Privacy Policy — Petadd
Version: 2026-09-16 · Last updated: 2026-09-16
1. Who we are
The controller of the personal data described here is [OPERATOR LEGAL NAME], [REGISTERED ADDRESS], [COUNTRY OF REGISTRATION]. Contact: privacy@pet.brave-robots.com. We have not appointed a data protection officer; privacy requests go to that address. [EU/UK REPRESENTATIVE, IF REQUIRED]
2. Who this policy covers
- Members — people with a Petadd account, and colleagues they invite.
- Business contacts — people whose business contact details appear in information we compile about shops, suppliers and brands, including from public sources, before anyone registers.
- Visitors — anyone browsing the public parts of the site.
Petadd is a business-to-business service. Most of what we hold is business information; this policy covers the parts of it that identify a person.
3. Data we collect from you
| Category | What it includes | Why |
|---|---|---|
| Account | Email, name, language, role, password stored as an argon2id hash | Identity and authentication |
| Sessions and devices | Session records with IP address, browser user agent, timestamps | Keeping you signed in, the device list, abuse prevention |
| Business profile | Shop or supplier name, addresses, tax or registration number, contacts, members | Running the account, verification, showing you to trading partners |
| Verification documents | Files you upload for Tier 2 review (up to 10 MB each) | Checking the business is real and is yours |
| Catalogue and brand content | Products, photos, video, brand pages, claims you submit | Publishing what you chose to publish |
| Orders | Carts, orders, items, amounts, currency, delivery and shipping details | Placing and fulfilling wholesale orders |
| Messages | Conversations, messages, attachments, read state, reports raised on them | Trade communication and handling reports |
| Reviews and favourites | Review text and rating, saved brands, products and shops | Publishing reviews, personalising your lists |
| Notifications | Browser push subscription (endpoint and keys), email preferences | Sending the notifications you switched on |
| Audit trail | Record of sensitive actions on accounts, shops, suppliers and brands | Security, dispute resolution, accountability |
| Server logs | IP address, user agent, request path, status code, timing | Operating and securing the service |
| Correspondence | Emails you send us and our replies | Support and record-keeping |
4. Data we collect from other sources
Petadd compiles a directory of shops, suppliers and brands so it is useful before every business has joined. Where that information is not given to us by you, it comes from:
- Public business listings — including map and business-directory data collected through a third-party collection service. Typical fields: business name, address, phone, website, opening hours, public rating.
- Company and brand websites — descriptions, product catalogues, logos, country of origin.
- Public social profiles— a brand's public Instagram profile: handle, avatar, follower count, public posts, used to illustrate a brand page.
- Business contact details published by the business itself, used to invite suppliers to join.
This is business information, but it can identify a person — a sole trader, or a named contact. Our lawful basis is legitimate interest in building a trade directory and reaching businesses that would want to be on it. You may object at any time (section 9), ask for correction, or ask us to remove the listing entirely: privacy@pet.brave-robots.com. Every invitation email carries an unsubscribe link, and unsubscribing stops further outreach; we keep a minimal suppression record so it stays stopped.
5. Why we process it, and on what basis
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Providing the account and the marketplace | Performance of a contract |
| Verification of businesses (Tier 2) | Contract, and legitimate interest in a trustworthy marketplace |
| Security, anti-bot checks, rate limiting, audit trail | Legitimate interest in protecting the service and its members |
| Moderation of content, reviews and reported messages | Legitimate interest, and legal obligation where applicable |
| Compiling the shop, supplier and brand directory from public sources | Legitimate interest in a complete trade directory |
| Inviting businesses to join, by business email | Legitimate interest in B2B outreach, with opt-out in every message |
| Service email and push notifications | Contract (essential messages); consent (push, marketing) |
| Keeping accounting and legal records | Legal obligation |
6. Automated tools and AI
We use AI assistance to draft parts of catalogue and brand information — for example an estimated assortment breakdown or a profile summary for a brand page. What is sent to the AI provider is public business information about the brand (name, website, public description), not your account data, messages, orders or verification documents. A person reviews the output before it is published, and these tools make no decision about any individual. There is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR.
