Privacy Policy
1. Introduction and Scope
Welcome to EquiDuty. We value your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect your personal information when you use our SaaS platform for stable management.
This policy applies to all users of EquiDuty's website, web application (PWA), iOS app, Android app, and related services.
By using EquiDuty, you agree to the terms of this privacy policy. If you do not agree with these terms, please do not use our services.
2. Data Controller
The data controller responsible for processing your personal data is:
- Data Controller: EquiDuty AB, which provides the EquiDuty service
- Reg. no.: 559593-8886
- Address: Stockholm, Sweden
- Email for data protection inquiries: info@equiduty.se
If you have questions about how we process your personal data or wish to exercise your rights under GDPR, contact us at the address above.
3. Personal Data We Collect
3.1 Contact Information
- Email address
- First name and last name
- Phone number (optional)
- Organization name and address
- Stable information (name, address, contact details)
3.2 Account and Authentication Data
- Firebase Authentication UID (unique user ID)
- Email verification status
- JWT tokens for session management
- OAuth provider data (Google login)
- User preferences (notification settings, dark mode, timezone)
- Device ID (UUID stored locally for session management)
3.3 Horse Data and User-Generated Content
- Horse information (name, breed, color, gender, microchip, passport ID)
- Health records for horses (veterinary, farrier, dental, medications)
- Photos and media (profile pictures, horse health record attachments)
- Schedule and shift data
- Daily notes and horse activity history
- Task information (routines, schedules, assignments)
3.4 Financial Information
- Stripe customer and subscription IDs
- Payment history and invoice records
- Subscription tier and billing interval
- Note: We do NOT store credit card details. All payment information is securely handled by Stripe (PCI-DSS compliant).
3.5 Usage Data
- Feed analytics (routine completions, completion rates)
- Fairness algorithm tracking (points, shift completion)
- Activity timestamps (logins, actions)
- IP addresses (audit logs for security only)
3.6 Device and Technical Data
- Firebase Cloud Messaging (FCM) tokens for push notifications
- Device type and operating system (app compatibility)
- Browser type and version
- App version and build number (mobile apps)
- A device identifier generated by the app itself (a random UUID created on first use and stored on your device) — we do not read hardware or platform-assigned identifiers such as the Android ID, IMEI, MAC address or advertising ID
- Analytics identifiers assigned by our processors (a PostHog device ID, and a Firebase installation ID used by crash reporting)
- Crash diagnostics (stack traces, device model, OS version, and the app state at the time of a crash) — see section 6.8
- Approximate location (country, region or city level) derived from your IP address by our analytics processor — see section 6.7. We do not collect GPS or precise location, and raw IP addresses are not stored alongside analytics events. You can stop this by turning analytics off under Settings → Privacy & communication
- Aggregated website CTA clicks (button, page, and destination) without analytics cookies
3.7 Audit and Compliance
- Audit logs (user actions, IP addresses, timestamps)
- GDPR export and deletion requests
3.8 What We DO NOT Collect
We do NOT collect the following:
- GPS or precise location data (the approximate, IP-derived location our analytics processor adds is described in section 3.6)
- Advertising profiling, session recording, or cross-site tracking
- Analytics for advertising purposes — in-app product analytics is used only to improve the service (section 6.7) and can be turned off under Settings → Privacy & communication
- Biometric data
- Full credit card details (handled by Stripe)
4. Why We Collect Personal Data
We use your personal data for the following purposes:
4.1 Service Provision
- Create and manage your user account
- Authenticate your identity and secure your session
- Store and manage horse information, schedules, and shifts
- Calculate fair work distribution via weight-based algorithm
- Send notifications about upcoming shifts and updates
4.2 Payment and Subscription Management
- Process payments via Stripe
- Manage subscriptions and billing
- Send invoices and payment confirmations
- Handle account upgrades and downgrades
4.3 Customer Support
- Respond to your questions and support tickets
- Troubleshoot technical issues
- Provide user guides and documentation
- AI-assisted writing help (Vertex AI Gemini) — optional, used when you choose to improve text in support tickets or stable bulletin board posts
4.4 Security and Compliance
- Prevent fraud and unauthorized access
- Detect and prevent security incidents
- Comply with legal obligations (e.g., Swedish accounting law requires 7-year retention of financial records)
- Enforce our Terms of Service
4.5 Service Improvements
- Analyze usage patterns to improve user experience
- Develop new features based on user needs
- Optimize performance and reliability
5. Legal Basis for Processing (GDPR)
Under GDPR Article 6, we process your personal data based on the following legal bases:
5.1 Contract Performance (Article 6.1.b)
Processing of account, horse data, schedule, and subscription information is necessary to provide the EquiDuty service you have signed up for.
