01
Who is the data fiduciary
For the purpose of this policy, PETSEVA PRIVATE LIMITED is the "Data Fiduciary" (DPDPA) and you, our customer, are the "Data Principal".
- Legal name: PETSEVA PRIVATE LIMITED
- CIN: U96092KA2026PTC213885
- Registered office: Bannerghatta Main Road, Kalena Agrahara, Bengaluru, Karnataka 560076
02
Grievance Officer
Under the DPDPA we are required to name a single contact for privacy-related queries and grievances.
- Name: Shashwat
- Designation: Director, PETSEVA PRIVATE LIMITED
- Email: shashwat@furdial.com
We aim to acknowledge grievances within 3 business days and resolve them within 30 days.
03
What personal data we collect
We collect only what we need to deliver and improve the service:
- Identity & contact: your name, mobile number, email (if you share one)
- Service address: the address(es) where you want the service, and optionally your GPS pin so the groomer can navigate to your doorstep
- Pet details: name, species, breed, age, weight, gender, vaccination status, and any notes you choose to share
- Booking history: services booked, dates, prices, cancellations, reviews
- Payment metadata: we do not store your full UPI ID, card details, or bank details. Our records only capture the booking reference, amount paid, and whether the payment was received
- Device & usage: minimum technical data needed to run the website/app (browser type, OS, IP address used briefly for anti-fraud, and rare diagnostic logs)
- Photos: our 4-phase SOP includes before/after photos of your pet and groomer arrival photos — these are stored against your booking record
- Sign-up attempts: if you enter your phone number to receive a one-time password but do not complete sign-up, we keep the phone number, the page you tried from, and the time of the attempt for up to 90 days. We use this only to follow up if you ran into trouble (for example, the OTP did not arrive) and to improve the sign-up flow. If you complete sign-up, this record is linked to your account; if you do not, it is auto-deleted after the 90-day window.
We do not knowingly collect data of children under 18. The pet parent must be an adult.
04
Why we use your data
We use the data above only for the following purposes:
- To create your account and authenticate you (OTP login)
- To match you with a nearby groomer (the "dispatch" process)
- To enable the groomer to navigate to your doorstep
- To deliver the service in accordance with our 4-phase SOP
- To process payment, generate receipts, and reconcile our books
- To send service-related notifications (booking status, arrival, completion, receipts)
- To respond to your support requests, complaints, or grievances
- To prevent fraud, abuse, and security incidents
- To comply with applicable laws (tax records, regulatory requests)
- To analyse aggregate, de-identified usage so we can improve the service
We do not sell your personal data. We do not use your data for behavioural advertising or re-targeting.
05
Lawful basis & consent
We process your data on one or more of the following bases under DPDPA:
- Consent: you give consent at the point of booking (necessary for service delivery)
- Legitimate use: for fulfilling a service you have requested, complying with law, and preventing fraud
You may withdraw consent at any time by contacting our Grievance Officer; withdrawal does not affect lawfulness of prior processing and may limit our ability to provide the service.
06
Who we share your data with
We share only the minimum necessary with third parties acting on our instructions:
- Your assigned groomer: name, contact number, service address, GPS pin (if shared), pet details, and any booking notes — so they can find you and serve your pet
- Communication providers: MSG91 (SMS / OTP) and, in future, Firebase Cloud Messaging (push notifications)
- Infrastructure providers: MongoDB (database), Cloudinary (image storage for SOP photos), Amazon Web Services (servers, email)
- Payment processing: currently direct UPI to our bank (Kotak Mahindra Bank); in future, Razorpay if you choose a pre-paid online option
- Government and law enforcement: only when required by valid legal process
- Business transfers: in the event of a merger or acquisition, your data may transfer to the acquirer; you will be notified
We do not transfer your data to third parties for their independent marketing use.
07
Cross-border data transfers
Some of our infrastructure providers (AWS, Firebase, Cloudinary) may store or process data in servers located outside India. We use providers with industry-standard security practices and contractual safeguards (encryption in transit and at rest, access controls).
08
How long we keep your data
- Account data (name, phone, email, addresses): for as long as your account is active. You may request deletion at any time.
- Booking history & SOP photos: retained for 7 years as required by Indian tax and corporate record- keeping law, then deleted or anonymised.
- Support messages: retained for 2 years after the issue is resolved, for quality and dispute purposes.
- Technical logs: retained for up to 90 days unless needed longer for a security investigation.
09
Your rights
Under the DPDPA, you have the following rights:
- Right to access: ask for a summary of personal data we hold about you
- Right to correction: ask us to correct inaccurate or incomplete data
- Right to erasure: ask us to delete your data (subject to legal retention requirements above)
- Right to withdraw consent: at any time, without affecting prior lawful processing
- Right to grievance redressal: contact our Grievance Officer (§02); if unresolved within 30 days, you may escalate to the Data Protection Board of India
- Right to nominate: you may nominate another person to exercise your rights in case of your death or incapacity
To exercise any right, email us at shashwat@furdial.com from the email or phone number registered with your account. We respond within 30 days.
10
Cookies & local storage
We use only essential cookies and browser local storage — for session management (keeping you logged in) and for remembering UI preferences. We do not use third-party advertising or analytics trackers in Phase 1.
If we add analytics later (e.g. for understanding which pages help customers convert), we will update this policy and offer a clear opt-in.
11
Security
We protect your data using industry-standard measures:
- TLS/HTTPS encryption for all data in transit
- Encrypted database connections; passwords/OTP codes hashed at rest
- Role-based access — only authorised personnel and your assigned groomer can see your details
- Regular review of access logs and credentials
No system is perfectly secure. If we ever experience a data breach that affects your personal data, we will notify you and the Data Protection Board of India as required by law.
12
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the latest version. Material changes will be notified via email or in-app message.
