At GroomWave, we respect your privacy and are committed to protecting your personal information. This policy explains how Gecko Grid (Pty) Ltd ("we," "us," or "our") collects, uses, and secures your data.
1. Information We Collect
We collect only the information necessary to provide you with a functional pet grooming management experience:
- Account Data: Email address and name provided during sign-up.
- Business Data: Client records, pet information (names, breeds, species, dates of birth, health notes), bookings, recurring schedules, invoices, and unit/vehicle details you create within the app.
- Subscription Data: We store your subscription status, plan type (Free, Pro, or Elite), and trial expiration dates.
- Usage Data: Basic technical data (IP address, browser type) to help us troubleshoot and improve the app.
2. How We Store Your Data
- Database: We use Supabase to store your account information, client records, pet data, bookings, and invoices. Your data is encrypted at rest.
- Payment Information: We do not store your credit card or bank details. All financial transactions are processed by Paddle, our Merchant of Record. Paddle provides us with a "Customer ID" and "Subscription ID," but we never see your full financial credentials.
3. Purpose of Processing
In accordance with POPIA, we process your data for the following reasons:
- To fulfill our contract with you (providing the pet grooming management service).
- To manage your subscription and trial status.
- To send you essential service updates (e.g., password resets or billing notifications).
4. Third-Party Service Providers
We share specific data with trusted partners to keep GroomWave running:
- Supabase: For data storage and authentication.
- Paddle: For secure payment processing and tax compliance.
- Email Provider: To send account-related emails.
- Error Tracking: For error tracking and improving user experience.
5. User Rights (Your POPIA/GDPR Rights)
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to update or fix inaccurate information.
- Deletion: Request that we delete your account and all associated data (subject to legal retention requirements).
- Portability: Export your client data, bookings, and invoices at any time.
6. Security of Your Information
We take "reasonable and appropriate" technical measures to secure your data, as required by South African law. However, because GroomWave is a business management tool, you are responsible for avoiding the storage of high-risk sensitive data (like unencrypted passwords, credit card numbers, or government ID numbers) within client or pet records.
7. International Data Transfers
By using GroomWave, you acknowledge that your data may be processed on servers located outside of your country (e.g., in AWS or Supabase data centers). We ensure these providers maintain security standards equivalent to POPIA requirements.
8. Retention of Data
We keep your data as long as your account is active. If you cancel your subscription and do not log in for an extended period (e.g., 12 months), we reserve the right to delete your data to minimize the information we hold.
9. Local Storage & Tracking
GroomWave uses your browser's local storage to maintain your authentication session and remember your preferences. We do not use cookies for tracking, advertising, or analytics purposes. No third-party tracking technologies are embedded in the application. Any optional analytics tools referenced in this policy are used solely to monitor application health and improve performance.
10. Children's Privacy
GroomWave is not intended for use by individuals under the age of 18 without parental consent. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete such information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page. We encourage you to review this policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Our Information Officer
If you have questions about your privacy or wish to exercise your rights under applicable data protection laws (including POPIA and GDPR), please contact: