Privacy policy
What BarkUp collects, why, and the design choices that keep your home, your location and your conversations out of our hands in the first place.
Last updated 14 August 2026Who we are and how to contact us
BarkUp helps dog owners find walking company nearby. This policy explains what we do with personal information across the BarkUp website at barkup.co, the waitlist, and the BarkUp app and its supporting services.
We are the data controller for that information, which means we decide what is collected and why.
- Controller: Arnold Kocsis, a sole trader established in the United Kingdom and trading as BarkUp
- Email: info@barkup.co
We are not required to have a Data Protection Officer and have not appointed one. Arnold Kocsis handles data-protection questions personally; email is the way to reach us.
If you are unhappy with how we handle your information you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would like the chance to put things right first.
The short version
BarkUp arranges meetings between people who do not know each other. That makes a data leak here a physical-safety problem, not just a privacy one, so the service is built to hold as little as possible in the first place. Six things are worth knowing before the detail:
- Your home is never stored. Not as an address, not as coordinates, not even as a precise point we promise not to show. What exists is a grid cell roughly a kilometre across, worked out on your own device.
- Nobody sees a distance or a direction to you - only a band such as "within 2 km", and only once enough households are nearby that the band cannot single anyone out.
- Photos are stripped of their metadata. A phone photo carries the GPS coordinates of where it was taken. Every image is re-encoded on our server, and none of that data survives.
- Messages are fixed phrases, not free text. Your device sends the phrase you chose, so the words in your conversations were written by us, not held by us.
- Live location is opt-in, one point at a time, and gone in minutes. There is no route, no history and no way for us to reconstruct where you walked.
- We sell nothing and track nothing. No advertising, no profiling, no analytics or session-recording tools, and no third-party trackers.
What we collect, and when
If you join the waitlist
- your email address;
- optionally, the outward part of your postcode, such as OX16 - never the full postcode;
- which page or campaign the sign-up came from;
- the time you gave consent and the time you confirmed it, so we can show your choice was yours; and
- short-lived anti-abuse signals: a Cloudflare Turnstile check, and a rate-limit counter keyed to a one-way hash of your IP address. We do not store the IP address itself.
If you create an account
- your email address and a securely hashed password, or the fact that you signed in with Google and the email address Google gave us - we never see your Google password;
- your first name or nickname, which is all any other member can ever see, and only after you have connected;
- your confirmation that you are 18 or over, the exact wording you agreed to, the version of that wording and the time you agreed;
- whether you are discoverable by other members; and
- whether an identity check has been completed - a yes or no, nothing more.
About your dogs
A dog profile holds a name, breed, size, temperament notes, a reactivity setting and a photo. Please keep the free-text fields about the dog: anything you type about yourself, your household, your health or where you live becomes information we are holding about you unnecessarily.
Location
- Your walking area - a precision-6 geohash cell, about a kilometre across. Your device works this out from your location or from a postcode and sends only the cell. If you use the postcode option, your full postcode goes to our server once, is turned into that same cell immediately, and neither the postcode nor the coordinates are written down anywhere.
- A temporary area, if you use "use my current location" while browsing. It is another coarse cell, it is private to you, it never changes your saved area, and it deletes itself after 24 hours.
- A meeting point for a walk - the label you chose, such as the name of a park gate, plus an optional pin. Place suggestions come through our own server rather than your browser, so the map provider never sees who is searching, and we discard the coordinates their search returns.
- Live location during a walk, only while you have switched it on: a single current point per person, overwritten roughly every ten seconds. There is no trail and no history.
- Hazard reports - the precise point of the hazard you reported, because a hazard is only useful where it is.
Messages
We store which fixed phrase you sent, to whom, and when - and, for the phrases that name a time, that time. We do not store text you typed, because messaging does not currently accept any. If free-text messaging is ever switched on we will update this policy before it happens.
Walks, connections and blocks
Walks you organise or join, which dogs are coming, requests and approvals, the connections between packs, and who you have blocked. Blocks are visible only to the person who made them; we never tell anyone that they have been blocked.