7. Who else processes your data
| Recipient | Role | Data involved | Where |
|---|---|---|---|
| Hetzner | Hosting and backups | Everything stored by the service | Germany / Finland (EU) |
| Resend | Transactional and outreach email | Email address, name, message content | EU / US |
| Cloudflare (Turnstile) | Anti-bot check on sign-up and sensitive forms | IP address, browser signals, challenge token | Global (EU entry points) |
| Apify | Collecting public business and brand data | Public listings and public social profiles; no member account data | EU / US |
| Anthropic | AI drafting of brand and catalogue information | Public brand information only (section 6) | US |
| Browser push services (Google, Mozilla, Apple) | Delivering push notifications you enabled | Push endpoint and encrypted payload | Global |
| Other members | Trading partners | Business profile, order and message content you send them | Wherever that member is |
We may also disclose data to professional advisers, or to authorities where the law requires it, and to a successor in the event of a merger or sale of the business. We do not sell personal data, and we do not use it for third-party advertising.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and business profile | While the account exists; erased or anonymised after deletion |
| Sessions | Refresh sessions expire after 30 days of the last use, and 90 days absolute regardless of activity |
| Verification documents | 24 months after the verification decision |
| Orders and invoicing data | As required by accounting and tax law in the operator's jurisdiction: [RETENTION PERIOD] |
| Messages, reviews, moderation records | While the account exists; retained in anonymised form afterwards where the other side needs the history |
| Audit trail | 24 months |
| Server logs | 30 days |
| Outreach suppression list | Kept indefinitely, minimal fields, so an unsubscribe is not undone |
9. Your rights
Under the GDPR (and equivalent local law) you can ask for: access to your data; correction; erasure; restriction of processing; portability; and you can object to processing based on legitimate interest, including our directory listings and outreach. You may also withdraw consent for push notifications and marketing at any time.
- Access and portability — download a machine-readable copy under Settings → Account → Your data, or ask us.
- Correction — edit your profile in the cabinet, or write to us for anything you cannot change yourself.
- Erasure — close your account under Settings → Account → Danger zone. We erase your personal details and revoke your sessions; order, review and audit history is retained in anonymised form so the other side keeps a coherent record. For suppliers, archiving de-identifies member accounts and cannot be undone.
- Objection and restriction — write to privacy@pet.brave-robots.com.
- Complaint — you may complain to your local supervisory authority; ours is [SUPERVISORY AUTHORITY].
We answer requests within one month and may ask you to confirm your identity first.
10. International transfers
Data is stored in the EU. Some processors listed in section 7 operate in the United States; those transfers rely on the European Commission's Standard Contractual Clauses, or an adequacy decision where one applies. Ask us for details of the safeguards for a specific processor.
11. Cookies and browser storage
We set only what is strictly necessary to run the service — no advertising or third-party analytics cookies. The full list, including the refresh-session cookie and the in-memory access token, is in the Cookie Policy.
12. Security
- Passwords are hashed with argon2id; we never store them in readable form.
- HTTPS everywhere, with strict transport security and defence-in-depth response headers.
- Access tokens are short-lived (one hour); refresh sessions can be reviewed and revoked from the device list.
- An anti-bot check protects sign-up and other sensitive forms.
- Sensitive actions are written to an audit trail.
- Encrypted backups are taken regularly and kept on separate infrastructure.
- Verification documents are stored outside the public web root and served only to reviewers.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we notify the supervisory authority and, where required, you, without undue delay.
13. Children
Petadd is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 18; accounts found to belong to a minor are removed.
14. Changes
We may update this policy. The version date at the top changes, and material changes are announced by email to account holders at least 14 days before they take effect.
15. Contact
Privacy questions and rights requests: privacy@pet.brave-robots.com. Other legal matters: legal@pet.brave-robots.com.