Version: 2026-08.1
Effective date:
Controller and contact
The Controller for TailLane services and accounts is Simone Antonio Domenighini, Via Motta 7/A, 25050 Niardo (BS), Italy. For processing carried out for TailLane's own purposes, contact privacy@taillane.app. No Data Protection Officer has been appointed; the Privacy contact handles requests and this decision is reviewed if scale or purposes change.
People and data covered
This notice covers owners, facility contacts, staff, invited collaborators and people who contact TailLane. We may process identification and contact details, OAuth identity and email, role and membership, service-relationship data, support requests and minimised feedback, technical metadata, security, audit and compliance evidence. Accounts are for authorised adults.
Customer, owner, pet, booking, document and facility-operation data is normally processed for the facility under its instructions. TailLane acts as Processor for that scope and a separate Article 28 GDPR DPA and facility notice apply; this notice does not replace them.
Purposes and legal bases
Account, access, session security and the service relationship rely on contract performance or pre-contractual steps. Administration, security, abuse prevention, support, minimised feedback, audit and business continuity rely on TailLane's balanced legitimate interests. Legal obligations rely on Article 6(1)(c) GDPR where applicable.
TailLane currently uses Google OAuth through Supabase Auth for human access and requests only identity scopes such as email and profile. Passwords, magic links, email or phone OTP and other social providers are not active for end users. Anonymous sessions are restricted to synthetic public-demo and QA scope and are not an end-user access method for facilities.
Providers and recipients
Technical processing uses Supabase for database, authentication and Storage; Vercel for hosting, functions and deployments; Cloudflare R2 for encrypted EU backups; GitHub Actions for the ephemeral runner that exports and encrypts backups before upload; and Resend, account petflowapp, only for minimised internal alerts. Resend does not receive free-text feedback and uses the technical sender onboarding@resend.dev; marketing communications are not active.
Google is an identity provider and MET Norway is an independent controller for weather: the proxy sends rounded, minimised coordinates and technical metadata and does not persist coordinates. Web Push, cloud OCR, WhatsApp Business API, analytics and other providers are not active in this scope. The public processor and subprocessor list is available at /en/subprocessors.
Transfers and safeguards
TailLane Supabase projects are in eu-north-1 and the operational Cloudflare R2 bucket is in the EU jurisdiction. Where a provider's service or support may involve countries outside the EEA, the provider's contract and the actual path use an adequacy decision, Standard Contractual Clauses or another GDPR safeguard where applicable. Contract references and provider reviews are maintained in the internal Privacy register and the public list; a transfer is not inferred merely from a theoretical capability.
Retention, deletion and backups
Account and service-relationship data is kept for the period needed to provide and secure the service and meet rights and legal obligations; support requests and feedback for the period needed to respond, evidence the outcome and manage security; and technical logs and audit data under the applicable operational and security criteria. On closure, access is revoked and data is deleted or anonymised by domain, subject to documented obligations or legal holds.
Encrypted backups are not an alternative operational copy: Production R2 uses a 30-day lock and 31-day lifecycle; authorised monthly historical backups use their own prefix with a 366-day lock and 367-day lifecycle. Restore is isolated and must reconcile deletions and the erasure ledger before reuse. Expired copies follow the verified lifecycle and are never restored directly into Production.
Security, rights and updates
We use access controls and RLS, environment separation, encrypted backups, server-only secrets, minimised logging, audit of sensitive operations, deletion procedures and restore tests. The processing described here is not used to train models. We do not carry out profiling or automated decisions producing legal or similarly significant effects.
You may request access, rectification, erasure, restriction, objection and portability where provided by GDPR by writing to privacy@taillane.app. You may also complain to the Italian supervisory authority. Material changes receive a new version, effective date and change summary; this version is effective from 26 August 2026.