Petscovery Privacy Policy
Last updated:
1. Who We Are
Petscovery ("we", "us", "our") is the data controller responsible for your personal data. We are a sole trader based in the United Kingdom, operating under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
If you have any questions about this privacy policy or how we handle your data, please contact us at: hello@petscovery.com
ICO Registration: We will register with the Information Commissioner's Office (ICO) when required. Our registration number will be published here once available.
2. What Data We Collect
We collect and process the following personal data:
Account Information
- Email address
- Display name
- Account creation and login timestamps
- Authentication provider used (email/password, Google, or Apple)
Pet Information
- Pet name, animal type, breed, date of birth, and sex
- Pet photographs (profile photos, milestone photos, and memories)
- Approximate location of your pet's birth (stored as a geohash, not a precise address)
Payment Information
- Payment transactions are processed by Stripe. We store a record of your payment amount, currency, status, and Stripe customer ID. We do not store your full card details.
Device Information
- Push notification tokens, device type (iOS, Android, Web), and device name — used solely to deliver push notifications you have opted into
Usage Data
- Page views, feature interactions, and other usage events to help us improve the Service. Where we use analytics tools such as Google Analytics, these are only activated with your consent (see our Cookie Policy).
Communication Preferences
- Your email and push notification preferences (e.g. new family member alerts, milestone reminders)
3. How We Use Your Data
We use your personal data on the following lawful bases under UK GDPR:
Contract Performance (Article 6(1)(b))
- To create and manage your account
- To process payments for unlocking litter features
- To match your pet with potential littermates based on birth location and date
- To store and display your pet's profile and photographs
Legitimate Interests (Article 6(1)(f))
- To detect and prevent fraud or abuse
- To maintain the security of our platform
Consent (Article 6(1)(a))
- To send you marketing emails (where you have opted in)
- To send push notifications (where you have enabled them)
- To place non-essential cookies on your device, including analytics cookies (see our Cookie Policy)
Legal Obligation (Article 6(1)(c))
- To retain payment records as required by UK tax and accounting legislation
You can withdraw consent at any time by updating your notification preferences in your account settings, changing your cookie preferences, or by contacting us.
4. Automated Decision-Making
Our Service uses automated matching to identify potential littermates for your pet based on birth location (geohash) and date of birth. This matching is used solely to suggest possible family connections and does not produce legal or similarly significant effects.
You are not subject to any decisions based solely on automated processing that significantly affect you. All suggested matches are presented for your consideration — you decide whether to act on them.
5. Who We Share Your Data With
We share your personal data with the following third-party service providers who process data on our behalf:
- Firebase (Google) — authentication and push notifications
- Google Analytics — website usage analytics (only with your consent)
- Stripe — payment processing
- Cloudflare — image storage (R2)
These providers are contractually obligated to process your data only as instructed by us and in accordance with applicable data protection laws.
We do not sell your personal data to any third party.
6. International Data Transfers
As we use service providers based outside the UK, your data may be transferred internationally. Where personal data is transferred outside the UK, we ensure it is protected by:
- UK adequacy regulations (for countries deemed to have adequate protection)
- International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs)
- Other appropriate safeguards as required under UK GDPR
You can request further details about the safeguards in place for specific transfers by contacting us.
7. How Long We Keep Your Data
- Account data: retained for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it by law.
- Pet data and photographs: retained for as long as your account is active. Where another user has purchased access to your pet's profile, photos may be retained in anonymised form after account deletion to honour that paid access. In all other cases, photos are deleted when your account or the associated pet profile is removed.
- Payment records: retained for 7 years to comply with UK tax and accounting obligations (HMRC requirements). Payment records are anonymised where possible after this period.
- Usage/event data: retained for up to 2 years, then anonymised or deleted.
- Push notification tokens: automatically cleaned up when stale or when you remove the app from your device.
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
- Right to restrict processing — request that we limit how we use your data while a concern is being resolved
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal
To exercise any of these rights, please contact us at hello@petscovery.com. We will respond within one month of receiving your request, as required by law. In exceptional circumstances, we may extend this by a further two months, in which case we will inform you.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: https://ico.org.uk/make-a-complaint/
- Helpline: 0303 123 1113
9. Cookies
We use cookies and similar technologies on our website. For full details on what cookies we use, their purposes, and how to manage them, please see our Cookie Policy.
10. Children's Privacy
Our Service is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you are aged 13 to 17, you should have the consent of a parent or guardian before using the Service.
If you believe we have collected data from a child under 13, please contact us immediately at hello@petscovery.com and we will take steps to delete it.
11. Security
We take appropriate technical and organisational measures to protect your personal data, including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Secure, httpOnly session cookies
- Private storage buckets for photographs with time-limited signed URLs
- Stripe webhook signature verification for payment security
- Access controls and authentication via Firebase
While we take reasonable steps to protect your data, no method of transmission over the internet is completely secure. We cannot guarantee the absolute security of your data.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by posting a notice on our website or by email. The "last updated" date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically.
13. Contact Us
If you have any questions, concerns, or requests regarding this privacy policy or your personal data, please contact us:
- Email: hello@petscovery.com