Privacy Policy
Privacy Policy
Effective date: April 23, 2026 · Version 1.0
WhiskerAlert is built on a privacy-first principle. We collect only what is necessary to operate the platform and reunite pets with their families. We do not sell your personal information, and we do not use it for advertising.
1. What We Collect
We collect the following information when you use WhiskerAlert:
- Email address — collected when you submit a lost or found pet report, or when you request a magic link or admin OTP code.
- Pet location (GPS coordinates or address) — the location where your pet was last seen or found. This is not your real-time location.
- Pet photos and descriptions — content you voluntarily submit as part of a pet case report.
- IP address — collected automatically by Cloudflare to detect abuse, apply rate limits, and protect the platform.
- Device and browser information — basic technical metadata collected by Cloudflare analytics. No persistent device fingerprinting is performed.
- One-time password (OTP) codes and session tokens — short-lived codes sent by email to authenticate your access. Session tokens expire automatically.
2. How We Use Your Information
- Displaying your pet report to community members who may be able to help.
- Sending you email notifications related to your case (sighting reports, status updates).
- Authenticating your access to manage or close your own case.
- Detecting and preventing abuse, spam, and fraudulent submissions.
- Moderating content to keep the platform safe and accurate.
- Operating and improving the technical infrastructure of the platform.
We do not use your information for targeted advertising, profiling, or sale to third parties.
3. Location Data — Your Pet’s Location, Not Yours
We capture the pet’s reported location, not your real-time location.
When you submit a report, we ask for the location where your pet was last seen or where a found pet was discovered. This location is used to place a pin on the public map to help searchers in the area.
The pet’s location is displayed publicly on the case page. Your home address or personal location is never required and is never shown publicly.
4. What We Share — Third-Party Services
- Cloudflare (infrastructure, CDN, analytics) — All traffic passes through Cloudflare’s network for DDoS protection, caching, and aggregate analytics.
Cloudflare Privacy Policy - Resend (transactional email) — Used to deliver OTP codes, case alerts, and sighting notifications. Your email address is transmitted to Resend for delivery only.
Resend Privacy Policy - Stripe (optional supporter payments) — Payment processed by Stripe. WhiskerAlert does not store card numbers.
Stripe Privacy Policy
5. Cookies and Analytics
WhiskerAlert does not use third-party tracking cookies, advertising pixels, or behavioural analytics tools. We use Cloudflare Web Analytics, which is privacy-preserving by design: no cookies, no cross-site tracking, no user profiles.
6. Data Retention
- Active cases — retained while the case is live and open.
- Closed cases — retained for 90 days after closure, then purged. Photos deleted at the same time.
- OTP codes — expire after 10 minutes and are purged nightly.
- Session tokens — expire after 8 hours (admin) or 72 hours (user access links).
7. Your Rights Under PIPEDA
You have the right to access, correct, or delete your personal information. To exercise these rights, contact us at privacy@whiskeralert.com. Requests fulfilled within 30 days.
8. Contact
Privacy: privacy@whiskeralert.com
Legal: legal@whiskeralert.com
Support: whiskeralert.com/support