Pretty Pooches

Privacy notice

Preson Limited, trading as Pretty Pooches ("Pretty Pooches", "we", "us") provides the booking + billing platform that UK dog grooming businesses use to run their bookings, payments and customer communications. This notice explains what personal data we handle, why, and the rights you have under the UK GDPR and the Data Protection Act 2018.

Version 1.1, last updated 25 September 2026. It explains our practices in plain terms and is not legal advice. What changed in 1.1: how customer payments are collected, how marketing to your customers works, what happens when a pet parent deletes their account, and an updated sub-processor list.

Who we are

Pretty Pooches is a trading name of Preson Limited, a company registered in England & Wales (company number 17477430), registered office 6 Riverside Court, Croft, Leicester, England, LE9 3HG. Preson Limited also operates Beatrice (heybeatrice.com), our sister platform for personal-care businesses, on the same core. We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC256320. Questions about this notice or your data can go to our data-protection contact Lewis Preson, Director at privacy@prettypooches.app.

Controller and processor — the two roles

Pretty Pooches wears two hats. For the personal data of operators and their platform usage (your name, your business account, billing and how you use the product) we are the data controller. For the personal data of your customers (pet parents) and their pets that flows through your bookings, we are your data processor: the grooming business is the controller of that data and we process it only on your documented instructions, under our Data Processing Agreement. Your customers should also be shown the booking-site privacy notice (we ship a template you can edit).

Operator data we collect (we are the controller)

When you sign up and run your business on Pretty Pooches we collect: your business name and details; your name, email address and phone number; login and authentication data (magic-link and refresh-token identifiers — never stored card numbers); the Stripe account identifier we use to route your payouts; your plan and billing history; push-notification tokens for the office app; and product usage, device, IP and diagnostic data needed to run, secure and support the service.

Customer + pet data we process on your behalf (you are the controller)

To run a booking on your behalf we process, on your instructions: the pet parent's name, email and phone; their postal address and geolocation / latitude-longitude (only for collect-and-return or mobile bookings, to plan travel); pet records (name, breed, size, coat, temperament, vaccination status, photos and care notes); booking history; marketing preferences; and reminder logs (email, SMS and — where enabled — WhatsApp sends and delivery receipts). We do not use this data for our own purposes and we do not market to your customers on our own behalf.Review requests and “due for a visit” reminders, where you use them, are marketing sent in your name. They rely on the soft opt-in in the Privacy and Electronic Communications Regulations (PECR): they go only to people who have booked with you, only about the kind of service they already had, every email carries an unsubscribe link, and anyone who has opted out, by that link or in their account, gets none of them on any channel. They are never sent by text message.

Payments — card data never touches us

All card data is collected and stored by Stripe, a PCI-DSS Level 1 service provider. Pretty Pooches never sees or stores card numbers. We collect customer payments and deposits as your commercial agent: Stripe takes each payment on our platform account and transfers it, less our fee, to your own connected Stripe account for payout. We keep the payment records (amounts, dates, the card brand and last four digits) that this requires, including for tax and for handling refunds and disputes.

Lawful bases (data we control)

For operator and platform data we rely on: performance of a contract (creating and running your account, taking your plan payments); legitimate interests (running, securing, improving and supporting the platform, and service communications such as billing and incident notices), balanced against your rights; and consent (any marketing email you opt into, and non-essential cookies / analytics, which are off by default). You can withdraw consent at any time.

