Last updated: August 2026 · DRAFT — pending legal review
El Pato de Madrid runs elpatomadrid.com, a community archive of El Pato street art. For privacy questions, contact us through the contact page.
If you browse the site without an account, we record only a daily count of page views per page. This contains no personal data — no cookies, no IP addresses, no profiles, no third-party analytics.
If you create an account, we store your email address, a securely hashed version of your password, your chosen username, and your profile picture. We never see or store your password itself.
If you submit a spotting, we store the photograph, the location you provide, and any note you add.
We do not collect your real name, address, phone number, date of birth, or payment details.
Photos from a phone or camera often contain hidden data such as GPS coordinates and device details. Profile pictures are re-encoded on upload with all of this metadata removed, and the original file is discarded. For spotting photos we deliberately read the location, because that is what places the duck on the map.
Your username, profile picture, spot count, rank and approved spottings are public. Anyone can view your profile page and see the spottings you have contributed. Your email address is never shown publicly and is never included in any public part of the site.
To let you sign in, to send six-digit confirmation codes when you verify an address, reset a password or change your email, and to tell you about your own submissions. We do not send marketing email and we never sell or share your data.
Under the GDPR you can access, correct, export or delete your data at any time. Most of this is self-service in My Patos: "Export my data" downloads everything we hold about you, and "Delete my account" removes your account permanently. When you delete your account, your spottings remain on the public map but are no longer linked to you or to any name — they become anonymous, and your points are removed. You also have the right to complain to the Spanish data protection authority (AEPD).
Account data is kept while your account is active. Accounts inactive for three years are deleted. Confirmation codes expire after 15 minutes. Sign-in sessions expire after 90 days. Backups are kept for 14 days.
The site is served over HTTPS. Passwords are hashed with scrypt and a unique per-account salt. Sign-in sessions use secure, HTTP-only cookies. Our database is not reachable from the internet, and no public page or interface can return an email address.
You must be at least 14 years old to create an account.
If we change this policy we will update the date above and, for significant changes, notify account holders by email.