Privacy Policy
Version 2026-10-03
Who is responsible for your data
PetsOnly is operated from Germany. The full name, registered address and contact details of the entity responsible for processing your data under the GDPR are published in our Impressum; until it is, you can reach us for any privacy question or request at privacy@petsonly.com.
What we collect
Account and provider identity. When you sign up, we store your account profile (your name, email address, and profile photo) (User model, auth.prisma). If you register as a service provider, we additionally store your provider profile (your business name, bio, and approximate service location) (Provider model, service.prisma) — this is the one profile visible to any signed-in visitor searching for a provider, whether or not you are their match. Pet profiles and photos. Every pet you add — name, species, breed, bio, birth date, weight and care records — plus every photo or video you upload for it, a post, or a message attachment. These are content you authored, stored so the features you posted them to can show them (a pet's profile, your feed, the conversation you sent an attachment into). Approximate location, never your exact address. Your pet's deck location and, if you are a provider, your service area, are stored only as coordinates offset by roughly 300–500 metres from what you enter — a fixed, per-pet offset we derive cryptographically from a secret we hold, so it is consistent (your pet does not appear to jump around) but never reversible back to your real address. The exact coordinates you type into the location field are read once, to compute that offset, and are never written to a database row. The one exception is a sighting of a missing pet that you choose to report, described below. Missing-pet reports, only if you file or answer one. Reporting your pet missing stores when it was last seen, an optional note of up to 280 characters and, if you mark one, the spot where it was last seen together with how widely to blur it — anything from 500 metres down to the exact spot, as you choose — beside the pet's already-offset home area (LostPetAlert model, lostPet.prisma). Owners within about 5 km of that home area are notified, and anyone looking at missing pets nearby sees the pet, your note and the spot as blurred as you chose. Reporting a sighting of someone else's missing pet is the one place we store an exact location on purpose: the pin you place (it starts at your device's position and you can move it), the time, an optional message and photo, and whether the owner may write to you (PetSighting model, lostPet.prisma). The pet's owner and anyone who can see the report see that pin, never your name, and you are told so before you send it. Map centering from your IP address, never stored. When you open a page with a location picker and haven't placed a pin yet, we look up an approximate region from your IP address (city- or country-level) so the map starts centred near you instead of showing the whole planet. That lookup runs entirely on our own server against an offline database — your IP address is never sent to a third party, never logged, and never written to a database row; only the resulting map view (a latitude, longitude and zoom level) is returned to your browser for that one page load. Message bodies. The text of every direct message you send is stored so the conversation can be shown to both sides of it (Message model, conversation.prisma) — up to 2000 characters per message, plus any photo or video attachment. Technical and session data. Signing in creates a session row that records the IP address and user agent your browser or app sent at the time (Session model, auth.prisma) — used to let you see and revoke your own active sessions in Settings, and to investigate abuse. Browser notifications, only if you turn them on. If you allow notifications for PetsOnly in a web browser, we store what that browser gives us to reach it: the address of its push service, two encryption keys, a random identifier for the browser, when it last checked in and how many deliveries in a row have failed (PushSubscription model, push.prisma). A notification then travels through your browser vendor's push service (Google, Apple, Mozilla or Microsoft, depending on the browser), encrypted so that only your browser can read it, and says only that you have a new match or a new message, which pets it is about and, for a message, its first words (about two lines), never an owner's name. Switching the permission off in your browser stops delivery; we delete the row once the push service reports the address gone, and at the latest with your account. iPhone notifications, only if you turn them on. If you allow notifications in the iPhone app, which it offers once after a match, we store the device token Apple's push service (APNs) gives that phone, whether it belongs to a test or a live build, when it last checked in and how many deliveries in a row have failed (ApnsDevice model, push.prisma). A notification travels through Apple's push service and says only that you have a new match or a new message and which pets it is about, never an owner's name or what a message says; for a message, the phone itself then fetches its first words (about two lines) from us through a link that stops working after ten minutes, so the words do not travel through Apple's service. Switching notifications off in iOS Settings stops delivery; signing out of the app removes the token, we delete it once Apple reports it invalid, and at the latest with your account. Android notifications, only if you turn them on. If you allow notifications in the Android app, which asks when you first set it up and once after a match, we store the token Google's push service (Firebase Cloud Messaging) gives that installation of the app, a random identifier the app makes for the installation, which of our apps it belongs to, when it last checked in and how many deliveries in a row have failed (FcmDevice model, push.prisma). A notification travels through Google's push service carrying the pets' names, or for a booking the pet and the service, and, for