Reports and safety records
When you report someone we record what you reported, the reason, the content in question and our notes on what we did about it. Reported messages and photos are kept as evidence even if the person who sent them deletes them or leaves.
These records can contain allegations about identified people, and sometimes allegations of criminal behaviour. They are held apart from everything else: no member can read the report queue, and reports cannot be read back even by the person who made them.
Identity verification and donations
Both run entirely on Stripe's own pages. For an identity check we send Stripe nothing but an internal reference for your profile, and we receive back a single yes-or-no. We never see or store your identity document, the photographs taken during the check, your name as it appears on that document, or any other output of it. For a donation we never see or store your card details.
Technical and security information
Two secure cookies keep you signed in, and two more exist for a few seconds if you sign in with Google. Our servers keep short operational records of failures, changes and slow responses, containing only a random request identifier, the route pattern, the method, the status code and how long the request took - no names, emails, identifiers, locations or message content. Rate-limit counters are keyed to one-way hashes rather than raw addresses.
If our error-monitoring tool is enabled it is configured with personal-data collection switched off, and a redaction layer removes request bodies, credentials, email addresses, identifiers, location cells, coordinates and payment references before anything is sent.
What we do not collect
- Your home address, your full postcode after the moment of lookup, or your precise location at rest.
- Your surname, date of birth, phone number, or payment card details.
- Special category data - health, ethnicity, religion, sexuality, biometrics - which we never ask for and ask you not to volunteer. Assistance-dog and disability information belongs in a conversation with an organiser, not in a profile field.
- Your contacts, your calendar, your photo library, or anything else on your device beyond the photo you choose to upload and the location you choose to share.
- Any advertising identifier, cross-site tracking signal or behavioural profile.
Photos and the metadata inside them
A photo taken on a phone usually carries hidden metadata: the make and model of the device, the moment it was taken and, very often, GPS coordinates accurate to a few metres. Publishing a dog photo taken in the garden can therefore publish the address, which would undo the entire location model.
So no uploaded file is ever stored as we receive it. Every image is decoded, resized and re-encoded to WebP on our server, and the output carries none of the original metadata. The file you uploaded is not kept.
Photos are only for dogs and walks. They cannot be sent in messages, and there is nowhere on BarkUp to publish a photo of a person.
Why we use your information, and our lawful basis
You can object to any processing based on legitimate interests. Tell us and we will stop unless we have compelling grounds not to, which for safety records is usually the case.
To send you what you asked for (consent)
Waitlist updates about the launch. You opt in, confirm by email, and every message has a one-click removal link. You can withdraw at any time, and withdrawing does not affect anything we sent before.
To provide the service (performance of a contract)
Creating and running your account, showing you dogs and walks nearby, arranging and approving walks, delivering messages between connected members, storing your dogs and photos, and sending the emails the service itself needs, such as verification and password resets. Without this information there is no service to provide.
To share live location during a walk (consent)
This runs only after you switch it on and allow your browser to share, it is limited to that walk, and stopping it or blocking someone ends it immediately.
To keep people and animals safe (legitimate interests)
Blocking, reporting, moderation, enforcement, the anonymity floor on discovery, rate limits, abuse prevention and account security. Our interest is in running a service where strangers can meet without being harmed, which is also the interest of everyone using it. Where a report concerns an alleged criminal offence we also rely on the substantial public interest conditions in the Data Protection Act 2018 for preventing or detecting unlawful acts and for protecting the public.
To run the service reliably (legitimate interests)
Operational logs, error monitoring, capacity and fault diagnosis, and backups. We keep these deliberately free of personal detail, so the interest is served without holding information about you.
To meet legal obligations (legal obligation)
Keeping donation records for tax purposes, responding to lawful requests from the police or a regulator, and meeting our duties under UK online-safety and data-protection law.
Fixed messages, and what that means for your privacy
Messaging accepts a fixed catalogue of coordination phrases rather than text you write. Your device sends the identifier of the phrase you tapped; the message body is composed by our system.
