🐾 Welcome To Taggzi 🐾 Use Discount Code WELCOME10 For 10% Off At Checkout Buy Now β†’
Taggzi
🎁 Gift 🐾 Sponsor
Β§ Legal

GDPR & data protection.

01 Data controller

The data controller responsible for your personal data is:

Data controller: Taggzi is currently operated as a UK sole trader by Steven Chowns trading as Taggzi. A UK limited company + registered trademark are planned; when the transition happens this notice will be updated with the new company number and registered address.

Correspondence address: Taggzi, Unit 172585, PO Box 7169, Poole, BH15 9EL

Contact for privacy / data-subject requests: privacy@taggzi.com

ICO registration: our registration with the Information Commissioner's Office has been applied for and is being processed. This notice will show our registration number once it is issued.

Effective date: 24/09/2026

Scope note: Taggzi is expanding across five verticals β€” Taggzi-Pet (live), Taggzi-Travel, Taggzi-Active, Taggzi-Care, and Taggzi-Luxe (each launching in turn). This notice currently applies to Taggzi-Pet and any general account / commerce activity. As each additional vertical launches we will update these terms to describe the specific data types it handles.

Data Protection Officer: Taggzi is not required to appoint a statutory Data Protection Officer under UK GDPR Article 37 because we are a small controller whose core activities do not involve large-scale, regular monitoring of data subjects or large-scale processing of special-category data. All privacy queries are handled directly by the sole trader named above (or their successor entity once incorporation completes) at privacy@taggzi.com. If our activities change so that Article 37 applies, we will appoint a DPO and publish their contact details here.

02 Personal data we collect and why

CategoryDataPurposeLegal basisRetention
AccountName, email address, password (hashed)Account creation, authentication and service deliveryContract (Art. 6(1)(b))Life of account + 90 days
Pet profilePet name, species, breed, colour, DOB, microchip number, medical notes, vet detailsPublic pet profile β€” displayed to finders who scan the tagContract (Art. 6(1)(b))Life of account + 90 days
Contact preferencesPhone, email, WhatsApp (only fields you choose to make public)Displayed on pet profile at your discretionContract (Art. 6(1)(b))Life of account + 90 days
Scan logsTimestamp, scan method (NFC/QR), SHA-256 hash of IP address (raw IP never stored)Tag activity analytics; fraud preventionLegitimate interest (Art. 6(1)(f))24 months, then auto-deleted
SubscriptionStripe customer ID, subscription tier, status, period end dateManaging your Pro subscriptionContract (Art. 6(1)(b))Life of account + 7 years (financial records)
PaymentProcessed entirely by Stripe β€” we receive only a customer reference IDPayment processingContract (Art. 6(1)(b)) β€” Stripe is independent controller7 years (HMRC)
Community alertsEmail address, geographic areaSending lost pet alerts in your areaConsent (Art. 6(1)(a))Until you unsubscribe
Order detailsName, email, delivery address, phoneProcessing and shipping physical tag ordersContract (Art. 6(1)(b))7 years (HMRC)
Push notification tokensAPNs / FCM device token, platform, app versionDeliver scan alerts, Lost Mode notifications, and account-critical messages to your deviceContract (Art. 6(1)(b))Until you sign out or uninstall the app
Support inboxEmail address, name, message body, attachmentsResponding to your support enquiriesContract (Art. 6(1)(b)) + Legitimate interest24 months in inbox, then archived off-platform for 5 further years (contract-record obligation)
Marketing preferencesEmail address + opt-out timestamp (suppression list only)Ensure we never email you again after unsubscribeLegitimate interest (Art. 6(1)(f))Indefinite as suppression list only
Competition entriesName, email, entry answer, entry timestampRunning competitions and delivering prizesConsent (Art. 6(1)(a))12 months after the competition closes

03 Legitimate interests

Where we rely on legitimate interests as our legal basis, we have carried out a balancing test and concluded that our interests are not overridden by your rights. Specifically:

  • Scan logs (IP hash): We record a one-way SHA-256 hash of the scanner's IP to detect abuse and provide owners with tag activity data. Raw IP addresses are never stored. You can object to this processing β€” see section 7.
  • Service security and fraud prevention: Detecting and preventing fraudulent or abusive use of the service.

