PetPark · Privacy
Privacy notice
How we use information and the choices available to you.
Updated: 30 September 2026.
1. Controller and contact
The data controller is LJEMICUS DIGITAL j.d.o.o., OIB 67287589092, Mate Balote 20D, 51000 Rijeka, Croatia. PetPark is its platform at petpark.hr. Contact info@petpark.hr with privacy questions and data requests. Company details: LJEMICUS DIGITAL jednostavno društvo s ograničenom odgovornošću za usluge i trgovinu; MBS 040499074; Commercial Court in Rijeka; share capital EUR 10.00.
2. Information and purposes
We process information you provide for your account and chosen features: name, email, city, phone, pet details, messages, photos and published content. Supabase supports authentication, the database and file storage. You use external sign-in only if you choose a provider currently offered in the interface. City and approximate location help connect owners with local providers; the location section below explains precise coordinates and GPS.
3. Provider applications and verification
We process the registered name, registration country, Slovenian tax number or Croatian OIB, registered address, responsible contact person, service location and description. We review business details in official registers, including AJPES for Slovenia, and record the source, date and result. The initial application does not ask for an identity document, selfie or bank details. If further information is needed for a service, lawful basis or clarification, we explain why and request only what is necessary. Registry review is not verification of personal identity. Marketing consent is separate from the application.
4. Legal bases
We process account and requested service data to perform a contract or take steps before entering it (GDPR Article 6(1)(b)); data required by law under Article 6(1)(c); and security and abuse prevention data on the basis of legitimate interests under Article 6(1)(f). Optional analytics, marketing measurement and features for which we request consent rely on Article 6(1)(a). Accepting terms or acknowledging this notice is not marketing consent.
5. Cookies and choices
Necessary cookies support sign-in, security and basic functions. Analytics and marketing are loaded according to configuration and your consent choice. You can refuse or change consent in Cookie settings in the footer. Refusing marketing does not prevent a provider application. Advertising personalisation is disabled. Cookie and localStorage names, purposes and durations are listed below.
6. Analytics
With analytics consent, Cloudflare Web Analytics and Plausible may measure visits and Vercel Speed Insights may measure public-page loading performance. We send sanitised URLs and technical measurements without search parameters, user identifiers or private routes. A network provider may receive your IP address when a request is made. Google Analytics is optional and is not currently loaded in the active interface.
7. Google Ads measurement
Only with marketing consent do we link advertising to a successfully submitted inquiry or provider application. For server-side application measurement, Google receives a click identifier, event time, technical application ID for deduplication, website source and consent signals. We do not send your name, email, phone or application content. A button click or draft is not a successful application. Click identifiers in the server queue are removed after processing, cancellation or expiry of the seven-day processing window. Withdrawal cancels still-pending events once the browser successfully notifies the server; it does not automatically retract previously processed events.
8. Recipients
Supabase provides authentication, the database and storage; the main project database is in the EU, with international transfers addressed below. Upstash Redis protects against excessive requests and abuse using technical identifiers (depending on the feature, IP addresses, account identifiers or an email-address hash when limiting confirmation resends) and expiring counters. An email hash is a pseudonymous identifier, not a guarantee of anonymity. Separate analytics of these counters is disabled. Vercel hosts the platform and processes technical requests, including network IP addresses. When configured, Sentry supports error diagnostics with sensitive content removed from telemetry. When you open a map, OpenStreetMap receives technical requests, IP address, the map area and zoom level. When email sending is enabled, Resend processes recipients’ addresses, subjects and transactional message content. The rules of your chosen external sign-in provider also apply. Optional analytics and marketing recipients and conditions are described above.
9. Stripe and payments
Stripe handles active card payments, refunds and providers’ connected accounts. For onboarding, PetPark sends the provider’s email, name and internal identifiers; Stripe collects verification and payout information through its own form. When payment starts, we send the amount, currency and identifiers for the booking, transaction and connected account. You enter card details on Stripe’s page; PetPark does not store the full card number or security code. We retain connection, payment and refund identifiers and statuses, and amounts required for bookings, accounting and dispute handling.
10. Private records and security
Verification documents are stored privately. Authorised administrators can access them; an authorised organisation-account owner can access that organisation’s documents. Document links expire. Completing a review does not automatically delete uploaded documents: contact info@petpark.hr to review continued retention or request deletion. Pet passport information, health details and documents are not publicly indexed. The owner accesses them in their account and explicitly shares a link or access with others. Lost-pet contact mediation does not publicly disclose the owner’s or finder’s private contact details; they are used to relay messages and prevent abuse with sending limits and security checks. We use safeguards including TLS in transit, hashed-password storage and restricted access.
