🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
PawPack

PawPack Privacy Policy

Your pet-care workspace is local-first, with clear choices for sync, sharing, diagnostics and personal backup.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Local-first Working records begin in the app's on-device database
Purposeful sync Supported business records synchronize to operate account features
Sharing choices You decide when to publish or send client-facing links
Private backup Google Drive access is optional and separately authorized
Your controls In-app export and account deletion tools are available
On this page
  1. Overview
  2. Data We Handle
  3. How We Use Data
  4. Storage and Residency
  5. Cloud and Backups
  6. Public Links and Client Pages
  7. Sharing and Processors
  8. Retention
  9. Security
  10. Your Rights
  11. Children
  12. International Transfers
  13. Changes
  14. Contact

Blue Sparrow, a solo developer based in India, operates PawPack for independent pet-care professionals. This policy explains the information handled by the mobile app, PawPack backend, public pages and connected providers. PawPack does not sell personal data or use it for personalized advertising.

Overview

This Privacy Policy applies to PawPack's mobile application, synchronized services, public booking and client pages, hosted reports and invoices, support channels and related communications. It covers users globally and is intended to reflect data-protection principles under the EU and UK GDPR, India's Digital Personal Data Protection framework, the California CCPA and CPRA, and comparable privacy rules in other regions.

Blue Sparrow generally acts as controller for account, service, diagnostic and support information. A pet-care professional generally decides why client, household and pet records are entered and shared; for that content, Blue Sparrow processes the information to provide PawPack on the professional's instructions.

Plain-language promise

PawPack collects and uses information to run the service, protect it, support users and provide features they choose. It does not sell personal data or build advertising profiles.

Data We Handle

The categories below depend on the features you use and the information you choose to enter.

  • Account identifiers from Google Sign-In and Firebase Authentication, such as Firebase user ID, name, email address and profile image.
  • Business profile and settings, including business name, logo, contact details, service area, timezone, currency, availability, services, pricing, booking policies and payment instructions.
  • Client and household records, including names, email addresses, phone numbers, service locations, access instructions, key or lockbox information, alarm or parking notes and communication preferences.
  • Pet records, including names, photos, type or breed, care and feeding instructions, medication notes, emergency or veterinary details and other notes the user enters.
  • Booking, visit and care records, including schedules, recurring series, packs, status history, care checklists, private and client-visible notes, photos, reports and reminders.
  • Precise location points recorded while route tracking is active, including coordinates, timestamps and accuracy. PawPack calculates duration, distance and an encoded route summary; the route summary can synchronize and can appear in a report the user chooses to share.
  • Billing and document records, including invoice items, prices, taxes, status, sequential identifiers, payment-instruction snapshots, generated PDFs, uploaded files, document types and expiry details. PawPack does not receive a client's card or bank credentials for direct client payments.
  • Client communication and portal activity, including message threads, posts, read status, profile-change requests, reviews, ratings, referrals and related audit events.
  • Public-page information submitted by clients or visitors, such as contact details, pet and service information, requested times, messages, booking status actions and content viewed through a shared link.
  • Subscription information from Google Play and RevenueCat, such as product, entitlement, purchase status and expiry metadata. Blue Sparrow does not receive full payment-card details from these providers.
  • Device and service information, such as app version, operating-system details, locale, timezone, Firebase Cloud Messaging token, request and sync identifiers, timestamps, security logs, IP address, browser or user-agent information and rate-limit or anti-abuse signals.
  • Crash and diagnostic information collected by Firebase Crashlytics in non-debug mobile builds, which can include stack traces, device and app state, error context and identifiers needed to investigate reliability issues.
  • Support, contact and feedback content, including the message, optional contact details, limited diagnostics the user elects to attach and delivery or receipt metadata.

PawPack does not include a third-party advertising SDK. Data entered about another person should be limited to what the pet-care professional is permitted to use for the service.

How We Use Data

Blue Sparrow uses information only for relevant operational purposes.

  • Authenticate users, protect accounts and maintain signed-in sessions.
  • Provide local-first scheduling, client and pet records, visit workflows, route summaries, reports, invoices, documents, messages and reminders.
  • Synchronize supported records, resolve conflicts, provide multi-device continuity and maintain server-owned invoice, subscription and public-link functions.
  • Operate public booking, client portal, report, invoice, status, export and file-delivery pages requested by users.
  • Send chosen push notifications, transactional emails and service messages.
  • Verify subscriptions, apply usage limits and unlock eligible features.
  • Diagnose crashes and failures, answer support requests, prevent abuse, secure infrastructure and improve reliability.
  • Meet record-keeping, safety, fraud-prevention and other obligations that apply to operating the service.

