Privacy Policy
Last updated: October 6, 2026
This privacy policy explains how personal data is processed on this site.
What we collect and why
Name and email address
Used to create and manage your account and to send one-time sign-in links. Some client accounts are phone-only and have no email address on file. Legal basis: Art. 6(1)(b) GDPR — necessary for performance of a contract.
Contact details
Phone number, postal address, and the notes trainers record to deliver training services. Legal basis: Art. 6(1)(b) GDPR — necessary for performance of a contract.
Cookies
A technically necessary cookie (__Host-id) that keeps you signed in. Sessions expire after 30 days of inactivity, or 90 days at most. A second, short-lived flash cookie carries a one-time status message — which can include the email address you requested a sign-in link for — and is cleared once shown. Your theme preference is kept in your browser's local storage. Legal basis: § 25(2) No. 2 TDDDG — strictly necessary.
Security and session records
When sessions are created or terminated, we record an event log including the event type, your user ID, device category, city, and country. We also record when each session was last used, refreshed at most once every five minutes. This data is processed by Cloudflare as part of the Workers runtime and is used solely to detect and investigate security anomalies. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting the security of this service.
Server request data
When a visitor loads a page or an image, edge servers process the visitor's IP address and basic request metadata (such as user agent and referring URL) to route and deliver the response. Pages and images are served via Cloudflare. To monitor the operational health and security of this service, request metadata (URL, HTTP method, status code, and duration) and application log events are processed by Cloudflare. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating, monitoring, and securing this service.
Records you create
Client and dog profiles (including contact details, vaccination records, allergies, and bite-history notes), training goals, homework and progress logs, one-to-one sessions, group-class registrations and attendance, session packages, and contact-log entries. Legal basis: Art. 6(1)(b) GDPR — necessary for performance of a contract.
Photos and documents
Dog photos that trainers upload to a dog's profile, vaccination certificate images, and scanned client waivers. Legal basis: Art. 6(1)(b) GDPR — necessary for performance of a contract.
Calendar links
If you choose "Add to Google Calendar" on a session, the session title, time, and location are placed in a link to Google Calendar and shared with Google when you open it. If you choose "Download .ics", the file is generated by us and no third party is involved. Legal basis: Art. 6(1)(b) GDPR — necessary for performance of a contract.
We do not use cookies for advertising or analytics, and we do not sell personal data.
Data processors
Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) — provides the technical infrastructure this site runs on, including the runtime environment, database, image storage, and sending one-time sign-in emails (Cloudflare Email Service). The database, image storage, and email sending are processed by Cloudflare in the United States. These transfers outside the EU are carried out under the EU Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR. Cloudflare's privacy policy.
Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855 Luxembourg) — used in the Frankfurt region (eu-central-1) for image transformation via a self-hosted imgproxy function on AWS Lambda: a Lambda function fetches a stored image from Cloudflare R2, produces a re-encoded or resized variant, and stores it back in R2. This runs when a visitor requests an image variant in a specific size or format, and when a vaccination certificate or waiver image is uploaded. For any processing or transfers outside the EU by AWS's parent entities, the EU Commission's Standard Contractual Clauses apply under Art. 46(2)(c) GDPR. AWS's privacy notice.
How long we keep your data
Session data is deleted automatically after 30 days of inactivity, or 90 days at most. Magic-link sign-in tokens are short-lived and invalidated once used. Account data and the records you create are retained for as long as your account is active. Following a deletion request, your data will be removed without undue delay.
Your rights
Under GDPR, you have the following rights:
- Access to the personal data held about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure of your data (Art. 17)
- Restriction of processing (Art. 18)
- Data portability in a common format (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
- Withdrawal of consent at any time, without affecting prior processing (Art. 7(3))
To exercise any of these rights, contact privacy@houndsync.com.
Right to complain
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible is the data protection supervisory authority of the German state in which the controller is established.
Who is responsible
Jakob Wells, operating as Houndsync
privacy@houndsync.com