Privacy policy
Version 2026-05-03
This policy explains which personal data gogeehaw collects, for what purpose, how long it is kept and how to exercise your rights, in accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and Law 25 (Quebec).
Data controller
gogeehaw, operated in Quebec (Canada) — general contact: support@gogeehaw.com.
Personal Information Protection Officer (Law 25)
Pursuant to Article 3.1 of Quebec's Law 25, a Personal Information Protection Officer has been designated. You can contact them for any question about your rights, a privacy incident, or to file a complaint prior to the Commission d'accès à l'information (CAI):
gogeehaw PIPO — dpo@gogeehaw.com. Reply within 30 days as required by Law 25.
For users residing in the EU/EEA: this same contact acts as the single point of contact within the meaning of Articles 27 and 38 GDPR.
Data collected
- Account: first name, last name, email, password (hashed server-side, never stored in clear text), locale, time zone, encrypted 2FA secret (when enabled)
- Profile: user type (musher, breeder, club…), bio, emergency contact, social networks (entered voluntarily)
- Dog records: veterinary, sport and lineage information, photos, notes, documents (entered and uploaded voluntarily by the user)
- Photos & documents: stored in a private Cloudflare R2 bucket and served via a signed URL. Deleted when the user removes the photo or deletes their account.
- Training sessions: distance, duration, GPS track, heart rate, speed, elevation, cadence — entered manually or imported after explicit authorisation. Sessions are retained without a time limit for the life of the account, except when the user requests deletion, deletes the account, or a provider requires deletion (including direct Strava revocation).
- Biometric data (special category GDPR art. 9): heart rate, when imported from your watch via Strava, constitutes health data within the meaning of Article 9 GDPR. Its processing relies on your explicit consent collected at the time of the Strava connection (dedicated checkbox). You can withdraw this consent at any time by disconnecting Strava — collection stops immediately; sessions already imported stay in your log and can be deleted individually at any time. Revoking from strava.com triggers full erasure of Strava data within 48 hours.
- Push notifications: if you enable them, we keep the endpoint URL and the public keys provided by your browser, until revoked.
- Payments: Stripe customer ID, subscription status, last payment token (never the card number)
- Security: IP address, user-agent, access logs and authentication log (login attempts, password changes, 2FA activations)
- Canine health AI: provided description, consultation metadata, AI response. Photos sent to the AI model are not stored.
- AI usage: number of tokens, cost, action type — only for the purpose of budget capping and abuse detection (automatically purged after 90 days).
- Compromised password check: when creating or changing a password, a prefix (first 5 characters of the SHA-1) is sent to the Have I Been Pwned service via their k-anonymous API. The full password and your email are never transmitted.
Legal bases
- Performance of the contract: account, records, payments, operation of the application
- Explicit consent: canine health AI module, newsletters, identified usage statistics (cookie banner), push notifications, Strava import
- Legitimate interest: security (logs, auth log, rate-limit, Turnstile), fraud prevention, customer support
Retention period
- Active account: as long as the account is open
- Deleted account: immediate soft deletion, permanent erasure after 30 days
- Accounting data (Stripe invoices): 7 years (tax obligation)
- Security logs: 30 days
- Authentication log: 180 days
- Rate-limit: 7 days
- AI usage (tokens, costs): 90 days
- Health AI consultations: 24 months — justified by (a) quality audit of the model and continuous improvement, (b) preservation of evidence in case of litigation (civil prescription in Quebec: 3 years, art. 2925 C.c.Q.). You can request their early erasure via the GDPR / Law 25 section of your account if you wish.
- Push notifications: until revoked by the user or rejection of the endpoint by the browser
Sub-processors
All transfers outside the EU/Canada are governed by Standard Contractual Clauses (EU-SCC 2021/914) or an equivalent transfer mechanism. List updated on 3 May 2026.
- Cloudflare (Workers, KV, R2, Hyperdrive, Analytics Engine, Web Analytics, Turnstile) — edge hosting, CDN, object storage, caching, anti-bot, cookieless analytics. United States (corporate) with EU/Canada presence (colos), Standard Contractual Clauses.
- Neon (main Postgres database) — region chosen based on the user, EU by default
- Stripe (payments and billing) — Ireland / United States, PCI-DSS Level 1 certified
- Resend (transactional emails, bounce tracking) — United States, Standard Contractual Clauses
- Anthropic (Claude AI model for the canine health module, coach and training analysis) — United States; certified EU-US Data Privacy Framework (mechanism recognised by the European Commission for EU→US transfers, adequacy decision 2023/1795). Requests are not used to train the models according to Anthropic's policy at the time of writing.
- OpenRouter (multi-LLM gateway upstream of Anthropic and other providers, routes requests to the most suitable model) — United States, Standard Contractual Clauses
- Strava (optional session import, OAuth triggered by the user, scopes
read+activity:read_allread-only) — United States. You can revoke this authorisation at any time from your Strava account or from /modules/training. Strava data is never sold, rented or shared with a third party, even in aggregated or anonymised form. Effective deletion of corresponding activities in our databases within 48 hours after revocation or after the deletion of an activity on the Strava side (webhookactivity:deleteetathlete:deauthorize). Anthropic AI analyses on these activities are inference calls without retention — no Strava data is used to train, fine-tune or evaluate a model. - Open-Meteo (historical weather and forecasts based on the GPS coordinates of a session or booking) — Germany (EU)
- Apple Push Notification Service (APNs) — iOS push notifications, United States
- Google Firebase Cloud Messaging (FCM) — Android push notifications, United States
- Have I Been Pwned (k-anonymous check of compromised passwords — only the first 5 characters of the SHA-1 hash transit) — United Kingdom / Australia
- better-auth (open-source auth library embedded in our Cloudflare servers — not an external service, mentioned for transparency)
The addition of a new sub-processor is subject to a list update at least 7 days before it takes effect, except in the case of an urgent replacement (provider outage, security incident).
Security measures
- TLS 1.3 encryption (certificates managed by Cloudflare)
- Hashed passwords (Better Auth, scrypt)
- Anti-leak check via Have I Been Pwned (k-anonymous) on every password creation or change
- Optional TOTP 2FA
- Database rate-limit against brute force
- Cloudflare Turnstile (invisible CAPTCHA) on sign-up
- HMAC cookies + IP/UA binding for the admin impersonation session
- Security headers (CSP, HSTS, X-Frame-Options) applied via middleware
- AI safeguards (rate-limit, budget cap, prompt-injection detection) before any call to the model
- Email suppression list on bounce or complaint (RFC 5322 / abuse)
- Encryption at rest (Neon, R2, KV — managed)
Your rights (GDPR / Law 25)
You have the following rights. Rights of access, portability and erasure can be exercised directly from your account ("GDPR" section under /account) — most others can be exercised by email:
- Right of access and copy (JSON and Markdown export in one click)
- Right to rectification
- Right to erasure ("right to be forgotten") — self-service account deletion
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw your consent at any time (cookie banner, Strava revocation, push notification disabling)
For any other request: support@gogeehaw.com. Reply within 30 days at most.
Cookies
gogeehaw uses only first-party cookies that are strictly necessary for operation (auth session, CSRF token, preferred language, consent preferences, anti-bot challenge cookie). No advertising or third-party tracking cookies are set. You can review your preferences at any time from the "Cookies" button in the footer.
Complaints
If a dispute remains unresolved, you may contact the competent supervisory authority: the CAI in Quebec, the CNIL in France, or the authority of your country of residence.