Privacy Policy

How we collect, use, and protect your personal information

Policy Version: 2.1 | Last updated: 24 June 2026 | Effective date: 24 June 2026

This Global Privacy Policy ("Policy") describes how NextPath Solutions Limited ("PocketPaw", "we", "us", or "our"), a company incorporated in Hong Kong, collects, uses, stores, shares, and protects personal information in connection with your use of the PocketPaw services on iOS, Android, and the web at pocketpawapp.com (collectively, the "Services").

Please read this Policy carefully. By continuing to use the Services on or after the Effective Date above, or by accepting Version 2.1 in the app, you acknowledge that you have read and understood this Policy. If you do not agree, please stop using the Services and you may delete your account.


Table of Contents

  1. Data Controller & Contact
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Basis for Processing (GDPR / UK GDPR)
  5. Sharing of Information
  6. International Data Transfers
  7. Data Retention
  8. Data Security
  9. Your Privacy Rights (by Jurisdiction)
  10. Children's Privacy
  11. Location Data (Including Background Walk/Hike Tracking)
  12. Device Permissions
  13. Push Notifications
  14. Cookies & Tracking Technologies
  15. Data Breach Notification
  16. Subscription Data & Multi-Platform Identity
  17. Business Account Data (PawPRO / PawPRO+)
  18. AI Assistants, Voice Assistants & App Intents
  19. Deep Links & Universal Links
  20. Changes to This Policy (Including Re-Consent for Material Updates)
  21. Contact Us

1. Data Controller & Contact

The data controller responsible for your personal data is:

For users in Hong Kong, Canada, and the other jurisdictions covered by this Policy (New Zealand, Australia, Singapore, Malaysia, the United Kingdom, the United States, Japan, Taiwan), NextPath Solutions Limited acts as data controller (or equivalent role under local law). We have not appointed an EU Article 27 Representative; we remain reachable at the address above and via privacy@nextpath.hk.


2. Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Information from Third Parties

2.4 Information We Do Not Collect


3. How We Use Your Information

We use the information we collect to:

We do NOT use your information to:


For users in the European Economic Area, United Kingdom, and elsewhere where GDPR-equivalent law applies, we process your personal data under the following legal bases:


5. Sharing of Information

5.1 Public PawFile Sharing (Within the App)

Other PocketPaw users may view your PawFile as part of normal use (PawRadar, PawMate, PawMatch, PawMunity event attendee lists, PawTime CompanionSession reviews, business review attribution). You can hide individual fields (sex, birth date, neutered status) via the per-field public/private toggles on your PawFile.

5.2 Public PawFile Display on pocketpawapp.com

Entirely opt-in via the "Share to PocketPawApp.com" toggle in Settings. When enabled, we display your dog's name, breed, bio, profile photo, age (if public), gender + neutered status (if public), and city name only (reverse-geocoded once at the time you enable the toggle). Owner name, email, exact GPS coordinates, and health data are never displayed publicly.

5.3 PawPicks Community Database (Website)

PawPicks product listings, ratings, and reviews are publicly displayed on pocketpawapp.com (currently read-only). Reviewers are identified only by their dog's breed and age — your name, email, and personal information are never displayed on product listings.

5.4 PawHeart Content (Website + App)

PawHeart Adopt, Rehome, and approved Lost posts are publicly visible on pocketpawapp.com and as map pins on PawRadar. Rehome posting is restricted to PawVIP subscribers (anti-spam measure); Want-to-Adopt text posts remain open to all users.

5.5 PawMunity Forum and Event Content

Forum posts, comments, reactions, search tokens, leaderboard rankings, and event listings are visible to other users within the same region. Your dog's PawFile snapshot (name, breed, photo) is attached to your posts and events to identify you to the community. Event venue coordinates, where provided, are visible only to the event organiser and confirmed RSVP'd attendees. Forum moderators (two-tier: region moderators + breed-board moderators) — elected annually via PocketPaw's official Instagram poll and assigned by PocketPaw admin — can see all posts in their assigned scope including taken-down content.

5.6 Business Profile Data (PawPRO / PawPRO+ Merchants)

If you operate a Business / Service Provider account, your business profile (name, type, address, opening hours, photos, description, menu, reviews) is publicly visible on the PawRadar map and within the app. This is the core purpose of a business listing. See Section 17 for the privacy boundary between your business and the dog-owner users who interact with it.

5.7 Service Providers (Data Processors)

We may disclose your information where required by law, court order, or governmental or regulatory authority, including: - Lawful requests by public authorities in the jurisdictions where we operate. - Reports of child sexual abuse material (CSAM), escalated to relevant child-safety hotlines (e.g., NCMEC in the United States) and law enforcement. - Reports of animal cruelty, where local law obliges or permits disclosure.

