Legal
Privacy Policy
Effective: September 4, 2026
Last updated: September 4, 2026
PawsClick ("PawsClick", "the App", "the Service", "we", "us", "our") is operated by Coderlook Solutions Private Limited ("Coderlook", "the Company").
This Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and what rights you have. By creating an account or using the Service, you acknowledge this Policy. If you do not agree, do not use the App.
- We do not sell your personal information.
- We do not display third-party advertising in the App today.
- We do not operate a social network. Your care records are not public.
1. Who we are and how to contact us
- Legal entity: Coderlook Solutions Private Limited
- Product name: PawsClick
- Address: 3rd Floor, J-1/12, EP Block, Sector V, Bidhannagar, Kolkata, West Bengal 700091, India
- Country: India
- Privacy requests: privacy@pawsclick.com
- General support: support@pawsclick.com
- Website: https://pawsclick.com
- In-app Privacy Policy: https://pawsclick.com/privacy (linked from the sign-in screen and from Account → About)
- In-app Terms and Conditions: https://pawsclick.com/terms (linked from the sign-in screen and from Account → About)
Please write from the email address linked to your PawsClick account when you request access, correction, or deletion. We may need to verify your identity before we act.
2. What PawsClick does
PawsClick is a pet-care organisation tool for pet owners and carers. It helps you:
- create and manage a user account — sign in with Google (available today in the Android app) or Apple (supported by our backend and used on other platforms where we offer it); there are no passwords anywhere in the system;
- store pet profiles (name, species, breed, age or date of birth, gender, weight, allergies, photo);
- log and schedule care records: medication, food/diet, vaccines, weight, health conditions, completed vet visits, grooming, notes;
- attach photos and documents (JPEG, PNG, PDF) to records;
- receive local and push reminders for care tasks;
- discover nearby pet-care providers using approximate location or a city you choose, and open maps or the phone dialler on your device;
- share a pet with another person (a "Paw Pass") so they can view, and in some cases add to, that pet's records.
PawsClick is NOT a veterinary clinic, marketplace, telemedicine service, emergency dispatch system, or payment processor. Nearby listings are for convenience only and are not a source of veterinary advice.
Platform today: Android (package com.pawsclick.app). Our backend also supports Sign in with Apple, which we use if and when we ship the App on other platforms; this Policy will be updated to describe any new platform when it launches.
Availability: the Service may be used wherever the App is distributed, subject to Google Play availability and applicable law. Core hosting is in India and with our cloud providers (see Section 10).
3. Who may use the Service (age)
The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you are under 18, you should use PawsClick only with the consent and supervision of a parent or legal guardian.
If you believe a child under 13 has created an account, email privacy@pawsclick.com. We will take reasonable steps to delete the data.
4. Information we collect
We collect information in three ways: (A) you provide it; (B) it is provided by your sign-in provider (Google or Apple); (C) it is generated by the App or our servers when you use features.
4.1 Account and profile (user)
There is no password anywhere in our systems. You sign in exclusively through Google or Apple; we never see, transmit, or store a password, and there is no password-reset flow.
From the verified sign-in token we read exactly three pieces of information, for both Google and Apple:
- a stable account identifier (the provider's "subject" value)
- your email address (for Apple, this may be an Apple private-relay address, which we store as provided)
- your display name
Stored in your PawsClick account: an internal ID, email, full name, profile photo URL, an optional phone number, which provider you signed in with, your city, gender, notification preferences, preferred weight unit, subscription status, and account status (including deletion timestamps if you request deletion).
All of the following are optional and never required to use the app: full name, phone number, city, gender, notification preferences, preferred weight unit, and profile photo.
Not collected: date of birth of the human user, postal address, government ID, payment details, precise home location, or marketing preferences.
4.2 Pet information
You may enter:
- pet name
- species (for example dog, cat, or other types supported in the App)
- breed — chosen from our reference list, or typed in as free text
- gender
- date of birth and/or approximate age in months
- weight
- allergies — condition, severity, and reaction notes
- pet photo
Pets are not human data subjects, but pet records are linked to your account and may include sensitive practical information about animal health. Treat them as confidential.
Privacy detail worth knowing. If you share a pet with someone through a Paw Pass (Section 4.10), we deliberately withhold that pet's exact date of birth from the person you shared with — they see only a derived age description and an age in months, never the birth date itself. This is enforced in our data model, not just in the interface.
4.3 Health and care records
Every record you create stores: a type, a title, a date/time, where it came from, which clinic or veterinarian is named on it (if any), your notes, and who created it.
Why "created by" matters. Because a pet can be shared with a co-carer (Section 4.10), the person who created a given record is not always the pet's owner — it may be a sitter, family member, or anyone else you've granted access to. That is what powers the "Recorded by …" label you see on a shared pet's timeline, and it means a record can contain personal data about a second person, not only about you.
