This policy describes what data Petvity collects, why we collect it, and the rights you have over it. We aim to write it in plain language — if anything is unclear, write to support@petvity.com.
1. Data we collect
Account
- Email address (required to log in)
- Display name (you set this; defaults to your email prefix)
- Password — stored only as a bcrypt hash; we never see the plaintext
- Role (pet owner, veterinarian, pet sitter, or admin)
- Preferred language and email-preferences flags
Pet data you enter
- Pet profile: name, species, breed, sex, birth date, photo, bio
- Health metrics you log: weight, temperature, heart rate, mood, energy, anxiety, socialization
- Vaccination, medication, and clinical-record entries
Activity
- Bookings you make with vets or sitters
- Reviews you write
- Orders you place and products you list in the marketplace
- Adoption listings and applications you submit
2. How we use it
- To run the service: render your dashboard, compute wellness signals, process orders, deliver email notifications
- To send transactional email (vaccination reminders, health alerts, order confirmations, booking reminders)
- To send the optional welcome onboarding series — opt-out from the email footer or in Settings → Email preferences
- To comply with legal obligations
We do not sell your data, share it with advertisers, or use it to train AI models.
3. Service providers
Petvity relies on a small set of vendors to operate. Each has its own privacy practices; we share only the minimum data each one needs.
- Vercel — application hosting and edge delivery
- Neon — managed PostgreSQL database (your data lives here)
- Resend — transactional email delivery
- Vercel Blob — pet avatar storage
- Google — only if you sign in with Google OAuth
4. Cookies
We use a small set of strictly-necessary cookies; details on the cookie policy page.
5. Your rights
Under GDPR (and similar laws elsewhere) you have these rights, all of which we make exercisable directly from your account:
- Access — download a copy of every row stored under your account from Settings → Your data, or via
GET /api/account/export - Erasure — delete your account and all related data from Settings → Danger zone. The deletion cascades through pets, metrics, vaccinations, records, bookings, orders, listings, and applications. This is irreversible.
- Rectification — edit any of your data directly in the app
- Portability — the export above is JSON, suitable for moving to another service
- Object / restrict— opt out of the welcome email series at any time; transactional emails remain because they're necessary for the service you signed up for
- Lodge a complaint — with your local data protection authority
6. Retention
We keep your data for as long as your account exists. When you delete your account, the cascade removes everything immediately. Transactional email logs at our email provider may persist for a short period for deliverability auditing.
7. Security
Passwords are hashed with bcrypt. All traffic to Petvity is served over HTTPS. Database connections use TLS. No system is perfectly secure — if we ever discover a breach affecting your data, we will notify you without undue delay.
8. Changes
If we materially change this policy we will update the effective date above and notify active users by email.
9. Contact
Privacy questions: support@petvity.com.