Document contents
PetSpot Privacy Policy
Version 1.1 Last updated: 10 September 2026
1. Who operates the service
PetSpot is a service for pet owners, veterinary clinics, and clinic staff and practitioners where needed for the clinic cabinet. The platform operator is PetSpot Technologies LLC, a limited liability company registered in Georgia on 7 September 2026, identification number 422961637.
Registered address: Georgia, Ambrolauri Municipality, Khvanchkara village, block N001, plot N047 Namosakhlevi.
Contact for personal data and account deletion: support@petspot.love. Additional contact: petspot@petspot.love. Website: petspot.love.
This Policy covers the PetSpot mobile applications, website, QR-based clinic check-in, web cabinets and associated server-side processes. Features vary by application version, country and participating clinic. Mentioning a feature does not mean that it is available to everyone.
This Policy explains processing; it is not consent to every action described. Consent for an action that requires it is obtained separately. The rules for using the service are set out in the Terms of Use.
2. The roles of PetSpot and a clinic
PetSpot as an independent controller. We determine the purposes of processing the platform account, requests addressed to PetSpot, service security and other features we provide directly to you.
A clinic as an independent controller. A clinic determines the purposes of maintaining its client records, arranging appointments and preparing veterinary documentation. When storing and processing these records on its instructions, PetSpot acts as a processor. The parties’ obligations are governed by a separate Data Processing Agreement (DPA).
Sharing information from your account with a selected clinic is a distinct process. Staff access depends on their permissions, branch and the access granted. Connecting a clinic to PetSpot does not give every clinic access to every pet and owner.
The selected clinic is identified in the relevant section. Ask the clinic for its legal details, processing grounds and retention periods for its own records; PetSpot will help identify the responsible party. “Owner” and “co-owner” labels in the interface identify service access roles, not legal ownership of an animal.
3. Data we process
We obtain data from you, your selected sign-in provider, a clinic you interact with, a user who grants you pet access, and your device and the service infrastructure.
A clinic may create a client record and pet information before you register in the app. After your identity is verified, for example by confirming control of the email address used to sign in, relevant pre-existing records may be linked to your account. This does not authorise access to someone else’s records and does not constitute marketing consent. Report an incorrect link to support; the clinic retains its obligations to inform you about the data it obtains.
| Scenario | Data and source | Purpose |
|---|---|---|
| Sign-in and account | Internal identifier, public ID, email, verification information, sign-in provider, name and photo if supplied by Google or Apple; selected language | Authentication, access recovery, synchronisation and account identification |
| Profile | Name, photo, telephone, contact email, description, languages and region supplied by you; additional profile fields, such as birthday day and month, if completed | Profile and selected contact methods; completing a field does not automatically make it public |
| Pets | Name, species, sex, breed, birth date, colour, photos; microchip details; allergies, blood group and other completed information | Pet records and sharing initiated by you |
| Care and history | Weight and measurements, vaccinations, parasite treatments, medicines, repeat dates, events, feeding and activities, notes and reminder settings in the sections used | Care history, calendar, reminders and available history |
| Booking and visit | Clinic, branch, practitioner, service, date, time, status, owner name and contact details, selected pet, reason for the visit, comment and queue number | Appointments, communication, queue management, cancellation and visit history |
| QR check-in without a regular account | Contact and pet details entered in the form, draft, guest-session identifier, status and attachments | Saving form steps and checking in. A draft may be transmitted to the server before final submission |
| Veterinary documents | Information entered by the clinic or you: complaints, examination, diagnosis, prescriptions, procedures, laboratory results, recommendations, files, author and recording time; personal information included in a document | The clinic’s service, documentation and delivery of results to the owner |
| Chats and shared access | Messages, attachments, participants, times, read/edit information, presence information, pet-access requests and decisions | Communication, delivery and access management |
| Clinics and staff | Representatives’ and staff contact details, names, photos, positions, roles, branches, invitations, work schedules and cabinet actions; entered supplier/contact-person information | Cabinet operations, access allocation, records and clinic operational statistics |
| Requests and applications | Name and contact details, request, idea, complaint, category, screenshot or other voluntarily attached content | Responding, clinic onboarding and complaint handling |
| Technical information | IP address and network information, device/browser and OS type, application version, language, installation and session identifiers, push tokens, diagnostic events and application-integrity results | Service delivery, notifications, abuse prevention and troubleshooting |
| Web analytics | Browser-session/cookie identifiers, pages visited, interaction events and device information when analytics is enabled | Understanding website and cabinet usage and improving the interface; see Cookies and Analytics |
Only information necessary for the selected action and identified as such is mandatory. A personal account cannot be created without the required sign-in information; booking may be unavailable without contact details required by the selected clinic. Additional personal information, photos, descriptions and optional fields need not be supplied.