a match or a message, a link to the pet's photo; for a message also a link through which the app fetches its first words (about two lines) from us. Both links stop working after ten minutes, and the notification never carries an owner's name or what a message says. Switching notifications off in Android's settings stops delivery; signing out of the app removes the token, we delete it once Google reports it invalid, and at the latest with your account. Usage analytics, on unless you switch it off. While you are signed in, our server reports what you do to Mixpanel, our analytics processor, as one of a fixed list of events: a screen opened, a swipe, a message sent, a pet added and a few like them. A report carries the name of the event, its time, whether it came from the web, the iPhone app or the Android app, the app's version when it came from one, the name of a screen (never its address), and an identifier we derive from your account with a key only we hold, so that Mixpanel can tell events belong together without ever holding your account identifier. It never carries your name, email address, messages, pet names, photos or anything else you typed, and your IP address never reaches Mixpanel, because the reports come from our server, not your device. Mixpanel sets nothing on your browser or phone. The switch is in Settings on the web, in Settings ▸ Privacy in the iPhone app and in More ▸ Privacy in the Android app; it is stored with your account, so it holds wherever you sign in, and switching it off stops new reports from your next request. Events already sent are not recalled automatically, so write to privacy@petsonly.com if you want them removed. Payment information, mostly not by us. Card and bank details are entered directly into Stripe, our payment processor, and never reach PetsOnly's own servers; we store the booking price, its status, and Stripe's own event and identifier for it (PaymentEvent model) so a charge can be matched to the booking it paid for. Sign-in provider data. If you sign in with Google or Apple, that provider gives us the account identifier and access tokens needed to keep you signed in (Account model, auth.prisma) — this is data those providers hold and disclose to us, not data we collect independently. Locale and time zone. The language and region you read PetsOnly in, and the IANA time zone your reminders and booking times are anchored to — detected from your device on first sign-in and editable afterwards in Settings. Feedback you send us from inside the app. If you report a bug or ask for a feature, we store what you wrote, whether it was a bug or a request, and the technical context that makes it actionable — the platform, app version, operating system, device model, language and the screen you were on (Feedback model, feedback.prisma). If you attach a screenshot or photo, we store that image too (FeedbackImage model), and only because you ticked the box saying we may: we record the moment you did, and the server refuses to store any image for a submission that did not carry that consent. Feedback is read by our own staff and nobody else — it is never shown to other users, though you can see your own attachment again on the Feedback screen. Screenshots can capture more than you meant them to, so send only what you are comfortable sharing, and write to privacy@petsonly.com if you want a submission deleted. Pre-launch waiting list, if you ask to be told when we open. Before PetsOnly is generally available, our home page offers to notify you when it is. If you take it up we store the email address you leave on our home page, the language you were reading it in, whether you ticked the box offering to help test the beta, which phone you would test it on (iOS or Android), and — only if you ticked it — the moment we sent you an invitation to it (WaitlistSignup model, waitlist.prisma) and nothing else — no name, no password, and no account is created. Leaving only your address signs you up for that one announcement and nothing more; if you also tick the beta-testing box, that ticked box is stored alongside the address and we may write to you again to invite you to try a pre-release build. If we do, we give your address to Apple (App Store Connect and TestFlight) or to Google (Google Play's testing programme), depending on the phone you picked, so that you can install that build; they handle it under their own privacy terms. Both rest on your consent (Art. 6(1)(a) GDPR): use the unsubscribe link in any email we send you, or write to privacy@petsonly.com, and we take the address off the list, and if we never write to you at all it is deleted automatically two years after you left it.
Why we are allowed to process it
Most of what we collect is necessary to perform the contract these Terms create with you (Art. 6(1)(b) GDPR) — a deck cannot show your pet without its profile, a conversation cannot exist without its messages, a booking cannot be paid without Stripe knowing its price. Session technical data and abuse investigation rest on our legitimate interest in keeping the service secure (Art. 6(1)(f)). Usage analytics rests on that same legitimate interest (Art. 6(1)(f)) in knowing which parts of PetsOnly are actually used, weighed against how little it takes to find out: signed-in accounts only, a fixed list of event kinds, a pseudonymous identifier we derive with a key only we hold rather than your account identifier, nothing stored on your device, no IP address sent, and a processor whose EU endpoint keeps the events in the EU. You can object at any time (Art. 21): the switch in Settings is that objection in one tap, and an email to privacy@petsonly.com does the same. Crash and error reports from our servers and from the iPhone and Android apps rest on our legitimate interest in noticing and fixing what breaks (Art. 6(1)(f)): they carry at most your account's identifier, never your name or email address, and you can object to them the same way, by email. Anything we ask you to switch on separately — push notifications, non-essential cookies — rests on your consent (Art. 6(1)(a)) and can be withdrawn as easily as it was given.
