Privacy Policy
This policy explains what personal data Walifi uses, why it is used, who receives it, how long it is kept, and the choices and rights available to you.
1. Controller and contact details
The controller is [LEGAL ENTITY NAME], registration number [REGISTRATION NUMBER], registered at [REGISTERED ADDRESS] ("Walifi", "we", "us"). Privacy and data-rights requests: support@walifi.app. Data protection officer or representative, if required: [DPO/REPRESENTATIVE CONTACT OR "NOT APPOINTED"].
2. Data we collect
- Account and identity: name, email, phone, profile image, verification status, country, language, currency, timezone, and account preferences.
- Pet information: pet identity, species, breed, photos, care instructions, behavior, medical or health notes you choose to provide, ownership, and member access.
- Provider and marketplace information: provider profile, identity or qualification checks, services, prices, availability, service areas, applications, listings, requests, bids, and reviews.
- Bookings and support: booking details, addresses needed for a service, cancellations, disputes, refund and support communications, and related evidence.
- Payments and wallet: transaction identifiers, amounts, currency, authorizations, refunds, payouts, platform fees, ledger records, and limited payment-method information supplied by the payment processor. Walifi should not store full card numbers.
- Community and communications: posts, comments, likes, media, reports, blocks, moderation actions, chat messages, attachments, and location messages you intentionally publish during supported booking flows.
- Device, security, and diagnostics: device and app version, operating system, push token, IP address, timestamps, request identifiers, authentication and security events, crash data, performance measurements, and technical logs.
- Usage and recommendation signals: views, taps, likes, comments, searches, feed interactions, and inferred relevance scores used to operate and improve recommendations.
3. Why we use data and our legal bases
- Contract: create and secure your account; provide bookings, chat, marketplace, payment, wallet, export, and account-deletion features; and provide requested support.
- Legitimate interests: prevent fraud and abuse; protect users and animals; moderate content; maintain service security and reliability; understand service performance; and improve non-intrusive recommendations. We balance these interests against your rights.
- Legal obligation: keep accounting, tax, payment, consumer, safety, sanctions, and law-enforcement records where applicable and respond to valid legal requests.
- Consent: optional marketing, device permissions, or processing that legally requires consent. You can withdraw consent without affecting earlier lawful processing.
- Vital interests or legal claims: handle a serious safety emergency or establish, exercise, or defend legal claims where applicable.
4. Sensitive and third-party information
Pet health notes can sometimes reveal information about an owner or household. Only provide information that is necessary for safe pet care and that you are entitled to share. Do not add another person's medical information to pet notes, posts, or chats.
If you provide information about another person—for example a co-owner, household member, emergency contact, or person shown in media—you are responsible for having an appropriate basis to share it and for directing them to this policy where required.
5. When information is visible or shared
- Other users receive information you make public, such as profile details, services, posts, comments, media, and reviews.
- A customer and provider receive booking and communication information needed to arrange and perform a service. Phone or precise address information should only be disclosed when the product indicates it is necessary for that booking.
- Moderators and authorized administrators access reports, evidence, account details, and audit records only as needed for safety, support, disputes, and compliance.
- We may disclose data to authorities or other parties when legally required or reasonably necessary to protect rights, safety, animals, users, or the service.
- If the business is reorganized or sold, data may be transferred subject to appropriate confidentiality and data-protection safeguards.
6. Service providers and international transfers
Walifi uses processors for hosting and databases, object storage and backups, transactional email, payment processing, push notifications, video processing, customer support, and—once enabled—error monitoring. Expected providers include Railway or the approved hosting provider; Cloudflare R2; [TRANSACTIONAL EMAIL PROVIDER]; [PAYMENT PROVIDER]; Expo; Coconut; and Sentry. The final published list must reflect the production configuration.
Some providers may process data outside the EU/EEA. Where required, Walifi will use an adequacy decision, the European Commission's Standard Contractual Clauses, and supplementary safeguards, and will maintain data-processing agreements with processors.
7. Retention
- Account data is generally kept while the account is active. An approved deletion request has a 30-day restoration period before final anonymization or deletion.
- Booking, payment, payout, refund, wallet, tax, accounting, dispute, fraud, moderation, and audit records may be kept after account deletion for the applicable statutory period or while a legal claim or safety need remains.
- Posts and associated media are deleted during final account purge; authored comments are tombstoned; review text is removed while the rating may remain; chat history linked to bookings or disputes may be retained with the identity anonymized.
- Security and technical logs should be kept for a short, documented period. Sentry event retention will follow the selected plan and Walifi's configured deletion period.
- Backups and point-in-time recovery data expire according to the documented backup schedule and are not restored to reactivate intentionally deleted accounts except where technically unavoidable during disaster recovery.
8. Account deletion and data export
You can request deletion in Walifi settings or through the public page at /delete-account. Active bookings, active service requests or bids, and ownership of a shared pet may need to be resolved first. Sessions and push tokens are revoked when deletion is confirmed. You can restore the account during the 30-day period.
A deletion-request email includes a time-limited export link. The current export covers core profile, pet, booking, post, comment, and review information. Before final GDPR launch approval, Walifi must verify that the export also covers all required wallet, transaction, preference, moderation, and other personal data without exposing another person's private data.
9. Your rights
Send requests to support@walifi.app. We may need to verify your identity. We normally respond within one month, subject to GDPR extensions for complex requests. Rights can be limited where the law allows or requires it.
- Request access to and a copy of your personal data.
- Request correction of inaccurate or incomplete data.
- Request deletion or restriction, subject to lawful retention exceptions.
- Object to processing based on legitimate interests and object at any time to direct marketing.
- Receive data you provided in a structured, commonly used, machine-readable format where data portability applies.
- Withdraw consent where processing relies on consent.
- Ask for human review where a legally significant decision is made solely by automated means. Walifi does not currently intend to make such decisions without human review.
- Lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
10. Security
We use measures intended to protect data, including access controls, encrypted network connections, credential and session controls, private backups, rate limiting, audit records, and restricted administrative permissions. No system is completely secure. Please report suspected account or security incidents to support@walifi.app.
11. Children
Walifi's paid booking and provider features are intended for adults. Walifi is not designed to collect children's data without an authorized guardian or another lawful basis. If you believe a child has provided data contrary to these rules, contact us so we can investigate and take appropriate action.
12. Changes to this policy
We may update this policy as the service, processors, or law changes. We will publish the updated date and version and provide additional notice or request acknowledgement where a change materially affects your rights or processing.