5.2 Consent (Article 6.1.a)
- Marketing emails and communications (you can withdraw consent at any time)
- Optional notifications (Telegram)
- Photos and media you upload
5.3 Legitimate Interest (Article 6.1.f)
- Security and fraud prevention
- Service improvements and product development
- In-app product analytics (PostHog EU) — see section 6.7; can be turned off under Settings → Privacy & communication
- Aggregated, cookieless website CTA-click measurement (PostHog EU) — see section 11.2
5.4 Legal Obligation (Article 6.1.c)
- Financial records (Swedish accounting law requires 7-year retention)
- Audit logs (security and compliance requirements)
6. Third-Party Services and Data Sharing
We share your personal data with the following third-party services necessary to operate EquiDuty. All vendors comply with GDPR requirements and have data processing agreements in place.
Data Processing Agreement (DPA): B2B customers may request a Data Processing Agreement by emailinginfo@equiduty.se — template available at/legal/dpa-en.pdf.
6.1 Google Cloud Platform (GCP)
- Purpose: Cloud infrastructure, database, storage, authentication
- Data shared: ALL application data (user accounts, horse data, schedules, photos)
- Location: Europe (europe-west1 region)
- Privacy Policy: https://cloud.google.com/terms/cloud-privacy-notice
- Services: Firebase Authentication, Firestore, Cloud Storage, Cloud Run, Cloud Functions
6.2 Stripe
- Purpose: Payment processing and subscription management
- Data shared: Email, name, payment methods, billing history. In the mobile apps, Stripe's SDK additionally collects a device fingerprint for fraud prevention, as described in Stripe's privacy policy
- Contracting entity: Stripe Payments Europe, Limited (Ireland), the Stripe entity that contracts with businesses in Sweden and the wider EEA
- Location: Ireland/EU, with onward transfers to the USA and India under EU Standard Contractual Clauses and the EU–U.S. Data Privacy Framework
- Privacy Policy: https://stripe.com/privacy
- Note: Stripe is PCI-DSS certified. We do NOT store credit card details ourselves.
6.3 send.one.com (SMTP)
- Purpose: Email delivery (organization invitations, notifications)
- Data shared: Email addresses, organization names
- Location: Denmark/EU
- Privacy Policy: https://www.one.com/en/about/privacy
6.4 Telegram Bot API
- Purpose: Notifications via Telegram
- Data shared: Telegram chat IDs, message content
- Location: Global
- Privacy Policy: https://telegram.org/privacy
- Note: Optional, only if you choose to enable Telegram notifications
6.5 Firebase Cloud Messaging (FCM)
- Purpose: Push notifications to iOS/Android apps
- Data shared: FCM tokens, message content
- Location: Global (Google servers)
- Privacy Policy: https://firebase.google.com/support/privacy
6.6 Vertex AI (Google Gemini)
- Purpose: Optional AI writing assistance when you choose to improve text in support tickets or stable bulletin board posts
- Data shared: Only the text you explicitly submit for AI improvement
- Location: Europe (europe-west1)
- Privacy Policy: Covered by GCP privacy policy
6.7 PostHog
- Purpose: Product analytics in the app (iOS, Android, and the web app) to understand feature usage and improve the service, plus aggregated, cookieless measurement of CTA clicks on the marketing website (see section 11.2)
- Data shared: In the app: user ID, email address, organization ID, role, subscription tier, language, a PostHog-assigned device ID, app version, approximate location (country, region or city) derived from your IP address, and feature-usage events (e.g. sign-in, bookings, routines). On the marketing website only: button label, page path, page title, language, and click destination — no cookies, no automatic click collection, no pageview tracking, no session recording, and no IP-based geolocation
- Location: EU (eu.i.posthog.com)
- Privacy Policy: https://posthog.com/privacy
- Note: On the marketing website we honor the browser Do Not Track setting. In the app, analytics is tied to your account since sign-in is required, and is on by default — you can turn it off at any time under Settings → Privacy & communication, which stops all analytics events from that device
6.8 Firebase Crashlytics
- Purpose: Automatic crash and stability reporting for the iOS and Android apps, so we can find and fix defects
- Data shared: Crash stack traces, device model, operating system version, app version, and a Firebase installation ID. Reports are sent automatically when the app crashes
- Location: Global (Google servers)
- Privacy Policy: https://firebase.google.com/support/privacy
- Note: Crash reports are not used for advertising or profiling and are retained by Google for a limited period
7. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy:
| Data Category | Retention Period | Justification |
|---|---|---|
| User accounts | Subscription duration + 30 days | Allows account recovery |
| Horse data and content | Subscription duration + 30 days | Service provision |
| Financial records | 7 years | Swedish accounting law |
| Audit logs | 2 years | Security and compliance requirements |
| Marketing consent | Until withdrawn | User consent |
| Support tickets | 3 years | Customer support history |
After the retention period expires, personal data is securely deleted from our systems. You can request earlier deletion at any time by contacting info@equiduty.se.