An animal’s health information is not automatically human health data. However, animal records may contain personal data about owners, practitioners and others; we take that connection into account when protecting data and granting access. Do not upload human medical records, identity-document details, payment credentials or other people’s sensitive information that is unnecessary for the selected feature.
4. Purposes and legal grounds
We use necessary account, booking, message and feature data to establish and perform our relationship with you. Before a contract is entered into, we process information needed to respond to your application or onboarding request.
Consent is used for actions that require it, including optional analytics, promotional messages and particular transfers to external services. You can withdraw that consent. Declining optional processing does not remove access to features that do not need it.
Legitimate interests may support proportionate fraud prevention, security and the handling of specific disputes, where your rights do not override those interests. Processing required by law is limited to the relevant obligation. “Legitimate interests” is not permission to collect any information.
The responsible clinic determines the grounds for its clinical records. Agreement to a booking, permission to access a pet record and consent to veterinary treatment are separate actions; none automatically replaces another.
5. Technology suppliers and recipients
Recipients depend on the action, platform and feature used.
| Supplier or recipient | Function and information involved |
|---|---|
| Google — Firebase / Google Cloud | Firebase Authentication for sign-in; Cloud Firestore and Cloud Storage for records and files; Cloud Functions for server operations; Realtime Database for presence; Cloud Messaging for push; App Check and Play Integrity for protection; Remote Config for application configuration where used. Relevant account data, content, technical identifiers and request information are processed |
| Google Sign-In and Google Maps / Google Play services | Selected sign-in information; map delivery, geographical requests and technical information for relevant features. This does not give PetSpot access to your mailbox or all your Google information |
| Google Analytics for Firebase / Google Analytics | Website and cabinet visits and interactions when analytics is enabled. Google’s legal role for Analytics may differ from its cloud-processor role |
| Apple | Sign in with Apple, iOS system functions and APNs notification delivery: authentication information, including a relay email when selected, tokens and notification data |
| Vercel | Website hosting and delivery, web requests and infrastructure logs: IP, request address, browser and other technical information; request content when it passes through the relevant web handler |
| Resend | Delivery of email codes, invitations and other service emails, including results sent by a clinic: recipient email, message content, included names, links and delivery information |
| Selected clinic, chat participant or user granted access | Information needed for the relevant booking, conversation, document or access grant |
| Authorised PetSpot personnel and contractors | Information needed for support, administration and security within their permissions |
Optional image processing by OpenAI. In sections and versions that offer AI photo processing, the selected image and processing parameters are sent to OpenAI through the PetSpot server following a separate informed user action. Images may contain people. Results are stored in PetSpot infrastructure. Declining does not require you to give up ordinary photo uploads. This feature does not mean that an entire pet record, conversation or veterinary history is sent to OpenAI. This description does not authorise voice transcription or AI diagnosis.
OpenAI’s published API rules provide that API data is not used for training by default unless the API customer separately enables data sharing; service retention and safety checks may nevertheless apply. PetSpot does not promise zero retention at OpenAI. See OpenAI API data controls.
Telegram integrations. Where connected, bot messages may contain technical application notifications, an idea submitter’s name/email and text, a support request and contact details, or a clinic booking client’s name, date, time and comment. Telegram and message recipients process these messages. Telegram message retention is distinct from PetSpot retention. Disabling a section or integration does not automatically erase messages already delivered. You may contact PetSpot about their processing and deletion. The existence of a notification bot does not by itself authorise sending clinical documents to Telegram.
We do not sell personal data. Supplier disclosures are limited by the relevant purpose, applicable obligations and user rights. Service processors must meet contractual confidentiality and protection requirements. Sign-in, map and communication-platform providers may independently determine processing within their own services; their policies do not replace PetSpot’s duties.
6. Visibility and access
When sharing material through available features, remember that a recipient may see and retain the information provided to them. You must have the necessary rights and grounds to share someone else’s contacts or photographs.
Avatars, pet photographs, galleries and other images delivered through direct links may be accessible to someone who obtains a link, including without signing in to PetSpot. Hiding a record in the interface does not guarantee that a previously shared image becomes inaccessible. This differs from access to restricted account records and clinical documents. Contact support to request image deletion or restriction of a link.
Messages are available to chat participants and, for clinic chats, the clinic’s authorised staff. We do not claim end-to-end encryption of conversations. A recipient may save, download or forward material; revoking access does not automatically erase external copies.
Granting pet access allows the specified recipient to see information covered by that feature; editing depends on separately granted permissions. Revocation ends the relevant future access but does not automatically destroy lawfully created visit records or clinic documents. Requests to erase those records are assessed separately against their retention grounds.
7. Location, files and permissions
Location may be used to identify a supported city, display maps and find nearby clinics in features that provide this functionality. A manually selected city or place is not the same as continuous device tracking. OS permissions govern access to system location; you can disable it and use manual selection where available.
Photos and documents are processed when you select and upload them. Media-library access depends on the OS version and permission chosen. Allowing file selection does not mean that the entire library is uploaded. Documents and original images may contain embedded information; avoid unnecessary personal information in filenames and content.
Disabling a permission may restrict only the relevant functions. System notification or location permission is not consent to advertising or every third-party disclosure.
8. Notifications and emails
We use notifications and emails for authentication, bookings, queues, messages, pet access, results and reminders. Delivery involves device tokens, recipient addresses, language and notification content. Depending on device settings, a pet name, sender name or message excerpt may appear on the lock screen.
You can manage push notifications in device settings and available reminders in their relevant sections. Required security communications and replies to your requests differ from advertising. Promotional communications require a separate basis and consent where legally required; continuing registration does not itself subscribe you to advertising.
9. Cookies and local storage
Websites and applications use local storage for sign-in, language, preferences and caching. This can include cookies, localStorage, IndexedDB and an application’s local database. Some information is stored on your device to improve performance. Web storage and optional analytics are explained in Cookies and Analytics.
Clearing browser storage or uninstalling an application does not automatically delete the server-side account. Signing out is particularly important on a shared device.
10. Processing outside Georgia
International suppliers’ infrastructure can involve storage and other processing outside Georgia, including countries in Europe and the United States. The region of one server function does not establish the location of every supplier’s data.
Relevant transfers require a legal basis and applicable safeguards, such as a recognised adequate level of protection or another legally available mechanism. Where a selected mechanism requires the competent authority’s permit, that permit is required before transfer. This Policy does not replace a permit or constitute blanket consent to transfers to any country.
You may request information about recipients, applicable countries and safeguards relating to your data using the contacts in section 1. Where separate transfer consent is used, material information and risks are explained before it is obtained.
