Last updated: August 11, 2026 · Compliant with PIPEDA (Canada)

Who We Are

Pet Services Lab is a grooming management platform for Canadian pet service businesses, operated by The Systems Lab. This policy covers the Pet Services Lab web application and mobile apps. We are committed to protecting the privacy of both our customers (salon owners and staff) and their clients (pet owners).

What We Collect

From salon accounts: business name, email address, password (stored only as a bcrypt hash, never in plain text), billing information, and usage data.

From salon client records (entered by you): pet owner names, phone numbers, email addresses, pet details, appointment history, and payment records. Where a client authorizes it, their payment card is tokenized and stored by Stripe or Square, whichever processor their salon has connected, so the salon can charge it for future visits, account balances, or memberships; Pet Services Lab stores only the card's brand, last four digits, and a record of the client's authorization (including the date and time it was given), never the full card number. This data belongs to you - we process it on your behalf.

From the mobile app: if you enable push notifications, a device token is registered with Google Firebase Cloud Messaging so notifications you have turned on can be delivered to your device. The token is removed when you sign out. The app's camera is used only for scanning barcodes and gift cards; scanning happens on your device, and no photos or video are stored or transmitted.

Staff clock-in location: where a salon turns on location checks for its timecards, the device asks the staff member's permission and reads its location at the moment they clock in and clock out, and only at those moments. The location is compared with the salon's address to confirm the punch was made on site, and is saved with that timecard entry so the owner can see where it was made. Location is never read while the app is in the background and staff are never tracked between punches. Permission can be refused, and a refused or unavailable location does not stop anyone from clocking in; depending on the salon's settings the punch is simply recorded without a location or flagged for the owner to review. This applies to salon staff using their employer's account, not to the salon's own clients.

Why We Collect It

To operate the Service: authentication, scheduling, reminders, payments, notifications, and reporting. We do not sell any data to third parties, ever.

Third-Party Services

We use Twilio for SMS, Resend for email, Stripe and Square for payment processing and recurring billing (card numbers are handled by Stripe or Square and never stored by Pet Services Lab; where a salon offers memberships, recurring payments are processed automatically through the processor that salon has connected on the client's authorized saved card), Google Firebase for push notifications, and Supabase, Railway, and Vercel for database and application hosting. Each has its own privacy policy and data processing agreements.

Consent

SMS messages are only sent to clients who have explicitly consented. Clients may opt out at any time by replying STOP. No automated marketing messages are sent before 9am or after 9pm local time, in accordance with Canadian anti-spam practice. Where a client authorizes a salon to save their payment card for future charges, that authorization is recorded with the date and time it was given. Salons are responsible for obtaining their clients' consent for SMS and for saved-card charges; Pet Services Lab provides the tools to capture and record it.

Data Retention and Account Deletion

We retain your data for the duration of your subscription plus 90 days after cancellation, during which you may export your data. After 90 days, data is permanently deleted. You can cancel your account at any time from Settings, and you can request deletion directly by emailing pslprivacy@systemslabhq.com.

Your Rights Under PIPEDA

You have the right to access, correct, or request deletion of your personal data at any time. Salon clients have the same rights regarding data held in your account - you are responsible for honouring those requests.

Security

All data is encrypted in transit (TLS) and at rest. Passwords are hashed with bcrypt and never stored in plain text. Every account is strictly isolated: tenant data separation is enforced at the application layer on every request, and database credentials are never exposed to client devices.

Contact

Privacy questions or data requests: pslprivacy@systemslabhq.com

Contact us