Legal · Last updated June 2026

Privacy policy

This page explains, in plain English, what data Pet & Post collects, what we do with it, and the rights you and your clients have under UK GDPR.

Draft policy. This is the working version of our privacy policy, written in plain English and reviewed by the founder. Before launching publicly, we'll have it reviewed by a UK data-protection lawyer.

Who we are

Pet & Post is operated by an independent UK software developer (sole trader). When you sign up, you become the "data controller" for your clients' data; we act as your "data processor." That means you decide what to do with the data, and we process it on your instructions.

What we collect

From you, the practice account holder:

  • Your name, email, and password (hashed, never stored in plaintext)
  • Your practice name, contact email, and timezone
  • Billing details (handled by Stripe — we never see card numbers)
  • Twilio configuration if you provide it (account SID, auth token, phone number)

From your clients (entered by you or imported from your CSV):

  • Client name, email, phone, postal address
  • Pet name, species, breed, date of birth, clinical due dates (boosters, dental, parasite treatments)
  • Last visit date, opt-in/opt-out status for SMS
  • Messages we send on your behalf and replies your clients send back

What we do with it

We use this data to provide the service you signed up for — sending SMS reminders to your clients about their pets' care, receiving replies, and giving you a dashboard to manage all of it.

Specifically, we:

  • Store your client data securely in a UK-based Supabase database
  • Pass phone numbers and message text to Twilio (or another SMS provider you configure) to send each SMS
  • Pass your billing email to Stripe to handle subscription payments
  • Never sell, share, or use client data for marketing

Who else sees the data

We rely on a small number of trusted sub-processors to operate the service. Each handles only the minimum data needed:

  • Supabase — UK-region database and authentication. Stores your data at rest.
  • Twilio (or your chosen SMS provider) — receives phone numbers and message text to deliver SMS.
  • Stripe — handles your subscription billing. Sees your email and card; we never see card details.
  • Vercel — hosts the Pet & Post application. Sees web traffic; doesn't access database directly.

How long we keep it

For as long as you have an active Pet & Post account, plus a short grace period after cancellation in case you change your mind. If you delete your account, your data and your clients' data are permanently deleted within 30 days, except for anonymised usage logs we keep for security and billing reconciliation.

Your clients' rights under UK GDPR

Your clients can ask you to:

  • Show them what data you hold about them (subject access request)
  • Correct anything that's wrong
  • Delete their data (right to be forgotten)
  • Stop sending them messages (opt-out via STOP reply, automatic)
  • Export their data in a portable format

As the data controller, you handle these requests. We provide tools in the app to help — delete a client, export, manage opt-out status — so you can respond within the 30-day GDPR window.

Security

Connections to the app are HTTPS-only. Passwords are hashed with bcrypt. Database access is restricted to the application service account. We follow the principle of least privilege — staff don't access your data unless you ask us to (for support). Audit logs record administrative actions.

Getting in touch

Questions, concerns, or data requests: hello@petandpost.com. We aim to respond within 2 working days.