Privacy
Your data, handled with care
We ask for as little as we possibly can, we tell you plainly what we do with it, and you can ask us to delete it at any time. This page explains all of that in normal language.
Last updated: 16 August 2026
Who is responsible for your data
DoggMatch is built and run by KM TECH LABS, org.nr. 934 044 029, in Kristiansand, Norway. KM TECH LABS is the data controller for personal data processed through this website, and decides why and how that data is used.
Norway is part of the EEA, so the EU General Data Protection Regulation (GDPR) applies to us in full, along with the Norwegian Personal Data Act (personopplysningsloven). Our supervisory authority is the Norwegian Data Protection Authority (Datatilsynet).
The easiest way to reach us about anything on this page is through our contact page.
What we collect, and why
Most of DoggMatch works without an account and without us storing anything about you. Your quiz answers, your dog profiles, your training progress and your care notes are kept in your own browser's local storage on your device — not on our servers.
- Quiz answers and dog profiles. Stored locally on your device so you can come back to them. We never see them. Clearing your browser data removes them.
- Account details. If you create an account, we store your email address and sign-in identity. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
- Membership details. For DoggMatch+ we store your subscription status, plan, member ID and valid-through date. Legal basis: performance of a contract.
- Payment details. Card data is handled entirely by Stripe. We never see or store your card number. We keep only the subscription reference we need to know whether your membership is active.
- Messages you send us. Your name, email, subject and message, so we can reply. Legal basis: legitimate interest in answering you (GDPR Art. 6(1)(f)).
- Technical data. Standard server logs such as IP address and browser type, kept briefly for security, abuse prevention and troubleshooting. Legal basis: legitimate interest in keeping the service safe.
What we do not do
- We do not sell or rent your personal data to anyone.
- We do not use advertising trackers or third-party advertising cookies.
- We do not build behavioural profiles of you for marketing.
- We do not make automated decisions with legal or similarly significant effects. Your match result is a transparent calculation you can see the reasoning behind, and it has no legal consequences.
Cookies and local storage
We only use what's strictly necessary to make the site work: a sign-in session, your light/dark preference, your language, and the local data described above. Under the ePrivacy Directive and Norwegian ekomlov, strictly necessary storage of this kind does not require consent, which is why you don't see a cookie banner. If we ever add analytics or marketing cookies, we will ask you first.
Who processes data on our behalf
We use a small number of carefully chosen providers, each bound by a data processing agreement under GDPR Art. 28:
- Hosting, database and authentication. Runs our servers, stores account and membership records, and handles sign-in.
- Stripe. Payments and subscription billing, as an independent controller for payment data.
- Google. Only if you choose to sign in with Google, and only for that sign-in.
- Email delivery. Used to send and receive the messages you write to us.
Where your data is stored, and transfers outside the EEA
We store personal data on servers within the EU/EEA wherever we can. Some of our providers are based in the United States. Where data does leave the EEA, the transfer relies on the European Commission's Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework, together with additional technical safeguards such as encryption in transit and at rest.
How long we keep things
- Local data on your device: until you clear it. It is yours, on your machine.
- Account and membership data: for as long as your account exists, then deleted or anonymised within 90 days of you closing it.
- Contact messages: up to 24 months, so we have context if you write again.
- Payment and invoice records: kept for 5 years, as Norwegian bookkeeping law (bokføringsloven) requires. Legal basis: legal obligation (GDPR Art. 6(1)(c)).
- Security logs: normally 90 days or less.
How we protect it
Data is encrypted in transit (TLS) and at rest by our hosting provider. Database access is restricted by row-level security rules, so an account can only ever reach its own records. Access to production systems is limited to the people who genuinely need it. If a breach ever puts your rights at risk, we will notify Datatilsynet within 72 hours and tell you directly where the law requires it.
Your rights
Under the GDPR you can ask us to:
- Tell you what we hold about you, and give you a copy (Art. 15).
- Correct anything that's wrong (Art. 16).
- Delete your data (Art. 17).
- Restrict how we use it (Art. 18).
- Send it to you or another provider in a portable format (Art. 20).
- Stop processing based on legitimate interest (Art. 21).
- Withdraw consent at any time, where processing is based on consent (Art. 7).
Write to us through the contact page and we will respond within 30 days, free of charge. If you're not happy with how we handled it, you can complain to Datatilsynet or to the data protection authority in your own country.
Children
DoggMatch isn't intended for children. You need to be at least 16 to create an account. If you believe a child has given us personal data, tell us and we will remove it.
Changes to this notice
If we change anything meaningful here, we'll update the date at the top of this page, and tell account holders by email when the change affects them.