Depending on the record type, we store:
- medication — name, dosage, frequency, start/end dates
- food and diet logs — meal type, food name, quantity, meal time, recurring days
- vaccines — name, administering clinic, next-due date
- weight — value and the unit you use
- health conditions — severity, status, and progress notes over time
- completed vet visits — clinic name, veterinarian name, reason for the visit
- grooming — type, provider name, and a cost figure you enter as a personal note (we do not process a payment)
We generate reminders from these records to power local and push alerts, and we keep an internal audit trail (who changed what, and when) for accountability on shared pets.
Scheduling a future vaccination, vet visit, or grooming task is an organisation feature only — it does not book a live appointment with a clinic. There is no in-app booking checkout with a veterinarian or groomer.
Clinic and veterinarian names inside your records are personal data about a third party. Please only record contact people who would reasonably expect to appear in your pet's care history.
4.4 Photos and files
You may upload profile and pet photos, and care-record attachments — typically photos of certificates, prescriptions, or clinic paperwork you choose to store.
- Accepted types: JPEG, PNG, and PDF only.
- Size limit: 10 MB per file.
- We check the actual content of every upload against its claimed file type before accepting it, rather than trusting the file name or declared type.
Attachments are often where vet reports and lab results end up, so we treat this as the most sensitive category of data we store.
4.5 Location — two different uses
Only ACCESS_COARSE_LOCATION (approximate location) is ever requested. There is no precise/GPS permission and no background location permission.
These two features handle location very differently, and it's worth being precise about each:
- Profile personalisation (city): your device converts coordinates into a city/region name locally, on the device itself. Only that resulting city name is ever sent to our servers and stored — we never receive or store raw coordinates for this feature.
- Nearby provider search: when you use the Nearby tab, your device does send your real approximate coordinates to our servers for that specific request, so we can rank pet-care providers by distance. We use those coordinates only to sort the results — we do not save them in any database table, and we do not write them into server logs. Even though we don't retain them, sending coordinates to a server still counts as "collecting" location for app-store disclosure purposes, and we declare it that way in our Google Play Data Safety listing.
You can refuse location permission and still choose a city manually, and you can revoke location access in Android Settings at any time. We do not require location for core pet-record features. When you tap a map or address action, your device may open Google Maps or another map app, which has its own privacy policy.
4.6 Notifications and device data
With your permission we may collect or generate:
- push notification token (Firebase Cloud Messaging)
- a device identifier used to register your device with our API
- platform (Android), app version, and last-seen time
- whether notifications, exact alarms, and reminder push are enabled on that device
Permissions related to this include INTERNET, ACCESS_NETWORK_STATE, POST_NOTIFICATIONS, RECEIVE_BOOT_COMPLETED, and SCHEDULE_EXACT_ALARM.
4.7 Permissions we deliberately do not hold
This is worth stating plainly: PawsClick holds no camera, microphone, contacts, or general file-system permission at all.
- Photos: you choose specific images through Android's built-in Photo Picker — PawsClick never gains access to your photo library.
- Camera: taking a photo hands off to your phone's own camera app, which returns a single picture. PawsClick has no direct camera access and does not hold the CAMERA permission.
- Files: you choose specific files through Android's Storage Access Framework — PawsClick does not browse your device storage.
- QR scanning (used for Paw Pass sharing) runs through Google's on-device code scanner as a separate process; PawsClick receives only the scanned result, never camera access.
- Microphone and contacts are not used anywhere in the App.
4.8 Technical, security, and usage data
To operate and secure the Service we may process:
- an authentication/session token, kept in the App's private on-device storage, accessible only to PawsClick
- a cached copy of your own data kept on-device for faster, more reliable loading
- IP address, timestamps, and request logs on our servers
- for our Paw Pass sharing-code feature, a one-way cryptographic hash of the requesting IP address (never the address itself), used only to block repeated guessing of someone else's sharing code
- error or diagnostic information needed to keep the Service reliable
We do not run any third-party analytics or crash-reporting SDK — specifically, Firebase Analytics, Firebase Crashlytics, Google Analytics, Meta/Facebook SDK, AppsFlyer, Adjust, Amplitude, Mixpanel, Segment, Branch, and Sentry are all confirmed absent from the App. (A Sentry integration point exists in our backend code but is currently an inactive stub that writes a log line and sends nothing anywhere; if we ever activate it, this Policy will be updated first.)
4.9 First-party product analytics
We record a small, fixed list of app-usage events — for example, account created, pet added, record added, reminder set, a clinic call button tapped, or the app being opened — together with a limited set of descriptive properties such as species, record type, or which screen was viewed.
