Privacy
Privacy Policy
Last updated: 30 July 2026
This Privacy Policy explains how Chengdu Paw Era Technology Co., Ltd., trading as BuddyOra ("BuddyOra", "we", "us" or "our"), collects, uses, discloses and otherwise processes personal information when you visit or make a purchase from our online store, communicate with us, subscribe to marketing, or otherwise use our websites and services (together, the "Services"). It also describes the rights you may have. Region‑specific provisions appear in Section 13 and apply in addition to the general provisions.
1. Who We Are and How to Contact Us
Chengdu Paw Era Technology Co., Ltd. is the data controller responsible for the personal information described in this Policy, except where another entity is identified as independently responsible.
Chengdu Paw Era Technology Co., Ltd.
Address: Tianfu New Area, Sichuan, China
Brand: BuddyOra
Email: support@pawsmart.com
2. Personal Information We Collect
Depending on how you interact with the Services, we may collect the following categories of personal information:
Category Examples
Identifiers and contact information Name, email address, telephone number, billing and shipping address, account identifiers and IP address
Order and commercial information Products viewed, purchased or returned; cart contents; order history; payment status; discounts; returns, exchanges and customer preferences
Payment information Payment method, billing information, payment confirmation and limited transaction details. Full card details are generally collected directly by our payment providers and are not stored by us
Account information Login details, account settings and saved preferences, if you create an account
Communications Customer‑support enquiries, reviews, survey responses and other communications with us
Device, network and technical information Browser and device type, operating system, unique device or cookie identifiers, log data, access times, referring URLs and approximate location derived from IP address
Internet and usage activity Pages and products viewed, searches, clicks, interactions with the Services, cart activity and marketing attribution data
Marketing information Newsletter subscription, marketing preferences, campaign interactions and inferred interests
Fraud‑prevention information Order, device, payment‑risk and account signals used to prevent fraud and protect the Services
Please do not send us sensitive personal information unless we specifically request it and explain why it is needed. We do not intentionally collect government identifiers, precise geolocation, health, biometric, genetic or similar sensitive information through the Services. If we process payment credentials or other data that may be classified as sensitive under applicable law, we use and disclose it only as necessary for the purposes described in this Policy and as permitted by law.
3. How We Collect Personal Information
We collect personal information:
Directly from you, including when you place an order, create an account, contact support, submit a form, review a product or subscribe to marketing.
Automatically, through cookies, pixels, local storage, server logs and similar technologies when you use the Services.
From service providers and business partners, such as Shopify, payment processors, delivery partners, fraud‑prevention providers, analytics and advertising partners.
From other parties, including social‑media platforms or referral partners when you interact with our pages or advertisements, subject to your settings and applicable law.
4. Why We Process Personal Information
We use personal information for the following purposes:
To provide the Services and perform our contract with you, including processing payment, fulfilling and delivering orders, providing account functions, handling returns or exchanges and providing customer support.
To operate, maintain and improve the Services, understand usage, troubleshoot errors and develop our products and customer experience.
To secure the Services, authenticate users, detect or prevent fraud, abuse and other harmful activity, and protect our customers, business and legal rights.
To communicate with you about orders, accounts, support requests and material service or policy updates.
To send marketing where permitted, measure campaigns and, where enabled and lawfully permitted, personalise content or advertising.
To comply with tax, accounting, consumer‑protection, sanctions, law‑enforcement and other legal obligations, and to establish, exercise or defend legal claims.
To complete a corporate transaction such as a merger, financing, acquisition, reorganisation or sale of assets, subject to appropriate safeguards.
Where EU data protection law applies, our legal bases are described in Section 13. We will not use personal information for a materially different, unrelated or incompatible purpose without providing any notice or consent required by law.
5. Cookies, Analytics and Advertising
We and our service providers may use cookies, pixels, software development kits and similar technologies to:
keep the store, cart, checkout and security features working;
remember preferences;
understand traffic, performance and use of the Services; and
measure or personalise marketing and advertising, where enabled.
Our store is hosted by Shopify. If enabled for this store, analytics and advertising tools may include Google Analytics/Google Ads, Meta Pixel/Conversions API and TikTok Pixel. These providers may receive identifiers, device and network information, browsing or interaction data, and purchase or campaign information. Depending on the service and context, a provider may act as our processor/service provider or as an independent controller/business under its own privacy terms.
Where required by law, we do not place or access non‑essential analytics or advertising technologies until you consent. You can use the cookie‑preference control displayed on the Services to accept, reject or change non‑essential cookie choices. Browser controls can also block or delete cookies, but doing so may affect store functions.
Provider information: [Shopify Privacy Policy](https://www.shopify.com/legal/privacy), [Google Privacy Policy](https://policies.google.com/privacy), [Meta Privacy Policy](https://www.facebook.com/privacy/policy/) and [TikTok Privacy Policy](https://www.tiktok.com/legal/page/row/privacypolicy/en).
