Effective Date: 2026-05-04
Applies To: Users of the Pawgloo Consumer Application ("Consumers") and the Pawgloo-Partners Service Application ("Partners").
The Bottom Line Up Front (BLUF): At Pawgloo, we take your privacy seriously. We are compliant with the Digital Personal Data Protection (DPDP) Act, 2023. This policy explains what data we collect (profile, pet info, location), how we store it securely using AWS, and your rights to access or delete your data.
1. Introduction and DPDP Act Compliance
Pawgloo Technologies ("Company," "we," "us," or "our") acts as a Data Fiduciary under the Digital Personal Data Protection (DPDP) Act, 2023. This policy comprehensively outlines the methodology by which we collect, store, process, and securely transfer your personal data across our cloud infrastructure. By utilizing our applications, you provide explicit, informed consent for the processing of your data as defined within this policy.
2. Data Segmentation and Flow Architecture
We operate a strictly segmented data architecture to ensure data minimization and purpose limitation. Data is routed and isolated based on the registered user type:
A. For Pet Parents (Consumer App Users)
- Profile Data: Upon registration via OTP, your Name, Email, and Phone Number are securely stored in the
userscollection within our primary database (meetnmate). - Pet Data: Information regarding your pet (breed, age, vaccination status, temperament) is stored to power the matchmaking algorithm and provide essential context to Partners during bookings.
- Media & Object Storage: Photographs and media files are transmitted directly to secure cloud object storage (AWS S3). We do not store raw media files or base64 payloads within our operational databases to ensure optimal performance and security.
- Geospatial Data: To connect you with geographically proximate services, we process your device's location. This data is utilized dynamically by our matchmaking queries and is expressly not archived to track historical movements.
B. For Service Providers (Pawgloo-Partners)
- Professional Profiles: Specialty, biography, and scheduling data are isolated in a dedicated database (
partners, undervetProfileorgroomerProfile). - Verification Documents (KYC): Sensitive identity documents (e.g., Aadhaar, PAN, Veterinary Licenses) are uploaded directly to an encrypted, private AWS S3 bucket. Access is restricted via strict Identity and Access Management (IAM) policies to authorized compliance personnel only.
- Service Telemetry: We record transactional metadata, including
slot_bookings(appointment timestamps) andcall_sessions(duration of audio/video calls), to ensure auditable, accurate payout calculations.
3. Third-Party Data Processors (Sub-Processors)
To operate the platform efficiently, we securely transmit limited data subsets to the following enterprise-grade infrastructure partners:
- Amazon Web Services (AWS): Our primary backend infrastructure—including databases, object storage, and compute instances—is hosted exclusively within the
ap-south-1(Mumbai) region, ensuring strict adherence to Indian data localization mandates. - GetStream: For in-app chat and video consultations, we securely pass a generated, temporary user token to GetStream. We expressly do not record, store, or archive the raw video streams of your consultations on our servers.
- Novu: For transactional communications (e.g., booking confirmations, OTPs), your contact details and device tokens are transmitted securely to Novu's notification infrastructure.
- Cashfree Payments: All financial transactions are processed via Cashfree. We do not store your bank account numbers, UPI PINs, or credit card details on our primary databases.
4. Temporary Caching and System State Management
To maintain application performance and prevent concurrent booking conflicts, we employ an in-memory caching layer (Valkey/Redis).
- Idempotency & Concurrency Locks: When a booking is initiated, a temporary digital lock (
temp_slot_lock) is generated in the cache. This lock contains minimal identifier data and is engineered with a strict Time-To-Live (TTL) to automatically self-destruct after 10 minutes. - Non-Persistence: Our caching infrastructure is strictly utilized for transient state management and is never used for the persistent archiving of personally identifiable information (PII).
5. Data Retention and Deletion (The Right to be Forgotten)
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy or as required by applicable Indian law.
- Account Deletion: Users may request complete account deletion via the application settings. Upon verification, profile data in our primary databases and associated media in AWS S3 will be permanently soft-deleted and subsequently hard-deleted within 30 days.
- Regulatory Retention: To comply with the Income Tax Act, 1961, and the Prevention of Money Laundering Act (PMLA), 2002, transactional records, ledger entries, and Partner KYC metadata may be securely archived in a restricted state for up to seven (7) years following account termination.
6. Data Security and Internal Access Controls
- Encryption: All data transmitted between your device and our backend APIs is secured using modern TLS/SSL protocols. Data at rest within our databases and S3 buckets is encrypted utilizing AWS Key Management Service (KMS).
- Role-Based Access Control (RBAC): We enforce the principle of least privilege. Customer support personnel can only view booking statuses and cannot access private chat histories or financial ledgers. Raw database access is restricted to authorized engineering personnel via secure, audited jump hosts.
7. User Rights and Grievance Redressal
Under the DPDP Act, 2023, you possess the right to:
- Access & Nominate: Request a summary of your personal data and nominate an individual to exercise your rights in the event of incapacity.
- Correction: Rectify inaccurate or incomplete profile information directly within the application.
- Grievance Redressal: If you have concerns regarding our data practices, please contact our designated Data Protection Officer (DPO) at privacy@pawgloo.com. We are committed to resolving grievances promptly in accordance with statutory timelines.
🐾 Find your pet's perfect match on Pawgloo
Join the community of thousands of pet parents in India. Play dates, tele-vet access, and verified dog walkers-all in one app.
Download Pawgloo