Legal

Privacy Policy

Effective date: May 2, 2026 · Last updated: September 8, 2026

Plain English summary: We collect your name and email when you sign up. We use trusted third-party services to run the platform. We never sell your data. This policy explains everything in full.

1. Who We Are

The Groomers Base ("we", "us", "our") is a cloud-based business management platform for independent dog groomers and small grooming salons, operated by CENP Digital Group Ltd (registration number HE 493655), a company registered in the Republic of Cyprus within the European Union.

For the purposes of applicable data protection law, The Groomers Base is the data controller for groomer account data. When groomers collect and store client and pet data through our platform, The Groomers Base acts as a data processor on behalf of the groomer, who remains the data controller for that client data.

Contact: support@groomersbase.com

2. Data We Collect

2.1 Groomer Account Data

  • First name, business name, email address
  • Password (bcrypt-hashed — we never store plain-text passwords)
  • Business address, phone number, timezone, currency preference
  • Profile photo / business logo (optional, stored in Supabase Storage)
  • Social media links (optional)
  • Signup source — the campaign tag (for example utm_source) or referring website you arrived from when you created your account, so we know which advert or site brought you to us. No cookies are used for this and it is never shared.
  • Billing information — processed and stored by Stripe; we store only transaction references and subscription status, never raw card numbers

2.2 Client & Pet Data (Collected by Groomers)

Groomers use our platform to manage their own clients. Data entered by groomers or submitted by clients through the public booking page may include:

  • Client: full name, email address, phone number, home address (for mobile visits)
  • Pet: name, breed, size, weight, health notes, behavioural notes, photo
  • Appointment history, service records, groom report cards, before/after photos

Groomers are responsible for ensuring they have obtained any necessary consent from their clients before entering client data into The Groomers Base.

2.3 Usage & Technical Data

Server logs, IP addresses, browser type, and pages visited — used for security, debugging and service reliability. We do not build profiles from them. The one exception, and only if you choose "Accept all" on our cookie banner: your IP address and browser user-agent are included in the sign-up event we send to Meta so it can match the sign-up to an advert (section 8). If you choose "Essential only" they are never sent anywhere for advertising.

We also count visits to our website with Vercel Web Analytics. It is cookieless, records only aggregate page views, the referring site and campaign tags, and cannot identify you or follow you across other websites.

For groomer accounts, we measure how the app itself is used — which pages you open, roughly how long you spend on them, and which features you use. This is first-party: it is recorded by us, stored in our own EU database, never sold or shared with an advertising network, and never used to build a profile of you as an individual. We do not record your screen, your keystrokes, or the content you type. Raw usage records are deleted after 90 days; only aggregate daily totals are kept beyond that. The legal basis is our legitimate interest in understanding and improving the service (Article 6(1)(f)), and you can object at any time by emailing us.

On public booking pages we count how many visits reach each step of the booking form. This is deliberately cookieless: nothing is stored on your device, no IP address or browser fingerprint is retained, and the counts cannot be linked back to you.

On our own marketing website we measure how many visits each page gets, which link or campaign brought you, how far down the page you scrolled, which buttons were clicked and roughly how long the page was open. By default this stores nothing on your device: a visit is a single page load. If you chose "Accept all" in the cookie banner, we also use the random id that banner created to recognise a returning visit, so we can tell a new visitor from someone coming back. If you chose "Essential only" that id is never used for measurement. If you later create an account, visits we recorded from that browser may be linked to it so we can understand which campaigns bring groomers who go on to use the product. Raw records are deleted after 90 days.

2.4 Data We Do NOT Collect

We do not use third-party product analytics, session recording, heatmaps or keystroke logging. Apart from the Meta advertising pixel described below, all analytics described above are first-party and stay in our own database. We do not collect biometric data or any sensitive personal categories under GDPR Article 9.

We do use one advertising technology, and only with your consent: if — and only if — you choose "Accept all" on our cookie banner, the Meta (Facebook) advertising pixel is loaded so we can measure whether our adverts bring groomers to us. If you choose "Essential only", or make no choice at all, it is never loaded. Section 8 and our Cookie Policy describe exactly what it does and what is sent.

