Privacy Policy

Last updated: 31 August 2026
App: mido / מידו ("the App")
Operator: Yuval Azriel Atzmon (עצמון יובל עזריאל), a sole trader registered in Israel (עוסק פטור no. 205390941), trading as MIDO — "mido", "we", "us"
Contact: midooapp@gmail.com

1. Who we are

mido is a pet-care marketplace that connects pet owners with pet sitters and dog walkers in Israel. This policy explains what personal data we collect, why we collect it, who we share it with, what other users can see, and what rights you have over it.

We are the data controller for the personal data described here. This policy covers the mido mobile app and the mido.co.il website.

By using the App you agree to this policy.

2. What data we collect

Account and identity — handled by our authentication provider, Clerk

Profiles and content you create

Booking and payment data

Location data

Location is collected only while the App is open and in use. The walk recording pauses when the phone is locked and resumes when it is unlocked. We do not track location in the background, and the App does not run location services when you are not using it.

Diagnostic data — handled by our error-reporting provider, Sentry

Product-usage analytics — handled by PostHog (EU, Frankfurt)

We use PostHog to understand how people use the App and to improve it. It receives your stable mido account identifier, app lifecycle information (such as when the App enters the foreground or background), the screens you visit, and a limited set of product-action outcomes, such as starting or completing a booking request or opening a payment checkout. It may also receive standard app and device context, such as app version, operating-system version, device model, and language.

We deliberately do not send your name, email address, phone number, messages, photos, addresses, precise location, pet or care notes, payment-card data, payment amounts, authentication tokens, free-text search, user-entered error text, feedback text, or screenshots to PostHog. We disable GeoIP, Session Replay, touch autocapture, heatmaps, and PostHog feature flags. The App cannot reliably know why an operating system terminates it; an App-background event is not a claim about why you closed it.

Other technical data

We do not use third-party advertising SDKs, we do not build behavioural or advertising profiles, and we do not sell your data.

3. How we use your data

4. Legal basis for processing

Our database is hosted in the EU, so the GDPR applies alongside Israel's Privacy Protection Law 5741-1981. We rely on the following bases:

WhatBasis
Running your account, bookings, chat, and paymentsPerformance of our contract with you
Camera, microphone, photo, notification, and location permissionsYour consent, which you can withdraw at any time in your device settings
Sitter bank details, tax status, and payment recordsLegal obligation (tax and accounting law) and performance of contract
Phone verification, fraud prevention, crash diagnostics, and product-usage analyticsOur legitimate interest in a safe, working service — balanced against your privacy by the data-minimisation and PII-exclusion measures described in section 2
Responding to a problem you reportYour consent, given by submitting the report

5. What other users can see

This is the part most people actually want to know, so we state it plainly.

6. Who we share data with

We share data only with service providers who help us run the App, under agreements that limit what they may do with it:

ProviderPurposeData shared
Clerk (USA)Authentication, account management, and SMS verification codesName, email, password hash, phone number, Google profile
Supabase (Frankfurt, Germany — EU)Database, backend, and file storageProfiles, pets, bookings, messages, photos, addresses, walk routes, payout and tax details
PayPlus (Israel)Payment processingTransaction data; card details are entered directly with PayPlus and never reach us
Google Maps / Places (USA)Maps and address searchLocation and address queries
Expo (USA)Push notifications and app updatesPush token, device information
Sentry (EU region — Germany)Crash diagnostics and problem reportsError data as described in section 2; your name and email only if you submit a problem report
PostHog (EU region — Frankfurt, Germany)Product-usage analyticsStable mido account identifier, lifecycle, screen, and limited product-action data, plus standard app/device context; never the content or sensitive data excluded in section 2
Israeli banksPaying sittersThe sitter's bank details and payment amount
Google Calendar (USA)Adding your confirmed bookings to your calendar — only if you connect itBooking date and time, service, pets, meeting address, and the other party's display name

We also share the relevant profile and booking details with the other party to your booking, as described in section 5, so that the service can actually be delivered.

We may disclose data where required by law, or where necessary to protect the rights, property, or safety of our users.

Google Calendar — only if you connect it

mido can add your confirmed bookings to your Google Calendar. This is optional and off by default. None of what follows happens unless you connect your Google account from the More screen in the App, and you can disconnect at any time.