6. Marketing Communications
We send promotional email or other electronic marketing only as permitted by applicable law. You can unsubscribe at any time using the link in a marketing email or by emailing us. Unsubscribing does not prevent service messages such as order confirmations. We may keep minimal suppression‑list information to respect your opt‑out.
7. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients for the purposes described above:
Shopify and other hosting, ecommerce and IT providers;
payment processors, banks and fraud‑prevention providers;
warehouses, carriers, customs agents and other fulfilment or logistics providers;
customer support, email, review, analytics and professional‑service providers;
advertising and social‑media partners, where enabled and permitted by your choices and applicable law;
regulators, courts, law‑enforcement bodies or other parties when required by law or necessary to protect rights and safety; and
parties to an actual or proposed corporate transaction, subject to appropriate confidentiality and safeguards.
We do not disclose personal information to third parties for their own direct marketing without any consent required by law. We do not sell personal information for money.
8. International Transfers
We are established in the People’s Republic of China, and our providers and recipients may operate in other countries, including Canada and the United States. Personal information may therefore be processed outside the country where you live, where privacy laws may differ.
Where the EU GDPR applies, we use a valid transfer mechanism as required by Chapter V of the GDPR, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate. You may contact us for information about the relevant safeguards and, where available, a copy subject to necessary redactions.
9. Retention
We retain each category of personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, maintain business and transaction records, comply with legal, tax and accounting duties, resolve disputes, enforce agreements and prevent fraud. The applicable period depends on the type and sensitivity of the information, the relationship with you and relevant limitation and statutory‑retention periods. We then delete or anonymise the information, unless deletion is not technically feasible; in that case, we isolate it from further use until deletion is possible.
Typical criteria include the life of your account or customer relationship; the time required to fulfil and support an order; applicable tax, accounting, consumer‑law and limitation periods; and the duration of a documented security or legal need. Cookie duration is shown in the cookie‑preference tool where required by law.
10. Security
We use reasonable and appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. No transmission or storage system is completely secure, and we cannot guarantee absolute security. Please use a unique password and notify us if you believe your interaction with us is no longer secure.
11. Children
The Services are intended for adults and are not directed to children. We do not knowingly collect personal information from children under 16 in the EEA or under the applicable digital‑consent age in another jurisdiction. If you believe a child has provided personal information to us, contact us so that we can investigate and delete it where required.
12. Requests, Verification and Authorised Agents
To exercise a privacy right, email support@pawsmart.com and state your country, the right you wish to exercise and enough information for us to locate the relevant records. We may request proportionate information to verify your identity and authority. We use verification information only to process the request. Where permitted, an authorised agent may submit a request; we may require proof of authority and direct identity confirmation. Rights are subject to legal exceptions, and we will explain a refusal where required. We will not discriminate or retaliate against you for exercising a privacy right.
13. European Economic Area Supplement
This section applies when the EU General Data Protection Regulation (“EU GDPR”) applies.
Controller and legal bases
Chengdu Paw Era Technology Co., Ltd. is the controller.
We rely on the following legal bases:
Contract (Article 6(1)(b)) for checkout, payment, fulfilment, accounts, returns and requested customer service.
Legal obligation (Article 6(1)(c)) for tax, accounting, product‑safety, regulatory and lawful disclosure duties.
Legitimate interests (Article 6(1)(f)) for store operation and improvement, essential communications, network and information security, fraud prevention, enforcing or defending claims, and limited measurement or marketing where law permits. Our interests are to operate a safe and effective retail business and understand and serve customers; we balance those interests against your rights and expectations.
Consent (Article 6(1)(a)) for non‑essential cookies, certain analytics or advertising, and electronic marketing where consent is required. You may withdraw consent at any time without affecting earlier lawful processing.
If we must collect information to enter into or perform a contract or meet a legal requirement, fields marked as required must be provided. Without them, we may be unable to accept or fulfil an order. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Fraud tools may flag an order for review, but we make or arrange appropriate human review where required.
Your EEA rights
Subject to the GDPR’s conditions and exceptions, you may request access, rectification, erasure, restriction, data portability, or object to processing. Where processing is based on legitimate interests, you may object based on your particular situation. You have an absolute right to object to processing for direct marketing, including related profiling. You may withdraw consent at any time.
You may complain to the supervisory authority where you habitually reside or work, or where an alleged infringement occurred. A list is available from the [European Data Protection Board](https://www.edpb.europa.eu/aboutedpb/aboutedpb/members_en).
14. Third‑Party Sites and Services
The Services may link to sites or services operated by others. Their privacy and security practices are governed by their own notices. We encourage you to review them before providing personal information.
15. Changes to This Policy
We may update this Policy to reflect changes to our practices, technology, legal requirements or other operational reasons. We will post the revised version, update the “Last updated” date and provide any additional notice required by law. Material changes apply prospectively unless applicable law permits otherwise.