5.9 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of all or substantially all of our assets, your personal data may be transferred to the acquiring or surviving entity. We will notify you and the acquiring entity will be required to maintain equivalent privacy protections.

5.10 No Sale of Data

We do not sell, rent, lease, or trade your personal data to any third party for marketing or commercial purposes. This statement serves as our "Do Not Sell or Share My Personal Information" notice for the purposes of CCPA / CPRA.


6. International Data Transfers

Your personal data may be transferred to and processed in countries outside your country of residence, including the United States (Google Firebase, Google Vertex AI, MapBox, and Stripe infrastructure), Hong Kong (NextPath and the asia-east2 Cloud Functions region), and other countries where Google, Apple, or MapBox operate infrastructure.

For transfers from the EEA / UK / Quebec / other restricted jurisdictions, we rely on: - EU Standard Contractual Clauses (SCCs) approved by the European Commission; - UK International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU SCCs; - Quebec Law 25 privacy-impact assessments for transfers outside Quebec (completed for current data flows); - APPI cross-border transfer notices (Art. 28) for the Japan market; - Singapore PDPA Transfer Limitation Obligation safeguards for the Singapore market; - Adequacy decisions where applicable.

Copies of these transfer mechanisms are available on request at privacy@nextpath.hk.

PawAdvisor AI Data: When you use PawAdvisor (chat or Insight), your dog's data is transmitted to Google's Vertex AI service for processing on globally distributed servers. Our Cloud Functions are deployed in asia-east2 (Hong Kong) but the Vertex AI model endpoint operates globally. By using PawAdvisor, you acknowledge this cross-border transfer as described in the PawAdvisor in-app disclaimer.


7. Data Retention


8. Data Security

We implement appropriate technical and organisational measures to protect your personal data:

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.


9. Your Privacy Rights (by Jurisdiction)

9.1 Universal Rights

Regardless of your location: - Access — request a copy of your data. - Correction — update inaccurate data via in-app settings or by contacting us. - Deletion — delete your account anytime via Settings → Delete Account, or privacy@nextpath.hk. - Data Portability — request your data in JSON or CSV (subject line "Data Portability Request"). We respond within 30 days (or the local mandate). - Withdraw Consent — withdraw location, notifications, public PawFile, PawAdvisor, business-announcement, App Intent integration, or material-policy-update consent at any time via device Settings or the relevant in-app toggle, without affecting the lawfulness of prior processing.

9.2 Hong Kong — PDPO (Cap. 486)

Right to a Data Access Request (DAR) and Data Correction Request (DCR). We respond within 40 days (PDPO requirement). A reasonable DAR fee may apply.

9.3 Canada — PIPEDA & Quebec Law 25

Access, correction, withdrawal of consent (for non-essential processing), de-indexation of online information (Quebec residents), explanation of automated decisions (Quebec residents where applicable). Complaints: OPC (priv.gc.ca) or CAI (Quebec). Quebec transfers outside the province are subject to a privacy impact assessment (completed for current data flows).

9.4 EU / EEA — GDPR

Object, restrict, lodge a complaint with your national DPA (edpb.europa.eu). The EU is not an active market; if you nonetheless use PocketPaw from within the EEA, these rights remain available.

9.5 United Kingdom — UK GDPR & DPA 2018

Equivalent rights. Complaints: ICO (ico.org.uk). PocketPaw registration with the ICO is filed / in progress for the UK market.

9.6 United States — CCPA / CPRA & State Privacy Laws

For California residents under CCPA / CPRA: right to know, delete, correct, opt out of sale/share (we do not sell or share), limit sensitive personal information use, non-discrimination. Email privacy@nextpath.hk with subject "California Privacy Rights Request." We honour equivalent rights for residents of other US states with comprehensive privacy legislation (VCDPA, CPA, CTDPA, UCPA, TDPSA, and others as enacted). COPPA applies to children under 13 (see Section 10).

9.7 Japan — APPI

Disclosure, correction, addition, deletion, cessation of use, cessation of third-party provision. Cross-border transfer notice per Art. 28.

9.8 Taiwan — PDPA

Review, copy, supplement, correct, cease collection / processing, request deletion.

9.9 Singapore — PDPA 2012

Access, correction, withdraw consent. Complaints: PDPC (pdpc.gov.sg). DPO: privacy@nextpath.hk.

9.10 Malaysia — PDPA 2010

Access, correction, withdraw consent. Complaints: JPDP (pdp.gov.my).

