Legal

Privacy Policy

Last updated: May 9, 2026 · Version 1.0

⚠️ Placeholder text: This text is a scaffold. Before going live, please have it reviewed by a Swiss law firm (e.g. Vischer, Walder Wyss) or a specialized privacy tool (datenschutzpartner.ch, iubenda). PETVITY processes health data — that requires a watertight policy under revFADP (Switzerland) and GDPR (EU).

1. Data Controller

PETVITY GmbH
Dufourstrasse 90
8008 Zürich, Switzerland
Email: privacy@petvity.com

2. Data we collect

We process the following categories of personal data:

  • Contact data — name, email, phone (when you reach out)
  • Account data — login, hashed password, membership status
  • Pet data — species, breed, age, health indicators (for Pet-Harmony Score™)
  • Payment data — processed exclusively by Stripe / HeyLight (PCI-DSS)
  • Usage data — IP, browser, click paths (anonymized via GA4 / Plausible)

3. Purpose of processing

  • Providing the PETVITY platform and membership services
  • Personalized recommendations and Pet-Harmony Score™ calculation
  • Newsletter delivery (with explicit consent)
  • Contract handling and payment processing
  • Security and abuse prevention

4. Legal basis

Processing is based on Art. 31 para. 2 lit. a revFADP / Art. 6 para. 1 GDPR: contract performance, legitimate interest, explicit consent (newsletter, health data).

5. Third-party processors

We use the following processors (DPA agreements in place):

  • Hosting — Netlify / Vercel (USA, Standard Contractual Clauses)
  • E-commerce — Shopify (Canada / EU)
  • Payments — Stripe Payments Europe Ltd (Ireland)
  • BNPL — HeyLight AG (Switzerland)
  • Newsletter — Mailchimp (USA, EU-US Data Privacy Framework)
  • CRM — HubSpot (USA / EU)
  • Analytics — Google Analytics 4, Plausible (EU)
  • Forms — Tally (USA, EU servers in GDPR mode)
  • Booking — Calendly (USA)

6. Cookies

We use technically necessary cookies (session, auth) without consent, and analytics cookies (with consent banner). You can withdraw consent at any time.

7. Your rights

You have the right to: access, rectification, erasure, restriction, portability and objection. Requests: privacy@petvity.com

8. Retention

Personal data is deleted as soon as the purpose of processing no longer applies — at the latest after legal retention periods (10 years for accounting under Swiss CO Art. 958f).

9. Complaints

Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Bern. EU: supervisory authority at your residence.

This policy may change — the latest version is always at /privacy.