Privacy Policy
1. Who we are
mido is a pet-care marketplace that connects pet owners with pet sitters and dog walkers in Israel. This policy explains what personal data we collect, why we collect it, who we share it with, what other users can see, and what rights you have over it.
We are the data controller for the personal data described here. This policy covers the mido mobile app and the mido.co.il website.
By using the App you agree to this policy.
2. What data we collect
Account and identity — handled by our authentication provider, Clerk
- Your name and email address.
- Your password, which is stored by Clerk in hashed form. We never see or store it.
- If you sign in with Google: your Google account name, email address, and profile photo.
- Your phone number, verified by a one-time code sent to you by SMS through Clerk. We accept Israeli mobile numbers (+972) only. Verifying your phone is optional when you sign up and can always be skipped; it is required only if you apply to become a sitter. A verified phone number also lets you sign in with your phone instead of your email.
Profiles and content you create
- Pet profiles: name, breed, age, size, care notes, and photos.
- Sitter profiles: biography, services offered, prices, availability, and photos.
- Service addresses and drop-off addresses, including their map coordinates.
- Chat messages between owners and sitters, including voice messages and images.
- "Mido Card" updates: the photos and timestamped events a sitter records during a service.
- Reviews and ratings you write.
- For group walks: the roster of the walk and, if the walker adds one, a link to an external WhatsApp group.
Booking and payment data
- Bookings: status, dates, times, the pets involved, and amounts.
- Payments are processed by our payment provider, PayPlus. Card details are entered on PayPlus's own secure hosted page. We never receive or store your full card number. We keep a record of the transaction: amount, status, and booking reference.
- Sitters only — to pay you and to meet Israeli tax obligations, we collect your bank details (bank, branch, account number, and account holder name) and your tax status (עוסק פטור / עוסק מורשה, your osek number, and the validity date of a withholding-tax exemption certificate, if you have one). These are visible only to you and to mido. No other user can ever see them.
Location data
- With your permission, your device's approximate or precise location, used to show you sitters near you.
- The service address you enter for a booking.
- During an active walk, the walker's device records the route of the walk (latitude, longitude, accuracy, and timestamp) so the owner can see where their dog went.
Location is collected only while the App is open and in use. The walk recording pauses when the phone is locked and resumes when it is unlocked. We do not track location in the background, and the App does not run location services when you are not using it.
Diagnostic data — handled by our error-reporting provider, Sentry
- Crash and error reports: the error and its stack trace, a trail of the actions leading up to it, your app version, operating system, device model, and your internal mido user ID. These reports are configured to exclude personal data — they do not carry your name, email address, phone number, or the contents of your messages.
- If you choose to use "Report a problem": the description you write, a screenshot of the screen you were on if you choose to attach one, and your name and email address so that we can reply to you. This is the one diagnostic path that deliberately carries your contact details, because you asked us to get back to you.
Product-usage analytics — handled by PostHog (EU, Frankfurt)
We use PostHog to understand how people use the App and to improve it. It receives your stable mido account identifier, app lifecycle information (such as when the App enters the foreground or background), the screens you visit, and a limited set of product-action outcomes, such as starting or completing a booking request or opening a payment checkout. It may also receive standard app and device context, such as app version, operating-system version, device model, and language.
We deliberately do not send your name, email address, phone number, messages, photos, addresses, precise location, pet or care notes, payment-card data, payment amounts, authentication tokens, free-text search, user-entered error text, feedback text, or screenshots to PostHog. We disable GeoIP, Session Replay, touch autocapture, heatmaps, and PostHog feature flags. The App cannot reliably know why an operating system terminates it; an App-background event is not a claim about why you closed it.
Other technical data
- A push-notification token, so we can send you booking updates.
- Your language preference, app version, and basic device information needed to deliver the App.
We do not use third-party advertising SDKs, we do not build behavioural or advertising profiles, and we do not sell your data.
3. How we use your data
- To create and manage your account, and to sign you in.
- To operate the marketplace: publish sitter listings, search for sitters near you, create and manage bookings, and coordinate services.
- To confirm that a phone number belongs to you, which reduces fraudulent and duplicate accounts.
- To process payments through PayPlus, to pay sitters, and to apply withholding tax correctly.
- To enable chat, photos, Mido Card updates, and walk tracking between the two parties to a booking.
- To send you notifications about your bookings and about the service.
- To diagnose crashes and fix bugs, to understand aggregate App use and product journeys, and to respond to problems you report.