11. Retention
Data must not be kept longer than necessary for a specific purpose or obligation. The following criteria apply:
| Category | Period or end-of-retention criterion |
|---|---|
| Account and profile | While necessary to provide the account and functions used; on an account-deletion request, account-only personal information is erased or anonymised, subject to specific lawful exceptions |
| Pet records, care and history | Not deleted automatically with the account. Pet information, vaccinations, treatments, events, weight, bookings, QR check-ins, clinical records, diagnoses, prescriptions, laboratory results and clinic documents are assessed separately according to the responsible party, function and retention ground |
| Bookings, conversations, documents and history | While needed for the relevant interaction, requested history or justified obligation; deletion is assessed separately for platform and clinical records |
| Drafts, codes and temporary sessions | While needed to complete the selected process, verification or abuse prevention. Code expiry does not prove that every related technical record has been erased |
| Requests and complaints | Until resolved; further retention is permitted only for a specific duty, review or dispute and in the necessary scope |
| Security logs | For a limited period needed to detect and investigate abuse; for an identified incident, until the associated investigation and lawful evidence retention end |
| Analytics information | Within the analytics service’s settings and relevant purpose; cookie expiry does not mean erasure of all previously collected events |
| Clinic documents | For periods justified by the clinic’s purposes and applicable duties. Merely being a clinic does not justify indefinite retention of any information |
| Backup and service copies | Under the relevant system’s limited cycle with restricted use; deletion requirements are taken into account on restoration. Copies are not used to bypass deletion requests |
On request, we provide the applicable period or criterion, including the basis for an exception to deletion. When no lawful ground remains, data must be erased or irreversibly anonymised. Replacing a name with an internal ID is not sufficient anonymisation if a person can be identified through remaining links.
12. Your rights and deletion
Where provided by law, you may obtain processing information, access and a copy; rectify or complete information; request termination of processing, erasure or restriction; withdraw consent; receive data in a portable format; and challenge significant decisions based solely on automated processing. Withdrawal does not invalidate earlier lawful processing or remove independent lawful grounds.
Write to support@petspot.love. For deletion, also use Account and Data Deletion. Installing the application is not required to send a web-based request. We may request proportionate proof that the account belongs to you, but we do not ask you to give a staff member your password or one-time sign-in code.
Deadlines depend on the right exercised. Under Georgian law, information and access are generally provided within 10 working days; an extension is used only for requests and circumstances for which the law permits it. A termination-of-processing or erasure request is handled within the statutory period, normally within 10 working days: data is erased/processing stopped or a reasoned response and appeal information are provided. Shorter mandatory deadlines remain applicable.
Deletion is not merely signing out or uninstalling. Where a lawful exception applies, we explain the retained categories, purpose and applicable period or criterion. Records for which a clinic is responsible are not automatically excluded from your rights; we help direct the request to the responsible party.
You may complain to the State Audit Office of Georgia (სახელმწიფო აუდიტის სამსახური), which supervises personal data protection, or to a competent court. Authority information: sao.ge. Applicable rights to contact authorities in other countries are not restricted.
13. Security
Relevant processes use secure network connections, authentication, access controls and server-side checks. Access must correspond to role and necessity. Application-integrity checks and rate limits help prevent abuse.
No system provides absolute security. We do not claim that every file is accessible only to its owner, that chats are end-to-end encrypted, or that independent certification covers all of PetSpot. Report suspected issues to support without publishing personal information or secrets. Incident notification is carried out where and as required by law.
14. Minors
Independent account creation is intended for people aged 16 or over. For users aged 16–17, legal-representative consent and capacity requirements continue to apply where relevant. This is a service age condition, not a statement that full contractual capacity begins at 16.
Do not create an under-16 child’s account to bypass this condition. When we identify a child’s data, we assess the processing grounds, restrict inappropriate processing and erase data where necessary. A clinic’s processing of information about an owner’s representative is also subject to its own duties.
15. Updates
For material changes, we publish a new version and provide the information required by law. A new version does not authorise any new purpose for previously collected data. New consent, where required, is obtained separately. The publication date and version appear on the page.
The Russian, English and Georgian versions are intended to have the same meaning. Translation differences do not restrict mandatory user rights; please report them to support.