Privacy policy
Updated on 1 October 2026: Google and Microsoft calendars are described in section 4 quater. Section 4 quinquies explains optional glasses testing, photos and videos, their retention and voice commands.
Paddoco is an app for riders and yards. This policy explains exactly what data it keeps, why, where, for how long and what you can do about it. It is written to be understood.
At a glance.
- We do not sell or rent your personal data, and there is no advertising. We may one day publish anonymous statistics about our users as a whole: section 4 explains exactly where the boundary lies.
- In the app, internal metrics linked to your account identifier record the dates when you use the app, categories and dates of useful actions, as well as authenticated clicks on certain links in reminder emails and the first useful action that follows. They help us improve app use and reminders. The dashboard for these metrics is restricted to superadmins and shows only aggregate results. Records linked to the account are erased when the account is deleted. These metrics do not retain any URL, referring page, address, content or information about your device. Information is shown in the app before an authenticated click is recorded. These metrics do not use email open tracking pixels or advertising trackers. There are no advertising cookies, so there is no consent banner to click. If this changes, this page will say so and you will be informed through the app beforehand.
- The database is hosted in Ireland and emails are sent from France. Some providers operate outside the European Union. The optional Fara assistant and its data transfers are described in section 4 ter.
- Nobody reads your private messages, not even a yard administrator.
- You decide what you share, section by section.
- Since 12 August 2026, friends can see your horses' profiles even if they belong to another yard. Three sections are shared by default, seven remain private, and you can make everything “Only me”.
1. Who is responsible
Clément Faure, 156 avenue Jean Jaurès, 47000 Agen, France.
For any question about your data: contact@paddoco.com.
Under the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), Clément Faure is the data controller. Under Quebec's Act respecting the protection of personal information in the private sector, he is also the person in charge of the protection of personal information, reachable at the same address.
2. What we collect, and why
We only ask for information that serves a purpose. Most fields below are optional, and the app works without them.
For your account
| Data | Purpose | Required |
|---|---|---|
| Email address | Signing in and resetting your password | Yes |
| Password | Signing in. We never see it: our hosting provider stores it as a hash | Yes |
| First and last name | Identifying you within your yard | No |
| Date of birth | Determining whether you are a minor, applying guardianship and calculating a price where the yard uses age-based pricing | No |
| Phone number, emergency contact | Contacting you, and contacting someone if something happens to you while riding | No |
| Profile photo | Identifying you | No |
| Riding level, federation licence | Yard activities and lesson bookings | No |
For your horses
Name, breed, coat colour, date of birth, SIRE number, photos, care records, shoeing, vaccination and worming reminders, exercise sessions, feed and observations. These concern an animal, but also reveal who looks after them and when, so they relate to you too.
For life at the yard
Your lesson bookings, rides, posts, replies, private messages and the photos you send in them, groups, friends, listings and payment records (paid or unpaid, never bank details).
What your device sends
| Data | When | Where it goes |
|---|---|---|
| Notification identifier | If you allow notifications | To Google, which delivers them to your phone. This is the only way to receive them. |
| Approximate location | Only when you tap “Near me” in the directories for yards, riders, listings, riding clinics or livery | To our database to calculate a distance. It is not stored or sent to anyone else. |
| A ride's GPS track | Only if you upload a GPX file to a ride or record the ride in the app | To our database, linked to that ride: track points, gaits and heart rate if your watch recorded it in the same file. It is visible to the audience you choose for the ride; see section 5. |
| Your position while following a route | When you tap “Follow this route” | Nowhere. Calculations happen on your phone. Nothing is written to the database or sent to anyone. |
A GPS track is location data, and we treat it as such. A ride remains private, shared with friends or shared within your yard until you decide otherwise. Heart rate is never shared with everyone: even on a public ride, it remains visible only to you and the people you choose.
We do not collect browsing data, page history or advertising profiles. The app keeps on your device the items needed for the features you use, including your session, the yard you are viewing, your preferences and local files you choose to create. Glasses and studio captures are described in section 4e.