11. Retention
We assess retention against the purpose, account use, open bookings, payments, refunds, disputes and legal obligations. Support handles deletion requests individually, identifying data for deletion, restriction or justified retention. A request does not itself delete an account or related records. For profiles and photos, we consider ownership, related posts and applicable exceptions. For messages, bookings and reviews, we consider the service, other participants’ rights and possible disputes; one person’s request does not automatically delete a shared record. Retention of Stripe and transaction information depends on connection status, payment, refunds, outstanding obligations and applicable accounting and tax periods. Stripe sets its own periods for processing it controls. For provider and organisation documents, we assess completion of verification, evidence of status or publication rights, objections and legal obligations. Approval does not automatically delete a document; the review result and document are separate records. Analytics retention depends on purpose and provider rules. Withdrawing consent stops future optional measurement but does not automatically erase existing records. Statistics from which individuals can no longer be identified differ from personal data. Contact info@petpark.hr for the purpose and retention criteria for particular records. If a request cannot be fully met, we explain the reason and scope of continued retention.
12. Your rights
Subject to GDPR conditions, you can request access, correction, erasure, restriction and portability and object to processing based on legitimate interests. You can withdraw consent for the future without affecting the lawfulness of earlier processing. Send requests to info@petpark.hr; export or deletion requests can also be submitted in account settings. Support processes these requests manually; acknowledgment does not confirm completion. We will inform you of action without undue delay and at the latest within one month of receipt. If complexity or the number of requests justifies up to two further months, we will explain the extension within the first month. This response period does not guarantee deletion of all records: we explain any refusal, restriction or necessary retention. You may complain to a competent supervisory authority, including Croatia’s AZOP or Slovenia’s Information Commissioner.
13. Minors and changes
The platform is intended for people over 16. If we discover data collected from a younger person without the necessary legal basis, we take appropriate steps to restrict processing or delete it. The registration age requirement does not establish legal capacity or authorise every contract or payment. You must have the capacity required for the particular service and, where applicable law requires it, a parent’s or guardian’s consent or representation. Anyone registering a business must be authorised to represent it. We will notify you of significant changes to this notice through the platform or email; please review this page periodically.
Location and GPS
We read device location only when you start a location feature and allow access in your browser. For a lost-pet report we store the selected coordinates; the public map receives an approximate location rounded to two decimal places, while the original record is accessible to the report owner and authorised administration. Text and photos you publish can also reveal a location, so do not include a private home address. When you start walk tracking, the GPS route, times, distance and checkpoints may be stored. This is not a public map: the record belongs to a booking and is available to its authorised participants and administration. When location access is refused or unavailable, use manual entry where the form offers it. GPS records follow the retention criteria and deletion request process for the related report or booking; we do not promise automatic deletion after a fixed number of days.
Browser storage names and duration
These periods are set by the application or the library currently used. Your browser may shorten them, and clearing site data removes local records. localStorage has no built-in expiry: unless an expiry check is stated, a record remains until changed, deleted or cleared by the browser.
- sb-…-auth-token (and numbered chunks)
- Supabase sign-in and session refresh. The library sets the cookie for up to 400 days and may renew it; signing out removes it. This does not guarantee a valid 400-day session: token expiry, security checks or revocation may require earlier sign-in.
- csrf_token
- Protects requests that change data; cookie up to 24 hours.
- pp_fb_state, pp_fb_next, pp_fb_role, pp_fb_link_user, pp_fb_link_session
- Facebook sign-in/linking security and return route; up to 10 minutes, removed when the callback is processed.
- pp_email_confirmation
- Temporary confirmation of an email link; HttpOnly cookie up to 15 minutes, removed when confirmation is processed.
- petpark-cookie-consent
- localStorage containing consent choices and policy version; no automatic expiry. A version change may request a new choice.
- petpark-language, petpark-theme
- Language: cookie up to 365 days and localStorage without expiry. Theme: localStorage without expiry.
- petpark-lost-report-draft-v1
- Lost-pet report draft text, contact and selected location, without files. The localStorage draft is valid for 24 hours; expired drafts are removed on the next read, and cancellation or successful publication deletes it.
- pp_mkt; pp_ads, pp_ads_last
- Only with marketing consent: consent signal up to 180 days; click and campaign data up to 90 days. Withdrawing consent removes attribution cookies.
- petpark-ads-revocation-pending
- localStorage marker to retry sending a marketing-consent withdrawal to the server; removed after successful processing.
- petpark-cart; petpark-notif-dismissed; push-notification-dismissed; rescue-onboarding-progress/completed/skipped
- Local cart, dismissed notification prompts and guide steps, only when you use the related feature. No automatic expiry; change/reset the feature or clear browser data to remove them.
International transfers
The primary project database is located in the EU. This does not mean all processing by every provider stays in the EU: hosting, support, security, payments and subprocessors may involve access or processing in other countries, including the US. Processing outside the EEA is subject to appropriate GDPR transfer mechanisms depending on the recipient and transfer, such as an adequacy decision or standard contractual clauses and associated safeguards. Providers publish their processing addenda and transfer mechanisms at the links below. Contact info@petpark.hr for information about recipients and protection for a particular transfer; using an EU region does not by itself exclude international transfers.