Who we share it with
We do not sell your data. It is shared only with the processors that make the service work: Stripe for payments and provider payouts; Resend for transactional email (a booking confirmation, a password reset); unless your account has switched it off, Mixpanel for usage analytics, through its EU data-residency endpoint; DigitalOcean Spaces (S3-compatible object storage) for photos, videos, documents and other uploaded files; only for the map shown when you set a location, and for the maps in the Android app, OpenStreetMap's public tile servers, which see the map area your browser or the app requests but not who requested it; Sentry for crash and error reports, through its EU data region — from our servers and both apps whenever something fails, from your browser only if you accept it in the storage banner, and never with your name or email address; and, only if you turn on notifications, your browser vendor's push service or, for the iPhone app, Apple's, or, for the Android app, Google's Firebase Cloud Messaging, which relay each notification carrying only what the paragraphs on notifications above describe. One processor sees you before you have an account at all: our home page runs Google reCAPTCHA on the email form so that an automated script cannot fill the waiting list, and for that one page Google receives your IP address, your browser and what you did on the page in order to score whether you are a person. It runs nowhere else on the site, and it is told nothing about the address you typed. Feedback you send, with its attachments, is shared with the tools we use to track and triage it — never with your name or email address — and is kept after you delete your account. The database and object storage we operate ourselves are both hosted in Frankfurt, Germany, within the EU. Another user sees only what a feature is designed to show them — your pet's public profile, a message you sent them, your provider listing — never a raw export of your account.
How long we keep it
We keep your data while your account is open. Deleting your account from Settings hides almost everything it holds immediately — your pets, photos, messages, sessions and social activity disappear from view, for you and for anyone you matched with — then erases it for good 30 days later, unless you cancel the deletion first. The one exception is a booking you have already paid for or been paid for: Art. 17(3)(b)/(e) GDPR lets us keep what a legal obligation or a legal claim still needs, so instead of erasing that booking we anonymise it — replacing your name with a generic label and detaching it from your account — and keep the record Stripe's own dispute and refund process may still need. Every other booking you made is erased along with the rest of your account, on that same 30-day schedule. A sighting you reported of someone else's missing pet also outlives your account: it stays on that pet's report with nothing left linking it to you, so an owner still searching keeps the pin, and it goes when the owner deletes that pet or their own account. One thing outlives that schedule: our database backups. We keep a rolling set of them so the service can be restored after a failure — daily backups for a week, weekly ones for a month, and monthly ones for up to 6 months — so data from an account that has been erased can still sit inside an old backup for up to 6 months after the erasure. A backup is only ever restored to recover from a failure, never to bring back something you deleted.
Your rights
Under the GDPR you can ask us to access, correct, delete, restrict, or receive a copy of your personal data, and to object to processing based on our legitimate interest. Deletion is self-service, from Settings, as described above; for access, correction, restriction, portability or an objection, write to privacy@petsonly.com. You also have the right to lodge a complaint with a data protection supervisory authority — in Germany, the one for the state this deployment is established in.
Age requirement
PetsOnly is not for use below the minimum age the Terms set for consenting to this processing under GDPR Art. 8. We ask for your age when you sign up and rely on what you state; see the Terms for what backs that check and what happens if we later learn it was false.
Cookies
PetsOnly sets a session cookie so you stay signed in, a cookie remembering your light/dark theme choice, a cookie remembering your colour theme, a cookie remembering the language you picked, and a cookie remembering your answer to this banner. None of these requires consent, as each is either strictly necessary for the service you asked for or, for the theme choices, the language and the banner answer, stores no personal data. Anything beyond that — error tracking in your browser — starts only once you consent, and stays off if you decline. On the home page only, Google reCAPTCHA stores its own value in your browser under a Google domain; it is there to tell a person from a script rather than to recognise you, which is why it is treated as strictly necessary and not offered here as a choice. This banner does not govern usage analytics: that sets no cookie and reads nothing from your browser, because its reports are sent by our server, and it is switched off in Settings rather than here.
Partner offers
The care record can show a clearly labelled insurance offer from a partner who pays us a commission if you take out a policy, and it does so only if you switch partner offers on in Settings — the setting is off for every account until you turn it on, and turning it off again is the same switch. Nothing about you or your pets reaches the partner: the link carries a partner identifier and your language, and nothing else. No pet, no breed, no health record, and no location is shared with an advertising partner, whether the setting is on or off, and we never sell your data.
Security
Passwords are hashed, never stored in the clear; connections to PetsOnly are encrypted in transit; and access to production data is limited to what operating the service requires. No system is perfectly secure, and we cannot guarantee against every breach, but we treat one as an incident to disclose, not one to hide.
Changes to this policy
We may update this Privacy Policy. A change to what we collect, why, or who we share it with moves the version at the top of this document. Signing in does not ask you to accept a new version of this policy — only a change to the Terms does that. Anything new that needs your consent, such as browser notifications, is switched on by you separately and stays off until you do.