3. Legal basis
Each processing activity relies on one of the legal bases set out in Article 6 of the GDPR.
| What we do | Legal basis |
|---|---|
| Maintain your account and provide access to the app | Performance of our contract with you |
| Send you a notification you requested | Your consent, which you can withdraw at any time in settings |
| Send an email essential to the service: registration confirmation or password reset | Performance of the contract |
| Email you an alert you have not disabled | Your consent, which you can withdraw for each alert type in settings |
| Show your horses' profiles to your friends | Your consent, adjustable for each section and withdrawable at any time |
| Prevent abuse and mass account creation | Our legitimate interest in keeping the service usable |
| Keep a record of reported payments | Performance of the contract and the yard's legitimate interest in knowing who has paid |
| Connect a Google or Microsoft calendar and view the busy times you choose | Your consent, withdrawable in My account, My calendars, or at the provider |
| Sending a request made to the assistant Fara to OpenAI | Performance of the contract, after your explicit consent, requested before the first request is sent and withdrawable in the assistant |
4. Who else sees your data
The services below help Paddoco operate. Google Calendar and Microsoft Outlook receive activity copies only if you connect them; those external accounts also follow their own terms and policies. No other partner receives your data today. Any new recipient and the reason for the transfer will be described on this page, and you will be informed before the transfer begins.
| Provider | What they do and receive | Where |
|---|---|---|
| Supabase | Hosts the database and files | Ireland, European Union |
| Brevo | Sends our emails: account emails (registration confirmation and password resets), and since 12 August 2026, alerts you have not disabled. It receives your email address and the alert's contents, which may name a horse, a yard, a role assigned to you or the person who triggered the alert. | France, European Union |
| Meta, glasses and Meta AI app | Optional glasses connection, permissions and exchanges needed for their operation. Data and choices are described in section 4e. | Depending on the Meta services used; processing may take place outside the European Union under Meta’s terms. |
| Google Calendar and Microsoft Outlook | Receive the activities you choose to copy to a dedicated calendar, after you voluntarily connect. Data and permissions are described in section 4 quater. | Depending on your Google or Microsoft account, under the provider’s terms and policies, with processing that may take place outside the European Union. |
| Google (Firebase Cloud Messaging) | Delivers notifications to your phone | Outside the European Union, subject to Standard Contractual Clauses |
| Cloudflare | Hosts paddoco.com, the website you are reading, as well as the web app and its updates, and stores responses to the anonymous feedback form (section 4a). Like any hosting provider, it receives the IP addresses of people loading pages; we never request this information from it or retain it ourselves. At sign-up, its Turnstile check confirms that a person is creating the account: it then receives the IP address and browser signals, for that check only. | Global network, US company, subject to Standard Contractual Clauses |
| OpenAI | Answers requests made to the optional assistant Fara, transcribes dictation and analyses attached files, after your explicit consent. What it receives and how long it keeps it is set out in section 4 ter. | United States, outside the European Union; safeguards set out in section 4 ter |
| IGN, Géoplateforme | Provides map backgrounds and address search in France. It receives your device's IP address, the map area displayed and the address you type. | France, European Union |
| OpenStreetMap and OpenTopoMap | Provide map backgrounds outside France, or when you choose them. They receive your device's IP address and the map area displayed, never any account data. | Public mapping services, under their own terms |
| Open-Meteo | Provides weather information | Receives the yard's coordinates, never yours, and no account data |
| YouTube, Dailymotion, Vimeo, Google Drive | When a member pastes a video link, its thumbnail is loaded from the platform hosting it, which then sees the IP address of whoever displays it. | Depends on the platform, often outside the European Union |
You can disable email alertsfor each alert type in your notification settings. Once disabled, no further alerts of that type are sent through Brevo. Essential account emails continue to be sent: without them, you cannot create an account or reset a password.
