Privacy Policy
Shelter Walk Tracker · effective September 3, 2026 · updated September 4, 2026
Shelter Walk Tracker ("the app") helps animal-shelter volunteers coordinate dog walks. It is operated by DW Digital Consulting, San Francisco, California. Contact: [email protected].
What we collect
- Google sign-in. When you sign in we receive your email address, name, and profile picture from Google. We store your email and name so shelter admins can approve you and attribute walks to you.
- Activity you log. Which dogs you walked and when, reservations you set, and any notes you type. This is stored per shelter and visible to that shelter's members.
- Shelter configuration. Shelter name, timezone, and any links a shelter admin enters.
- Access requests and bug reports you submit.
- Notification subscriptions, if you turn notifications on: the push endpoint your browser issues for this app and its encryption keys, so shelter admins can send you alerts. No message content is stored on the device by us; alert text is kept in the shelter's history.
We do not collect payment information, location data, or advertising identifiers.
Google user data
This section describes exactly how the app handles data received from Google APIs.
What Google user data we access
- Sign-in (scopes openid, email, profile): your email address, display name, and profile picture URL.
- Google Drive, per-file (scope
https://www.googleapis.com/auth/drive.file), shelter admins only: this scope lets the app reach only files the admin explicitly picks in the Google Drive picker or that the app itself created. From the one picked or created walk-list spreadsheet the app reads cell values and cell fill colors (its Kennels, Playgroup, and QR code mapping tabs) and the list of tab names. It cannot see, list, or open any other file in the admin's Drive; Google enforces that, not just our code.
How we use it
Sign-in data identifies you to shelter admins and attributes the walks you log. Spreadsheet data from that one file is read to build the shelter's walk roster and is written back, one cell at a time, when a volunteer logs a walk, sets a reservation, or corrects a kennel, so staff working in the sheet see the same state. Nothing else.
Whether we share it
Spreadsheet contents are shown only to that shelter's approved members inside the app. We do not sell, rent, or transfer any Google user data, raw or aggregated, to third parties. Our only processors are Cloudflare (hosting, database, key-value storage) and Google itself. No data is used for advertising, credit or lending decisions, or market research.
How we protect it
All traffic uses HTTPS. The Google tokens for a connected sheet (a refresh token and a short-lived access token) are stored in Cloudflare KV, which encrypts data at rest; they are used only server-side by the Worker and are never sent to any browser or returned by any API. Spreadsheet contents are held only in a short-lived in-memory cache (under one minute) on the server and are not written to our database. Our database stores what volunteers do in the app: the animal ID, activity, time, optional note, and email for each log; reservations; and kennel corrections (the new kennel code and the code that was in the sheet at the time). It does not store dog names, notes, or any other spreadsheet contents. Each shelter's data is isolated by shelter and reachable only by that shelter's approved members.
Retention and deletion of Google user data
We keep your email and name while you are a member of at least one shelter. Disconnecting a sheet (Users → Disconnect) deletes the stored Google token immediately; you can also revoke access at myaccount.google.com/permissions. Cached spreadsheet data expires within a minute and is never retained. To delete your account and all activity attributed to you, email [email protected] and we will do so within 30 days.
Limited Use
Shelter Walk Tracker's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train artificial-intelligence or machine-learning models, and we do not transfer it to any third-party AI or ML service.
How we use it
Only to run the app: show the roster, record walks, notify members of changes, and let admins manage their shelter. We do not sell data, use it for advertising, or share it with third parties except the service providers below.
Service providers
Cloudflare (hosting, database, storage) and Google (sign-in and Sheets). No other third party receives your data.
Retention and deletion
Walk history is kept so shelters can see past activity. A shelter admin can remove any member, which deletes their membership and notification subscriptions, and can delete the whole shelter from Users → Data, which removes every record the app holds for it and its stored Google token immediately. To delete your individual account and all activity attributed to you, email us and we will do so within 30 days. Disconnecting a sheet deletes the stored Google token immediately.
Security
Data is transmitted over HTTPS and stored on Cloudflare's infrastructure. Access to each shelter's data is limited to that shelter's approved members.
Children
The app is intended for adult volunteers and is not directed to children under 13.
Changes
We will post any changes to this page and update the effective date.