The safety reason is that nobody can be sent an abusive, sexual, threatening or scam message through BarkUp. The privacy consequence is just as real: the words in your conversations are ours rather than yours, so there is no store of private correspondence here to be breached, subpoenaed or mined. The only thing you supply is a time, and it is handled as a time.
Messaging is also gated. You can only message someone you have connected with or who is approved for the same walk, and a block ends it in both directions instantly. There is no way for a stranger to message you.
Age, and children
BarkUp is for adults only. You must be 18 or over, and you confirm that when you create an account; we record the wording, its version and the moment you agreed, so that the confirmation stays meaningful if we ever change it.
This confirmation is a declaration by you rather than a verified check. We are honest about that. We do not knowingly hold information about anyone under 18, and if we learn or reasonably believe that an account belongs to a child we close it and delete the content associated with it.
If you believe a child is using BarkUp, tell us at info@barkup.co and we will treat it as a priority. If we introduce stronger age checks we will update this policy first and explain what the provider does with your data.
Who we share it with
We do not sell personal information, share it for advertising, or hand it to data brokers. We share it only with the providers that run the service for us, each under a contract that limits them to our instructions:
- Supabase - the database, sign-in and photo storage behind the app and the waitlist, in a London region.
- Vercel - hosting and delivery of the website and app, with server functions pinned to London.
- Resend - sending email, such as waitlist confirmations, address verification and password resets.
- Stripe - identity checks and donations, on Stripe's own pages.
- Cloudflare - the Turnstile anti-abuse check on the website's waitlist form.
- Sentry, where error monitoring is switched on - with personal-data collection disabled and our own redaction applied first.
- OpenStreetMap, for place search, which reaches it through our server rather than your browser, and a map tile provider, which serves the map images your browser displays.
One honest caveat about maps: tiles are ordinary image requests made by your browser, so the tile provider can tell roughly which part of the country a map is being looked at. It cannot tell who is looking, and the area is the same coarse cell everything else uses.
We also share information with other members, but only in the deliberate ways described here: your dog and its details, your first name once you have connected, a distance band, and - for a walk you have been approved for - the meeting point.
We may disclose information to the police, a regulator or another authority where the law allows or requires it, or where it is necessary to protect someone from serious harm. If BarkUp is ever transferred to another operator, information moves with it and we will tell you before that happens.
Where your information is held
The database, the photos and the application servers are in the United Kingdom, in London regions chosen for exactly that reason.
Some providers - email delivery, payments, identity checks, error monitoring - process information outside the UK, including in the United States. Where they do, the transfer is covered either by UK adequacy regulations or by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the provider's own safeguards. You can ask us for details of the mechanism used for a particular provider.
How long we keep it
- Waitlist entries - until you unsubscribe or ask us to remove you, or until the launch period the list exists for has ended. Unconfirmed sign-ups are removed within 30 days.
- Your account, dogs and photos - while your account is open. When you ask us to close it we delete them, other than what is listed below.
- Messages - deleted automatically 90 days after sending. A message you delete is redacted immediately. A reported message is kept as evidence.
- Live location points - a point expires about two minutes after its last update, a sharing session ends after eight hours at the very latest, and a cleanup job removes expired points and sessions every minute. Ending a walk deletes them straight away.
- Your temporary browsing area - 24 hours.
- Hazard reports - they expire on their own according to the kind of hazard, from a few hours to at most 14 days, and are then removed.
- Reports, blocks and enforcement records - kept for 3 years after the report is closed, so that a pattern of behaviour across time can still be seen, and longer where there is an investigation, a complaint or a legal claim.
- Operational logs and error reports - we keep no copy of our own. They live with our hosting and monitoring providers and age out on their schedule, which is 30 days or less for server logs and up to 90 days for error reports. Neither contains names, email addresses, locations or message content.
- Donation records - 7 years, because tax law requires it.
Backups are kept on a rolling basis and overwrite themselves, so information deleted from the live service can persist in a backup for a short period before it is cycled out.