Currently, no personal data is sent to third parties for commercial purposes. The services named above are used only for these features. Google and Microsoft calendars you choose to connect also remain subject to your provider’s rules. Paddoco needs to sustain itself, and may one day be supported by horse professionals who pay to reach riders. Rather than leave you to discover this later, here are three possible forms and the rule for each.
- Industry statistics. What horses eat, or how often farriers visit in a region. These are aggregated and anonymous : they cover groups large enough that nobody can identify you, your horse or your yard. Truly anonymous data is no longer personal data, which allows this use without asking for your consent. If we publish such statistics, this page will say so and specify the minimum group size below which nothing is published.
- Professionals appearing where you look for them : a farrier, vet or tack shop paying to be listed where people search. Paid placements are clearly identified. This does not require information about you: the professional is being promoted, rather than you being targeted.
- An introduction, if you request it. If we ever offer to share your contact details with a professional, this will require your explicit consent, with the box initially unticked and consent withdrawable at any time. The screen asking you will state exactly what is shared and with whom.
The rule underpinning all three, consistent with the law: nothing that identifies you leaves here without your permission. Any new use of your data will be described on this page and brought to your attention before it begins. No such contract currently exists.
There is currently no advertising in the app, and there are no advertising trackers on this website or in the app. If paid placements are introduced, they will be clearly identified and described on this page.
This website loads nothing from elsewhere. Images, fonts and the small amount of code it uses are served from paddoco.com. No other server receives your IP address while you read this page, including servers that ordinarily distribute fonts.
The website remembers your language choice on your device, without cookies or sharing it with a third party. If you switch languages while completing a public form, its draft is temporarily transferred within the same tab to preserve your text, then removed when restored. Passwords are excluded. You can clear the saved language choice in your browser’s site data settings.
4a. The anonymous feedback form
A page excluded from search indexing, paddoco.com/avis, which we share directly with people who have just tried Paddocoto learn what to improve first. It is described here because it is the only part of the website that stores what you write . The contact form on the home page simply opens your email app and stores nothing.
What we record : your answers to the three questions and the date. Nothing else.
What we do not record, as enforced by the code : your IP address, device, referring page or language. No cookie is set. The function reading the form cannot access this information: it receives only your answers, so it cannot record anything else even accidentally. An automated check verifies this whenever the website changes.
What this does and does not mean. We do not know who wrote a response, so we cannot reply. However, if we give the link to one person and receive a response a minute later, the time is enough to make a guess. This is true of any anonymous form shared with a small group; no technical choice can prevent it, and we prefer to be clear. Leave out your name if you want to stay anonymous.
Where responses go. Responses are stored by Cloudflare, the website's hosting provider, and read only by us behind a password. Each response is also reported to us by email through Brevo, named above. They are used only to improve Paddoco : they are never sold, passed to a partner or matched to an account, since we do not know which account they would belong to.
How long we keep them. For as long as they help us decide what to improve. We cannot locate your response to delete it on request, precisely because it is anonymous: this is the trade-off for knowing nothing about you.
4 ter. AI assistant and voice dictation
Fara is optional and available to signed-in accounts through her avatar. Free includes the Economy model with an allowance of USD 0.50 per person per month. Personal, Pro and Yard Premium trials are granted separately by the platform. Enabling access sends no data to OpenAI: relevant data is sent when you use the corresponding features, as described below.
Since 24 September 2026, Fara asks for your consent before your first request. A card sets out what is sent to OpenAI: your message, your dictation, the files you attach and the data relevant to your request, within the limits of your permissions. Nothing is sent until you accept; typing, dictation and attachments stay closed until then. The time of your consent is recorded. You can withdraw it at any time in “About the assistant”: Fara then sends nothing until you consent again, and your conversations stay in your history.