Sub-processors

We engage a small set of vetted sub-processors to deliver the service. Each is bound by data-protection terms and processes data only to provide its function. The current list:
Sub-processorPurposeRegion
StripeCard payments, deposits, payouts (Connect) and plan billingUK / EU / US
Amazon Web Services (RDS, S3, SES, CloudFront)Hosting, database, file storage, transactional email (SES) and our public-asset CDNEU (eu-west-1, Ireland); CloudFront edge is global
Amazon Bedrock (AWS)AI drafting assistance for our own outreach messages and, where enabled, in-product suggestions; prompts are not used to train the underlying modelsEU (eu-west-1)
TwilioSMS sign-in codes, booking reminders and notificationsUK / EU / US
Meta — WhatsApp Cloud APIWhatsApp messaging and sign-in codes (where enabled — feature-flagged off by default)EU / US
postcodes.ioKeyless UK postcode geocoding for travel planning (postcodes only — no names or contact details)UK
Google Maps PlatformTravel-time (Distance Matrix) and geocoding, only where a business enables it with its own keyEU / US
Google PlacesFinding businesses for our own outreach (search terms and area only — no customer or operator account data)EU / US
Push notifications — Apple (APNs), Google (FCM), ExpoDelivering push notifications to the mobile apps (device token + notification payload), where enabledUS
Umami (self-hosted)Cookieless product analytics — page views and named funnel events with no personal identifiers, on our own servers; nothing is shared with an analytics vendorOur own AWS infrastructure (eu-west-1)
PostHogOptional product analytics — funnels, heatmaps and session replay (replay masks all form input by default). Not currently active; loads only after analytics consent.EU (eu.i.posthog.com)
SentryError monitoring and diagnostics for the websites, apps and API (error reports carry technical details of the request that failed)EU / US
EntriSearching for and buying a new web domain, only if a business buys one through us (not currently active; connecting a domain a business already owns does not use Entri)US
Google Business ProfilePosting updates and reading reviews on a business's Google Business Profile, only where the business connects itEU / US
Meta — Facebook and InstagramPosting to a business's Facebook and Instagram accounts, only where the business connects themEU / US
TikTokPosting to a business's TikTok account, only where the business connects it (not yet available)US / EU
We will give operators advance notice of any new or replacement sub-processor so an objection can be raised, as set out in our DPA.

International transfers

Our primary hosting, customer-data storage and transactional email run in the EU (AWS region eu-west-1, Ireland), which the UK recognises as adequate. Some sub-processors (for example Stripe, Twilio, Google and Meta) may process limited personal data outside the UK and EU. Where they do, the transfer is protected by an appropriate safeguard — UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.

Retention

We keep operator account data for as long as your account is active and for a reasonable period afterwards to meet legal, tax and dispute obligations. When an operator deletes their account, we delete their business data 30 days later (they can cancel until then), keeping only minimised financial records for 7 years (amounts, dates and payment references, with no customer details) to satisfy UK tax and accounting requirements. When a pet parent deletes their account, it closes at once and can be restored by signing in again within 30 days; after that their identity (name, contact details, address, sign-ins, saved card reference and photos) is erased, while each business keeps its own records of their appointments, payments and pet care. When a salon deletes its account, customers it imported or entered itself, who never signed in and use no other business here, are erased along with it. Login tokens are kept only while valid; notification logs are kept for delivery troubleshooting and usage metering.Our database is backed up automatically, encrypted, and each backup is kept for 35 days. Data that has been deleted or erased can therefore remain in those backups for up to 35 days before it is gone for good. We never restore a backup except to recover from a disaster.

Your rights

Under UK data-protection law you have the right to: access a copy of your data; rectify inaccurate data; erase your data; restrict or object to processing; and data portability. Operators can export their business + customer records from the back-office and delete their account at any time (after a 30-day window in which they can cancel, we delete everything except minimised financial records, kept for 7 years). Pet parents can export their own data and delete their account from the customer app or booking site, as described under Retention. To exercise a right, contact us — or, for booking data, the salon as controller.

Cookies

Our sites use strictly-necessary cookies to keep your session signed in and the booking flow working. Our own product analytics (Umami) is cookieless and stores nothing on your device. Any analytics cookies are off by default and set only if you opt in via the cookie banner; you can change your choice at any time.

Complaints

If you have a concern we couldn't resolve, you can complain to the UK Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to put things right first.

Contact

For any data-protection question, contact privacy@prettypooches.app. Operators can review our Data Processing Agreement and Terms of Service.
Privacy — Pretty Pooches