users, enforce role and tenant access, provide care and business workflows, deliver messages and notifications, synchronize enabled integrations, protect the service, diagnose failures, and respond to support requests.
Product and legal reviewers must approve the final purpose, legal-basis, sale, sharing, and tracking disclosures before this notice becomes effective.
Location controls
The production configuration reviewed for this draft permits foreground location for enabled visit workflows and disables production background-location collection. The current technical design queues encrypted route points on the device for up to 24 hours when delivery is interrupted.
The service evidence describes a 30-day default for authoritative exact-location points, configurable by a business owner to 30, 90, 180, or 365 days, plus owner controls that erase exact points from closed visits while retaining coordinate-free audit records. Legal and product approval of the production purpose and selected retention remains pending.
Service providers and connected services
The technical inventory identifies Supabase, Vercel and Vercel Blob, Fly, Expo/EAS, Expo Push Service, Apple Push Notification service, Google, OpenAI, OpenRouter, Anthropic, NVIDIA NIM, Sentry, Stripe, Resend, and business-selected integration providers as potential processing surfaces for the features they support.
This list does not establish final controller, processor, subprocessor, international-transfer, or retention terms. Those terms and the exact providers enabled in the submitted release require approval.
Retention and deletion
Some feature-specific controls exist, including the location windows described above and device-scoped encrypted cache reset. Complete production retention rules for messages, photos and files, credentials, business and financial records, push records and tokens, logs, audits, and backups remain pending.
The reviewed source includes an authenticated in-app path to submit, view, and cancel an account-deletion request. A narrow backend fulfillment procedure can delete an eligible staff-only authentication account after a 24-hour cancellation window and records completion only after the database confirms that deletion. Client-portal requests require manual data review, while owner, admin, mixed-role, and restrictive-dependency identities remain outside automated fulfillment.
Approved retention and anonymization decisions, broader-role fulfillment, backup handling, a confirmation channel usable after authentication deletion, and final completion-time commitments remain pending. Until those requirements are approved, implemented, and tested end to end, this request path is not a complete Apple account-deletion flow.
Signing out or clearing a device cache does not delete an account or authoritative server records.
Questions and privacy requests
Contact hello@topdogsf.com with a privacy question or data request. The final notice must add any legally required rights, verification steps, response periods, appeals, and regional disclosures before approval.
Change history
- 1.0-draft.3 — : Adds the evidence-derived opt-in voice data category and the known AI, diagnostics, billing, and email processing surfaces without changing draft approval status.
- 1.0-draft.2 — : Records the request, status, and cancellation surface while keeping end-to-end erasure and retention decisions explicitly blocked.
- 1.0-draft.1 — : Initial repository-backed review draft covering the current mobile privacy inventory and explicit approval gaps.
Need help? Visit PackStack Support.