Privacy policy
What PawPass keeps, and why.
Last updated 2026-09-16. Draft pending legal review before App Store submission.
Who we are
PawPass is an independent product built by Princeton students to run the guest list at eating-club doors. It is not affiliated with Princeton University or any eating club. Each club that uses PawPass decides what parties to run on it and who its officers are.
What we collect
- Your Princeton email and directory record. When you sign in we look upyour own entry in Princeton's public directory once to confirm your netid and read your name, class year and affiliation. We store those fields on your profile only. We never bulk-query, cache or market from the directory.
- Profile photo. Required for guest passes so the door can compare a face to a pass. Location and camera metadata are stripped on upload.
- Passes, spots and invites. Which parties you hold a pass for, who gave you the spot, and when it was scanned.
- Door scans. Time, door and result of each scan, kept for one year and then aggregated.
- Device tokens for push notifications and Live Activities, if you turn them on.
- Club rosters uploaded by that club's officers: netid, name, class and role.
How we use it
- To issue, show and verify passes at the door, and to show officers live counts and guest lists for their own club.
- To send you sign-in codes, invites and party notifications you have opted into. Every notification carries an action; none are marketing.
- To keep the service safe: rate limiting, abuse reports, and audit logs of officer actions.
Who can see what
- Door staff and officers of a club see the names, photos and inviters of guests holding passes for that club's parties.
- Friends can see that you are going to a party only if you allow it (default: friends). Names of attendees are never public.
- We do not sell data and do not share it with the University. Clubs receive exports of their own parties on request.
Where it lives
Data is stored with Cloudflare (United States) and email is sent through Resend. Photos are served through short-lived signed links. Secrets and signing keys are never on your device.
Your choices
- Delete your account in the app under You › Settings. Passes are revoked and your profile is removed; anonymised audit rows are kept.
- Report or block anyone from their profile.
- Turn off notifications and visibility to friends at any time.
Contact
Privacy questions: privacy@pawpass.app. Security disclosures: security@pawpass.app. We answer within two business days.