Property values are restricted to a fixed allow-list per event type. Free text, pet names, note content, your email address, and location coordinates can never enter this analytics table — anything outside the allow-list is dropped automatically.
We keep these events for 180 days, after which they are permanently deleted. If you delete your account, any earlier events tied to you are stripped of the link to your account rather than deleted outright, so aggregate product statistics survive without identifying you.
4.10 Pet sharing (Paw Pass)
You can share a pet's profile with another person — for example a co-owner, family member, or sitter — using an in-app "Paw Pass".
- Depending on the access level you grant, the person you share with may be able to view the pet's records, or view and add new records themselves.
- The pet's exact date of birth is never shared this way — see Section 4.2.
- We also support granting a clinic a scoped, revocable "consent" to view a pet's records. This capability exists in our systems but is not yet connected to any live clinic integration — no clinic currently receives data through it.
4.11 Android assistant access (App Functions)
PawsClick registers a set of "app functions" with Android. This lets an on-device assistant — on a standard Android phone, Google's — carry out PawsClick actions when you ask it to: listing your pets, reading a pet's care records or upcoming reminders, finding nearby clinics, and adding entries such as a weight, meal, medication, vaccine, or condition record.
This works only while you are signed in to PawsClick on that device, and only when you invoke it. The functions run on your device, against your own account, and call the same API the App itself uses — so we receive nothing beyond what the equivalent action inside the App would send us. PawsClick never starts them on its own.
What matters for your privacy is the other side of it: the assistant you use receives the pet information it asked for, which can include health record content, and what it does with that is governed by that assistant's own privacy policy, not this one. If you would rather pet data were not reachable this way, do not ask an assistant to use PawsClick; you can also disable or restrict the assistant in Android Settings.
4.12 Information we do not collect today
- passwords — none exist anywhere in our systems
- in-app payments or card numbers
- live clinic booking confirmations with third-party vets
- precise / background location
- contacts, SMS content, camera, or microphone access
- date of birth of the human user
- postal address or government ID
5. How we use information
We use personal data to:
- Create and authenticate your account (Google or Apple Sign-In + our API).
- Provide pet profiles, care records, attachments, and reminders.
- Sync your data across signed-in sessions on your devices.
- Personalise nearby results and city when you use those features.
- Send local and/or push notifications you enable.
- Register devices so reminders and invalidation work correctly.
- Support pet-sharing features (Paw Pass) that you choose to set up, including an audit trail of who logged what on a shared pet.
- Protect the Service (security, abuse prevention, debugging).
- Comply with law and respond to lawful requests.
- Communicate important service notices (for example account deletion status or material policy changes).
- Improve reliability of the App (without selling data to advertisers).
We do not use pet health records for third-party advertising.
Legal bases (where a law such as India's Digital Personal Data Protection Act, 2023 requires a basis): performance of our contract with you; consent (for example optional location or notifications); legitimate interests in security and service operation that do not override your rights; and legal obligation.
6. How we share information
We share data only with the processors below, each acting on our instructions, and only for the purpose stated.
- Neon (managed PostgreSQL, on AWS) — receives all application data, for database hosting.
- AWS S3 / compatible object storage — receives photos, PDFs, and attachments, for private file storage; files are never public and are served through short-lived, expiring links.
- Redis — receives temporary cache and rate-limit data, for performance and abuse prevention; not long-term storage.
- Google — Identity Services — receives the sign-in token, email, name, and account subject ID, for sign-in.
- Google — Firebase Cloud Messaging — receives the push token and device metadata, for push notifications.
- Google — Play Services code scanner — runs on-device only; PawsClick receives just the scanned result, for Paw Pass QR scanning.
- Apple — Sign in with Apple — receives the sign-in token, email (or private relay), and name, for sign-in on platforms where we offer it.
Separately from the processors above, an Android assistant you ask to use PawsClick receives the pet information it requests, on your device — see Section 4.11. That is a transfer you set in motion, not one we make.
6.1 Nearby providers and clinics
Provider listings (name, address, phone, distance) are directory data shown to you. Using nearby search does not automatically send your pet medical records to those clinics. If you call or visit a clinic, that relationship is between you and the clinic.
6.2 Legal, safety, and business transfers
We may disclose information if required by law, court order, or government request; to protect users, the public, or Coderlook; or as part of a merger, acquisition, or asset sale, with appropriate safeguards.
6.3 What we do not do
- We do not sell personal information.
- We do not share care records publicly.
- We do not run third-party ads in the App today.
- We do not use AI features in the App today, and we do not send your data to any AI provider.