The assistant helps organise equestrian activities, consult authorised data, prepare actions and write drafts. OpenAI is the selected provider for replies, voice transcription and attachment analysis. For chat, it receives the text you send, part of the recent conversation and the necessary data your permissions allow you to consult: names, horses, relationships, lessons, registrations, work, care or listings. Fara follows your profile across your yards, with permissions checked separately in each. It does not receive direct database access.
The microphone opens only when you tap it. When you tap Finish, the audio is automatically sent through our server to OpenAI for transcription. Authorised horse names may accompany the audio to improve recognition. Paddoco does not retain the audio file. If transcription fails, the recording remains temporarily on your device so you can try again while the screen is open. The transcript remains an editable draft: it is sent to the chat only when you tap Send. No background listening is provided.
Fara's personal memory is separate from conversations. It stores up to 12 notes of 180 characters in Supabase, for no more than one year after their last update: presentation preferences, nicknames of accessible horses and routines specific to a yard. These notes are private to their author; only notes compatible with the current context and permissions are sent to OpenAI to personalise a reply. They must not contain secrets or health or financial records, and are not used for Internet searches. You can view and delete notes, or turn off their use and the recording of new memories, in Fara's information panel. Turning memory off keeps the notes; deleting a conversation does not erase them. Deleting the account removes them. No additional subscription is required; the small text cost is included in the AI budget.
Fara may perform a web search when a question calls for public or up-to-date information. To prepare it, OpenAI receives your question and, if needed, up to two recent clarifications, without previous responses, records or personal memory. Search terms are intended for a public search: do not include secrets or confidential information. Sources are displayed as links; their content may be inaccurate. Following those links is also subject to the visited site’s policy. Search costs are included in your allowance, at USD 0.01 per completed search plus the text processed. A search triggers no operational action.
AI conversations are restricted to their author in the app. Their retention period is displayed: 30 days by default, configurable up to 90 days. You can delete them. Technical request details are kept for 62 days. Counters needed for monthly and annual limits, without conversation text, are retained for the current and previous calendar years. A file's volume records remain for as long as the file is retained; their link to your account is removed if the account is deleted. A technical receipt of confirmed actions, without the text of your requests, is retained for one year to verify operations. Deleting a chat does not undo lessons, care records or other actions already recorded.
Usage and subscription brings together personal storage and shared services. Monthly and annual limits follow the UTC calendar, with their reset dates displayed; older rolling thirty-day limits remain shown separately. Each AI request is charged to one allowance: the yard's for covered management, otherwise the person's. The meter shows estimated costs and pending reservations, not the OpenAI balance. Reaching a limit does not trigger a charge to another allowance. Premium Pro includes personal use; no coverage grants additional business permissions. Removing a file frees storage but does not refund uploads already consumed. A reduced limit does not delete existing files. Your model and automatic-action preferences follow your account independently of conversation history. Word and PDF exports are prepared on your device. No payment or paid subscription is activated during this pilot.
For attachment analysis, prepared files and your instructions are sent to OpenAI after you press Send. Several files can be combined in one request: six by default, up to a combined eight MB after preparation. Applicable limits are displayed and may be adjusted by the platform. Photos are prepared on your device; by default, each video becomes up to eight timestamped still images over thirty seconds, without audio. Analysis is isolated from memory, web research and action tools. A comparison can include attachments from earlier care: Fara first checks their references, then loads only relevant files accessible under your current permissions. Permissions are checked again before the answer. Unless you explicitly request filing in the horse’s diary, Paddoco does not retain newly supplied originals or extracted images on its servers. The response and file references remain in your conversation for its retention period. Reattach an unfiled file for a later analysis. A filed report is labelled as AI-generated and can automatically receive supplied files still available on the device. Diary visibility, retention and media quotas then apply independently of chat deletion. Earlier media remain referenced to their original care entry. Processing all selected files is charged as an analysis against your usual AI allowance. For earlier-care research, source selection and analysis are two steps charged at their actual cost against that same allowance. Only send files you are authorised to use and avoid unnecessary personal information. Premium or trial coverage, its expiry date and administrative changes are retained; their private audit log is purged after one year.
