3. Third-Party Services and Data Sharing
We absolutely do not sell, rent, or share your personal data or pet information with
third parties for commercial purposes.
However, we work with the following trusted third-party service providers to deliver application
services:
Supabase (Backend and Database)
All user, pet, and application data is securely stored on AWS servers (US/EU regions).
Privacy Policy: https://supabase.com/privacy
OneSignal (Notifications)
Processes device ID and notification segments to send reminder notifications. Data center: USA.
Privacy Policy: https://onesignal.com/privacy_policy
Apple App Store / Google Play Store (Subscription Management)
Premium subscription purchases are processed by Apple or Google. Billing information (name, address,
payment method) is stored by Apple/Google and not shared with us. Credit card/bank information is
never stored on our servers. We only receive subscription status (active/cancelled) and purchase
date information.
Firebase Crashlytics (Error Reporting)
Sends anonymous error reports to detect application crashes and errors.
Privacy Policy: https://firebase.google.com/support/privacy
Important: Users will be notified in advance for planned maintenance (in-app
notification and/or email). In case of emergency outages, post-incident notification will be
provided. We reserve the right to disclose your data to authorities in case of legal obligation
(court order, legal process).
10. International Data Transfer
Snouty is a Turkey-based application, but some third-party services we use may store your data on
international servers:
- Supabase: AWS US/EU regions
- OneSignal: US servers
- Firebase: Google Cloud servers (global)
GDPR Compliance and Schrems II Ruling
These transfers are protected by Standard Contractual Clauses (SCC) under Article 46 of GDPR. In
accordance with the European Court of Justice's Schrems II ruling (C-311/18), additional security
measures are implemented for US transfers:
- End-to-End Encryption: All data transfers are encrypted with TLS 1.3 protocol
- Storage Encryption: Data on servers is stored encrypted with AES-256
- Access Control: Only authorized users can access their data through Row Level
Security (RLS)
- Data Minimization: Only necessary data is transferred to third-party services
- Regular Security Audits: Our service providers have SOC 2, ISO 27001
certifications
EU-US Data Privacy Framework
Supabase is registered with the EU-US Data Privacy Framework and implements GDPR-compliant data
protection standards.
User Rights
EU/European Economic Area (EEA) users can object to the transfer of their data to the US and exercise
their right to erasure. To object, contact legal@bearcodestudio.com .