GroomSome
GroomSome — Pet Grooming Business Management Software
Version 1.2 — Last updated: September 17, 2026
GroomSome is operated by Cre8-it B.V., registered with the Dutch Chamber of Commerce (KvK) under number 42147119, VAT NL869923651B01, with its place of business at Baron van Nagellstraat 136, 3771 LL Barneveld, the Netherlands.
We are the controller (verwerkingsverantwoordelijke) for the personal data of our Users (the grooming businesses that sign up). When Users enter their customers’ data (pet owners’ personal data) into GroomSome, we act as processor (verwerker) on behalf of the User. A separate Data Processing Agreement (verwerkersovereenkomst) governs this processing.
Contact: info@groomsome.app
When you create an account, we collect: your name, email address, phone number, business name, and business address. We use this to create and manage your account, to provide the Service, and to communicate with you about your subscription.
Legal basis: performance of a contract (Article 6(1)(b) GDPR).
Payments are processed by Stripe (Stripe Payments Europe, Ltd.). We only store the last four digits of your payment method and the expiration date for identification within the app. We never store full card numbers.
Legal basis: performance of a contract.
You may enter personal data about your clients (pet owners): names, contact details, pet information, medical/grooming notes, and appointment history. This data is processed on your behalf under the DPA. You are the controller for this data; we are the processor.
Legal basis: the Data Processing Agreement between you and us.
When you use our website or app, we automatically collect: IP address, browser type, device type, operating system, pages visited, and usage patterns. This is used for security, troubleshooting, and improving the Service.
Legal basis: legitimate interest (Article 6(1)(f) GDPR).
On groomsome.app (our marketing site) the cookie banner asks about two separate purposes, and nothing in either group is loaded until you allow that purpose:
Allowing one purpose does not allow the other, and neither is ever switched on automatically. You can change or withdraw either choice at any time through Cookie settings in the site footer; withdrawing advertising consent stops the pixel and clears its cookies.
Legal basis: your consent (Article 6(1)(a) GDPR, and Article 5(3) of the ePrivacy Directive as implemented in the Dutch Telecommunicatiewet Art. 11.7a and the German TDDDG § 25). For the Meta pixel, GroomSome and Meta act as joint controllers for the collection and transmission of the data, following the Court of Justice's judgment in Fashion ID (C-40/17); Meta's further processing is governed by Meta's own terms.
Inside the GroomSome application (my.groomsome.app and the mobile app) we use PostHog (EU Cloud, hosted in Frankfurt, Germany) for two purposes: to understand which features are used so we can operate and improve the Service, and to detect and diagnose software errors and crashes.
Product-analytics events record which pages and features are used, whether feature flows complete or fail, and technical AI-call telemetry (model, token counts, latency). Error and crash reports carry technical context — error type, stack trace, app version, operating system and device model — and are not intended to contain personal data. Events are associated with your company account rather than with individual pet owners, and PostHog stores a device identifier in your browser or app for this purpose. We do not use session recording or replay inside the application. Analytics events contain no client names, contact details, or notes; page URLs may include pseudonymous record identifiers.
Objecting: contact us at info@groomsome.app and we will switch product analytics off for your account.
Legal basis: legitimate interest (Article 6(1)(f) GDPR) — understanding how the Service is used and keeping it working. You may object at any time (see Section 6).
GroomSome uses AI services to improve functionality:
Data processed through Azure AI Foundry stays within our own Microsoft Azure environment in the EU and is not used by Microsoft to train foundation models.
Legal basis: for features you initiate (such as imports), performance of a contract; otherwise legitimate interest (improving service quality and user experience).
We share personal data only with service providers (sub-processors) necessary to deliver the Service. All are bound by data processing agreements:
We do not sell or rent personal data for money. If you are in the United States, note that several state privacy laws — including the California Consumer Privacy Act as amended by the CPRA — define a “sale” or “share” broadly enough to cover the use of advertising cookies for cross-context behavioural advertising. Where you have allowed advertising cookies on our marketing site, that use may fall within those definitions; section 6.1 explains how to opt out. We may also share data if required by law, by court order, or to respond to valid legal process.