3. How We Use Your Data

  • Create and maintain your groomer account
  • Provide booking, calendar, client management, and reporting features
  • Send transactional emails: booking confirmations, appointment reminders, groom report cards, subscription and payment notices
  • Send transactional SMS notifications to your clients (Pro plan only — coming soon, not yet active). When live, SMS will only be sent to clients who have given explicit opt-in consent, collected when the feature launches. Clients may opt out at any time by replying STOP to any SMS.
  • Process subscription payments and manage your billing relationship with us
  • Respond to support requests
  • Comply with legal obligations including financial record-keeping
  • Improve the platform using aggregated, anonymised usage data

We never sell or rent your data, and we never share your clients' data, their pets, your bookings or your payments with anyone for advertising or profiling — with no exception. The single exception for your own account data is the advertising measurement described in section 8: if, and only if, you choose "Accept all" on our cookie banner, we tell Meta that a sign-up happened and include your email address as an irreversible hash, your IP address and your browser user-agent so it can be matched to an advert. Choose "Essential only" and none of that is sent.

5. Third Parties We Share Data With

We share only the minimum data necessary for each service to function. All providers are bound by data processing agreements (DPAs), except Meta, with whom we are joint controllers for the advertising measurement described in section 8. We never sell your data, we never share it with data brokers, and the only advertising network we share anything with is Meta — and only if you have chosen "Accept all" on our cookie banner. Nothing about your clients, their pets, your bookings or your payments is ever shared for advertising.

Supabase

Database & Authentication

Data shared: All account, client, pet, and appointment data

Processing region: EU (Dublin, Ireland)

View Supabase privacy policy →

Stripe

Payment Processing

Data shared: Billing information, subscription data, transaction records

Processing region: USA (Standard Contractual Clauses)

View Stripe privacy policy →

Resend

Transactional Email Delivery

Data shared: Recipient email address, name, appointment details included in email body

Processing region: USA (Standard Contractual Clauses)

View Resend privacy policy →

Twilio

SMS Notifications — Coming Soon (Pro plan)

Data shared: Recipient phone number, appointment reminder message text. Not yet active — no data is currently processed by Twilio.

Processing region: USA (Standard Contractual Clauses)

View Twilio privacy policy →

Meta Platforms Ireland

Advertising measurement — joint controller, and only if you choose "Accept all"

Data shared: Page views and the fact that a sign-up happened, the _fbp and _fbc advertising cookies, IP address, browser user-agent, and your email address as an irreversible SHA-256 hash. Never any client, pet, booking or payment data.

Processing region: EU (Ireland), with onward transfer to Meta Platforms, Inc. (USA) under Standard Contractual Clauses and the EU-US Data Privacy Framework

View Meta Platforms Ireland privacy policy →

Vercel

Hosting, Serverless Infrastructure & Web Analytics

Data shared: Server request logs, IP addresses, response metadata. Web Analytics: aggregate page views, referring site and campaign tags — cookieless, no personal identifiers, no cross-site tracking

Processing region: EU (Dublin, Ireland)

View Vercel privacy policy →

Sentry (Functional Software, Inc.)

Error monitoring — session recordings only if you choose "Accept all"

Data shared: Error reports and performance samples: the page address (with any booking, payment or cancellation link tokens and email addresses removed before sending), browser type, and technical details of what went wrong. If you choose "Accept all", a small share of visits is also recorded as an anonymised session replay in which every piece of text is masked and every image blocked — no names, client details or form contents are captured. Never recorded on "Essential only".

Processing region: EU (Frankfurt, Germany)

View Sentry (Functional Software, Inc.) privacy policy →

Upstash

Rate limiting (abuse protection)

Data shared: Short-lived request counters keyed by your IP address, the email address entered on a booking form, or the booking-page name — used only to limit repeated requests (abuse protection). They expire automatically, at the latest 24 hours after the last request.

Processing region: EU (Ireland)

View Upstash privacy policy →

OpenStreetMap Foundation (Nominatim)

Address suggestions while typing an address

Data shared: The text typed into an address field, sent as you type to return address suggestions: the groomer's business address on the business-profile and complete-profile forms, and — for home-visit bookings only — the address a client types on the booking page. Nothing else about the person is sent.