OpenAI API data is not used to train its models by default. Paddoco disables response storage at OpenAI. Abuse prevention logs may nevertheless retain content for up to 30 days, unless legally required otherwise. An encrypted technical cache may remain for up to 24 hours, separately from Paddoco’s personal memory. According to the provider’s documentation, the audio transcription service used does not retain application state or abuse logs for that transcription. Image and file inputs may undergo specific safety checks.
The provider’s arrangements are described in its API data documentation.
Exclusive European residency or complete absence of retention by OpenAI is not promised. Processing may involve transfers outside the European Union. Before activation, Paddoco must check OpenAI's data processing agreement, its subprocessors and applicable transfer safeguards, including Standard Contractual Clauses. These details will be updated if the selected configuration changes.
Send only information needed for your request, without secrets, passwords or human health data. The yard remains responsible for the purpose and lawfulness of its members' data used for management. Requested assistance forms part of providing the service; abuse prevention and traceability serve the legitimate interest of securing it. Access, erasure and objection requests can be made using the contact on this page. The AI does not independently make decisions with legal effects.
4 quater. Personal Google and Microsoft calendars
Connecting a personal calendar is optional. In My account → My calendars, you choose which Paddoco activities to copy to a dedicated calendar in your Google or Microsoft account. The provider receives each selected activity’s title, date, times when available, time zone and a link to that activity in Paddoco. These copies remain subject to the rules of your provider account, including when you share or forward them.
Paddoco receives the external account’s identifier and email address, the authorisations needed for the connection, and the identifiers of the dedicated calendar and its copies, so that it can update them without duplicates. Access and refresh tokens are encrypted on the server in Supabase. They are not sent to other Paddoco members or to Fara.
You can separately allow Paddoco to display your busy times and select calendars that you own. Google provides free/busy time intervals. Microsoft provides times, busy status and cancellation status, which are immediately reduced to busy intervals. Paddoco does not store the titles, descriptions, locations, guests or attachments of your personal appointments. Busy intervals appear as “Busy”, for you alone, and are not recorded in the shared planner. Hiding this display does not pause copies to the dedicated calendar.
Google allows Paddoco to create and manage calendars created by the application; access to your calendar list and free/busy information is requested only for the busy-times option. Microsoft requires delegated calendar read and write permission to create the dedicated calendar. Paddoco’s code limits writes to that dedicated calendar and busy-time reads to calendars that you own and have selected. External calendars do not feed the shared planner, and no invitations are sent.
You can pause copies, disconnect the provider or revoke authorisation in your Google or Microsoft account. When disconnection is complete, the tokens and connection identifiers are deleted. You can choose to remove only the copies created by Paddoco; the dedicated calendar and appointments you added yourself remain. If you have already revoked access, complete disconnection while keeping copies, then remove them at the provider. Activity changes and removals are reflected at the next successful run; an outage may delay them. Tokens remain encrypted while the connection exists, including when copies are paused or removal is still pending. Deleting your Paddoco account deletes the tokens but cannot recall copies at the provider: disconnect the calendar and choose to remove its copies first.
This connection is used only for the calendar features you request. Data obtained through these APIs is not used for advertising, data sales or training artificial intelligence models. Paddoco’s use and transfer of information received from Google APIs comply with the Google API Services User Data Policy, including its Limited Use requirements. Data you keep or share directly in Google Calendar or Microsoft Outlook is also subject to those providers’ terms and privacy policies.
4 quinquies. Connected glasses, memories and voice commands
This section prepares for the optional glasses integration in Paddoco’s next app update. Initial tests are restricted to the authorised superadmin account in the Android and iOS apps, with a compatible phone, glasses and operating system. These screens are not offered on the website, in a mobile browser or in the PWA. Other users continue to use Paddoco without glasses.