How we protect it
- Access rules are enforced by the database itself, not only by the app, and are covered by an automated test suite that fails the build if a rule is weakened.
- There is no way for one member to read another member's records directly. Everything visible about someone else comes through a narrow function that returns only the fields it is supposed to return.
- Sign-in tokens live in secure cookies your browser's JavaScript cannot read, and cross-site requests that would change something are refused.
- A content security policy restricts what the pages can load and where they can send data.
- Rate-limit identifiers are one-way hashes; card details are never on our systems; error reports are redacted before they leave.
- Distances are coarse before they are stored, so the most sensitive information about you does not exist in a form that could leak.
No service can promise perfect security, and we will not pretend otherwise. What we can say is that the design assumes a breach is possible and minimises what a breach would expose. If a breach does happen and it puts your rights at risk, we will report it to the ICO within 72 hours where required, and tell you directly where the risk to you is high.
Cookies and storage on your device
The marketing website sets no advertising, analytics or profiling cookies. The Turnstile anti-abuse check on the waitlist form is a strictly necessary security control. Our cookie notice has the detail.
The app sets four strictly necessary cookies, named and explained in that notice: two that keep you signed in, and two that exist only for the moments a Google sign-in takes. All four are httpOnly, secure and restricted to our site, and the sign-in pair is cleared when you sign out. Nothing is kept in your browser's local storage.
We use no analytics, heatmap or session-recording product anywhere. If that ever changes, non-essential technologies will not load until you have chosen to allow them.
Automated processing
Messages pass through a narrow keyword check that flags a small number of scam and grooming patterns into the report queue for a person to look at. It never blocks, alters, delays or censors a message, and it is not a judgement about you - it is a prompt for human review, and it both misses things and raises false alarms.
Discovery ranks nothing and profiles nobody: it returns dogs within a distance band, and returns nothing at all where too few households would make a result identifying.
We do not make decisions about you by automated means alone that produce legal effects or similarly significant effects. Enforcement decisions - hiding a profile, suspending an account - are made by a person, and you can ask us to look again.
Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal information we hold about you;
- have inaccurate information corrected;
- have information deleted, where we no longer need it;
- restrict or object to how we use it, including any use based on legitimate interests;
- receive information you gave us in a portable format, or have it sent to another provider;
- withdraw consent at any time, where we relied on consent; and
- complain to the Information Commissioner's Office.
To exercise any of these, email info@barkup.co from the address on your account. We will respond within one month, and will tell you if a complex request needs longer. There is no charge unless a request is clearly unfounded or excessive. We may need to check who you are before we act, and we will ask for the least information that lets us do that.
Some limits apply, and we would rather set them out than surprise you. Deletion does not extend to reports and safety evidence about you, which we keep on the basis described above - a service where a reported account can erase the report is not a safe service. It also does not cover records we must keep by law, such as donation records. Information that identifies someone else, including a report they made about you, is not disclosed in an access request.
Account closure and deletion is handled by us on request rather than by a button in the app, so that it can be confirmed properly. Email us and we will do it.
Marketing
The only marketing we send is the waitlist and launch updates you asked for, and you can leave with one click in any of them or by emailing us.
Emails the service has to send - confirming your address, resetting your password, telling you about a report or a change to these policies - are not marketing and continue while you have an account.
We do not share your details with anyone else for their own marketing, and we never will.
Other sites and services
BarkUp links to other places, including our social media pages, and shows maps produced by other organisations. This policy does not cover them, and what they do with your information is governed by their own policies.
Changes to this policy
We update this policy when the service changes, when we add or change a provider, or when the law requires it. The date at the top of this page always shows when it last changed.
For a significant change - a new purpose, a new category of information, or anything that widens what is shared - we will tell registered users by email or in the app before it takes effect, and ask again for consent where consent is what we rely on.
Contact
For anything in this policy, including a request about your own information, email info@barkup.co.
- Controller: Arnold Kocsis, a sole trader established in the United Kingdom and trading as BarkUp
- Email: info@barkup.co