Processing is based, as applicable, on providing the requested service, legitimate interests in security and reliability, consent for optional permissions or integrations, and obligations that apply to Blue Sparrow. Where consent is the basis, it may be withdrawn through the relevant device, provider or app control without affecting earlier processing.

Storage and Residency

PawPack uses a split storage model. Working records and cached files are held in the app's Drift database and app storage within the device operating system's sandbox. Supported account and business records synchronize with the PawPack API and backend storage when backend services are enabled and the device is connected. PostgreSQL is the server authority for synchronized and multi-device features, and hosted files support user-requested public deliverables.

Blue Sparrow-controlled synchronized content, hosted files and service backups are intended to remain on infrastructure in the European Union. This commitment is subject to verification of each production data-centre, backup region and deployment configuration. It does not apply to on-device storage, a user's optional Google Drive, or limited data processed by third-party identity, notification, diagnostics, subscription, email, store and security providers under their own infrastructure arrangements.

Release builds must be configured with the production PawPack API and public-web endpoints for the corresponding cloud and public-page functions to operate. A build without those endpoints can continue to offer local capabilities but cannot provide every synchronized feature.

Cloud and Backups

Google Drive backup is optional and is separate from PawPack's live synchronization. PawPack asks for the Drive app-data scope only after a user chooses to connect the integration. The scope is limited to PawPack-created content in the private app-data area and does not grant PawPack general access to ordinary Drive files.

When a backup runs, PawPack can upload a database archive and associated media needed for restore. Database backup archives are encrypted on the device before upload. Associated media can be uploaded as separate files in the private app-data area and does not necessarily receive the same archive-level encryption. Google protects the account and transfer according to its services and controls. Encryption keys for database archives are deterministically derived from the signed-in Firebase user identifier and an app-specific derivation process so an eligible signed-in user can restore on another device.

Users control whether to connect Drive, start or schedule backups, choose retained backup count within the app's options and remove PawPack backup files through their Google account. Deleting a PawPack or Firebase account does not by itself delete files already stored in the user's Drive; those files must be removed separately. Google may process Drive account and backup data outside the European Union under its terms and transfer safeguards.

Public Links and Client Pages

PawPack can create public booking pages, client portal functions, booking-status actions, hosted reports, hosted invoices and time-limited data-export downloads. Users choose what to publish or share. Pages and links can expose contact details, pet information, visit notes, photos, route displays, invoice details, payment instructions, messages, documents or other selected content to the recipient.

Public and hosted links use slugs or access tokens and may support revocation or expiry. A token is not the same as signing in: anyone who receives a working link may view or act on the content allowed by that link. Users should check recipients, avoid placing sensitive household-access information in public content, revoke links that are no longer needed and use portal-safe fields. PawPack applies redaction rules to selected household-access fields before public serialization, but users remain responsible for reviewing what they intentionally publish.

Public services may log IP address, user-agent, access time, requested resource and security outcome. They may use an anti-abuse provider such as Cloudflare Turnstile when that control is enabled. Search-exclusion instructions can reduce discovery on some hosted pages but cannot guarantee that a recipient will not copy or redistribute content.

Sharing and Processors

Blue Sparrow does not sell or rent personal data. Information is disclosed only as needed to provide the service, at the user's direction, for a business transition with appropriate protections, or when reasonably necessary to meet valid obligations, protect people, investigate abuse or secure the service.

Third-party processors and platforms can include:

  • Google Sign-In and Firebase Authentication for identity and account access.
  • Firebase Cloud Messaging and the Blue Sparrow push gateway for push delivery, and Firebase Crashlytics for release-build crash diagnostics.
  • Google Drive for a backup the user separately connects, and Google Play for app distribution, purchases, renewals and cancellations.
  • RevenueCat for subscription entitlement and purchase-state management.
  • Blue Sparrow's API, infrastructure and database hosting providers for synchronized records, files, public pages, security logs and service backups.
  • Blue Sparrow's mail gateway and transactional email or support delivery providers for booking, document, message, support or account communications.
  • Cloudflare Turnstile or a comparable security provider if enabled for public-page abuse prevention.