9.11 Australia — Privacy Act 1988 (APPs)

Access, correction, opt-out of direct marketing (we do not engage in direct marketing). Complaints: OAIC (oaic.gov.au).

9.12 New Zealand — Privacy Act 2020

Access, correction. Complaints: Office of the Privacy Commissioner (privacy.org.nz).

9.13 How to Exercise Your Rights

Contact privacy@nextpath.hk. We respond within 30 days (or the local mandate). We may need to verify your identity first.


10. Children's Privacy

PocketPaw is not directed at children under 13. We do not knowingly collect data from children under 13. If we discover inadvertent collection we will delete it and, where required (e.g., COPPA in the US), notify the appropriate authority.

For users 13–17, parental or guardian consent is required.

Where local law sets a higher minimum (16 in certain EU member states; 14 in Quebec; 14 in Singapore for sensitive processing; 14 in Hong Kong for sensitive processing), we apply the higher threshold. A neutral age gate operates at registration and at first launch of social features (PawMate / PawBark / PawMunity).


11. Location Data (Including Background Walk/Hike Tracking)

Location data is collected only when you grant location permission. PocketPaw uses location in three distinct modes — please read this section carefully because mode 11.2 (background location during active Walk / Hike sessions) is significant.

11.1 Foreground Proximity Location (PawRadar, PawMate, Dog Parks, businesses)

11.2 Background Location for Walk / Hike Sessions (Exercise feature)

11.3 City-Level Location for Website Publication (opt-in)

City name only (e.g. "Hong Kong", "Toronto"), reverse-geocoded once when you enable the "Share to PocketPawApp.com" toggle. Public on pocketpawapp.com. Disable in Settings.

11.4 Country / Region Detection

We use a coarse region signal (derived from device locale and / or your declared region) to filter PawHeart, PawPicks, PawMunity, dog park, and event content. We store both region and countryCode on every doc to support future sub-national personalisation. This signal is not used for tracking.

11.5 MapBox Geocoding

When a Business account submits an address, or when you submit a Lost report and use the in-app location picker, we send the relevant address text or selected coordinates to MapBox for forward or reverse geocoding. MapBox processes only what is necessary to fulfil the request. See Section 5.7.


12. Device Permissions

We request only the permissions necessary for the features you use, and we honour your declines (the affected feature will be unavailable, but the rest of the app continues to work).

Permission Why we ask When Mandatory?
Location — When in Use / Foreground PawRadar, PawMate, Dog Park proximity, business map When you open the map Optional — required for map features
Location — Always / Background Active Walk / Hike session GPS tracking Only when you start a Walk / Hike session Optional — required only for the Exercise feature
Photos / Photo Library Upload PawFile photo, Growth Marks, PawHeart photos, forum post images, business photos, dog park photos, Lost report photos When you tap an "upload photo" affordance Optional — required only to attach photos
Camera Take a photo directly from within the app for any of the upload flows above When you tap "take photo" Optional
Push Notifications PawMate requests, PawBark messages, PawMunity event reminders, PawTime drop reminders, dog birthday / vaccination reminders, business announcements (if subscribed), subscription / referral updates At first launch, with separate granular toggles in Settings Optional
App Intents / Siri & Apple Intelligence (iOS 26+) Allow voice / agent activation of Walk / Hike start / stop and section navigation When you use Siri or the Shortcuts app Optional — see Section 18
Sign in with Apple / Google Sign-In Account creation / login At registration One auth method is required

Local push notifications for vaccination boosters and important dates use iOS UNUserNotificationCenter (and the Android equivalent); these share the platform 64-pending-notification quota.


13. Push Notifications

We use Firebase Cloud Messaging (FCM) to deliver push notifications. Notifications cover: - New PawMate requests, accepted PawMate requests. - New PawBark messages. - PawMunity event reminders (approximately 24 hours before an event you have RSVP'd to). - PawTime exercise-drop reminders (sent when your dog's tracked exercise minutes drop ≥50% over 3 or 7 days; wellness reminder, not medical advice). - Dog birthday reminders. - Vaccination booster reminders (iOS local notifications + push fallback). - Business announcements from PawPRO / PawPRO+ merchants you have opted in to via Bookmark (subject to per-tier monthly limits). - Subscription and Referral updates (renewals, expiries, bonus PawVIP grants).

You can disable any category in your device Settings → Notifications → PocketPaw (or via the relevant in-app toggle for granular control). Disabling notifications will not affect your ability to use the Services but may mean you miss time-sensitive alerts.


