Privacy policy
ZooPlanet keeps only what the site and the app cannot work without: your account, the content you publish yourself, and a record of donations. There is no analytics, no advertising identifier, no cookie of any kind, and no third-party SDK inside the app collecting anything. This page sets out, specifically and without boilerplate, what is stored, why, who else sees it, and how to have it deleted.
Who we are, and who is answerable for your data
ZooPlanet is a volunteer project based in Serbia that connects animal shelters with people willing to cover the monthly costs of one particular animal. It is built and run in their own time by Marko Dinić, Marko Aleksić, Dušan Manić and Nikola Ristić. Those same people are the data controller under Serbia's Law on Personal Data Protection (ZZPL), which follows the European General Data Protection Regulation (GDPR) closely.
We have no employees and no appointed data protection officer. Every question, request or complaint about data goes to kontakt@zooplanet.org and is answered by the people named above.
What we collect
We collect what you give us and what the server has to record in order to answer a request at all. We buy data from nobody and import it from no external source.
One item deserves a line of its own, because people do not expect it in either direction: every photograph has the metadata written by the phone or camera stripped from it as it is published — the GPS coordinates of where the picture was taken, the device model and serial number, and the exact capture time. None of it reaches the site. The server builds the display versions from your upload and copies none of those records into them, and the upload itself is not kept. The one thing it does read is the orientation tag, so that the picture is not published on its side. What remains is the image, so a photograph taken at a sensitive address does not disclose where it was taken.
We never see or store card details. Payment happens entirely on Stripe's own pages, which we send you to; the card number, expiry date and security code never pass through our server.
- Account: e-mail address, first and last name, password (stored only as a bcrypt hash, never as text), chosen language, the roles you hold on the site, and whether your e-mail has been confirmed.
- Sign-in: a random session token, which sits on your account until you sign out, and a last-seen date — written at most once a day, and used only so that a shelter's administrators can see which volunteers are still active.
- Content you publish: photographs of animals and their captions, descriptions and stories on animal and shelter profiles, care-journal notes, and cost figures. Everything except the journal notes is public.
- Interactions: the animals you have saved as favourites, the ones you follow, and the reactions you have left.
- Donations: the e-mail address you give Stripe, the amount, currency and frequency, Stripe's transaction identifiers, which animal, shelter or campaign the gift is earmarked for, and — if you enter one — a message and the name of the person the donation honours.
- Server request logs: IP address, request method and URL, status code and a request id. Request headers and bodies are not logged, and passwords, tokens and donor e-mail addresses are redacted automatically.
- Shelter administration log: if you administer a shelter, every change to its settings, roles and membership is recorded with your e-mail address, a one-sentence description, the time, and the IP address it came from. That log is deliberately immutable — nothing in the application edits or deletes a row in it.
- Requests you send us: an account-deletion request is recorded in the database — who sent it, when, and the reason if you gave one — because the deadline cannot be tracked without it. A report sent through the safety form is stored nowhere: it reaches us as an e-mail, and that message is the only record of it.
Why we process it, and on what legal basis
Every kind of data here has one reason and one legal basis. If a field serves none of the purposes below, we do not ask for it.
We never process data for profiling, targeted advertising, or automated decisions that affect you.
- Performance of a contract: so that an account can exist, sign-in can work, your post can reach an animal's profile, and a donation can be earmarked for the shelter you chose.
- Legitimate interests: keeping the service secure, preventing abuse and spam, diagnosing faults, and the shelter administration log, which exists so a shelter can reconstruct who changed what.
- Consent: the daily digest for people who follow animals is sent only to those who switched it on, and is switched off again by one link inside every such message.
- Legal obligation: the record of donations received and of their onward transfer to shelters is kept because accounting and money-trail rules require it.
- Vital interests and the protection of children: we act on abuse reports and pass them to the authorities where necessary — see the child safety page.
What we do NOT do
This section is short on purpose, because there is no exception hiding in it. What follows is not a policy we intend to honour; it is a description of code that does not exist.
If any of it ever changes, this page changes with it — before the change takes effect, never afterwards.
- No analytics. No page views, sessions, events, funnels or heatmaps. We do not know how many people have seen a given page and we have no way to find out.
- No cookies. The public site sets no cookie of its own and none belonging to anyone else, which is why there is no cookie banner. The little that does stay in your browser is described in the next section.
- No third-party SDKs. The Android and iOS app carries no Firebase, no crash-reporting tool, no advertising identifier and no library that sends anything to anyone else. It asks for two permissions only: internet and camera.
- No cross-site tracking. Fonts are served from our own server, so no page makes a request to any content delivery network, and the site's own security policy forbids outbound requests to any other domain.
- We do not sell, rent or trade your data with anyone, for money or for services.