Connection uses the Meta AI app and permissions from the phone and Meta. Paddoco uses the selected device’s identifier and name, connection status and capabilities to find the correct glasses. The selected device and connection preferences are stored on the phone. Connecting or reconnecting does not itself authorise a photograph, recording or broadcast. You can stop the session, forget the glasses and revoke permissions in the relevant settings.
Images received from the glasses are used for the capture you start. Original photographs and videos are initially kept in Paddoco’s private storage on your phone. Native files from the glasses are excluded from automatic system backups. Videos from this first glasses integration are silent. Sound in a video recorded with the phone depends on microphone permission and the choice made in the studio. The integration described here enables neither continuous voice listening nor facial recognition.
“Keep in Paddoco” is a separate choice from capture. It sends the selected original photo or completed video to our private Supabase storage, with your account identifier, title, indication of recognisable people, optional link to a ride, lesson or session, format, size and, for a video, duration and markers you added. An operation identifier, file fingerprint and upload log allow a transfer to resume without creating a duplicate. Reconnecting glasses does not automatically start an upload. Original JPEG or HEIC photos may retain EXIF metadata, which may reveal where they were taken; Paddoco does not promise to remove it.
Photos and videos saved this way remain private to their authorised owner in the native app during testing. Linking them to an activity does not give other participants, the yard or website visitors access. Marker transfers do not include GPS coordinates. A recorded ride track nevertheless retains its own visibility rules. Places, faces or information visible in images remain in the files; also check their metadata before exporting or sharing them.
Local copies stay on your phone until you delete them from the library or clear the app’s data. Personal memories saved in Paddoco remain linked to your account until you delete them. You can change or remove their activity link; deleting that activity does not delete these personal memories. Older media saved directly within an activity still follow that activity’s deletion. Deleting a remote memory removes its annotations and prevents new access; a previously issued playback link may remain valid for up to two minutes. Physical file deletion then runs through the storage purge queue and is not promised to be immediate. A minimal technical receipt, without annotations or media, prevents an old transfer from recreating a deleted memory; it remains until account deletion. An incomplete upload may also leave temporary data until storage cleanup or expiry.
Remote deletion does not delete the original on your phone or copies already exported or shared: manage those copies separately. Sharing through the phone’s share sheet sends the file to the app or recipient you choose, under their own terms. It does not automatically post the content on La Place. This preparation does not enable live streaming or a connection to a YouTube or Twitch channel; their recipients and arrangements will be explained before they are introduced.
Studio voice commands are optional and restricted to the authorised pilot. After you explicitly select the glasses’ Bluetooth microphone and choose “Open and listen”, detected phrases are sent through our server to OpenAI for transcription, together with the language and equestrian vocabulary that may include names or nicknames of horses accessible to your account. Any detected phrase may be transmitted, even if it contains no command: filtering happens after transcription. An Internet connection, your personal Fara consent and available quota are required.
Recognised commands can take a photo, start or stop a video, add a marker or stop listening. They act directly in the studio, without a draft to confirm, and do not publish memories. Listening stays in the foreground, lasts no more than five minutes and stops, among other cases, when you leave the app or lose the selected microphone. “Stop listening” also closes the camera; returning to the app does not restart listening. Glasses videos remain silent even while voice commands are enabled.
This voice flow does not create an audio file in phone or Supabase storage and does not save the transcript as a Fara conversation message. Text is processed in memory to recognise commands. Fara usage counters and technical controls still apply. This does not guarantee zero retention by providers or infrastructure logs: the OpenAI terms, transfers and limits described in section 4 ter also apply to this transcription. This voice flow does not attach camera media or GPS coordinates.
Meta provides the glasses connection and SDK. Its documentation states that Meta may receive information about communication between Meta devices and the app. Paddoco configures the SDK’s usage analytics and crash reporting to be disabled. This setting does not remove processing associated with your Meta account, Meta AI or the operation of the glasses, which is governed by Meta’s terms and may involve processing outside the European Union. Paddoco does not promise that Meta holds no data, or a retention period it does not control.
