Privacy Policy
Last updated
This policy explains what personal data we process when you use Peyda Track, why, who receives it, how long we keep it and what you can ask us to do about it.
This English text is the governing version. The Czech, Slovak, German and French versions are translations provided for convenience; if they differ from this text, this text applies.
Who we are
Peyda Track is operated by Pixeesoft GmbH, Rue Fendt 1, 1201 Geneva, Switzerland. We decide why and how the data described here is processed, which makes us its controller.
Write to privacy@pixeesoft.ch with any question about this policy, or to exercise any of the rights in Your rights.
We have not appointed a data protection officer, and we have not appointed a representative in the European Union.
What this policy covers
This policy covers:
- The Peyda Track apps for iOS and Android.
- The Peyda Track web app, where it is available to you.
- This website.
- The tracking service behind them, including what the tracker reports to our servers.
It does not cover what the App Store or Google Play do with your data, the shop that sells the tracker, or other sites we link to.
Tracker here means the collar hardware; your phone means the handset or browser you use.
The data we process
The list below is complete. We do not collect a phone number, a postal address, a date of birth, browsing history or advertising identifiers, and no analytics or advertising code runs in our apps or on our websites.
Account data
When you create an account we store:
- Your email address.
- A name: the display name held for your sign-in, or the part of your email address before the @ sign. There is no separate first name or surname.
- Two identifiers for the account, one issued by Firebase Authentication and one we generate.
- The date the account was created, and an internal flag marking test accounts.
- The trackers linked to the account.
Your password is handled by Firebase Authentication and held by Google in hashed form; we never see it. Verification and password reset messages are sent by Firebase for us. Email and password are the only way to sign in.
Tracker and position data
The tracker reports to our servers through our edge network. We store each report and update the tracker's last known position. A report contains:
- Latitude, longitude and the time of the reading.
- Battery level and capacity, and whether the tracker is charging.
- Whether it is moving, and whether the SOS button was pressed.
- GPS speed, altitude and satellite count.
- A verbatim copy of the values the tracker sent, kept alongside the fields above.
We also store the name you give the tracker, battery summaries for the last 24 hours and 7 days, and the serial number and IMEI from the pairing code. The IMEI identifies the tracker record.
Pet data
The name you give a tracker is usually your pet's name. A photo you upload is stored under your account in our media storage; the web app resizes it in your browser to 512 pixels on its longest edge first.
Your account picture is a pattern generated from your account identifier when the account is created. It is not derived from any photo of you.
Safe zones
Where your app version supports safe zones, we store for each zone:
- Its shape: a centre and a radius, or the corners of an area you draw.
- Its name, the trackers it applies to, and whether it alerts on leaving, on entering, or both.
- Optional active hours, with the days and time zone they apply in.
- Per tracker: whether it is inside or outside, the position last checked against the zone, and when it last crossed.
An account may have up to 20 safe zones, and up to 5 may be active for one tracker.
Notifications
If you turn on push notifications we store a registration token for that phone or browser, with the platform, the device name and model where sent, when the registration was first and last seen, whether notifications are on, and counts of failed and sent deliveries.
We keep a record of each notification: type, title, body, any attached data, when it was created and sent, and whether you read it.
Three notifications exist: a safe-zone entry or exit alert, a test notification you can send yourself, and a message about a change to your Google Play subscription. Push reaches the Android app and supported browsers; the iOS app does not receive push notifications.
Subscription data
Subscriptions are bought and charged in the App Store or Google Play. No card, bank or payment data reaches us. From the store we receive and store:
- The platform, the purchase token or original transaction identifier, the start and expiry dates, whether it renews automatically, and whether it was a test purchase.
- For Google Play also: the account identifiers passed to the store, the price, currency and country code it reports, the payment state, the purchase type and whether the purchase was acknowledged.
- A log of each event the store sends us about the subscription.
So the store can match a purchase to your account, the iOS app sends Apple an identifier we generate, and the Android app sends Google a one-way hash of it.
Permissions on your phone
The apps ask for these permissions, and only for these purposes:
| Permission | What it is used for |
|---|---|
| Camera | Scanning the pairing code on a new tracker. The web app does the same. |
| Photo library | Choosing a photo of your pet. |
| Location while using the app | Drawing your own position on the map beside your pet. Your phone's position is never stored on our servers and never sent to us. |
| Notifications | Delivering the alerts described above. |
You can grant or withdraw each of these in your phone's or browser's settings. The apps never ask for background location and do not track you across other apps.
