Draft pending legal review.
Effective date: September 2, 2026
This Privacy Policy explains how Intellizu LLC, which operates Groomerzu (“Groomerzu”, “we”, “us”), collects, uses, shares and protects personal information through the Groomerzu web application at app.groomerzu.com, the public booking pages it serves, the salon websites we host at *.groomerzu.com, and this marketing site (together, the “Service”).
1. Who this policy covers, and our role
Groomerzu is used by two kinds of people, and our role is different for each:
- Salons. Grooming businesses that create a Groomerzu workspace and pay for a subscription (our “Customers”). For the account information Customers give us about themselves, and for how they use the Service, Groomerzu acts as the data controller.
- Pet owners. People who book with a salon, receive reminders from a salon, or whose details a salon enters into Groomerzu (our Customers’ “End Users”). For End User information, the salon is the data controller and Groomerzu is the data processor (or “service provider” under US state privacy laws). We handle that data only on the salon’s instructions and under our terms of service.
If you are a pet owner with a question about how a particular salon uses your information, please contact that salon first. We will help them respond.
2. Information we collect
From salons (Customers)
- Account details: name, email address, password (stored only as a hash), phone number, business name, address, website, logo and time zone.
- Staff details: names, email addresses and roles of the people a salon invites to its workspace.
- Billing details: subscription plan and status. Card numbers are collected and stored by Stripe, not by us; we keep a Stripe customer reference and the last four digits and card brand that Stripe returns.
- Usage data: log records (IP address, browser type, pages requested, timestamps, request IDs), error reports and product analytics as described in section 8.
From pet owners (End Users), on behalf of salons
- Contact details: name, email address and phone number.
- Pet details: pet name, species, breed, size, grooming and behaviour notes, vaccination or vet notes the salon chooses to record.
- Appointment details: services booked, dates and times, staff member, status, notes, invoices and payment status.
- Communication records: confirmations, reminders and review requests we send on the salon’s behalf, and whether delivery succeeded.
We do not knowingly collect health, financial, biometric or other sensitive categories of personal information about pet owners. Salons should not enter such information in free-text notes.
3. How we use information
For Customers we use information to:
- create and secure accounts, authenticate users and detect abuse;
- provide, maintain and improve the Service, including support;
- bill subscriptions and communicate about the account (invoices, trial and renewal notices, security alerts);
- send product updates, which you can opt out of at any time;
- comply with legal obligations and enforce our terms.
For End User data we act only as a processor: we store it, display it to the salon, use it to send the confirmations, reminders and review requests the salon has enabled, and delete or export it when the salon instructs us to. We do not use End User data for our own marketing and we do not build profiles across salons.
4. How we share information
We do not sell personal information, and we do not share it with third parties for their own marketing. We share information only:
- with subprocessors that help us run the Service (section 5);
- with a salon, for the End User data that salon controls, and with the staff the salon has invited;
- with payment processors, when a salon takes a card payment from a pet owner through Stripe;
- when required by law, for example to respond to a valid legal request, or to protect the rights, property or safety of Groomerzu, our Customers or others;
- in a business transfer, if Groomerzu is involved in a merger, acquisition or sale of assets, in which case this policy continues to apply to the transferred data.
5. Subprocessors
The following providers process personal information on our behalf. We will update this table before adding a new subprocessor that handles Customer or End User data.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, file storage, backups, static site delivery, transactional email via SES | All Service data | United States |
| Stripe | Subscription billing for salons; card payments collected by salons | Billing contact, card data (held by Stripe), payment amounts | United States |
| Twilio | SMS delivery for reminders and notifications | Phone numbers, message content | United States |
We may also use analytics providers on this marketing site only, as described in section 8. They do not receive End User data.
6. Data retention
- Customer account data is kept for as long as the workspace exists. When a salon deletes its workspace, all workspace data, including End User data, is permanently deleted from our production database at the time of deletion and from backups within 35 days.
- Trial and lapsed accounts. If a trial ends or a subscription lapses without a plan being chosen, the workspace becomes read-only and its data is retained so the salon can resume. We do not automatically delete inactive workspace data; a salon can delete its workspace at any time.
- Billing records are retained for as long as required by tax and accounting law, typically seven years.
- Server logs are retained for up to 90 days for security and troubleshooting.
- Notification logs (which reminder was sent to whom, and whether it was delivered) are kept for as long as the related workspace exists.
7. Security
We protect personal information with measures that include encryption in transit (TLS) and at rest, hashed passwords, workspace-level isolation so one salon can never see another salon’s data, role-based access for staff, rate limiting on authentication endpoints, and audit logging of platform operations. Access to production systems by our team is limited to the people who need it to operate the Service. No method of transmission or storage is completely secure; if we learn of a breach affecting your information we will notify affected Customers without undue delay, and Customers are responsible for notifying their End Users where required.
8. Cookies and analytics
- The web application uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These cannot be disabled while using the app.
- This marketing site may use a privacy-focused analytics service (Plausible) that does not set cookies, and may use Google Analytics 4 with IP anonymisation. You can block analytics scripts with a browser extension without affecting the site.
- Public booking pages and salon websites do not use advertising or tracking cookies.
We do not respond to browser “Do Not Track” signals because there is no common standard for them, but we honour Global Privacy Control signals where required by law.
9. Your rights
Everyone
You may ask us to access, correct, delete or export personal information we hold about you, and to object to or restrict certain processing. To make a request, email hello@groomerzu.com. We will verify your identity and respond within 30 days (45 days where the law allows and the request is complex). We will not discriminate against you for exercising any privacy right.
If you are a pet owner
Because the salon controls your information, we will usually forward your request to the salon and help them act on it. Salons can correct or delete your record and export your data from their Groomerzu account.
California residents (CCPA/CPRA)
You have the right to know what personal information we collect and how it is used and shared, the right to delete, the right to correct, the right to opt out of “sale” or “sharing” (we do neither), and the right to non-discrimination. You may designate an authorised agent to make a request for you. We do not use or disclose sensitive personal information for purposes that require a right to limit.
European Economic Area, United Kingdom and Switzerland (GDPR)
Our legal bases for processing Customer data are performance of a contract (providing the Service), legitimate interests (securing and improving the Service, communicating with you), and consent where we ask for it (marketing email). You may withdraw consent at any time, and you have the right to lodge a complaint with your local supervisory authority. Where we transfer data outside your region we rely on Standard Contractual Clauses or another lawful mechanism. Customers who need a data processing agreement can request one at hello@groomerzu.com.
10. Children
The Service is intended for businesses and adults. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
11. International transfers
Groomerzu is operated from the United States and our subprocessors store data in the United States. If you use the Service from another country, your information will be transferred to and processed in the United States.
12. Changes to this policy
We may update this policy from time to time. If a change materially affects how we use personal information we will notify Customers by email or an in-app notice at least 14 days before it takes effect. The effective date at the top of this page always shows the current version.
13. Contact
Intellizu LLC, United States Privacy requests and general support: hello@groomerzu.com