Capture, storage and retrieval of memories provide the features you request; their basis is performance of the service. Access protection and prevention of duplicates are based on the legitimate interest in securing that service. Camera, microphone and connection permissions remain under your control, and refusing them must leave other features usable. Only record and share people and places for which you have the necessary permission, particularly when a minor appears. The rights and contact details in section 8 also apply to these data.
5. Who sees what in the app
This is the most important question, and the app is built around it.
- Yards are kept separate. What happens in one yard cannot be seen in another. This is more than a display setting: the database itself refuses to return a yard's data to a non-member. A yard's schedules, care records, feeding records, posts and listings stay within that yard.
- You control what crosses that boundary, and only one thing crosses it by default: your name in the rider directory. Since 13 August 2026, the app has included a public circle: a feed, listings, livery offers, creator showcases and rides can be shared with all accounts, never the open internet. Each item starts private; publishing opens it up, and counts as your consent. The rider directory is the exception: adult accounts are listed by default, showing only their first name, last name and the yards they belong to, to someone who searches for that name. The app asks you about this when you first arrive, and you can untick it at any time under My account, “What I show”. Two points deserve to be clear in advance: minors never appear in the platform's rider directory or marketplace, regardless of their settings; and a ride made public is public in full, including its start and finish points, and therefore the place you set off from. The app reminds you of this when you publish.
- Your horses' profiles, shared with friends. Since 12 August 2026, someone you have accepted as a friend can see the profiles of horses linked to you, even if they belong to another yard. Three sections are shared by default: identity (name, coat colour, sex, age and height), pedigree and competition record, plus one photo of the horse: the one already shown in the thumbnail. Seven sections remain private: care records, journal, feeding, sessions, equipment, location and people linked to the horse. None of this appears in a list or search: access is through your friend's profile.
- You can adjust each section, including setting it to “Only me”. Each horse's profile includes a grid showing what the yard, linked people, friends and others can see. You can share more, or close all sections to an entire audience in one step, and reverse that choice later.
- Your own profile is shared section by section. You decide what is visible and who can see it.
- Five things are inaccessible to anyone but you, including your yard administrators: private messages, secret ballot votes, blocked people, favourites and progress on a learning course.
- Messaging and what it has included since 12 August 2026. Private messages can now contain photos. These follow exactly the same rule as the message: only conversation members can see them. A sent message can be edited or deleted. Two points deserve to be clear: a recipient can forward a photo you send to another conversation, as with any messaging service; and conversations keep an album, so previously sent photos remain available there.
- A yard administrator can see everything within their own yard, and nothing elsewhere. This access is necessary to manage the yard and has clear boundaries.
- Image consent : you can refuse to appear in photos, and this refusal is enforced by the database, not just on screen.
6. Minors
The app accepts minors. A guardian can be linked to them, and the yard usually asks for the guardian's name and phone number. However, a minor's account can exist without a guardian account linked to it. We prefer to say this clearly rather than imply that parental supervision is mandatory.
- A minor never appears in the public rider directory or friend suggestions, regardless of their settings. This is enforced by the code, even if the directory option is ticked on their profile.
- A linked guardiancan view and manage matters concerning the child: bookings, payments, consent and notifications. This does not include their private messages : nobody reads them, whether a guardian or an administrator.
- Guardianship ends automatically when the person reaches adulthood.
- Sharing with friends also applies to minors. If a minor is linked to a horse, their friends can see its profile under the same rules and defaults as everyone else (section 5). Access can be closed in the same way, section by section on the horse's profile.
7. How long we keep data
- For as long as your account exists, and in most cases until it is deleted.
- Deletion is under your control: in My account, under Leave. It is immediate, and the app first lists exactly what would be removed. See the details on Delete my account.
- After deletion, your account and personal data are erased. Some records remain because they also belong to others, such as attendance at a past lesson or a payment recorded by a yard. These are detached from your identity.
