Privacy Policy
Last updated 2026
Who we are
JAP (Justaskpet) is software for pet care businesses: boarding, daycare, grooming, training and dog walking. Businesses use JAP to run bookings, staff and billing. Pet parents use it to see their pets' stays, updates and invoices.
When a business uses JAP to store client and pet records, that business is the data controller and JAP is the processor. For the business owner's own account with us, JAP is the controller.
What we collect
- Account data: name, email, phone, role and business membership.
- Client data entered by the business: pet parent contact details and notes.
- Pet data including health information: vaccination records, medication and feeding notes, behaviour notes. We treat these as sensitive.
- Operational data: bookings, appointments, shifts, tasks, messages, photos and report cards.
- Billing data: subscription tier, invoices and payment status.
- Security data: audit records of who viewed or changed client, pet health and payment records.
Payments
All card payments run through Stripe's hosted, tokenised flow. JAP never receives, stores or processes raw card numbers, CVCs or full bank details. We only store Stripe's references, amounts and statuses.
Pet health data
Medication, vaccination and behaviour notes are visible only to the pet's linked owner and staff at the single business that record belongs to. They never appear in public booking pages, business discovery views, the shared demo, or search engine indexes.
Data categories we handle
- Business account data.
- Owner and staff account data.
- Client contact data.
- Pet profile data.
- Vaccination and treatment information.
- Behaviour and allergy notes.
- Vet contact details, where a business records them in a pet's notes.
- Booking and reservation data.
- Invoice and payment-status data.
- Uploaded documents and photos, and the invoices generated from bookings.
- Messages between the business and pet owners.
Who can see what
Access follows the role assigned inside a business. JAP has four roles and nothing here widens them:
- Owner: full access to their own business, including billing and the business data export.
- Manager: the operational areas the product already permits, without owner-only billing and export.
- Staff: the day-to-day areas the product already permits for staff.
- Freelancer: limited to the clients, pets and bookings they are assigned to.
Sign-in and sessions
- Everyone signs in through JAP's authentication system: email and password, or Google.
- Pet parents can also open their portal through a single-use link sent to their email address.
- Passwords are stored only as hashes by the authentication provider, never in readable form.
- Repeated failed sign-ins temporarily lock an email address.
- Two-factor authentication is available and can be switched on in account settings.
- You can sign every device out at once from account settings, and removing a staff member ends their access to the business.
- Signed-out users cannot reach protected screens through the back button or by typing a URL.
How businesses are kept apart
Every client, pet, booking, invoice, payment, document, message, staff record, report and export is tied to one business identifier, and the database enforces that scope on every read and write, not the screen you are looking at. Changing a URL, an identifier or a request does not reveal another business's records.
How we protect it
- Row-level security scopes every query to a single business.
- Card payments run through Stripe's hosted flow; JAP never receives raw card numbers.
- Optional two-factor authentication, sign-in lockouts and one-click session revocation.
- Audit records of who viewed or changed client, pet health and payment records, and of data exports.
We only list controls that are actually configured in the product. JAP does not claim any security or compliance certification on this page.
Cookies
Essential cookies keep you signed in and keep the app working. Optional analytics cookies only load after you accept them in the cookie banner. Rejecting optional cookies changes nothing about how JAP works for you. You can change your mind at any time by clearing site data.
Your rights
You can access, correct, export or delete your data. Both business accounts and pet parent accounts have a Data & Privacy panel in settings with:
- Download my data: a JSON export of everything tied to your account.
- Export business data: owners can download their business records as a ZIP of CSV files.
- Delete my account: erasure of your personal records, not a deactivation flag.
You may also object to processing, restrict it, or complain to your local data protection authority.
Retention and deletion
- Account and operational data is kept while the account is active.
- Deleting your account from settings erases your personal records at the moment you confirm it. Business records such as invoices are not removed by that action.
- Any deletion beyond that (for example removing a whole business after cancellation) is handled as a manual request through the support contact below. JAP does not delete data automatically on a schedule.
Hosting, encryption and retention periods
Fixed retention periods, storage locations, hosting regions and encryption-at-rest details are not stated here because they have not been confirmed for publication. This section requires confirmation from the JAP owner before it can make those statements.
Contact
Privacy questions and data requests: privacy@getjap.com.