7. Data storage, security, and retention
Account, pet, and care data live in a managed PostgreSQL database (Neon, on AWS). Photos, PDFs, and attachments live in a private S3-compatible object store. Short-term caching and rate-limiting use Redis. Your session token and a cached copy of your own data are kept only in the App's private on-device storage, accessible solely to PawsClick.
We use reasonable technical and organisational measures (access control, HTTPS to our API, least-privilege practices, private storage buckets served only via short-lived links). No system is perfectly secure. You must keep your Google or Apple account and device secure.
7.1 Retention periods
- Account, after you request deletion — 28-day cancellable grace period, then erased (immediately if you choose "erase now")
- A deleted pet profile — kept 7 days so you can restore it, then permanently erased
- First-party analytics events — 180 days, then permanently deleted
- Session login token — expires automatically after 30 days
- Pet-sharing (Paw Pass) grants — active until they expire on their own terms or you revoke them
- Care records, pets, and attachments — kept for as long as your account is active; we do not auto-expire your pet's history
We do not auto-expire health records because a care history that silently disappeared would defeat the purpose of the App. You stay in control of this through account or individual-pet deletion.
7.2 What account deletion actually does
Account deletion (current App) — Path: Account / Profile → request deletion. Options:
- Schedule deletion — a grace period (currently up to 28 days) during which the account may be pending_deletion and you may cancel.
- Erase now — process deletion as soon as reasonably practicable.
When erasure runs, we:
- delete every file you uploaded from cloud storage — your profile photo and all attachments;
- permanently delete your pets and everything linked to them — records, allergies, and reminders;
- delete your account itself, your registered devices (including push tokens), sharing consents, and pet-transfer history;
- clear related short-term caches;
- anonymise, rather than delete, your first-party analytics events, so aggregate product statistics survive without identifying you.
One consequence we want you to know about in advance. If you logged care records on a pet that belongs to someone else — because they shared it with you — those records stay with that pet and its owner after your account is deleted. They are the pet owner's data, not yours to remove. The link to your deleted account is removed from them, so they stay in that pet's history without being attributed to you.
Freezing or merely logging out is not deletion. Google Play requires a real deletion path for apps that create accounts; PawsClick provides in-app deletion as described above.
8. Your choices and rights
In the App you can typically:
- view and update certain profile fields;
- manage notification preferences and weight units;
- control location in Android Settings;
- add, edit, or delete pets and records (subject to record rules);
- restore a recently deleted pet within 7 days;
- manage who a pet is shared with, and revoke a Paw Pass at any time;
- delete your account (Section 7).
Depending on applicable law (including the DPDP Act in India and, if you are in another region, local privacy laws), you may have rights to access, correct, erase, withdraw consent, or complain to a supervisory authority.
To exercise rights, email privacy@pawsclick.com. We will respond within the time required by applicable law where it applies.
9. Children
See Section 3. PawsClick is a general-audience pet-care tool, not a children's app under Google Play Families policies unless we later designate it as such and update this Policy.
10. International transfers
Coderlook is established in India. Our database and object storage are managed through Neon and AWS respectively. Data may therefore be processed in India and in other countries where our providers operate. Where required, we rely on appropriate contractual and legal safeguards for these transfers.
11. Third-party policies (services used in the App and backend today)
These are the third parties involved in the App and our backend today.
Currently used
- Google Sign-In / Credential Manager / Google Identity Services
- Firebase Cloud Messaging (push)
- Google Play services code scanner (Paw Pass QR scanning, on-device only)
- Sign in with Apple (on platforms where we offer it)
- Neon (managed PostgreSQL, on AWS)
- AWS S3 / a compatible private object storage host
- Redis (short-term caching and rate-limiting)
- Android App Functions — on-device assistant access to the App (Section 4.11)
Not currently used
- OpenAI or any other AI provider
- Firebase Analytics / Crashlytics, Google Analytics
- Facebook / Meta SDK, AppsFlyer, Adjust, Amplitude, Mixpanel, Segment, Branch
- advertising networks
- Razorpay, Stripe, PayPal, Google Play Billing
- OneSignal, Sentry (an inactive integration stub exists in the backend code but sends no data anywhere)
Each third party has its own policy. Review Google's, Apple's, and AWS's privacy documentation as well as this Policy.
12. Changes to this Policy
We may update this Policy. The Last Updated date at the top shows the current version. Material changes will be communicated through the App, the website, or other reasonable means. Continued use after an update takes effect means you acknowledge the revised Policy, except where law requires fresh consent.
13. Contact
- Coderlook Solutions Private Limited
- 3rd Floor, J-1/12, EP Block, Sector V, Bidhannagar, Kolkata, West Bengal 700091, India
- Privacy: privacy@pawsclick.com
- Support: support@pawsclick.com
- Web: https://pawsclick.com
See also our Terms and Conditions.