04 Who we share data with

Stripe, Inc.

Payment processing. Stripe acts as an independent data controller for payment data and is certified PCI-DSS Level 1. Stripe's privacy policy: stripe.com/gb/privacy

USA (SCCs + UK IDTA)
StackCP / 20i Ltd

Web hosting and StackCDN caching. All website data is stored on UK servers.

United Kingdom
Resend

Transactional and marketing email delivery (via Resend Ltd's API).

USA (SCCs + UK IDTA)
Apple Inc.

Apple Push Notification service (APNs) β€” delivery of iOS companion-app notifications. Only the device token + notification payload transit APNs.

USA (SCCs + UK IDTA) β€” iOS only
Google LLC

Firebase Cloud Messaging (FCM) β€” delivery of Android companion-app notifications. Same conditions as APNs.

USA (SCCs + UK IDTA) β€” Android only
Apple App Store & Google Play

Where you download the companion app. Independent controllers for the download transaction.

USA (independent controllers)
Postcodes.io (Ideal Postcodes Ltd)

Postcode checks on address forms, and postcode → location lookups for Community Alerts and vet routing. Only the postcode (or a map point) is sent β€” no user identifier.

United Kingdom
Photon by komoot (OpenStreetMap data)

Turns a map point a finder chooses to share into a street and town name for the owner’s alert. Only the map point is sent β€” no names or contact details.

Germany (EU)
ShipStation (Auctane / carrier partners)

Physical tag fulfilment when you order a tag β€” receives delivery address and order details.

USA (SCCs + UK IDTA) & UK carriers
Meta Platforms Ireland Ltd

Facebook, Instagram, and Threads publishing when we cross-post announcements from our own admin. We store OAuth tokens; user data is not sent to Meta beyond what appears on our public posts.

Ireland (EU)
Google LLC (Gemini API)

AI-assisted caption drafting for our social posts. Only the caption prompt transits Gemini β€” no personal data. Optional, admin-only.

USA (SCCs + UK IDTA)
Anthropic PBC (Claude API)

AI-assisted caption drafting for our social posts. Same conditions as Gemini above. Optional, admin-only.

USA (SCCs + UK IDTA)
Finder of a lost pet / item

Contact details you choose to make public on your profile are visible to anyone who taps or scans the tag. You control this from your privacy settings.

N/A β€” you control this

We never sell, rent, or trade your personal data to third parties for marketing purposes.

05 International data transfers

Your data is primarily stored on UK servers (20i / StackCP). Certain sub-processors listed in section 4 are established in the United States (Stripe, Resend, Apple, Google/FCM, Google/Gemini, Anthropic, ShipStation) or the European Union (Meta Platforms Ireland). All transfers outside the UK are protected by:

  • Standard Contractual Clauses (SCCs) as approved by the EU Commission; and
  • The UK International Data Transfer Addendum (IDTA) issued by the ICO, which brings each transfer within the UK's adequacy framework.

No transfer takes place to any country the ICO has not confirmed as adequate or to any recipient not bound by SCCs + IDTA. You can request a copy of any transfer safeguard by emailing privacy@taggzi.com.

05a Special category data (UK GDPR Article 9)

Taggzi-Pet may contain optional veterinary or animal-medical notes. This is data about an animal, not a human data subject, so Article 9 does not apply to the current live service.

The Taggzi-Care vertical (medical-alert and carer-contact tags for people) is announced but not yet accepting orders. When it launches, it will process Article 9 human health data under one or more of:

  • Article 9(2)(a) β€” explicit consent, obtained through a dedicated consent flow separate from general account signup;
  • Article 9(2)(c) β€” protection of vital interests where the data subject is physically or legally incapable of giving consent (e.g. medical emergency after a Taggzi-Care tag is scanned).

