Skip to main content

Privacy policy

Cori Dog develops pre-launch pet-care products and owner-first research concepts. This policy explains what personal data we collect through this website, why we collect it, how long we keep it, and the rights you have over it.

Last updated: 11 September 2026.

Controller

The data controller for this website is CoriDog.com.

For privacy questions or requests, email contact@coridog.com.

Data we collect

  • Waitlist details: first name, email address and, optionally, your dog's name.
  • Your separate contact choices: whether you request occasional marketing updates and whether you ask to be considered for early-testing contact.
  • Research answers: the responses you choose to give in our optional questions.
  • Concept-interest details: for Pet Diary, your email, optional first name, preferred first interface, whether you may consider a private pilot, and your 16+ confirmation. Before activation, we also keep a short-lived digest of a one-time email-confirmation token; the token itself is sent by email and is not stored in the Cori database.
  • Request and consent records: the applicable waitlist, offer, marketing, early-testing and research versions, plus a timestamp only for each action or consent actually given.
  • Basic context: the page you signed up from and campaign parameters (UTM) if present.

We do not collect special category data, and we do not ask for payment details at this stage. The Pet Diary interest form does not ask for pet names, health history, diagnoses, medications, evidence, or veterinarian details, and it does not process a pet record through AI.

A waitlist request uses separate 256-bit email-confirmation and optional survey-linkage proofs. Cori stores only SHA-256 digests. The short-lived linkage proof stays in a secure HttpOnly browser cookie and no database record identifier is returned to the browser.

If you submit the same pending request again after five minutes, Cori may send another confirmation message. This is user-triggered, never automatic, and does not replace your earlier details or extend the original 48-hour deadline. Confirmed and legacy-unverified entries do not receive another confirmation from this form. Once that fixed window has expired, a later form starts a new request with a new deadline; it does not revive an old link or update the expired request. At most five confirmation-send attempts per address are reserved in any 24 hours, including when a request expires and is made again. To enforce this limit, we retain a pseudonymous SHA-256 digest of the address and up to five reservation times until 24 hours after the last reservation; scheduled cleanup removes expired guard records.

Purposes and legal bases

Each purpose relies on one legal basis. We do not stack bases to keep processing alive after you withdraw consent.

  • Holding a waitlist request briefly, verifying the email address, and—only after confirmation—administering waitlist membership and the founding offer: steps taken at your request before a possible purchase (Art. 6(1)(b) GDPR). A form receipt alone does not create membership or benefit eligibility.
  • Occasional marketing email, possible early-testing contact, and use of optional product-research answers are three separate purposes based on your consent, which you can withdraw at any time (Art. 6(1)(a) GDPR). Marketing and early-testing contact choices activate only after email confirmation; research consent is given separately with the survey.
  • Sending one email to verify a concept-interest request, limiting misuse, and holding the unconfirmed request briefly: our legitimate interests in verifying requests and protecting the form (Art. 6(1)(f) GDPR). The request is not active before confirmation.
  • After email confirmation, recording your interest in a named Cori concept and contacting you about its research or possible private pilot: your consent (Art. 6(1)(a) GDPR). Each interest is purpose-bound; joining Pet Diary does not join the skincare waitlist, create a Cori account, or grant pilot access.
  • Keeping the site and waitlist secure, preventing fraudulent or abusive sign-ups, and basic aggregate measurement of which pages are useful: our narrowly defined legitimate interests (Art. 6(1)(f) GDPR).
  • Keeping consent and compliance records where the law requires it: legal obligation (Art. 6(1)(c) GDPR).

Providers and transfers

We use service providers for hosting and database infrastructure, email delivery, and measurement, including Google Ads conversion measurement.

Confirmed processors may process data outside the European Economic Area. Where a transfer requires it, we rely on an adequacy decision for the destination country or, where no adequacy decision applies, on the European Commission's Standard Contractual Clauses together with appropriate additional safeguards.

We do not sell your personal data. The Google tag can receive the measurement and conversion information described below; the Pet Diary form does not send Google the email, first name, interface preference, or private-pilot preference you enter.

Retention

We mark an unconfirmed skincare waitlist request and its confirmation digests for deletion when its fixed 48-hour window ends. We mark a confirmed waitlist row for deletion no later than 24 months after confirmation unless you ask us to remove it sooner. Raw research answers—whether linked by valid proof or stored without an email association—are marked for deletion no later than 24 months after completion. Aggregated, genuinely anonymous statistics may be kept longer because they are no longer personal data.

Pre-migration waitlist and survey rows are quarantined as legacy unverified data: they are not treated as members or contactable consent, and historical caller-controlled survey links are severed. They have a 90-day reconciliation deadline. Any reconfirmation or deletion is a separately reviewed operation; an anonymous repeat form submission cannot update them.

When collection is enabled, an unconfirmed Pet Diary request will be kept no longer than 48 hours and deleted rather than used for updates. A confirmed concept-interest entry is kept for no more than 24 months from your latest consent for that named interest, unless you ask us to remove it sooner. A future interest uses a separate purpose key and consent record rather than silently extending this permission.

Your rights

You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing carried out before withdrawal.

To exercise any of these rights, email contact@coridog.com. To stop Pet Diary updates or withdraw that interest, use the unsubscribe option in an update when available or email the same address.

Withdrawing skincare marketing consent stops marketing only; it does not remove a confirmed waitlist entry or its founding-benefit state. Asking to leave the skincare waitlist deletes that entry and any survey linked to it through verified proof. Research stored unlinked has no email association and follows its own 24-month limit; email us if you want help identifying any research record you can reasonably describe.

If you believe we have handled your data improperly, you may lodge a complaint with your local supervisory authority. In Poland this is the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland.

Cookies and measurement

We use first-party session storage and interaction events, together with a necessary Google Ads conversion-measurement tag. The tag loads before you make a cookie choice, and keeps loading the same way if you choose essential technologies only, with analytics storage, ad storage, ad user data and ad personalisation all denied. In that state it sets no cookies and stores no advertising identifier. It does send Google a cookie-free signal with your consent state and the address of the page you are on, and that request reaches Google with your IP address and browser details like any other web request; Google uses these signals for aggregate modelling. A confirmed waitlist request can send Google Ads a cookie-free conversion signal without the email, confirmation proof or a stored advertising identifier; this supports aggregate conversion modelling. In the European Economic Area, the United Kingdom and Switzerland, advertising storage remains off unless you grant advertising consent. The browser session identifier helps us avoid counting the same visit twice. We do not sell this data.

Strictly necessary HttpOnly cookies briefly hold a survey-linkage proof (up to 30 minutes) and an email-confirmation proof while you complete the confirmation page (up to 15 minutes). They contain random proofs, not database UUIDs, and are cleared after use. The database accepts a survey link only once and only for the exact page and experiment variant that created it.

Security and children

Data is stored on access-controlled infrastructure, encrypted in transit, and is available only to the people who need it for the purposes described above. No online service can be guaranteed to be perfectly secure, and we do not claim otherwise; we take reasonable technical and organisational measures and review them as the project grows.

The waitlist and concept-interest forms are intended for people aged 16 or older. This site is not directed to children, and we do not knowingly collect data from them. If you believe a child has signed up, ask us to remove the entry and we will delete it.

Changes and contact

If we change this policy, we will update the date above and, where the change is significant, tell you by email. For questions about this policy, contact contact@coridog.com.