This Privacy Policy explains how Pet Passport (“we”, “us”, or “our”) collects, uses, stores, and protects information when you use our mobile application and related services.
Information We Collect
We collect only what is needed to operate the service:
- Account data — email address and authentication identifiers used for sign-in and account recovery. If you provide a display name, we store it with your profile.
- Pet profiles — name, species, breed, microchip ID, and other details you enter.
- Travel itineraries — origin, destination, airline, and travel dates you create for checklists.
- Local concierge queries — the destination name you choose when you open Local Pet Concierge (a trip destination, or the label “Nearby” from Home). We do not access GPS, background location, or precise device location for this feature.
- Vault documents — photos and files you upload, such as vaccination records, health certificates, titer tests, import permits, and airline forms. These may contain personal information printed on the document (for example owner address or veterinarian details).
- Device / operational metadata — limited technical signals needed to run the app securely (for example session tokens stored on-device, and diagnostic information from Apple or Google when you report a crash).
- Purchase history and payment metadata — whether you bought a Single Export ($6.99 one-time), Weekly Trip Pass ($6.99/week), Monthly Pro ($15.99/mo), or Annual VIP ($119.99/year), entitlement status, product identifiers, transaction identifiers, and website promo-redemption records. Payment data is handled by Apple (App Store / StoreKit), Google (Play Billing), and Razorpay for website checkout in India. RevenueCat receives store tokens so we can restore entitlements. Pet Passport does not store raw credit card numbers, bank account numbers, or full payment credentials.
How We Use Information
We use your information to authenticate your account, store pet profiles, generate travel checklists, fetch informational local-place suggestions when you open concierge, maintain your document vault, process in-app purchases, restore subscriptions, and enable PDF export or sharing that you initiate. We do not sell personal data and we do not use pet documents, concierge queries, or purchase history for advertising.
Legal bases (GDPR): performance of a contract (providing the vault, checklist, and local concierge features you request), and legitimate interests for security, rate limiting, and service reliability. Where required, we rely on your consent for optional permissions such as photo library or camera access.
Third-Party Processors
Account data and vault files are hosted on Supabase (Auth, Postgres, and private Storage) under access controls and row-level security. Supabase acts as a data processor; Pet Passport is the data controller.
Paid subscriptions and one-time export credits are processed by Apple (App Store / StoreKit; Apple’s standard EULA applies) on iOS, Google (Google Play Billing) on Android, Razorpay for UPI and card checkout on this website, and RevenueCat, which receives store purchase tokens, product identifiers, transaction metadata, and an app user ID so we can unlock Weekly, Monthly, or Annual access, grant export credits, and restore purchases. Apple, Google, and Razorpay are the merchants of record for their checkouts. Pet Passport does not store raw credit card numbers. Cancel a store subscription in iOS Settings → [your name] → Subscriptions or Google Play → Payments & subscriptions → Subscriptions.
When you open Local Pet Concierge, we send the destination name (not your GPS coordinates) to Google Places / Google Maps Platform to look up nearby veterinary clinics, pet stores, and parks, and to Google Gemini to draft a short informational summary from those listings. Gemini may also mention well-known pet-sitting apps from its training knowledge; that is not a booking, marketplace, or endorsement. A request counter keyed to your account ID is stored temporarily in Upstash Redis (about one hour) only to enforce a rate limit. We do not keep a permanent history of concierge searches on your profile. Business names, addresses, ratings, and map coordinates returned by Google are displayed in the app and are not stored as vault documents.
Google Play Data Safety: we collect purchase history / financial information solely for app functionality (unlocking paid plans, export credits, and restore). It is not used for advertising, is not sold, and is not shared for advertising purposes. Apple Privacy Nutrition: Purchase History is collected, linked to your identity, not used for tracking, and used for App Functionality.
We may also disclose information when required by law or to protect the security of the service.
Retention
We retain account, pet, trip, and document data until you delete the specific item or delete your account. Concierge rate-limit counters in Upstash Redis expire automatically (about one hour). We do not keep a searchable history of concierge queries on your profile. After a verified deletion request, we remove identifiable account data from production systems within 30 days, except where retention is required by law. Purchase records retained by Apple, Google, or RevenueCat for tax, fraud, or store policy reasons are controlled by those processors and are not fully recalled by deleting the Pet Passport account. Google Places and Gemini may log queries under their own terms. Files you previously exported or shared outside Pet Passport cannot be recalled by us.
Your Rights (GDPR / CCPA)
- Access & portability — request a copy of personal data we hold about you.
- Correction — update inaccurate profile or pet information in the app.
- Erasure — delete individual vault documents, or delete your entire account in-app via Settings → Delete Account & Data, or request deletion at /data-deletion.
- Opt-out of sale/sharing — we do not sell personal information.
International transfers
Our processors (including Supabase, Google, RevenueCat, Apple, and Upstash) may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as the processors’ published transfer mechanisms.
Security
Vault uploads are stored in private storage with path isolation by user ID. Database access is enforced with row-level security so users can only access their own records (and pets explicitly shared with them as co-pilots).
Contact
Privacy questions and rights requests: ntmtechnologies@gmail.com.