14. Cookies & Tracking Technologies

Website (pocketpawapp.com): Minimal essential cookies (e.g. language preference). For visitors from the UK, EEA, or other jurisdictions requiring prior cookie consent, we display a cookie banner for any non-essential analytics cookies. No advertising, tracking, or third-party marketing cookies.

In-App Analytics (first-party): We use our own first-party usage analytics on iOS, Android, and Web, stored only in our own database (Firebase Firestore). We do not use Google Analytics, Firebase Analytics, or any third-party analytics / attribution service. We record an anonymous installation identifier (a random on-device ID — not your account, never an advertising ID), the day the app was active, your platform / app version / region, a coarse area (your city, or — in Hong Kong — your district) derived from the self-declared city on your dog's profile (never your precise location or GPS coordinates), and anonymous in-app events — including which screen you viewed and roughly how long it was on screen, and whether you opened an upgrade / paywall screen. From these we compute aggregate metrics only (e.g. daily active users, retention, active users by city / district, feature usage, upgrade funnel). Never shared with advertisers or third parties; never used for advertising or cross-app tracking. Raw records are deleted after 90 days.

No third-party advertising networks, retargeting pixels, or social-media tracking scripts.


15. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you and the relevant authorities as required by applicable law:

Notification to you will be provided via in-app alert and / or email.


16. Subscription Data & Multi-Platform Identity

16.1 One account, three platforms

PocketPaw is one service across iOS, Android, and the web at pocketpawapp.com — all now live. The same account, your dog's PawFile and PawHub data, your community activity, and your subscription entitlement are shared across all three platforms. We use Firebase Authentication as the cross-platform identity layer — your Firebase uid is your account identity on every platform. Sign in with email / password, Google, or Apple (Sign in with Apple is currently iOS only; email / Google are recommended for full Android / Web cross-compatibility).

16.2 Server is the source of truth

Your subscription entitlement (PawVIP / PawPRO / PawPRO+) and all business data live in Firestore. We never rely on "this device bought it" — feature access is gated on the server-side entitlement record, so if you buy on iOS the entitlement applies on Android and Web automatically (and vice versa).

16.3 Per-source records & resolver

We record subscriptions with a "source" tag — apple (iOS), google (Android), stripe (Web), manual (a small number of administratively-granted subscriptions), or referral (bonus PawVIP time earned through the Referral programme). A server-side resolver computes your effective active entitlement as the latest (highest-expiry) active record across all sources, so buying on one platform never wipes an entitlement from another. We retain the original transaction ID for each platform for renewal validation and refund handling.

16.4 Apple App Store Server Notifications V2

When you subscribe via Apple, Apple sends server-to-server lifecycle notifications (appStoreServerNotifications Cloud Function) on every event — initial purchase, renewal, cancellation, refund, billing retry, grace period, expiry. Our backend verifies the signed JWS against Apple's root CAs, decodes the transaction, maps the originalTransactionId to your uid, and updates your entitlement record server-side. This means your subscription state stays correct even if the app is closed or uninstalled.

Equivalent server-to-server flows are live for Google Play Billing (Android — Real-time Developer Notifications) and Stripe (Web — webhooks), each verified server-side and resolved onto the same entitlement record.

16.5 Pricing parity & anti-steering

We charge the same price across iOS, Android, and Web (the platform commission differs but is absorbed by PocketPaw). To comply with Apple's anti-steering rules, we do not direct iOS users to buy elsewhere from within the iOS app. You may always choose where to subscribe; cross-platform recognition is automatic.

16.6 What we share with payment processors

We receive only the subscription state and transaction identifiers necessary to grant the entitlement.


17. Business Account Data (PawPRO / PawPRO+)

This Section 17 supplements (and does not replace) the rest of this Policy. It applies only to users who hold a Business / Service Provider account.

17.1 Information collected for business accounts

17.2 Sharing and visibility

17.3 The "Active Dashboard" is not real-time

PawPRO+ Analytics → Active Dashboard refreshes on a short periodic delay. It is not a real-time feed and must not be relied upon for time-critical decisions. Marketing and UI must use "Active Dashboard / 動態儀表板" — never "real-time / 即時".

17.4 No vet-specific health data sharing

PocketPaw does not — and will not — build features that allow veterinarian PawPRO / PawPRO+ merchants to receive individual user health data, vaccination records, weight history, or other PawHub data. Vets are welcome to operate as PawPRO merchants for marketing exposure only, on the same terms as any other business.

17.5 Payment data

All payment processing for PawPRO and PawPRO+ subscriptions is conducted by Apple StoreKit 2 (iOS), Google Play Billing (Android), or Stripe (Web) — all now live. We do not store payment card data. See Section 16.

