Legal
Privacy Policy
Effective date: May 13, 2026 · Last updated: May 14, 2026
BoomBoomBuddy ("we", "us", "our") respects your privacy. This Privacy Policy explains what personal data we collect when you use our websites, apps, AI features, walker bookings, marketplace, missing & found pet network, and community feed (the "Service"); how we use and share that data; and the rights you have. It applies in addition to our Terms of Service.
1. Who we are
BoomBoomBuddy operates the Service. For questions about this policy or to exercise your rights, contact us at privacy@boomboombuddy.com. EEA/UK users can also reach our data protection contact at the same address.
2. Data we collect
Account data: name, email, password hash, profile photo, language, time zone, household members and roles, and authentication identifiers (including Google sign-in if used).
Pet data: name, species, breed, sex, weight, date of birth, photos, microchip number, vet contacts, vaccinations, allergies, behavior notes, and other records you choose to add.
Location data: precise GPS during active walks, last-seen coordinates on missing/found reports, approximate location (from your IP) for nearby alerts and weather, and home or service area you set.
Booking & marketplace data: walker bookings, schedules, messages with providers, listings, orders, ratings, and reviews.
Payment data: handled by our payment processor (Stripe). We receive limited information (last 4 digits, brand, country, transaction status) but never your full card number.
Community data: posts, comments, likes, reactions, photos, hashtags, follows, and reports/blocks you submit or receive.
Device & log data: IP address, browser/OS, device identifiers, crash logs, referrer URLs, pages viewed, and timestamps.
Communications: emails, in-app messages, and support tickets you exchange with us, including content and metadata.
AI inputs and outputs: prompts you send, photos you submit for analysis, and the responses generated for you.
3. How we use your data
We use personal data to: (a) provide, operate, and improve the Service; (b) authenticate accounts and prevent fraud; (c) match missing & found pets, deliver hazard and broadcast alerts within range, and surface nearby walkers and parks; (d) process bookings, payouts, and marketplace orders; (e) personalize content, recommendations, and AI assistance; (f) send transactional emails (receipts, password resets, found-pet matches) and, with your consent or where allowed, marketing emails; (g) maintain safety, enforce our Terms, and comply with law; (h) conduct analytics and product research using aggregated or de-identified data.
4. Legal bases (EEA/UK users)
We rely on the following GDPR legal bases: contract performance (to deliver the Service you requested), legitimate interests (to keep the Service safe, secure, and improving), consent (for marketing communications, optional cookies, and certain location uses where required), and legal obligation (to comply with tax, accounting, and law-enforcement requirements). You may withdraw consent at any time without affecting prior processing.
6. Location data & GPS
Precise location is collected only when you actively use a location-dependent feature (start a walk, share last-seen location on a report, opt into nearby alerts). You can revoke device-level location permission at any time in your operating system settings; some features will then stop working.
Missing-pet broadcasts use the report's last-seen coordinates and your approximate location to filter alerts within roughly 25 km. Coordinates attached to reports are visible to other users.
7. Photos & uploads
Photos you upload (pet photos, missing/found photos, community posts, marketplace listings) are stored on Cloudinary and served via secure URLs. Embedded EXIF metadata may be stripped during processing. Be mindful that publicly visible photos can be saved or shared by other users.
8. AI features
When you use AI features, your prompts and any photos you submit are sent to our AI model providers solely to generate a response for you. We do not use your AI inputs to train third-party foundation models. We may retain logs for safety, debugging, and product improvement and may use aggregated, de-identified information to evaluate model quality.
10. Emails & broadcasts
We send transactional emails (receipts, security alerts, booking confirmations, found-pet matches, password resets) as part of the Service. Marketing emails (newsletters, product updates) require consent and include an unsubscribe link in every message. Missing-pet broadcast emails are sent to nearby members in connection with the safety network; you can opt out of broadcast emails at any time.
11. Children's privacy
The Service is not directed to children under 16 (or the age of digital consent in your country). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. International data transfers
Our service providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, and we apply additional technical and organizational measures.
13. Data retention
We keep personal data only as long as needed for the purposes above, to comply with law, resolve disputes, and enforce our agreements. When you delete your account, we delete or anonymize your personal data within 30 days, except where we are required to retain it (for example, financial records for tax purposes, or fraud prevention logs).
14. Security
We use industry-standard measures including encryption in transit (TLS), encryption at rest for sensitive fields, role-based access control, row-level security on our database, and regular monitoring. No system is perfectly secure; please use a strong unique password and enable 2-factor authentication where available.
15. Your privacy rights
Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; restrict or object to certain processing; withdraw consent; receive a portable copy of data you provided; and lodge a complaint with your local data protection authority. To exercise these rights, email privacy@boomboombuddy.com or use the in-app account controls. We will verify your identity before responding.
16. California rights (CCPA/CPRA)
California residents have the right to know what categories of personal information we collect, the purposes of collection, the categories shared with service providers, and to request deletion or correction. We do not sell or share personal information for cross-context behavioral advertising. You may exercise your rights through the contacts above; we will not discriminate against you for exercising them.
17. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in the app or by email. The "Last updated" date at the top reflects the most recent revision.
18. Contact us
For privacy questions or requests, email privacy@boomboombuddy.com or visit our contact page.