GroomerMap
Privacy Policy
Effective from 21 July 2026
This policy describes what personal data the GroomerMap platform (the “Platform” or “GroomerMap”) processes, for what purpose, on what legal basis, to whom it is disclosed, and what rights you have as a data subject. This policy is issued in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”) and Czech Act No. 110/2019 Coll., on the Processing of Personal Data.
1. Who is the controller of your personal data
The data controller is:
IČO: 75412853
Place of business: Ke Křížku 242, Kunice ‑ Vidovice
E-mail: kristyna@groomermap.com
(the “Provider” or “we”). You can contact us at the email address above for anything related to the processing of your personal data. Given the scale of its activities, the Provider has not appointed a separate Data Protection Officer (DPO).
2. What personal data we process
The scope depends on how you use the Platform.
2.1 Visitors (without registration)
- Technical connection data (IP address) and the approximate location derived from it (country, city, coordinates) — used to sort “nearest to you” results and to set the map's default view. Derived automatically from the request on the server (Vercel); not stored in a cookie or otherwise persisted on your device.
- Data entered in the contact form (name, email, message), if you contact us.
2.2 Registered users and professional profiles
- Registration data: email and password (the password is stored only in an irreversibly hashed form — we never see it in readable form).
- Profile data: name, salon/business name, photos, description, role (groomer, handler, trainer, breeder, judge, educator, brand…), contact details (phone, website, social media), business address/location, languages, breeds, certifications, competition results.
- Communication: the content of messages sent through the platform's built-in messaging between users.
- Payment and billing data to the extent necessary to issue an invoice and process a payment — the Provider never sees or stores actual card numbers; these are processed exclusively by the Stripe payment gateway (see section 5).
- For recipients of affiliate/referral rewards: data needed to pay out commission via Stripe Connect (linked payment account, identification data required by Stripe for onboarding).
2.3 Cookies and similar technologies
The Platform currently does not use any third-party analytics or marketing cookies (e.g. Google Analytics, Facebook Pixel). We use only technically necessary means for operation — in particular the login (session) cookie from Supabase Auth, without which staying logged in would not be possible, and local storage (localStorage) of small UI preferences in your browser (e.g. that you've already seen the map's hint). These do not require consent under Section 89a of Czech Act No. 127/2005 Coll., on Electronic Communications, because they are strictly necessary to provide the service you requested. If we deploy analytics or marketing cookies in the future, we will update this policy and obtain your consent in advance via a cookie banner.
3. Purposes and legal basis for processing
- Performance of a contract (Art. 6(1)(b) GDPR) — creating and managing your user account and profile, displaying your profile in the directory and on the map, facilitating contact between users, processing subscription payments, selling seminar tickets, paying out affiliate rewards.
- Legitimate interest of the Provider (Art. 6(1)(f) GDPR) — securing the platform, preventing abuse and fraud, personalising displayed content based on approximate location, improving the service, enforcing compliance with the terms of use.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR) — keeping accounting and tax records under Czech Act No. 563/1991 Coll., on Accounting, and related regulations.
- Consent (Art. 6(1)(a) GDPR) — only where we explicitly request it (e.g. for marketing communication, should it be introduced in the future). You may withdraw your consent at any time.
4. How long we retain data
- Data of an active user account and profile: for the entire duration the account exists.
- After an account or profile is deleted: we erase or anonymise the data without undue delay, no later than 30 days, except for data we are legally required to retain longer (e.g. accounting and tax records are retained for the period set by the Accounting Act, typically 5–10 years).
- Content of internal messages: for as long as both communicating parties' accounts exist, but no longer than 24 months from the last message in a given conversation.
- Data from the contact form: 24 months from resolving the inquiry.
5. Who we share data with (processors)
We use the following processors to operate the Platform. We have a data processing agreement in place with all of them (or such an agreement applies to them under their own processor terms):
- Supabase, Inc. — database, authentication and file storage (profile photos).
- Stripe, Inc. — payment, subscription and affiliate payout processing (Stripe Connect). Stripe is a certified payment services provider (PCI-DSS); the Provider never processes or stores card numbers. See Stripe's own Privacy Policy for how it processes data on our behalf.
- Vercel Inc. — hosting and delivery of the Platform, including deriving approximate location from an IP address.
- Resend — delivery of transactional emails (confirmations, subscription-expiry notices, messaging notifications).
- OpenAI, L.L.C. — used exclusively to automatically look up and process publicly available information about shows and events from kennel-club websites; Platform users' personal data is not shared with this processor.
- OpenStreetMap / Nominatim — a public geocoding service used to convert event venue addresses into map coordinates; does not process users' personal data.
Personal data may also be disclosed to public authorities where required by law (e.g. tax authorities, law enforcement).
6. Transfers of personal data outside the EU/EEA
Some of the processors listed above (in particular Supabase, Stripe, Vercel, OpenAI) may process data on servers outside the European Union and the European Economic Area, typically in the United States. In such cases, the transfer is safeguarded by Standard Contractual Clauses approved by the European Commission or another mechanism under Art. 46 GDPR, to which the given processor has committed under its own data processing terms.
7. Data security
Access to data is protected by technical and organisational measures appropriate to the nature of the data processed — encrypted transmission (HTTPS), database-level access control (Row Level Security), and limiting administrative access to a necessary circle of people. User passwords are stored exclusively in an irreversibly hashed form.
8. Your rights
As a data subject, under the GDPR you have the right to:
- access your personal data (Art. 15 GDPR);
- rectify inaccurate data (Art. 16 GDPR);
- erasure (the “right to be forgotten”) once there is no longer a lawful ground for processing (Art. 17 GDPR);
- restrict processing (Art. 18 GDPR);
- data portability in a machine-readable format (Art. 20 GDPR);
- object to processing based on legitimate interest (Art. 21 GDPR);
- withdraw given consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal;
- lodge a complaint with the Czech Office for Personal Data Protection (Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz), if you believe the processing violates the GDPR.
You can correct or delete most of your profile data yourself after logging in, in your account settings. We will handle other requests sent to kristyna@groomermap.com without undue delay, no later than within 1 month.
9. Automated decision-making
The Platform does not carry out any automated individual decision-making or profiling with legal effects on you within the meaning of Art. 22 GDPR. (Artificial intelligence is used on the Platform only to mine publicly available event information from third-party websites, not to make decisions about users.)
10. Minors
The Platform is not intended for persons under 16. If we discover that we have processed the personal data of a child under 16 without the appropriate consent of a legal guardian, we will delete that data.
11. Changes to this policy
We may update this policy from time to time, in particular in response to changes in law or Platform features. We will inform you of a material change by email or a prominent notice on the Platform. The current version is always available on this page.
12. Contact
For any questions about the processing of personal data, contact us at kristyna@groomermap.com.