17.6 Pre-seeded Free Pins

PocketPaw may pre-seed Free Pins on the PawRadar map for businesses publicly identified in a launch region. Rightful operators may Claim This Business in the app. Claims are reviewed manually against one of: a phone-number match, business registration, or in-store photo evidence.

17.7 Address change requests

Address changes are submitted via the in-app form and routed via MapBox forward geocoding for verification, then approved manually.


18. AI Assistants, Voice Assistants & App Intents

18.1 PawAdvisor (in-app AI chat and Insight)

PawAdvisor is a PawVIP-exclusive AI assistant powered by Google Vertex AI / Gemini 2.5 Flash, with two surfaces: - PawAdvisor Chat — interactive Q&A. Every turn injects a context block containing your dog's PawFile (name, breed, gender, age, neutered status, city, region), PawHub profile (chip no., water intake), a bounded set of recent weight entries, document metadata (no file contents), recent vaccinations, capsule count only, upcoming dates, PawPicks food picks (brand + name + community rating + structured nutrition) and toy picks, plus the recent messages in the conversation. - PawAdvisor Insight — a separate, periodic AI-generated summary surfaced in-app (e.g., trend observations on your dog's water intake or exercise patterns). The same data classes as Chat may be sent; no file contents, photos, or your personal email / password are ever sent to the AI.

Each session opening shows the in-app disclaimer; your acknowledgement is recorded for audit.

18.2 Voice assistants & App Intents (Siri, Spotlight, Shortcuts, Apple Watch, Apple Intelligence)

On iOS (deployment target iOS 26+), PocketPaw exposes a small set of App Intents that allow voice / on-device-agent activation of: - Start a Walk / Start a Hike (with type parameter); - Stop the current walk / hike; - Open a section (PawRadar, PawMunity, PawMate, PawHub).

Apple's voice / agent assistants (Siri, Apple Intelligence, Apple Watch voice, Shortcuts, Spotlight) may pass the voice / text query through Apple's own systems (which may include on-device or Apple-cloud processing under Apple's own privacy policy) and then invoke our App Intent. The App Intent runs locally in the app; we do not receive a transcript of your voice query — only the resulting parameter values (e.g. "type=hike").

Destructive / paid actions (subscribe, public forum post) require confirmation in-app — assistants never commit such actions silently. Navigation-only intents are safe to expose broadly.

The same architectural approach (via Google's App Actions / App Functions) is planned for the Android app. Apple's and Google's own data-processing terms govern the assistant layers themselves; once the intent is invoked, our standard data-handling described in this Policy applies.

18.3 No silent agent purchases or posting

We do not allow third-party agents (cloud or on-device) to silently purchase subscriptions, post to the forum on your behalf, or accept PawMate requests on your behalf. Any such action goes through an explicit confirmation step in the app.


PocketPaw supports two URL conventions: - Universal links under pocketpawapp.com (e.g. /paw/{pawFileId}, /business/{businessId}, /product/{productId}) — open content directly in the app if installed, or in the website if not. - Custom-scheme deep links under pocketpaw:// (e.g. pocketpaw://walk/start?type=hike, pocketpaw://open/pawhub) — used by App Intents, Shortcuts, and other automation surfaces.

These links carry only identifiers and verbs; they do not transmit your account credentials. When a link opens a private surface (e.g. your own Walk / Hike record), normal authentication is required.


We may update this Policy from time to time. We classify changes as:

The "Last updated" date at the top of this Policy reflects the most recent revision. You may always view the current version and all prior versions (2.0, 1.0) at Settings → Legal → Privacy Policy → Version history.

If you do not agree to the updated Policy, you should stop using the Services and may delete your account; we will continue to apply the last version you accepted to retained data only insofar as required for legal compliance and dispute resolution.


21. Contact Us

For any questions or requests regarding this Policy or your data:

We respond within 30 days (or the legally mandated timeframe for your jurisdiction).


This Privacy Policy (Version 2.1) was reviewed by NextPath Solutions Limited's legal team on 24 June 2026 in connection with the completion of PocketPaw's three-platform launch (iOS, Android on Google Play, and the web at pocketpawapp.com), full cross-platform data and subscription / entitlement interoperability, the move to a server-side per-source entitlement resolver, and a corrected description of our first-party anonymous analytics (no Firebase Analytics, Google Analytics, or Firebase Crashlytics). This document is provided for general informational purposes and does not constitute legal advice. If you have questions about your specific legal rights in your jurisdiction, consult a qualified legal professional.


← Back to Home