8. Your Rights Under GDPR
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
8.1 Right to Access (Article 15)
You have the right to obtain a copy of all personal data we hold about you. Contact info@equiduty.se to request a data export.
8.2 Right to Rectification (Article 16)
You have the right to correct inaccurate or incomplete personal data. You can update your profile information directly in the app or contact us for assistance.
8.3 Right to Erasure - "Right to be Forgotten" (Article 17)
You have the right to request that we delete your personal data. Sign in to the app and choose Settings → Account → Delete account, or follow the instructions at /en/delete-account if you can no longer sign in. Note that some data may need to be retained for legal obligations (e.g., financial records for 7 years).
8.4 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, machine-readable format (JSON) and transfer it to another service provider. Contact info@equiduty.se to request a data export.
8.5 Right to Object (Article 21)
You have the right to object to processing of your personal data based on legitimate interest. Contact info@equiduty.se with your case.
8.6 Right to Withdraw Consent
If processing is based on consent, you can withdraw your consent at any time. This does not affect the lawfulness of processing based on consent before withdrawal.
8.7 Right to Lodge a Complaint
You have the right to lodge a complaint with the Swedish Data Protection Authority (Integritetsskyddsmyndigheten - IMY):
- Website: https://www.imy.se
- Email: imy@imy.se
- Phone: 08-657 61 00
- Address: Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm, Sweden
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration:
9.1 Technical Security Measures
- Encryption: All data encrypted in transit (TLS/SSL) and at rest (AES-256)
- Authentication: Firebase Authentication with JWT tokens and secure session management
- Access Control: Role-based access control (RBAC) with field-level permissions
- Firewalls and Security: GCP firewalls, DDoS protection, security rules
- Backups: Regular automated backups with point-in-time recovery
9.2 Organizational Security Measures
- Access to data limited to authorized personnel on a need-to-know basis
- Procedures for handling security incidents and data breaches
9.3 Data Breaches
In the event of a data breach, we will notify affected users and the Swedish Data Protection Authority within 72 hours as required by GDPR.
10. International Data Transfers
Your personal data is primarily stored within the EU (GCP europe-west1 region in Belgium), but some third-party services may involve data transfers outside the EU/EEA:
10.1 Transfers Outside the EU/EEA
- Stripe: contracted through Stripe Payments Europe, Limited (Ireland); personal data may be transferred onward to the USA and India under EU Standard Contractual Clauses and the EU–U.S. Data Privacy Framework
10.2 Safeguards
For all international data transfers outside the EU/EEA, we ensure appropriate safeguards:
- EU Standard Contractual Clauses (SCCs): Legally binding agreements requiring the same level of data protection as GDPR
- Data Processing Agreements: All third-party services have data processing agreements in place
- Encryption: All data encrypted in transit and at rest
12. Children's Privacy
EquiDuty is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16 without parental consent.
If you are a parent or guardian and discover that your child has provided us with personal data without your consent, please contact us at info@equiduty.se. We will delete such information from our systems.
13. Changes to Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal reasons. We will notify you of material changes via:
- In-app notification
- Updating the "Last Updated" date at the top of this page
We encourage you to review this privacy policy regularly. Continued use of EquiDuty after changes constitutes acceptance of the updated policy.
14. Contact Information
If you have questions, concerns, or requests about this privacy policy or our data protection practices, please contact us:
- Email: info@equiduty.se
- Address: Stockholm, Sweden
- GDPR Contact: EquiDuty AB, info@equiduty.se
- Support: https://equiduty.se/support
We strive to respond to all requests within 30 days as required by GDPR.