- To provide support, prevent fraud and abuse, keep users safe, and comply with legal obligations.
4. Legal basis for processing
Our database is hosted in the EU, so the GDPR applies alongside Israel's Privacy Protection Law 5741-1981. We rely on the following bases:
| What | Basis |
|---|---|
| Running your account, bookings, chat, and payments | Performance of our contract with you |
| Camera, microphone, photo, notification, and location permissions | Your consent, which you can withdraw at any time in your device settings |
| Sitter bank details, tax status, and payment records | Legal obligation (tax and accounting law) and performance of contract |
| Phone verification, fraud prevention, crash diagnostics, and product-usage analytics | Our legitimate interest in a safe, working service — balanced against your privacy by the data-minimisation and PII-exclusion measures described in section 2 |
| Responding to a problem you report | Your consent, given by submitting the report |
5. What other users can see
This is the part most people actually want to know, so we state it plainly.
- Sitter listings are public. A sitter's display name, photos, biography, services, prices, and reviews can be seen by anyone browsing the App, including people who are not signed in. This is what a marketplace listing is.
- A sitter's exact location is never published. Search results show a sitter's position deliberately shifted by 250 to 500 metres, so browsers see the neighbourhood, not the doorstep. A sitter's exact address is never shown to anyone.
- Owners are shown to sitters under a masked name — a first name and a surname initial, for example "Dana L." Your full name, photo, and phone number become visible to a sitter only once you have a confirmed booking with them.
- Your exact service address is released to a sitter only when you book them, and only for that booking.
- Chat messages, photos, and Mido Card updates are visible to the two parties to that booking, and to nobody else.
- Reviews are public, shown under the masked reviewer name described above.
- A sitter's availability notes are private. Free-text notes a sitter writes about an absence are never shown publicly.
- A sitter's bank details and tax information are never visible to any other user, owner or sitter.
- WhatsApp groups for group walks are outside mido. If a walker creates one, we store only the link and have no visibility into the group. Note that WhatsApp shows group members each other's phone numbers and profile names — something mido itself never does. Joining is your choice.
6. Who we share data with
We share data only with service providers who help us run the App, under agreements that limit what they may do with it:
| Provider | Purpose | Data shared |
|---|---|---|
| Clerk (USA) | Authentication, account management, and SMS verification codes | Name, email, password hash, phone number, Google profile |
| Supabase (Frankfurt, Germany — EU) | Database, backend, and file storage | Profiles, pets, bookings, messages, photos, addresses, walk routes, payout and tax details |
| PayPlus (Israel) | Payment processing | Transaction data; card details are entered directly with PayPlus and never reach us |
| Google Maps / Places (USA) | Maps and address search | Location and address queries |
| Expo (USA) | Push notifications and app updates | Push token, device information |
| Sentry (EU region — Germany) | Crash diagnostics and problem reports | Error data as described in section 2; your name and email only if you submit a problem report |
| PostHog (EU region — Frankfurt, Germany) | Product-usage analytics | Stable mido account identifier, lifecycle, screen, and limited product-action data, plus standard app/device context; never the content or sensitive data excluded in section 2 |
| Israeli banks | Paying sitters | The sitter's bank details and payment amount |
| Google Calendar (USA) | Adding your confirmed bookings to your calendar — only if you connect it | Booking date and time, service, pets, meeting address, and the other party's display name |
We also share the relevant profile and booking details with the other party to your booking, as described in section 5, so that the service can actually be delivered.
We may disclose data where required by law, or where necessary to protect the rights, property, or safety of our users.
Google Calendar — only if you connect it
mido can add your confirmed bookings to your Google Calendar. This is optional and off by default. None of what follows happens unless you connect your Google account from the More screen in the App, and you can disconnect at any time.
What we ask for. A single Google permission, https://www.googleapis.com/auth/calendar.app.created, which Google defines as the ability to make secondary Google calendars and to see, create, change, and delete events on those calendars only. We deliberately do not request the broader “see and edit events on all your calendars” permission.
What this lets us do — and what it does not. When you first connect, we create a new secondary calendar named “mido” inside your Google account, and we write your confirmed bookings into it. We cannot see, change, or delete anything in any of your other calendars, because the permission does not reach them. We never read your calendar to work out when you are busy. The App has its own availability settings for that, and reading your calendar would need a far wider permission than we ask for.