Diagnostics and monitoring
The apps send crash reports and handled errors to Firebase Crashlytics. On iOS this is always on and your account identifier is attached to the reports; on Android it is on in the released app. Neither app can turn it off.
Our servers and edge network send warnings, errors and crashes to Sentry with your account identifier, a request identifier and the context of the failure. Some contexts currently include your email address when an account or account picture could not be created, the store transaction when a purchase could not be processed, and a tracker's raw coordinates when a position could not be saved.
One analytics event exists, and it is not about you. When a tracker reports a position while linked to no account, we send Mixpanel its identifier, position and battery level under a fixed identifier tied to no user, so that we can find unpaired hardware in the field. It goes to Mixpanel's European service with address-based location lookup off.
BetterStack checks from outside that the service is up. Every request to our API, including every tracker report, passes through Cloudflare's edge network.
Why we process it, and on what basis
| What we do | Data and legal basis |
|---|---|
| Run your account and sign you in | Account data. Performance of our contract. |
| Show your tracker's position, its recent history and its battery | Tracker, position and pet data. Performance of our contract. |
| Watch safe zones and alert you | Safe-zone and notification data. Performance of our contract. |
| Check and record your subscription | Subscription data. Performance of our contract, and our legal duty to keep business records. |
| Keep the service running, find faults, prevent abuse | Diagnostics data. Our legitimate interest in a service that works and is not misused. |
| Find trackers reporting while linked to no account | A tracker identifier, position and battery level, under no user identifier. Our legitimate interest in supporting hardware in the field. |
| Answer you when you write to us | Your message and email address. Our legitimate interest in replying. |
| Use your camera, photo library, phone location or notifications | Your permission, given in your phone or browser and withdrawable there. |
An email address and a paired tracker are necessary for the service. Nothing here rests on your consent to the policy itself.
Who receives the data
We do not sell personal data and do not share it for advertising. These services process it for us:
| Recipient | What it receives |
|---|---|
| Google (Firebase and Google Cloud) | Sign-in and passwords, the database holding every record above, photos, the servers running our API, push delivery, message queues, hosting and crash reports. |
| Apple and Google Play | Subscription purchases and renewals, and the identifiers above. |
| Cloudflare | Every request to our API, including the tracker's reports, as it passes the edge. |
| Sentry | The error reports described above. |
| Mixpanel | The single unpaired-tracker event described above. |
| BetterStack | Uptime checks against our API. No customer data. |
| OpenStreetMap and Google Maps | Map tile requests your browser or phone makes when a map is shown, revealing your network address and the area you are viewing. |
Two other recipients matter. Where more than one account is linked to the same tracker, each can see that tracker's positions. And our staff, through an internal console, can look up an account with its email address, name, trackers and subscription state, see a tracker's recent positions, correct a name and delete an account.
We also disclose data where the law requires it, or where it is necessary to bring or defend a legal claim or to protect others.
Where the data is processed
Our servers run in Google's europe-west1 region in Belgium, and our scheduled jobs run on Prague time. The unpaired-tracker event goes to Mixpanel's European service.
The regions of the database and the media storage holding the records above are being confirmed and will be named here.
Some of the recipients above process data outside Switzerland and the European Economic Area. The safeguard for each of those transfers is being confirmed and will be named here.
How long we keep it
| Data | How long we keep it |
|---|---|
| Position history | 7 days. Older records are deleted every night at 03:00 Prague time. |
| A tracker's last known position | Kept on the tracker's record; not covered by the 7-day deletion. |
| Account data, tracker records, photos, safe zones | As long as the account exists. See Deleting your account. |
| Push registration tokens | Deleted after 90 days without use. |
| Notification records | 72 hours. |
| Subscription records and their event log | Kept after the account is deleted, as a record of the transaction. |
| Store notification identifiers | Kept indefinitely, so the same store message is not processed twice. |
| Records of a deleted account and its trackers | Retained in deactivated form. See below. |
When an account is deleted we deactivate rather than erase the account record, which keeps the email address, name, identifiers and creation date, and its tracker records, which keep their name, last known position and battery summaries. We do not delete them after a fixed period.