What we ask for. A single Google permission, https://www.googleapis.com/auth/calendar.app.created, which Google defines as the ability to make secondary Google calendars and to see, create, change, and delete events on those calendars only. We deliberately do not request the broader “see and edit events on all your calendars” permission.

What this lets us do — and what it does not. When you first connect, we create a new secondary calendar named “mido” inside your Google account, and we write your confirmed bookings into it. We cannot see, change, or delete anything in any of your other calendars, because the permission does not reach them. We never read your calendar to work out when you are busy. The App has its own availability settings for that, and reading your calendar would need a far wider permission than we ask for.

What we send to Google. For each confirmed booking: its date and time, the service, the pets involved, the meeting address, and a link back to the booking in the App. What appears in the event title depends on which side of the booking you are on. An owner's event names the sitter. A sitter's event shows the owner's name only in the shortened form other users already see — for example “Dana L.” — never their full name, consistent with section 5.

What we store. We store the identifier of the calendar we created for you, and a record of which bookings we have already written, so that a rescheduled booking can be moved and a cancelled one removed. We never store your Google password or your Google credentials. Those stay with Clerk, our authentication provider, which issues a short-lived access token only when a sync is due.

When we write to your calendar. Only on a booking's own events: when it is confirmed, when a reschedule is accepted, and when it is cancelled. A completed booking keeps its event — it happened. Bookings confirmed before you connected are not backfilled.

How to disconnect. Disconnect from the same screen in the App, which stops all future syncing. You can also revoke mido's access at any time from your Google Account permissions page at myaccount.google.com/permissions. Events already written to your calendar stay in your calendar and remain yours to keep or delete. Deleting your mido account also stops syncing and removes future events.

Limited Use. mido's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties except as needed to provide this feature, to comply with applicable law, or as part of a merger or acquisition.

7. International transfers

Our database and files are hosted in the EU (Frankfurt, Germany). Some of the providers listed above process data in the United States. Where that happens, transfers are made under appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision.

8. How long we keep data

DataRetention
Account and profile dataUntil you delete your account
Bookings, payments, and payout recordsSeven years after the transaction, as required by Israeli tax and accounting law
Messages, photos, Mido Card updates, walk routesKept with the booking they belong to; anonymised when you delete your account
ReviewsKept, shown under an anonymised name after account deletion
Sitter bank and tax detailsDeleted when you delete your account, except where a payment record must be retained for tax purposes
Crash reportsUp to 90 days at Sentry, then deleted automatically
Product-usage analyticsUp to 90 days at PostHog, then deleted automatically
Push notification tokensDeleted when you sign out or delete your account

When data is no longer needed for any of these purposes, we delete it or anonymise it so it can no longer be linked to you.

9. Security

No system is perfectly secure, but we take reasonable and appropriate measures to protect your data.

10. Your rights

Subject to Israel's Privacy Protection Law and, where applicable, the GDPR, you may:

To exercise any of these, email midooapp@gmail.com. We will respond within the time the applicable law allows.

11. Deleting your account and your data

You can delete your account in the App, under More → Delete account, or by emailing midooapp@gmail.com.

Deletion takes effect immediately, with no waiting period. Your name, email, phone number, and profile photo are removed; your pet profiles and photos are deleted; your sitter listing disappears from the marketplace; and your push tokens are deleted.

Records we are required to keep — bookings, payments, reviews, messages, Mido Card updates, and walk routes — are retained in anonymised form, detached from your name, photo, and contact details. This is what lets the other party to a past booking keep their own records, and what lets us meet our tax and fraud-prevention obligations.

If you connected Google Calendar, deleting your account also disconnects it and removes future mido events from your calendar. Events for bookings that already happened are left in place.

12. Children

mido is not intended for anyone under 18. Bookings are paid contracts and sitters receive bank payouts, so an adult must hold the account. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy. The current version is always published at mido.co.il/privacy, and we update the "Last updated" date at the top when we change it. If a change materially affects how we use your data, we will tell you in the App.

14. Contact

Questions, requests, or complaints about privacy: midooapp@gmail.com.

Operator: Yuval Azriel Atzmon (עצמון יובל עזריאל), עוסק פטור no. 205390941, Israel.