Necessary cookies are always on. Analytics and marketing only with your consent. More in our privacy policy.
How pet2vet collects, uses, and protects your data.
Last updated:
This policy is effective as published and is updated on an ongoing basis. It will additionally be reviewed by counsel before public launch.
pet2vet is a digital service operated from Berlin, Germany, that helps pet owners find a vet, book appointments, and track their pet's health. The data controller under Art. 4(7) GDPR is the pet2vet team.
Account data (email, hashed password, display name) and language preference. Pet profile data you provide (name, species, breed, sex, date of birth, weight, photos, and the microchip number if you enter it). Diary entries (mood, appetite, stool, water intake, energy level, structured symptom entries, weight, notes). Health-related medication and treatment data, including reminders. Bookings (including guest bookings, which store a name, email address, and any free-text emergency notes) and verified reviews. Uploaded documents, for example appointment attachments that may contain veterinary records. Gamification data from the quiz, points ledger, badges, and prize draw. For vet accounts we also process: clinic name, address, location coordinates, opening hours, contact details, calendar metadata, verification documents (for example a practice licence), and, optionally, expense entries for clinic bookkeeping. If you recommend a clinic or send an invitation (clinic team, pet-profile sharing), we process the contact details you enter. For technical reasons we also process shortened, salted-and-hashed IP addresses and a hash of your browser's user agent, to document consent under Art. 7(1) GDPR and to prevent abuse (rate limiting).
To deliver the service (book and remind), to keep the platform safe, and, only with your consent, to run product analytics. The legal basis is primarily performance of a contract under Art. 6(1)(b) GDPR, supported by our legitimate interest in secure operation (Art. 6(1)(f) GDPR) and your consent where required (Art. 6(1)(a) GDPR), for example for analytics. Health-related information about your pet is processed as core functionality under Art. 6(1)(b) GDPR and handled with heightened care. This data does not fall under Art. 9 GDPR, which protects personal data about people only. We keep to a minimum any sensitive personal information you may inadvertently enter in free-text fields (such as notes).
Hosting and data storage (including uploaded documents) on Supabase (EU/Frankfurt) and Vercel (EU edge), email delivery via Postmark, error tracking on Sentry, audience measurement via Vercel Web Analytics (cookieless, only after your consent); product analytics and session recording via PostHog on its EU data infrastructure (eu.posthog.com), loaded only after you opt into the “Statistics” category and with all inputs and text masked in session recordings. To display and resolve clinic addresses we use the Geocoding and Places services of the Google Maps Platform, which transmits address data to Google. Clinic profile texts (description, services, team introductions) are machine-translated by DeepL SE (Cologne, Germany); these texts may contain personal data a clinic chooses to include. Maps are rendered using map tiles from OpenStreetMap; for technical reasons your browser sends your IP address to the OpenStreetMap Foundation when a map loads. Calendar data flows to Google or Microsoft only if you connect those accounts (see section 8). Once we enable WhatsApp messaging, it will run through 360dialog; we will obtain your prior consent and update this policy before then. Each processor is bound by a Data Processing Agreement under Art. 28 GDPR. Some of these providers process data in, or transfer it to, the United States, namely the Google Maps Platform (Google), Postmark, and Sentry. We base such third-country transfers on appropriate safeguards under Art. 13(1)(f) and 44 et seq. GDPR: the EU-US Data Privacy Framework where the provider is certified, and otherwise the European Commission's Standard Contractual Clauses.
Access, correction, deletion, portability, objection, and withdrawal of consent at any time (Art. 15–22 GDPR). Email support@pet2vet.app; we respond within 30 days. You can also lodge a complaint with the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Account data: until you delete your account; after deletion the data is permanently removed within 30 days. Bookings linked to an account: 7 years (tax and commercial-law retention). Guest bookings with no account: personal details are anonymised after 12 months and the records deleted after 24 months. Diary and health entries: 5 years from creation, then deleted; if you delete the pet profile, deletion follows a 30-day window. Reviews: kept as long as the clinic profile exists, then anonymised. Clinic recommendations: anonymised after 24 months. Clinic verification documents (for example a practice licence): until account deletion, then removed within 30 days. Expense entries recorded by clinics: until the clinic deletes them, and at the latest when the clinic account is deleted. Consent records: up to 3 years after account deletion (proof obligation under Art. 7(1) GDPR). Backups: rotated within 30 days.
pet2vet uses strictly necessary cookies (login session, language preference); these do not require consent under § 25(2) TDDDG. For audience measurement we use Vercel Web Analytics, a cookieless analytics tool that stores no personal data or cross-device identifiers; it loads only after you opt into the “Statistics” category in the consent banner (§ 25(1) TDDDG). For product analytics we additionally use PostHog; this tool stores a cookie and entries in your browser's local storage to recognise returning sessions, and records sessions to improve usability, with all inputs and text content automatically masked. PostHog also loads only after you opt into the “Statistics” category and does not run without that consent; the analytics data is processed on PostHog's EU data infrastructure (eu.posthog.com). We embed no advertising or marketing cookies and no third-party tracking pixels. You can withdraw your consent at any time via the consent banner, after which collection stops. If we add any further consent-requiring service in the future, we will collect your prior opt-in via the consent banner and update this policy before doing so.
When you sign in with Google or connect your calendar, pet2vet requests only the OAuth scopes listed below. You grant consent in the Google consent screen and can revoke it at any time at https://myaccount.google.com/permissions. • openid: Identifies you to pet2vet (Google's opaque account ID, the "sub" claim). Used to link the Google account to your pet2vet account at sign-in. • email: Reads your Google-verified email address. Used to create or look up your pet2vet account and to send booking confirmations. • profile: Reads the display name and (optionally) the avatar picture on your Google profile. Used to show your name in the app; we do not store the avatar. • https://www.googleapis.com/auth/calendar.events (vet accounts only): Reads, creates, updates, and deletes events on the Google Calendar you connect. Used for (a) reading existing events so busy time is hidden from your public booking page, (b) creating one calendar event per confirmed pet2vet booking, and (c) deleting that event if the booking is cancelled. pet2vet does not access any other calendars on your Google account, nor does it read events written by other applications outside of this use. You can disconnect the calendar from your clinic dashboard at any time; on disconnect, pet2vet calls Google's token-revocation endpoint and deletes the locally-stored encrypted tokens. An equivalent permission set applies to Microsoft 365 / Outlook (scopes: openid, email, profile, offline_access, User.Read, Calendars.ReadWrite). The Microsoft Calendars.ReadWrite scope is functionally equivalent to calendar.events above. Access tokens and refresh tokens are stored server-side only and encrypted with AES-256-GCM; the encryption key is managed separately from the database in the secured hosting environment. Tokens are never sent to your browser or shared with third parties.
We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects within the meaning of Art. 22 GDPR. Providing certain data is partly required by law and partly necessary to use the service: to create an account and make a booking we need at least your name and email address, and without them we cannot provide the service. All other information, such as diary entries or photos, is optional.
On the booking page, signed-in users can optionally use an AI assistant that helps choose an appointment type and length. For this purpose your chat messages are transmitted to Anthropic PBC (USA) as a processor and used there solely to generate the reply; the transfer is safeguarded by EU standard contractual clauses and Anthropic does not use the content to train AI models. We do not store the conversation and do not link it to your account. Please do not enter personal data in the chat. The legal basis is Art. 6(1)(b) GDPR (supporting the booking at your request). The assistant does not make automated decisions within the meaning of Art. 22 GDPR and does not give veterinary advice; the choice of appointment is yours alone.
Questions? Email support@pet2vet.app.