Scope and applicable law

This page applies to the Doodle Save mobile app and the marketing websites at doodlesave.co, doodlesave.ca, and doodlesave.in. We are subject to:

Privacy and Grievance Officers

Privacy Officer (Canada)

Responsible for PIPEDA Principle 1 (accountability) and Quebec Law 25.

privacy@doodlesave.co

Grievance Officer (India)

Responsible for DPDP §13 grievance redressal. Response within 30 days.

grievance@doodlesave.co

Canada — PIPEDA

PrincipleHow we implement it
1. AccountabilityA named Privacy Officer at privacy@doodlesave.co.
2. Identifying purposesEach category of data we collect and the purpose for collecting it is listed in the Privacy Policy.
3. ConsentRecorded at signup with version numbers and timestamps. Marketing consent is opt-in. Re-consent is requested in-app when we materially update the Terms or Privacy Policy.
4. Limiting collectionNo payment data, no government IDs, no precise GPS, no contacts, no calendar, no email contents.
5. Limiting use, disclosure, retentionData is used for the purposes stated. Affiliate-click logs purge at 13 months; audit logs at 24 months.
6. AccuracyYou can edit your profile and subscriptions in-app.
7. SafeguardsSee Security controls below.
8. OpennessThis page plus the public Privacy Policy.
9. Individual accessIn-app data export and email-based access requests, fulfilled within 30 days.
10. Challenging compliancePrivacy Officer email above, with escalation to the Office of the Privacy Commissioner of Canada.

Quebec — Law 25

Quebec residents have all the rights described in PIPEDA, plus:

India — DPDP Act 2023

SectionHow we implement it
§4 — Lawful processing on consentConsent captured at signup with version and timestamp.
§6 — Notice at consentPrivacy Policy linked from the signup screen.
§8(4) — Erasure on withdrawalSoft-delete flow with a 30-day grace period, then hard delete.
§8(5) — Reasonable security safeguardsSee Security controls.
§8(6) — Breach notificationTo the Data Protection Board and affected Data Principals within 72 hours of awareness.
§8(7) — Storage limitationRetention windows enforced by automated database jobs.
§11 — Right of accessIn-app data export plus email request.
§12 — Right to correction & erasureProfile editor and account-deletion flow.
§13 — Grievance redressalGrievance Officer at grievance@doodlesave.co, 30-day response window.
§14 — Right to nominateAvailable by written request to the Grievance Officer.

Security controls

Retention

DataRetention
Account & subscription dataKept while the account is active.
Affiliate-click logs13 months.
Audit log24 months.
Soft-deleted accounts30 days, then hard delete.
BackupsRotated within 35 days.
Required tax / transaction recordsHeld for the minimum period required by law, with personal identifiers stripped.

Breach response

  1. Detect: automated alerts on suspicious sign-in clusters and unusual export volume.
  2. Contain: rotate credentials, isolate affected components, revoke compromised sessions.
  3. Assess: use the append-only audit log to determine scope, data categories affected, and likelihood of harm.
  4. Notify:
    • India residents and the Data Protection Board within 72 hours (DPDP §8(6)).
    • Canadian residents and the Office of the Privacy Commissioner of Canada as soon as feasible where the breach poses a real risk of significant harm (PIPEDA s. 10.1).
    • Quebec residents and the Commission d’accès à l’information where required (Law 25).
  5. Record: retain the incident record for at least 24 months (PIPEDA s. 10.3).

Sub-processors

The following providers process personal data on our behalf. All are under contractual privacy obligations and use the minimum data necessary to operate.

ProviderPurposeRegion
Supabase Inc.Database, authentication, file storage, serverless functionsCanada Central (ca-central-1)
Universe, Inc. (Expo)Push-notification deliveryUnited States
Netlify Inc.Marketing website hostingGlobal CDN
Anthropic / model providersAI-assisted catalog and price work; not used on personal dataUnited States
Booking.com, MakeMyTrip, CueLinks, FlippAffiliate deal sourcing and click attributionVarious

Exercising your rights

If you are not satisfied with our response, you may complain to your data-protection regulator: the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, or the Data Protection Board of India.