These providers receive only the information needed for their role and operate under their own privacy terms and geographic infrastructure. Client-facing content is also disclosed to a recipient when a user sends a file, notification, email or public link.

Retention

Local information remains until the user removes it, clears app storage, completes an in-app deletion flow or uninstalls the app, subject to platform behavior. Synchronized records generally remain while the account is active and for a limited period afterward when needed for deletion recovery, security, backup rotation, fraud prevention, support, financial records or other valid operational obligations.

Retention depends on the record and release configuration. Current service rules can keep booking-status tokens for up to 30 days, generated export downloads for about 24 hours, hosted deliverables until revoked or expired and then for cleanup periods that can reach 90 days, and synchronized route summaries for up to 365 days. Security logs can rotate on shorter operational schedules. Provider-held Crashlytics, Google Play, RevenueCat, Google Drive and email data follows provider settings and terms.

PawPack provides an in-app account deletion flow that can remove backend-controlled data, local data and the Firebase account after account confirmation. Backend deletion can retain a minimal billing deletion marker where needed to prevent entitlement replay. It also provides a backend data-export request when the service is configured. Uninstalling or signing out does not necessarily erase the local database, cancel a Google Play subscription, remove synchronized records, or delete Google Drive backup files.

Security

PawPack uses safeguards designed for the nature of the information, including HTTPS or TLS in transit, authenticated API access, provider-issued identity tokens, database access controls, device sandbox storage, random public-link tokens, revocation controls, sensitive-field redaction for public payloads and encrypted database backup archives.

Some household-access details are obscured in the operator interface and excluded from selected public payloads. They remain in the local SQLite database and can synchronize for operator multi-device use; field-level encryption for those synchronized values is not currently claimed. Users should secure their device and Google account, share links carefully, avoid unnecessary sensitive details, keep the app updated and report suspected access promptly.

No technical system can promise complete security. Blue Sparrow reviews safeguards and responds to confirmed incidents in line with applicable notification duties.

Your Rights

Depending on region, a person may have rights to know or access personal data, correct it, receive a portable copy, delete it, restrict or object to processing, withdraw consent, opt out of qualifying sale or targeted advertising, and raise a concern with a data-protection authority. PawPack does not sell personal data or use it for targeted advertising, but the corresponding rights are respected where applicable.

Users can edit many records in the app, request a backend export, delete their account, change notification and location permissions in device settings, disconnect Google Drive and manage subscriptions in Google Play. For another person's information entered by a pet-care professional, contact that professional first when practical because they control the client record.

To submit a privacy request, email [email protected] with enough information to identify the account and request. Blue Sparrow may verify identity and authority before responding. Requests are handled without unlawful discrimination and within the timeframe that applies to the request. Authorized agents may be asked for proof of authority.

Children

PawPack is a business tool for adult pet-care professionals and is not directed to children. Blue Sparrow does not knowingly invite a child to create an operator account. Client-entered booking or household information could incidentally refer to a minor; users should avoid entering a minor's information unless it is necessary, permitted and accompanied by any required guardian notice or permission.

If a parent or guardian believes a child supplied personal data improperly, contact [email protected] so the information can be reviewed and removed where appropriate.

International Transfers

Blue Sparrow is operated from India, while Blue Sparrow-controlled synchronized content is intended for European Union infrastructure as described above. Support access may occur from India. Third-party providers may process limited identity, notification, diagnostic, billing, backup, communication or security data in other countries.

Where cross-border safeguards are required, Blue Sparrow relies on measures available for the transfer, such as contractual protections, provider data-protection terms, recognized adequacy arrangements or consent where appropriate. Users understand that local privacy rules can differ, while the rights and contacts in this policy remain available globally.

Changes

Blue Sparrow may revise this policy when PawPack, its providers or privacy requirements change. The updated date will change, and material changes may also be announced in the app or on https://bluesparrow.dev. Continued use after an update means the revised policy applies from its stated effective date, subject to any additional notice or consent required.

Contact

Blue Sparrow is a solo developer based in India.

  • Privacy and data requests: [email protected]
  • General support: [email protected]
  • Website: https://bluesparrow.dev

Please use email for requests so Blue Sparrow can verify and track the response securely.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.