Privacy Policy
Last updated: 21 September 2026
This Privacy Policy explains how FurryOps (“we”, “us”), based in Bengaluru, Karnataka, India, handles personal data when you use our website, web app and installable app (the “Service”). It is written to meet the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 and its rules, each as applicable from time to time. It should be read with our Terms & Conditions.
1. Who we are and what this covers
FurryOps is software that pet businesses use to run billing, grooming, boarding, inventory and payroll. That means two different kinds of personal data pass through it, and we play a different role for each:
- Account and billing data. Information about the people who sign up and use the Service (store owners, managers and staff) and about their subscriptions. For this data FurryOps decides why and how it is used and is the Data Fiduciary.
- Store Data. Information a Store puts into the Service about its own customers, their pets, its bookings and sales, and its employees. For this data the Store is the Data Fiduciary and FurryOps is a processor that handles it only to provide the Service on the Store's instructions.
If you are a pet owner whose details a Store holds, please see section 10 and section 9 for how to reach us or the Store.
2. What we collect
Account and profile
- Name and email address, and your password, which we store only in hashed form.
- If you sign in with Google: your name, email address and profile picture, as shared by Google.
- Your role and permissions, the Stores you belong to, and invitations you receive or send.
Store profile
- Business name and legal name, GSTIN and GST registration status, address, state and PIN code, phone, email, logo, opening hours, and your public booking link.
Store Data entered by a Store
- Customers: name, phone number, optional email, and, for visitors, city and state of origin.
- Pets: name, type, breed, age, gender, vaccination status and notes.
- Sales and services: bills and invoices, bookings and appointments, packages, payment mode, products, inventory, vendors, spends, and any invoice or attachment files uploaded.
- Employees: name, phone, email, designation, joining and exit dates, PAN, UAN and ESIC numbers (as reference text), bank name and the last four digits of an account number, salary structure, attendance, advances, commission, pay runs and payslips.
- An activity log recording who did what in a Store and when.
Subscription and payment records
- Plan, amount, payment method, reference number (such as a UPI transaction reference), invoice number and period paid. We do not collect or store card numbers.
Public booking page
- When someone books through a Store's public link, the name, phone, email, pet details and slot they enter go to that Store and are stored in the Store's records.
Technical data
- IP address, browser and device type, pages visited and basic diagnostic logs, gathered through cookies and similar technologies (section 6) and our hosting provider.
- Messages you send us for support.
Please do not enter Aadhaar numbers, full bank account or card numbers, passwords, or health records of people into the Service. It is not designed for them.
3. Why we use it
- To create and secure accounts, verify email addresses, and authenticate you.
- To provide the Service: billing, bookings, inventory, GST reports, payroll and payslips, and reading vendor invoices with AI.
- To send messages the Service is built to send: verification and password-reset emails, invitations, subscription reminders, and, on a Store's behalf, WhatsApp and email updates to its customers such as invoices, booking confirmations and reminders.
- To bill for subscriptions, issue invoices and keep financial records.
- To give support, prevent fraud and abuse, and keep the Service secure.
- To understand how the marketing pages perform and to improve the Service, using aggregated data.
- To meet legal obligations and respond to lawful requests.
We rely on your consent, which you give by using the Service and, where asked, by ticking or submitting a form, and on the other lawful uses the Digital Personal Data Protection Act, 2023 allows, such as providing a service you asked for and complying with law. You can withdraw consent at any time (section 9); some features will then stop working.
We do not sell personal data.
4. Who we share it with
We share personal data only with service providers that help us run the Service, and only as needed for the purpose in the table.
| Provider | Purpose | What it may receive |
|---|---|---|
| Vercel | Hosting, file storage (logos, invoices, attachments), page-view and performance analytics | All data the Service handles; technical and usage data |
| Managed database provider | Storing Store Data and account data | All data the Service handles |
| Resend | Sending email | Recipient email, message content |
| Meta (WhatsApp Business Cloud API) | Sending WhatsApp messages on a Store's behalf | Recipient phone number, message content, invoice files |
| Sign-in with Google; Google Analytics on our marketing and sign-in pages | Sign-in profile; analytics identifiers and page data | |
| OpenRouter and its AI model provider (currently Google Gemini) | Reading vendor invoices you upload to create products | The invoice file you upload for scanning |
We may also disclose personal data:
- where required by law, a court order or a lawful request from a government authority, or to protect our rights, safety or the security of the Service; and
- to a successor if the FurryOps business is merged, sold or transferred, on terms that keep this policy's protections in place.