What we send to Google. For each confirmed booking: its date and time, the service, the pets involved, the meeting address, and a link back to the booking in the App. What appears in the event title depends on which side of the booking you are on. An owner's event names the sitter. A sitter's event shows the owner's name only in the shortened form other users already see — for example “Dana L.” — never their full name, consistent with section 5.
What we store. We store the identifier of the calendar we created for you, and a record of which bookings we have already written, so that a rescheduled booking can be moved and a cancelled one removed. We never store your Google password or your Google credentials. Those stay with Clerk, our authentication provider, which issues a short-lived access token only when a sync is due.
When we write to your calendar. Only on a booking's own events: when it is confirmed, when a reschedule is accepted, and when it is cancelled. A completed booking keeps its event — it happened. Bookings confirmed before you connected are not backfilled.
How to disconnect. Disconnect from the same screen in the App, which stops all future syncing. You can also revoke mido's access at any time from your Google Account permissions page at myaccount.google.com/permissions. Events already written to your calendar stay in your calendar and remain yours to keep or delete. Deleting your mido account also stops syncing and removes future events.
Limited Use. mido's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties except as needed to provide this feature, to comply with applicable law, or as part of a merger or acquisition.
7. International transfers
Our database and files are hosted in the EU (Frankfurt, Germany). Some of the providers listed above process data in the United States. Where that happens, transfers are made under appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
8. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | Until you delete your account |
| Bookings, payments, and payout records | Seven years after the transaction, as required by Israeli tax and accounting law |
| Messages, photos, Mido Card updates, walk routes | Kept with the booking they belong to; anonymised when you delete your account |
| Reviews | Kept, shown under an anonymised name after account deletion |
| Sitter bank and tax details | Deleted when you delete your account, except where a payment record must be retained for tax purposes |
| Crash reports | Up to 90 days at Sentry, then deleted automatically |
| Product-usage analytics | Up to 90 days at PostHog, then deleted automatically |
| Push notification tokens | Deleted when you sign out or delete your account |
When data is no longer needed for any of these purposes, we delete it or anonymise it so it can no longer be linked to you.
9. Security
- All traffic is encrypted in transit (HTTPS/TLS).
- Our database denies access by default. Every table is protected by row-level security, so one user's query cannot reach another user's data, and changes to sensitive records such as booking status and payments only happen through controlled, audited server-side functions.
- Sitter bank details are readable only by the sitter they belong to.
- We never hold card numbers. They go directly to PayPlus.
- Personal data is excluded from automatic crash reports and from the PostHog analytics payloads described in section 2.
No system is perfectly secure, but we take reasonable and appropriate measures to protect your data.
10. Your rights
Subject to Israel's Privacy Protection Law and, where applicable, the GDPR, you may:
- Access the personal data we hold about you.
- Correct data that is wrong or out of date — most of it directly in the App.
- Delete your account and data (see section 11).
- Receive a copy of the data you gave us, in a portable format.
- Object to or restrict certain processing, including our legitimate-interest processing.
- Withdraw consent for camera, microphone, photos, notifications, or location at any time in your device settings. The App keeps working; the features that need those permissions do not.
- Complain to a regulator — in Israel, the Privacy Protection Authority (הרשות להגנת הפרטיות); in the EU, your local data protection authority.
To exercise any of these, email midooapp@gmail.com. We will respond within the time the applicable law allows.
11. Deleting your account and your data
You can delete your account in the App, under More → Delete account, or by emailing midooapp@gmail.com.
Deletion takes effect immediately, with no waiting period. Your name, email, phone number, and profile photo are removed; your pet profiles and photos are deleted; your sitter listing disappears from the marketplace; and your push tokens are deleted.
Records we are required to keep — bookings, payments, reviews, messages, Mido Card updates, and walk routes — are retained in anonymised form, detached from your name, photo, and contact details. This is what lets the other party to a past booking keep their own records, and what lets us meet our tax and fraud-prevention obligations.
If you connected Google Calendar, deleting your account also disconnects it and removes future mido events from your calendar. Events for bookings that already happened are left in place.
12. Children
mido is not intended for anyone under 18. Bookings are paid contracts and sitters receive bank payouts, so an adult must hold the account. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy. The current version is always published at mido.co.il/privacy, and we update the "Last updated" date at the top when we change it. If a change materially affects how we use your data, we will tell you in the App.
14. Contact
Questions, requests, or complaints about privacy: midooapp@gmail.com.
Operator: Yuval Azriel Atzmon (עצמון יובל עזריאל), עוסק פטור no. 205390941, Israel.
mido