Privacy Policy
Version 2026-09-10
Who is responsible for your data
pets-only is operated from Germany. The full name, registered address and contact details of the entity responsible for processing your data under the GDPR are published in our Impressum; until it is, you can reach us for any privacy question or request at privacy@petsonly.com.
What we collect
Account and provider identity. When you sign up, we store your account profile (your name, email address, and profile photo) (User model, auth.prisma). If you register as a service provider, we additionally store your provider profile (your business name, bio, and approximate service location) (Provider model, service.prisma) — this is the one profile visible to any signed-in visitor searching for a provider, whether or not you are their match. Pet profiles and photos. Every pet you add — name, species, breed, bio, birth date, weight and care records — plus every photo or video you upload for it, a post, or a message attachment. These are content you authored, stored so the features you posted them to can show them (a pet's profile, your feed, the conversation you sent an attachment into). Approximate location, never your exact address. Your pet's deck location and, if you are a provider, your service area, are stored only as coordinates offset by roughly 300–500 metres from what you enter — a fixed, per-pet offset we derive cryptographically from a secret we hold, so it is consistent (your pet does not appear to jump around) but never reversible back to your real address. The exact coordinates you type into the location field are read once, to compute that offset, and are never written to a database row. Map centering from your IP address, never stored. When you open a page with a location picker and haven't placed a pin yet, we look up an approximate region from your IP address (city- or country-level) so the map starts centred near you instead of showing the whole planet. That lookup runs entirely on our own server against an offline database — your IP address is never sent to a third party, never logged, and never written to a database row; only the resulting map view (a latitude, longitude and zoom level) is returned to your browser for that one page load. Message bodies. The text of every direct message you send is stored so the conversation can be shown to both sides of it (Message model, conversation.prisma) — up to 2000 characters per message, plus any photo or video attachment. Technical and session data. Signing in creates a session row that records the IP address and user agent your browser or app sent at the time (Session model, auth.prisma) — used to let you see and revoke your own active sessions in Settings, and to investigate abuse. Payment information, mostly not by us. Card and bank details are entered directly into Stripe, our payment processor, and never reach pets-only's own servers; we store the booking price, its status, and Stripe's own event and identifier for it (PaymentEvent model) so a charge can be matched to the booking it paid for. Sign-in provider data. If you sign in with Google, Apple or Facebook, that provider gives us the account identifier and access tokens needed to keep you signed in (Account model, auth.prisma) — this is data those providers hold and disclose to us, not data we collect independently. Locale and time zone. The language and region you read pets-only in, and the IANA time zone your reminders and booking times are anchored to — detected from your device on first sign-in and editable afterwards in Settings. Feedback you send us from inside the app. If you report a bug or ask for a feature, we store what you wrote, whether it was a bug or a request, and the technical context that makes it actionable — the platform, app version, operating system, device model, language and the screen you were on (Feedback model, feedback.prisma). If you attach a screenshot or photo, we store that image too (FeedbackImage model), and only because you ticked the box saying we may: we record the moment you did, and the server refuses to store any image for a submission that did not carry that consent. Feedback is read by our own staff and nobody else — it is never shown to other users, though you can see your own attachment again on the Feedback screen. Screenshots can capture more than you meant them to, so send only what you are comfortable sharing, and write to privacy@petsonly.com if you want a submission deleted. Pre-launch waiting list, if you ask to be told when we open. Before pets-only is generally available, our coming-soon page offers to notify you when it is. If you take it up we store the email address you leave on our coming-soon page, and the language you were reading it in (WaitlistSignup model, waitlist.prisma) and nothing else — no name, no password, and no account is created; leaving your address signs you up for that one announcement and nothing more. The basis is your consent (Art. 6(1)(a) GDPR): write to privacy@petsonly.com and we take the address off the list, and if we never write to you at all it is deleted automatically two years after you left it.
Why we are allowed to process it
Most of what we collect is necessary to perform the contract these Terms create with you (Art. 6(1)(b) GDPR) — a deck cannot show your pet without its profile, a conversation cannot exist without its messages, a booking cannot be paid without Stripe knowing its price. Session technical data and abuse investigation rest on our legitimate interest in keeping the service secure (Art. 6(1)(f)). Anything we ask you to switch on separately — push notifications, non-essential cookies — rests on your consent (Art. 6(1)(a)) and can be withdrawn as easily as it was given.
Who we share it with
We do not sell your data. It is shared only with the processors that make the service work: Stripe for payments and provider payouts; Resend for transactional email (a booking confirmation, a password reset); DigitalOcean Spaces (S3-compatible object storage) for photos and videos; and, only for the map shown when you set a location, OpenStreetMap's public tile servers, which see the map area your browser requests but not who requested it. Another user sees only what a feature is designed to show them — your pet's public profile, a message you sent them, your provider listing — never a raw export of your account.
How long we keep it
We keep your data while your account is open. Deleting your account from Settings hides almost everything it holds immediately — your pets, photos, messages, sessions and social activity disappear from view, for you and for anyone you matched with — then erases it for good 30 days later, unless you cancel the deletion first. The one exception is a booking you have already paid for or been paid for: Art. 17(3)(b)/(e) GDPR lets us keep what a legal obligation or a legal claim still needs, so instead of erasing that booking we anonymise it — replacing your name with a generic label and detaching it from your account — and keep the record Stripe's own dispute and refund process may still need. Every other booking you made is erased along with the rest of your account, on that same 30-day schedule.
Your rights
Under the GDPR you can ask us to access, correct, delete, restrict, or receive a copy of your personal data, and to object to processing based on our legitimate interest. Deletion is self-service, from Settings, as described above; for access, correction, restriction, portability or an objection, write to privacy@petsonly.com. You also have the right to lodge a complaint with a data protection supervisory authority — in Germany, the one for the state this deployment is established in.
Age requirement
pets-only is not for use below the minimum age the Terms set for consenting to this processing under GDPR Art. 8. We ask for your age when you sign up and rely on what you state; see the Terms for what backs that check and what happens if we later learn it was false.
Cookies and local storage
pets-only sets a session cookie so you stay signed in, and a cookie remembering your light/dark theme choice — neither requires consent, as each is either strictly necessary for the service you asked for or, for the theme, stores no personal data. Anything beyond that (error tracking, analytics) is set only once you consent, and stays unset if you decline.
Partner offers
The care record can show a clearly labelled insurance offer from a partner who pays us a commission if you take out a policy, and it does so only if you switch partner offers on in Settings — the setting is off for every account until you turn it on, and turning it off again is the same switch. Nothing about you or your pets reaches the partner: the link carries a partner identifier and your language, and nothing else. No pet, no breed, no health record, and no location is shared with an advertising partner, whether the setting is on or off, and we never sell your data.
Security
Passwords are hashed, never stored in the clear; connections to pets-only are encrypted in transit; and access to production data is limited to what operating the service requires. No system is perfectly secure, and we cannot guarantee against every breach, but we treat one as an incident to disclose, not one to hide.
Changes to this policy
We may update this Privacy Policy. A change to what we collect, why, or who we share it with moves the version at the top of this document; if you are signed in when that happens, you will be asked to review and accept the new version before continuing to use pets-only.