How long the crash and error reports above are kept is set in the services that hold them, and is being confirmed.
Your rights
Under the General Data Protection Regulation and the Swiss Federal Act on Data Protection you can ask us to:
- Tell you what data we hold and give you a copy of it.
- Correct data that is wrong.
- Delete your data.
- Restrict what we do with it while a question is open.
- Give you the data you provided in a portable form.
- Stop processing that rests on our legitimate interests, which you may object to at any time.
Some of this you can do yourself: change your name in the app, delete the account, turn notifications off, and withdraw the camera, photo library or location permission in your phone's settings. Withdrawing a permission does not affect what was done while it was granted.
For anything else, write to privacy@pixeesoft.ch. We may ask you to confirm who you are first, so that we do not hand your data to someone else.
Complaints
If you think we have handled your data wrongly, tell us at privacy@pixeesoft.ch so that we can put it right. You may also complain to a supervisory authority:
- In the Czech Republic, the Office for Personal Data Protection.
- In Slovakia, the Office for Personal Data Protection of the Slovak Republic.
- In Switzerland, the Federal Data Protection and Information Commissioner.
You may also complain to the authority where you live or work.
Deleting your account
You can delete your account yourself, in the settings screen of the iOS and Android apps and the account screen of the web app. It is immediate and cannot be undone.
Deleting the account removes:
- The link between your account and every tracker; the tracker records are deactivated.
- Your pet photos and your account picture.
- Every safe zone you created.
- Your notification records and every push registration.
- Your sign-in, so that email address and password no longer work.
What remains: the deactivated account record with your email address, name, identifiers and creation date; the deactivated tracker records with their last known position and battery summaries; position records until the nightly job reaches them, within 7 days; your subscription records and their event log; and any crash or error report already captured.
Deleting your account does not cancel your subscription. Cancel it in the App Store or in Google Play separately, before you delete the account.
If you cannot reach the in-app option, write to privacy@pixeesoft.ch and we will delete the account for you.
How we protect the data
No system is perfectly secure. These are the measures actually in place:
- Everything travels over encrypted connections.
- No app, browser or console can write to our database directly. Every change goes through our API, which checks who you are.
- You can read only your own records and the trackers linked to your account. Your photos are readable by you, and by our staff console in read-only form.
- The tracker's reports are accepted only from our edge network and only with a shared secret.
- Store notifications are accepted only with a valid signature, are rejected if too old, and are processed once.
- Our API accepts browser requests only from our own web addresses, and rejects any field it does not expect.
Children
Peyda Track is a paid service for adults. You must be 18 to take out a subscription, and the service is not intended for anyone under 16. We do not verify age, so please do not create an account if you are younger.
If you believe a child has given us personal data, write to privacy@pixeesoft.ch and we will delete it.
Cookies and storage in your browser
None of our websites sets a cookie. There is no consent banner because there is nothing to consent to: no analytics, no advertising and no third-party scripts. This website stores nothing in your browser at all.
The web app keeps a few values in your own browser, which never reach us:
| What is stored | Why |
|---|---|
| Your light or dark theme choice | So the site looks the way you left it. |
| Your language choice | So the app opens in the language you picked. |
| Your push registration token | So that signing out can hand it back. |
| A flag that a prompt has been shown | So it is not shown twice in one visit. |
| Your signed-in session | So you stay signed in. It is kept by the Firebase sign-in library. |
Automated decisions
We make no automated decisions about you with legal or similarly significant effects, and we do not profile you. A safe-zone alert compares a reported position with a shape you drew.
External services and links
This website loads the App Store and Google Play badge images from Apple and Google, so your browser requests them. Our fonts are served from our own site. Nothing else is loaded from a third party.
When a map is shown, the web app loads tiles from OpenStreetMap and the mobile apps use their platform's Google Maps components. Those requests reveal your network address and the area you are viewing.
Links to the app stores, to the shop that sells the tracker and to other sites are for convenience. We do not control them.
Changes to this policy
When this policy changes we publish the new version on this page and update the date at the top. Where a change materially affects you, we will say so on this site.
Contact
Pixeesoft GmbH, Rue Fendt 1, 1201 Geneva, Switzerland.
Privacy questions and requests: privacy@pixeesoft.ch. Anything else: track@peyda.app.
See also our Terms and Conditions, the End User Licence Agreement and the Disclaimer.