Your privacy is important to us. This policy explains how we collect, use, and protect your personal data in compliance with GDPR and UK data protection laws.
Scot Pooper Scoopers Limited ("we," "us," "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our pet waste removal services.
This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using our services, you agree to the collection and use of information in accordance with this policy.
Data Controller: Scot Pooper Scoopers
Registered Office: 2 McNeill Place, Blantyre, Glasgow G72 9FE, Scotland
ICO Registration: Registered with the Information Commissioner's Office
Contact: privacy@scotpooperscoopers.com
We send SMS messages via Twilio Inc. (US-based processor, UK GDPR Standard Contractual Clauses in place) and emails via Resend Inc. We may also send messages via WhatsApp Business (Meta Platforms Ireland Ltd).
When you register for our services, we collect: Full name, email address, phone number, service address, payment information (processed securely through our payment provider), and property details (yard size, access codes, photos).
We collect information about your pets (names, breeds, sizes, photos), service preferences and schedules, appointment history and service reports, and feedback and ratings you provide.
When you use our website or app: IP address, browser type and version, device information, pages visited and time spent, cookies and similar tracking technologies, and geographic location (with your permission).
We use your personal data to: Provide and manage our pet waste removal services, schedule and coordinate appointments, assign technicians to your location, send service confirmations and reminders, process payments and issue invoices, and provide customer support.
To send you: Service-related notifications (appointment reminders, technician en-route alerts, service completion reports), account updates and important notices, marketing communications (only if you've opted in), and responses to your inquiries and feedback.
We analyze data to: Improve our services and customer experience, develop new features and offerings, conduct internal research and analytics, optimize routes and scheduling, and identify and prevent fraud or security issues.
Processing is necessary to fulfill our service contract with you, including scheduling services, payment processing, and service delivery.
We process data based on legitimate business interests such as: Improving our services, preventing fraud, maintaining security, and conducting business analytics.
We process data to comply with legal requirements including: Tax and accounting obligations, responding to legal requests, and maintaining records as required by law.
Where required, we obtain your explicit consent for: Marketing communications, optional data collection (photos, preferences), and cookie usage beyond essential cookies.
We share data with trusted third parties who help us operate: Payment processors (for secure payment handling), cloud hosting providers (for data storage), communication services (for SMS and email delivery), and mapping services (for route optimization). All providers are contractually bound to protect your data.
Your service address, contact information, and property details are shared with assigned technicians to enable service delivery. Technicians are bound by confidentiality agreements.
We may disclose information when required by law, in response to legal process, to protect rights and safety, in connection with business transfers, or with your explicit consent.
We use the following third-party data processors under UK GDPR-compliant Data Processing Agreements: Twilio Inc. (SMS delivery, US-based, SCCs in place), Resend Inc. (email delivery), Meta/WhatsApp Business (messaging), Stripe Inc. (payment processing), Base44 (application platform and database hosting, EU/UK infrastructure), and Google (Calendar, Drive, Analytics — where applicable). A full list of sub-processors is available on request.
We never sell your personal data to third parties. We don't share your data for third-party marketing. We don't use your data for purposes unrelated to our services without your consent.
We implement industry-standard security measures: Encryption of data in transit (SSL/TLS) and at rest, secure authentication and access controls, regular security audits and vulnerability assessments, firewalls and intrusion detection systems, and secure backup and disaster recovery procedures.
Staff training on data protection and privacy, limited access to personal data on need-to-know basis, confidentiality agreements with all staff and contractors, regular review and update of security policies, and incident response procedures for data breaches.
In the event of a data breach that poses a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR.
You can request a copy of all personal data we hold about you. We'll provide this free of charge within one month.
You can request correction of inaccurate or incomplete personal data.
You can request deletion of your personal data in certain circumstances, such as when data is no longer necessary or you withdraw consent.
You can request we limit how we use your data in certain situations.
You can request your data in a structured, commonly used format to transfer to another service.
You can object to processing based on legitimate interests or for direct marketing.
Where processing is based on consent, you can withdraw it at any time.
You have the right to complain to the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.
While you're an active customer, we retain your data to provide services and fulfill our contractual obligations.
Account and service data: Retained for 7 years (for tax and legal purposes). Payment data: Retained per payment provider's policies and legal requirements. Communication logs: Retained for 2 years. Marketing preferences: Retained until you opt out.
If you request deletion, we'll delete your data within 30 days, except where retention is required by law (e.g., accounting records).
Required for basic website functionality, authentication, and security. These cannot be disabled.
Remember your preferences and settings to enhance your experience.
Help us understand how visitors use our website to improve performance (with your consent).
Track your activity for advertising purposes (only with explicit consent).
You can control cookie preferences through our cookie banner and your browser settings. See our Cookie Policy for detailed information.
Your data is primarily processed and stored within the United Kingdom.
Some service providers may be based outside the UK/EEA. Where this occurs, we ensure appropriate safeguards are in place: Standard Contractual Clauses approved by the European Commission, adequacy decisions recognizing equivalent data protection, or your explicit consent for the transfer.
Our services are not directed to children under 16. We do not knowingly collect personal data from children. If we become aware we've collected data from a child, we'll delete it promptly. Parents/guadians who believe we may have information about a child should contact us immediately.
Email privacy@scotpooperscoopers.com with "Data Access Request" in the subject line.
Log into your client portal or contact us to update your details.
Request account deletion by emailing privacy@scotpooperscoopers.com.
Contact the ICO at ico.org.uk or call 0303 123 1113.
If you have any questions about this Privacy Policy or how we handle your data, please contact our Data Protection Officer.
© 2026 Scot Pooper Scoopers. All rights reserved.
Registered with the ICO • UK GDPR & Data Protection Act 2018 Compliant