5. Transfers outside India
Some of our providers process data on servers outside India. By using the Service you understand that your personal data may be transferred to and processed in other countries. We take reasonable steps to ensure providers protect it, and we transfer it only in the ways the Digital Personal Data Protection Act, 2023 and its rules permit.
6. Cookies and similar technologies
| Technology | What it does | Where |
|---|---|---|
| Session cookie | Keeps you signed in. Essential; the Service cannot work without it. | The whole Service |
| Theme preference (browser storage) | Remembers your light, warm or dark setting | The app |
| Service worker cache | Lets the installed app load faster and start when the connection is poor | Your device |
| Vercel Analytics and Speed Insights | Aggregate page-view and performance measurement | The Service |
| Google Analytics 4 (cookies such as _ga) | Measures visits and how people reach and use our pages | Marketing, sign-in and public booking pages only. Never inside the signed-in dashboard. |
You can block or delete cookies in your browser settings, and you can opt out of Google Analytics with Google's browser add-on. Blocking the session cookie will stop you from signing in.
7. How long we keep it
- We keep account and Store Data for as long as your Store has access to the Service.
- When access ends, we keep Store Data for 30 days so you can export it, unless you ask us to delete it sooner. After that we delete or anonymise it. Backups are overwritten on their normal cycle.
- We keep records we must retain by law, such as invoices, payment and tax records, for as long as the law requires, and information needed to resolve a dispute or enforce our terms.
8. Security
We use reasonable security practices and procedures suited to the data we hold, including:
- encrypted connections (HTTPS) between your device and the Service;
- passwords stored only as salted hashes, never in readable form;
- role-based permissions, so staff see only what a Store's administrator allows, and separation of each Store's data from others';
- sessions that stop working when a password is changed;
- rate limiting on public endpoints; and
- an activity log of changes made in a Store.
No system is completely secure, and we cannot guarantee that data will never be accessed without authorisation. Keep your password private and use a strong one. If a breach affects you, we will inform you and the authorities as the law requires, including the Indian Computer Emergency Response Team (CERT-In).
9. Your rights
Subject to applicable law, you may ask us to:
- tell you what personal data of yours we process and how;
- correct, complete or update it;
- erase it, where we no longer need it for the purpose or to meet a legal duty;
- stop processing it, by withdrawing consent; and
- nominate another person to exercise these rights for you if you die or become unable to, and have any complaint about your data addressed.
Write to the Grievance Officer in section 13. We may need to verify your identity first, and we aim to respond within 30 days.
If your details were entered by a Store (for example as its customer or employee), the Store decides what it holds about you, so please ask the Store first. We will help the Store act on your request.
10. Stores and their own customers and staff
If you run a Store, you are the Data Fiduciary for your customers', pets' owners' and employees' data. That means you must:
- give them a clear notice of what you collect and why, and obtain their consent where the law requires it, including before you message them on WhatsApp or email;
- keep the data accurate and enter only what you need;
- respond to their requests to access, correct or erase their data; and
- tell them if your public booking page is used to collect their details, and that analytics may run on it (section 6).
We process Store Data only on your instructions, to provide the Service, and keep it confidential.
11. Children
The Service is for businesses and adults aged 18 and over. We do not knowingly collect personal data of anyone under 18. If you think a child's data has been entered, contact us and we will help remove it.
12. Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date and, for material changes, give reasonable notice by email or in the app. Continuing to use the Service after a change takes effect means you accept the updated policy.
13. Grievance Officer and governing law
For questions about this policy, to exercise your rights, or to make a complaint about how your personal data is handled, contact our Grievance Officer:
- Grievance Officer: Akash Gautam, FurryOps, Bengaluru, Karnataka, India
- Email: the support contact shown under Billing in your account settings
We aim to acknowledge every request within 24 hours and to resolve it within 15 days.
This policy is governed by the laws of India. Any dispute about it is subject to the exclusive jurisdiction of the courts at Bengaluru (Bangalore), Karnataka, India, as set out in our Terms & Conditions.