Before Taggzi-Care goes live we will publish a dedicated Data Protection Impact Assessment (DPIA) and update this notice with the specific safeguards for Article 9 data (encryption at rest, minimisation, retention, breach-notification thresholds). We will not begin collecting Article 9 human data before that update is published on this page.

06 Your rights under UK GDPR

πŸ”

Right of Access (Art. 15)

Request a copy of all personal data we hold about you. We will respond within 30 days.

✏

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data at any time from your account settings.

πŸ—‘

Right to Erasure (Art. 17)

Request deletion of your data. You can self-serve via the Delete Account option in settings.

πŸ“¦

Right to Portability (Art. 20)

Download all your data as a structured JSON file from Account Settings β†’ My Data.

βœ‹

Right to Object (Art. 21)

Object to processing based on legitimate interests (e.g. scan log IP hashing).

⏸

Right to Restriction (Art. 18)

Ask us to restrict processing of your data in certain circumstances.

🚫

Withdraw Consent (Art. 7)

Withdraw consent for community alert emails at any time using the unsubscribe link.

πŸ€–

Automated Decision-Making (Art. 22)

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

07 How to exercise your rights

Self-service (instant): Download your data or delete your account from Account Settings.

Email request: Contact privacy@taggzi.com for access, rectification, restriction, or objection requests. We will respond within 30 calendar days as required by UK GDPR. We may ask you to verify your identity before processing requests.

Contact form: taggzi.com/contact

08 Cookies

CookieTypePurposeDuration
wordpress_logged_in_*Strictly necessaryWordPress login session β€” keeps you authenticatedSession
wordpress_sec_*Strictly necessaryWordPress security tokenSession
wp-settings-*FunctionalWordPress user preferences (admin only)1 year
pt_cookie_consentFunctionalStores your cookie choice1 year
Stripe (_stripe_*)Strictly necessaryFraud prevention during checkout (Stripe sets these)Session/30 min
_gcl_au, _gcl_aw (Google Ads)Advertising β€” only if you acceptMeasures which of our Google ads led to a sign-up or order. Never set on pet profile pages.Up to 90 days

Google Ads cookies are only set if you choose "Accept" in the cookie banner, and never on pet profile or other finder-facing pages. Change your choice any time with Cookie settings.

09 Children's data & age of use

Two distinct age thresholds apply, in line with UK law:

  • Age 13 β€” UK GDPR digital-consent floor. Taggzi is not directed at children under 13 and we do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided us with data, contact privacy@taggzi.com and we will delete it promptly.
  • Age 18 β€” contractual capacity. A Taggzi account is a paid contract (Pro subscription, tag order, delivery of goods) which under English law requires contractual capacity. We therefore require the account holder to be aged 18 or over. Parents / guardians aged 18+ may hold the account and add pet or item profiles on behalf of a minor. The account-holder eligibility clause is at section 3 of the Terms of Service.

10 Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • HTTPS encryption in transit (TLS 1.2+)
  • Passwords stored as bcrypt hashes β€” never in plaintext
  • IP addresses never stored β€” only one-way SHA-256 hashes
  • Payment data never touches our servers β€” Stripe handles all card processing
  • Access to personal data restricted to authorised personnel only
  • Email verification required before account activation

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay as required by Article 33–34 UK GDPR.

11 Changes to this notice

We may update this notice to reflect changes in our practices or legal obligations. We will notify registered users by email of any material changes. The "Last updated" date at the top of this page indicates when the notice was last revised.

12 Complaints

If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113 (local rate) Β· 01625 545 745
Web: ico.org.uk/make-a-complaint

We would appreciate the opportunity to address your concerns before you contact the ICO β€” please email privacy@taggzi.com first.

13 Related documents

For complete details, read our full Privacy Policy. To exercise your rights immediately, visit Account Settings β†’ My Data.