Our primary infrastructure is hosted in the EU (Azure West Europe, Netherlands). Some sub-processors may process limited data outside the EEA (for example PostHog support operations, although the data itself is stored in the EU; Google Cloud Vision text recognition for the paper import feature; and Resend email delivery). Where this occurs, we ensure appropriate safeguards are in place, such as EU Standard Contractual Clauses (SCCs) or an adequacy decision by the European Commission.
If you allow advertising cookies on the marketing site, data collected by the Meta pixel is transferred to Meta Platforms, Inc. in the United States under the EU–US Data Privacy Framework, to which Meta is certified.
Under the GDPR, you have the right to: access your personal data; rectify inaccurate data; erase your data (“right to be forgotten”); restrict processing; data portability; object to processing based on legitimate interest; and withdraw consent at any time where consent is the legal basis.
You can exercise most of these rights directly through your account settings at my.groomsome.app. For other requests, email us at info@groomsome.app. We will respond within 30 days.
If you believe we are processing your data unlawfully, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
We apply the same consent-first rule everywhere: advertising cookies are not loaded in any country until you allow them, so nothing is shared for advertising purposes unless you opt in. There is no regional variation that switches them on automatically.
If you are a resident of California or another US state with a comprehensive privacy law, you may also have the right to opt out of the “sale” or “sharing” of personal information, to know what we collect, to request deletion or correction, and not to receive different treatment for exercising those rights. To opt out, decline advertising in the cookie banner, or open Cookie settings in the site footer and switch advertising off. We also honour the Global Privacy Control signal: if your browser sends it, we treat it as an instruction to keep advertising cookies off. For the other rights, email info@groomsome.app.
We implement appropriate technical and organizational measures to protect personal data, including: encryption in transit (TLS 1.2+) and at rest, role-based access controls, regular security reviews, and monitoring for unauthorized access. No system is 100% secure, but we are committed to protecting your data in accordance with industry standards and the GDPR’s requirements.
In the event of a personal data breach affecting data for which we are the controller, we will notify the Autoriteit Persoonsgegevens within 72 hours where required under Article 33 GDPR. If the breach poses a high risk to your rights and freedoms, we will also notify you without undue delay.
Where we act as processor for your Customer Data, we will notify you (the controller) without undue delay after becoming aware of a breach, so that you can fulfill your own notification obligations under the GDPR. Details of our breach notification procedures are set out in the DPA.
The Service is designed for professional business use. We do not knowingly collect personal data from children under 16 years of age (the Dutch age of digital consent under the Uitvoeringswet AVG). If we learn that we have inadvertently collected such data, we will delete it promptly.
Our marketing website (groomsome.app) uses a cookie consent banner covering two separate purposes, analytics and advertising. Neither is set until you allow it, and allowing one does not allow the other. Accepting and declining are offered with equal prominence, and the per-purpose choice sits one click away behind “choose what you allow”. Functional cookies essential for the application (my.groomsome.app) are necessary for the Service to operate and do not require consent under the Dutch Telecommunications Act (Telecommunicatiewet, Art. 11.7a).
Your choice is stored for twelve months, after which the banner asks again. A choice recorded before advertising cookies existed covers analytics only; those visitors keep their analytics preference and are asked once about advertising.
How to change or withdraw consent: Click the “Cookie settings” link in the footer of groomsome.app at any time — withdrawing is as easy as giving consent. Withdrawing advertising consent stops the Meta pixel and clears its cookies. Alternatively, clear your browser’s cookies and site data for groomsome.app, and the consent banner will reappear on your next visit.
We may update this privacy policy from time to time. Material changes will be communicated to you via email or in-app notification at least 14 days before taking effect. The latest version is always available on this page with the revision date shown at the top.