Privacy Policy

Last updated: July 2026

How GroomCard handles personal information: your salon account, and the client and dog records you keep in the app.

1. Who we are

GroomCard is operated by Matej Havlik, a sole trader registered in the Czech Republic, business ID (ICO) 14371758, Heroutova 831, Ceska Lipa, Czech Republic. Below, we and us mean the operator.

For anything to do with privacy, email support@groomcard.com. A real person reads it and answers.

The operator is based in the European Union and most GroomCard customers are in the United States, so this policy covers both the GDPR and California privacy law.

2. Two different kinds of data

Your account data is the information about you and your salon: your name, email, salon details and billing. We decide what happens with it, which makes us the controller of that data.

Your salon's records are the information you put into GroomCard about your own clients and their dogs: names, phone numbers, notes, photos, appointments and receipts. You decide what goes in and why, which makes you the controller and us your processor. Section 5 explains what that means in practice.

The difference matters. If one of your clients asks what you hold about them, that is your record to answer for, and we help you do it.

3. What we collect about you

Account details: your name, email address, your password stored only as a salted hash that we cannot read, and the salon information you enter such as name, address and business details.

Subscription and billing: your plan, billing period, subscription status, and payment records that come back from Stripe. We never receive or store full card numbers.

Technical data we need to run and secure the service: sign-in events, IP address, browser and device information, and server logs.

Anything you send us by email when you ask for help.

If you accept analytics cookies on our public pages, measurement data collected through the Meta pixel. See section 9.

4. Why we use it and on what legal basis

To provide the service and perform our contract with you, under GDPR Article 6(1)(b): running your account, the app itself, and service emails such as booking notifications, appointment reminders, receipts and account notices.

To meet legal obligations, under Article 6(1)(c): accounting and tax records.

For our legitimate interests, under Article 6(1)(f): keeping the service secure, preventing abuse, diagnosing faults and improving the product.

With your consent, under Article 6(1)(a): analytics and advertising cookies, and any marketing email. You can withdraw consent at any time and it does not affect anything we did before you withdrew it.

We do not sell personal information. Section 12 explains how the one piece of advertising technology on our site is handled and how to switch it off.

5. Your client records: we act as your processor

When you add a client, a dog, a note, a photo, an appointment or a receipt, you are the controller of that personal information and we are your processor. We process it only to run GroomCard for you and only on your instructions.

We access salon records only when you ask us for support, when it is necessary to diagnose or fix a fault, or when the law requires it. Everything we see stays confidential.

Each salon's data is separated at the database level, so one salon can never reach another salon's records.

We use the sub-processors listed in section 6 and no others. If we plan to add one, we tell you first so you can object.

You are responsible for telling your own clients how you use their information and for having a lawful basis to keep it. The app gives you the tools to answer their requests: you can view, correct, export and delete any record.

This section, together with the Terms of Service, is our data processing agreement with you. If your business needs a separate signed DPA, write to support@groomcard.com.

6. Sub-processors and other recipients

Supabase: the database, file storage for photos, and sign-in. This is where your salon's records live.

Stripe: subscription billing and card processing.

Resend: sending transactional email such as booking notifications, appointment reminders and account messages.

Vercel: hosting and delivery of the application.

Meta Platforms: the advertising pixel on our public marketing pages, and only if you accept it in the cookie banner.

Beyond these, we share personal data only with our accountant and tax advisers, and with public authorities where the law obliges us to. Every provider may use the data only to deliver its service to us, never for its own purposes.

7. International transfers

We are in the European Union, most of our customers are in the United States, and our infrastructure providers are mostly US companies, so personal data does move across the Atlantic.

Those transfers are covered by appropriate safeguards under the GDPR, primarily the European Commission Standard Contractual Clauses, and, where the provider is certified, the EU-US Data Privacy Framework.

If you want to know exactly where a specific provider stores data, ask us at support@groomcard.com and we will tell you.

8. How long we keep it

Account data and salon records: for as long as your account is open. When you close the account, we delete or anonymize the data within a reasonable period.

Records you delete inside the app go to Trash first, where you can restore them for 30 days. After that they are removed.

Accounting and tax documents: for as long as Czech law requires us to keep them, which can be several years after the last payment.

Technical and security logs: for a limited period, and then they are deleted.

9. Cookies and local storage

Essential cookies keep you signed in and keep the app working. That includes the session cookies issued by Supabase and the gc_remember cookie that records whether you asked to stay signed in on that device. These cannot be switched off, because without them you cannot log in.

Analytics and advertising: the Meta pixel loads on our public marketing pages only after you accept it in the cookie banner. If you decline, it never loads and the site works exactly the same. Your choice is stored in your own browser, so clearing your site data brings the banner back.

We do not use cookies to track you inside the app itself.

10. Security

Everything travels over encrypted connections. Passwords are stored as hashes, never in readable form. Database access rules make sure a salon can only ever read its own rows. Administrative access is limited to the operator and used only when necessary.

Our infrastructure providers keep backups of the database, so an accidental deletion is recoverable.

No system is perfectly secure. If a breach affects your personal data, we notify you and the relevant supervisory authority as the law requires, without undue delay.

11. Your GDPR rights

You have the right to access your data, to have it corrected, to have it erased, to restrict how we process it, to receive it in a portable format, and to object to processing based on our legitimate interests. Where processing relies on consent, you can withdraw it at any time.

To use any of these rights, email support@groomcard.com. We answer within one month, free of charge. We may ask you to confirm your identity by writing from the email address on the account.

If your data sits inside a salon's records rather than in an account of your own, the salon is the controller. Send your request to the salon, or send it to us and we will pass it on.

You also have the right to complain to a data protection supervisory authority. Ours is the Czech Office for Personal Data Protection (www.uoou.cz), and you may also complain to the authority where you live.

12. California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and how we use it, the right to delete it, the right to correct it, the right to opt out of the sale or sharing of it, the right to limit the use of sensitive personal information, and the right not to be discriminated against for using any of these rights.

We do not sell personal information. We have never sold it and we have no plans to. The only advertising technology on our site is the Meta pixel on the public marketing pages, which some California rules would treat as sharing for cross-context behavioral advertising. It loads only if you accept it in the cookie banner, so declining the banner, or clearing your site data and declining again, is how you opt out.

In the last 12 months we have collected these categories: identifiers such as your name, email address and IP address; commercial information such as your plan and payment history; internet activity such as log and usage data; and the content you upload into your salon's records. We collect it from you, from your use of the service, and from Stripe. We use it for the purposes in section 4 and we disclose it only to the service providers in section 6, for business purposes.

We do not collect sensitive personal information for the purpose of inferring characteristics about you.

To make a request, email support@groomcard.com. We verify it against the email address on the account, and an authorized agent may submit it for you with written permission. If the information is held inside a salon's records, that salon is the business responsible and we act as its service provider, so we pass the request on.

13. Children

GroomCard is business software and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email support@groomcard.com and we will delete it.

14. Changes to this policy

We update this policy as the service and the law change. If a change is material, we tell you by email or in the app before it takes effect. The date at the top of this page shows when it was last updated.

15. Contact

Privacy questions, requests and complaints: support@groomcard.com.

Postal address: Matej Havlik, Heroutova 831, Ceska Lipa, Czech Republic.