Draft: company details still to be completed.
Privacy Policy
This policy explains how [Company name Ltd] ("Pawdiary", "we") handles personal data. It covers two groups: groomers and their staff who use Pawdiary (our customers), and the pet owners whose details groomers keep in Pawdiary.
Who we are
[Company name Ltd], company number [company number], registered at [registered office address]. We are registered with the Information Commissioner's Office ([ICO registration number]). Contact us about privacy at hello@pawdiary.co.uk.
Groomers and their staff: we are the controller
- What we collect: your name, email, password (stored only as a secure hash), business details you enter, your plan and billing status, sign-in times, and basic technical data such as IP address and browser.
- Why: to provide your account and Pawdiary (contract), to take payment for your plan (contract), to keep the service secure and prevent abuse (legitimate interests), and to tell you about important changes (legitimate interests).
- Payments for your plan are handled by Stripe. We never see or store your full card number.
- We keep account data while your account is open, and for up to 6 years after for tax and accounting records where the law requires it.
Pet owners: the groomer is the controller, we are the processor
- Groomers use Pawdiary to keep their clients' contact details, addresses, pets' records, bookings, payments, photos and signed terms. The groomer decides what to keep and why, and is responsible for it. We only process it on their instructions, under our Data Processing Agreement.
- If you are a pet owner and want to see, correct or delete your details, contact your groomer. If you contact us, we will pass your request to them.
- When you sign a groomer's terms through a link, we record your typed name, signature, the time, your IP address and browser, so the groomer has evidence of what was agreed.
Who we share data with
- Only the service providers we need to run Pawdiary (listed below), under contracts that protect the data. We never sell personal data or use it for advertising.
- Where a provider is outside the UK, transfers are covered by UK adequacy regulations or the UK International Data Transfer Addendum.
Cookies and similar
- We only use what is needed to keep you signed in and secure (browser storage for your session, and Cloudflare's bot check on sign-in). We don't use advertising or analytics cookies, so there is no cookie banner.
Your rights
- You can ask for a copy of your data, to correct it, delete it, restrict or object to how we use it, or to receive it in a portable format. Owners can export or delete their whole business from Settings > Account.
- Contact hello@pawdiary.co.uk. If you're unhappy with our answer, you can complain to the ICO (ico.org.uk).
Security
- Data is encrypted in transit and at rest. Each business's data is kept separate from every other business's by access rules in the database, and access by our own staff is limited and logged.
Changes
- We will tell you by email or in the app before any significant change to this policy.
Last updated 28 September 2026.
Sub-processors
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in, file storage and server functions | UK (London region) |
| DigitalOcean (via Laravel Forge) | Hosting the web app | [confirm server region] |
| Stripe | Pawdiary subscriptions, and card payments for businesses that connect Stripe | EU / US (UK adequacy and SCCs) |
| Resend | Account emails, and booking reminders, sign-in links and campaigns for businesses that use them | EU / US (SCCs) |
| Twilio | Text messages, only for businesses that turn texts on | US / EU (SCCs) |
| Cloudflare | Bot protection on sign-in (Turnstile) | Global (SCCs) |
| Calendar sync and Google sign-in, only if a business turns them on | Global (SCCs) | |
| postcodes.io (Ideal Postcodes) | Turning postcodes into map locations (postcode only) | UK |
| OpenStreetMap Foundation | Map tiles on the route page | UK / EU |
[Company name Ltd] · hello@pawdiary.co.uk