Privacy Policy

Last updated: 12 February 2026

1. Introduction & Scope

PetBoard ("we", "us", "our") is a two-sided marketplace that connects pet owners with pet boarding and care providers across India. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the PetBoard mobile application and associated services.

This policy applies to all users of the PetBoard platform, including pet owners, service providers, and visitors. It covers data processed digitally within India and data of Indian residents processed in connection with our services.

This policy is published in compliance with:

2. Definitions

TermMeaning
Data PrincipalYou — the individual whose personal data is being processed
Data FiduciaryPetBoard — the entity that determines the purpose and means of processing your data
Data ProcessorThird parties that process data on our behalf (e.g., Supabase, Razorpay)
Personal DataAny data about an individual who is identifiable by or in relation to such data
SPDISensitive Personal Data or Information — includes financial information, identity documents, biometric data, and passwords
ProcessingAny operation performed on personal data, including collection, storage, use, sharing, and deletion

3. Personal Data We Collect

CategoryData PointsSensitivity
IdentityFull name, email address, phone number, profile photoPersonal Data
Pet InformationPet name, species, breed, age, weight, size category, medical notes, photosPersonal Data
LocationGPS coordinates, address, city, service areaPersonal Data
KYC DocumentsPAN card, driving licence, or passport scans; selfie photoSPDI
FinancialPayment method details (processed via Razorpay), transaction historySPDI
CommunicationsIn-app chat messages between owners and providersPersonal Data
Device & TechnicalDevice type, OS version, app version, push notification tokensPersonal Data
UsageSearch history, booking history, app interaction patternsPersonal Data
We do not collect Aadhaar data. The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, Sections 29 and 37, prohibits private entities from collecting or storing Aadhaar numbers without a licence from UIDAI.

4. Purpose of Data Collection

Data CategoryPurpose
IdentityAccount creation, authentication, communication, customer support
Pet InformationMatching with suitable providers, displaying pet profiles, service customisation
LocationFinding nearby providers, displaying service areas, delivery of location-based services
KYC DocumentsIdentity verification of service providers for trust and safety. Documents are automatically deleted after verification review is complete.
FinancialProcessing payments, refunds, invoicing, tax compliance (via Razorpay)
CommunicationsFacilitating pre-booking and during-booking communication between owners and providers
Device & TechnicalDelivering push notifications, debugging, security monitoring
UsageImproving the app experience, analytics, detecting misuse

We process your data only for the purposes stated above. We will not use your data for purposes beyond what is disclosed here without obtaining fresh consent (DPDPA, Section 6).

We rely on the following legal bases for processing your data:

For KYC documents and financial data (classified as SPDI), we obtain explicit written consent as required under SPDI Rules 2011, Rule 5.

6. Children's Data

Under the DPDPA, any individual under 18 years of age is classified as a child. PetBoard does not knowingly collect data from or provide services to children under 18 without verifiable parental or guardian consent.

If we become aware that we have collected data from a child without appropriate parental consent, we will delete that data promptly. We do not engage in tracking, behavioural monitoring, or targeted advertising directed at children.

7. Data Storage & Retention

Storage Location

All data is stored on Supabase, hosted on AWS infrastructure in Mumbai, India (ap-south-1). Your data resides within Indian territory in compliance with data localisation requirements.

Retention Periods

Data TypeRetention Period
Account dataWhile your account is active, plus 90 days after deletion request
KYC documents (files)Automatically deleted immediately after verification review. Safety-net purge within 7 days for any files not cleaned up.
KYC metadata (status, timestamps)Retained for the duration of the provider relationship to maintain verification status
Booking & payment recordsMinimum 7 years (Income Tax Act, GST compliance)
Webhook payment metadataSanitised subset only (event type, payment ID, order ID, status, amount, method). Full Razorpay payloads are not stored.
Chat messagesDuration of the service relationship plus 90 days
Location dataStored for matching and booking purposes; historical location data anonymised or deleted after 1 year
Push notification tokensWhile notifications are enabled; deleted when disabled or account is deleted
Server logs180 days (CERT-In Directions 2022)
System/security logsMinimum 1 year (DPDP Rules 2025)
Inactivity rule: If your account is inactive for more than 1 year, we will send you a notification 48 hours in advance before erasing your personal data, unless retention is required by law (DPDP Rules 2025).

8. Data Sharing & Third Parties

We share data only as necessary for delivering our services. We do not sell personal data to third parties.

Third PartyData SharedPurpose
RazorpayPayment details, transaction amounts, user identityPayment processing, refunds, fraud prevention. Razorpay Privacy Policy
SupabaseAll stored data (as data processor)Database hosting, file storage, authentication infrastructure. Supabase Privacy Policy
Expo / FCM / APNsDevice tokens, notification contentDelivering push notifications
Other platform usersLimited profile info (name, business name, ratings, service area)Facilitating marketplace discovery and bookings
Government / regulatorsAs required by lawLegal compliance, law enforcement, tax authorities

All third-party data processors are contractually obligated to process data only for the stated purpose and to implement adequate security safeguards.

9. Cross-Border Transfers

Your primary data is stored in India (Supabase on AWS Mumbai). Certain third-party services (push notification infrastructure, analytics) may process limited data outside India.

Under the DPDPA, personal data may be transferred outside India unless the Central Government has restricted transfer to the destination country. Where data is transferred outside India, we ensure adequate protections are in place through contractual safeguards with the data processors.

10. Data Security

We implement reasonable security practices commensurate with the sensitivity of the data we process:

We maintain security practices aligned with IS/ISO/IEC 27001 standards and conduct periodic security reviews as required under SPDI Rules 2011, Rule 8.

11. Data Breach Notification

In the event of a personal data breach:

12. Your Rights

Under the DPDPA and SPDI Rules, you have the following rights. We will respond to all requests within 90 days:

To exercise any of these rights, contact us at privacy@petboard.in or use the in-app settings.

You may withdraw your consent at any time through:

Withdrawal of consent is as easy as giving it, in compliance with DPDPA requirements.

Consequences of withdrawal: If you withdraw consent for essential processing (e.g., account data), we may be unable to provide our services and your account may be deactivated. We will inform you of the specific consequences before processing your withdrawal.

14. KYC Document Handling

Service providers may optionally complete identity verification (KYC) to earn a "Verified" trust badge. Our KYC process is designed with privacy by default:

15. Location Data

16. In-App Chat & Messaging

17. Push Notifications

18. Cookies & Tracking

The PetBoard mobile application does not use cookies. Our admin dashboard (web-based) uses browser session storage for authentication persistence only — no analytics or marketing cookies are used.

We do not use third-party analytics or advertising trackers in the mobile app.

19. Grievance Redressal

In accordance with the DPDPA and SPDI Rules 2011, Rule 5(9), we have appointed a Grievance Officer to address your concerns:

Grievance Officer

Name: Sahil Verman

Email: grievance@petboard.in

Phone: +91 9740551629

Address: G-128 Brigade Lakefront, Seetharampalya Hoodi Road, EPIP Zone, Bangalore, Karnataka 560048

We will acknowledge your grievance within 48 hours and resolve it within 30 days of receipt.

If you are not satisfied with our resolution, you may file a complaint with the Data Protection Board of India established under the DPDPA 2023.

20. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

21. Contact Us

PetBoard

Email: privacy@petboard.in

Website: petboard.in

Registered Address: G-128 Brigade Lakefront, Seetharampalya Hoodi Road, EPIP Zone, Bangalore, Karnataka 560048

© 2026 PetBoard. All rights reserved.
This policy is available in English. Translations into Hindi and other scheduled languages will be made available as required under DPDP Rules 2025.