What stays in your browser and on your phone
In your browser's local storage we keep the session token, your e-mail address and first name (so we still know who you are after a page reload), your chosen language, your chosen theme, a flag for browsing as a visitor, and the time of your previous visit, which is used only to show you what is new since then. Signing out clears the token, the e-mail and the name; language and theme stay, because they are about appearance rather than about an account.
In the mobile app the same sign-in details are also held in the phone's system vault — Keychain on iOS, Keystore on Android — so that a session survives the app being restarted.
The app additionally keeps a local database for working offline: a queue of photographs and text not yet sent to the server, and a cache of images already downloaded. That data lives only on your phone and goes when you uninstall the app.
Who else processes your data
We use three service providers and no others. Each one handles only the part of the data its job needs, and none of them may use it for their own purposes.
Posts can also be syndicated to a shelter's own social accounts (a Facebook Page, Instagram, TikTok), but only if that shelter connects one. No shelter has connected an account and the feature is switched off system-wide.
- Postmark — sending e-mail (account confirmation, password resets, donation receipts, the daily digest, the app invitation). It receives the recipient's address and the name used inside the message.
- Stripe — payment processing. It receives the amount, currency and frequency, the e-mail address you give it, and the card details, which we never see.
- DigitalOcean — the server the site runs on, in a data centre in Frankfurt, Germany. The database, every published photograph and the daily disk backups live there.
Transfers outside Serbia
The server is physically in Germany, inside the European Economic Area. Postmark and Stripe are international companies and may carry out part of their processing outside Serbia and outside the EEA.
For those transfers we rely on the standard contractual clauses and other mechanisms those providers publish in their own data processing agreements. If you want to see exactly which documents, write to us and we will send you the links.
How long we keep what
We do not hold data "just in case". One part of it, though, cannot be deleted on the spot, and it is better to read that here than to discover it when you ask for deletion.
The full account of what is deleted, what is separated from your name and what remains is on the account deletion page.
- The account and its content: for as long as the account exists. Deletion happens on your request.
- E-mail confirmation and password reset tokens: deleted the moment they are used, and the reset token also when it expires.
- Server request logs containing IP addresses: rotated daily or every 10 MB, with the last fourteen rotations kept — on the order of two weeks.
- Daily whole-disk backups at DigitalOcean: seven days, after which the oldest expires by itself.
- The record of donations and of their transfer to shelters: kept for as long as accounting rules require, which is longer than the account the donation was made from.
Your rights
Under the Law on Personal Data Protection you have the rights listed below. To exercise any of them, write to kontakt@zooplanet.org from the address attached to the account. There is no charge and you do not have to give a reason.
We answer within thirty days at the latest. If a request is complex enough to need longer, we will tell you inside that same period and say why.
- The right of access: to receive a copy of the data we hold about you.
- The right to rectification: your name and e-mail you can also change yourself, in your profile.
- The right to erasure, within the limits set out on the account deletion page.
- The right to restrict processing, and to object to processing based on legitimate interests.
- The right to portability: we send your data in a machine-readable form.
- The right to withdraw consent at any time, with no effect on the rest of your account. The daily digest also unsubscribes from a link inside the message itself.
- The right to complain to the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade. We would be grateful if you came to us first, but it is not a precondition.
How we protect it
Passwords are stored as bcrypt hashes at cost 12 and cannot be read out of the database or out of a backup. A session is a random token with no meaning of its own, and it is never sent as a cookie. All traffic runs over HTTPS, the database accepts connections only from the server itself and from no external address, and a shelter's social media tokens are stored encrypted with AES-256-GCM.
Server access is limited to the people who run the project, by key rather than by password. No card data exists in the database or in the logs, because it never reaches us in the first place.
What security cannot change is that some content is public by design: an animal's profile, its photographs, captions and the shelter's details are visible to anyone on the internet and are indexed by search engines. Care-journal notes are not public and are visible only to someone entitled to edit that animal.
Children
The service is not intended for anyone under 16 and they should not create an account. We do not ask for a date of birth and do not verify age, because verifying it would mean collecting more data about everyone rather than less.
If we learn that an account belongs to a child under 16, we delete it and everything attached to it. If you are a parent or guardian and believe your child has an account, write to kontakt@zooplanet.org and we will deal with it without further questions. How we handle content that endangers children is on a page of its own.
Changes to this policy
The date of the last change is at the top of this page. The policy is edited in the same code change that alters whatever it describes, so it cannot fall behind what the application actually does.
If something substantial changes — a new kind of data, a new processor, a new purpose — we will publish it on the site before it takes effect, and e-mail everyone with a confirmed address.
Contact
For any question about data, for a copy, a correction or a deletion request, and for complaints, write to kontakt@zooplanet.org. If it concerns an account, please write from the address on that account — then we do not have to ask you for further proof of identity.
If it is easier, the site's contact page carries the same address and a short note on what to write.