Processing region: United Kingdom

View OpenStreetMap Foundation (Nominatim) privacy policy →

Google (Sign in with Google)

Optional sign-in provider — only if you choose to sign in with Google

Data shared: The email address, name, profile picture and account identifier of your Google account, supplied by Google when you sign in. Nothing about your account or your clients is sent to Google.

Processing region: EU (Google Ireland Limited), with onward transfer to Google LLC (USA) under the EU-US Data Privacy Framework

View Google (Sign in with Google) privacy policy →

6. Data Retention

  • Active account: Data retained for the duration of your subscription.
  • After cancellation: Data retained for 30 days to allow export and reactivation. After 30 days, all data is permanently deleted from our systems.
  • Financial records: Certain payment and invoice records are retained for up to 7 years as required by law.
  • Server logs: Retained for up to 90 days for security and debugging, then automatically purged.

7. Your Rights

Depending on your location, you have the following rights regarding your personal data. We respond to all verified requests within 30 days.

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Ask us to correct inaccurate or incomplete data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Right to Restrict Processing

Ask us to pause processing while a dispute is resolved.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests at any time.

Withdraw Consent

For marketing emails: the unsubscribe link in any email. For the Meta advertising pixel: the “Cookie settings” link in the footer of any page reopens the cookie banner — choose “Essential only” and the pixel stops loading, the Meta cookies are deleted from your browser, and no further sign-up events are sent.

Lodge a Complaint

Contact your national supervisory authority if you believe your data has been mishandled.

To exercise any of these rights, email support@groomersbase.com with the subject line "Data Request". We may ask you to verify your identity before processing your request. If you are in the EEA and believe we have not handled your data correctly, you have the right to lodge a complaint with your national data protection authority.

8. Cookies

Without your consent we set only essential cookies, required for authentication and security, and our own visit measurement stores nothing on your device at all.

If you choose "Accept all", three further things happen: the Meta (Facebook) advertising pixel is loaded, which is a third-party cross-site tracking pixel used to measure our ads; a random id of our own is stored that lets us recognise a returning visit to our website; and a small share of visits may be recorded as an anonymised Sentry session replay (all text masked, all images blocked) to help us fix bugs. Choosing "Essential only" loads none of these and the id is never used to recognise you. You can change your choice at any time with the "Cookie settings" link in the footer of any page, which reopens the banner. Choosing "Essential only" stops the pixel loading and deletes the Meta cookies from your browser.

See our Cookie Policy for the full list of cookies we set and how to manage them.

9. Security

We implement industry-standard security measures including:

  • TLS 1.2+ encryption for all data in transit
  • Encrypted storage for all data at rest (Supabase EU region)
  • Row-level security — each groomer can only access their own data
  • Bcrypt-hashed passwords — we cannot read your password
  • Rate limiting on authentication and public-facing booking endpoints
  • Regular dependency updates and security patch management

In the unlikely event of a data breach affecting your rights or freedoms, we will notify you and relevant supervisory authorities within 72 hours as required by GDPR Article 33.

10. International Data Transfers

The Groomers Base operates from within the European Union. Our primary database and authentication (Supabase) and hosting infrastructure (Vercel) use EU-region servers.

Some third parties process data in the United States: Stripe, Resend, Twilio once SMS is activated, and — only if you chose "Accept all" — Meta, whose EU entity may transfer the advertising measurement data onward to Meta Platforms, Inc. in the United States. All such transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46, ensuring adequate protection of your personal data.

11. Children's Privacy

The Groomers Base is a professional business tool intended solely for adults (18+). We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected data from a minor, please contact support@groomersbase.com and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 14 days in advance and update the "Last updated" date above.

We will never materially reduce your rights under this policy without explicit notice and, where required, renewed consent.

13. Contact

For any questions, data requests, or concerns about this Privacy Policy:

The Groomers Base

Operated by CENP Digital Group Ltd

Agias Paraskevis 158, Germasogeia, 4044, Limassol, Cyprus

Registration No: HE 493655 · Tax ID/TIN: 60382799U · VAT: CY60382799U

Email: support@groomersbase.com

Subject line: "Privacy Request" or "Data Request"

We aim to respond within 5 business days and to complete data subject requests within 30 days as required by law.