- Files you uploaded are deleted along with the records they were attached to.
- Items deleted in the app first go to a binfor forty-eight hoursto allow mistakes to be undone. They are then permanently deleted without anyone needing to ask. This period is a yard setting: if your yard changes it, it will tell you.
- This recycle bin does not apply to photos and videos in the studio library: their deletion and that of local copies are described in section 4 quinquies.
- Emailed alerts leave a record with our email provider for the period set by its own policies. We do not use this to track you.
8. Your rights
At any time, you can access your data and obtain a copy; correct it, mostly directly in the app; request erasure; object to processing or request its restriction; withdraw consent to notifications; and leave instructions about your data after your death.
You can exercise three of these rights without writing to us, in My account, under Leave : download a copy of your data, pause your account and delete it. For anything else, email contact@paddoco.com. We reply within one month.
If you are not satisfied with the response, you can contact the CNIL, the French supervisory authority.
9. How data is protected
- All data is encrypted in transit between your device and our servers.
- The database denies access by default. Each table determines who may read each row, and an unauthorised request returns nothing. The database enforces this, rather than the screen: bypassing the app grants no extra access.
- Your private messages and their photos are not end-to-end encrypted. They are encrypted in transit and protected by the rule above, but we prefer to be explicit rather than imply otherwise.
10. Changes on 6 September 2026
Two types of information collected since the summer were missing from this policy. They are now included. This is a policy update to reflect the app, rather than new processing.
- Ride GPS tracks (section 2): a ride can include a GPX track, gaits and heart rate. The track follows the ride's visibility; heart rate is never shared with everyone. Following a route does not send any position data off the phone.
- Sharing across yards (section 5): this page previously said that only horses' profiles shared with friends crossed the boundary. That was true on 12 August. A public circle has existed since 13 August, with a clear rule: nothing enters it by default, publishing counts as consent, and a public ride includes its full route.
- “Near me” now also works for listings, riding clinics, livery and riders. The rule is unchanged: location is used to calculate distance and is not stored.
11. Changes on 18 August 2026
Nothing changed in practice : no new recipients, additional data collection or trackers. What changed was a promise clarified before it was needed.
- This page previously said “we sell nothing to anyone”. Section 4 now explains how Paddoco plans to earn revenue : anonymous industry statistics, professionals paying for visibility and introductions made only at your request.
- It no longer promises “never” where the meaningful rule is this: nothing that identifies you leaves here without your permission, and every new use is described here before it begins. A service promising never to earn money risks making a promise it cannot keep; ours prefers to explain its plans in advance.
- Why explain this beforehand? Because narrowing a policy when it becomes inconvenient is backtracking, while clarifying it while it is still fully accurate is transparency. No such contract currently exists.
12. Changes on 12 August 2026
Four changes made that day affect this page. Two expanded access and are described above. Two restricted it and also deserve mention.
- Sharing with friends (sections 4 and 5): friends at another yard can now see your horses' profiles. This is the first time information has crossed yard boundaries, which is why this page explains it explicitly.
- An email delivery provider (section 4): our email alerts now go through Brevo, which receives your email address and the alert's contents. It already handled account creation emails but was not named here. It is now.
- Access to horse photos was restricted. Until that date, a confirmed member of a yard could see photos of horses at other yards and horses belonging to no yard. This was a defect, which was identified and fixed: a horse's photos now follow that horse's yard permissions, with access granted only by the rules in section 5.
- Twenty-three internal database functions were closed to signed-in accounts. No screen used them, but they remained accessible externally. None was needed by the app, and none has become necessary since.
- Messaging now supports photos (sections 2, 5 and 9), and sent messages can be edited or deleted. This grants access to nobody new: a message photo can only be viewed within its conversation.
12. If this policy changes
We will update it here with a new date. Any change affecting what we collect or who receives it will be announced in the app, as well as described on this page.