B.F.C.

Privacy policy

Breto Dog Concepts, S.L.U. is responsible for the personal data you give Breto Food Club. We use it to run your account, feed your dogs and deliver your boxes, and we never sell it. Last updated: 4 October 2026.

Who is responsible

BRETO DOG CONCEPTS, S.L. (Sociedad Unipersonal), NIF B21659651, Carrer de Badajoz 65, local 2, 08005 Barcelona. Write to legal@bfc.dog about anything in this policy. We have no Data Protection Officer; at our size and activity the law doesn't require one.

Consultations are given by independent veterinarians (see the Terms). Every consultation, first or follow-up, is between you and the veterinarian. When you book one, or ask us something in the chat that we pass to them, we share your name, contact details, your question and your dog's details with the veterinarian so they can answer, and you ask them to share their plans and reports with us. The veterinarian is responsible for the data they hold, including their own notes, under their own privacy notice. We are responsible for the copies of their plans and reports we keep in your club account. We use them to show them to you and to build your boxes.

What we collect

WhatExamplesWhen
Youfirst name, surname (optional), email, phonesign-up, checkout, your account page
Delivery and billingaddress, postcode, delivery slot, billing address; your tax ID only if you ask for a full invoicepostcode check, checkout
Your dogsname, breed, photo, age, weight, activity, allergies, health conditions, body condition, feeding plans and reportssign-up questions, consultations, your dog pages
Orders and paymentswhat you bought, prices, delivery status, payment statuscheckout and each renewal
Bookingsdate, time, which dogs, statuswhen you book a consultation
Messagesyour chats with the BFC teamwhen you tap "Ask us"
How you found usthe invite code or campaign link you arrived withsign-up
Out-of-area interestpostcode, and your email if you ask us to tell you when we deliver therepostcode check
Waitlistemaillanding page
TechnicalIP address (used for security checks and kept only in disguised form), server logs kept for about an hourevery visit

Card details go straight to Stripe. We never see or store them.

Data we get from others. The veterinarian gives us the plans and reports they write. Calendly tells us about consultations you book, Stripe whether a payment went through, couriers how your delivery went. If you also buy at breto.store with the same email, we show those orders in your club account: Breto Dog Concepts runs both.

Information about your dog is not "health data" under data protection law, but we treat it carefully. Please don't put details of your own health in notes or chats.

Why we use it

PurposeLegal basis
Create your account and sign you in with email codesOur contract with you
Sell and deliver your boxes, run your subscription, take paymentsOur contract with you
Service emails: sign-in codes, order confirmations, renewal reminders, payment problems, delivery changesOur contract with you
Estimate your dog's daily energy needs and portion sizes from your answersOur contract with you
Arrange consultations and keep the plans and reports the vet writes for youOur contract with you
Answer your messages and requestsOur contract with you, or our legitimate interest in helping you
Invoices, accounting and taxLegal obligation
Tell you when there's room (waitlist) or when we deliver to your postcodeYour consent: you asked us to
Marketing emails, such as offers or reminders about a plan you haven't orderedYour consent. If you are a customer, our legitimate interest in telling you about similar products, with an unsubscribe link in every email
Security: bot checks, rate limits, fraud preventionOur legitimate interest in keeping the service safe
Seeing which invite batches and campaigns bring people, from the invite code or campaign tag in your link. We only look at totalsOur legitimate interest in knowing which campaigns work. You can object
Handling claimsOur legitimate interest in defending ourselves

The portion estimate is an automatic calculation, but it decides nothing about you: it suggests amounts you can change at any time. We make no automated decisions with legal or similarly significant effects.

We need your name, email, address, phone and payment to sell and deliver. Your dogs' names and the sign-up questions are needed to join, because we build your box and plan from them. Health details beyond those are optional.

Who we share it with

We use these providers to run BFC. They act on our instructions under data processing agreements, except where the table says otherwise.

ProviderWhat forWhere the data is
SupabaseDatabase and staff sign-inEU (Ireland). Supabase may reach it from the US or Singapore for support, under standard contractual clauses
VercelHosting the websiteEU (Ireland) for processing; global network for delivery. Vercel is a US company: transfers under the Data Privacy Framework and standard contractual clauses
Stripe (Stripe Payments Europe, Ireland)Payments. Stripe also uses payment data as its own controller, for fraud prevention and its legal dutiesEU, with transfers to the US under the Data Privacy Framework and standard contractual clauses
Shopify (Shopify International, Ireland)Catalogue, stock, orders and the waitlist; one customer record shared with the Breto shopIreland, with transfers to Canada (EU adequacy decision) and other countries, including the US, under Shopify's binding corporate rules and standard contractual clauses
ResendSending our emailsEmails are sent from the EU (Ireland). Resend and its providers are in the US: transfers under the Data Privacy Framework and standard contractual clauses
CrispChatEU (servers in the Netherlands and Germany). Some of Crisp's providers are US companies, under standard contractual clauses
CalendlyBooking consultationsUS, under the Data Privacy Framework
CloudflareThe "are you human" check on sign-up, login and waitlist. Cloudflare also uses the check's signals to improve it, as its own controllerGlobal, including the US, under the Data Privacy Framework and standard contractual clauses
Apple (iCloud Mail), under Apple's own terms, not a data processing agreementOur email inboxesApple's and its providers' data centres, including the US, under standard contractual clauses
HoldedInvoicesEU (Spain)
Paack (Paack Logistics Iberia, Barcelona), and sometimes other couriersDelivering boxesSpain. Paack says some of its IT providers may be outside the EU; ask us for details

We also share data with the veterinarian when you book a consultation through us, and with tax authorities, courts or police when the law requires it. Our courier contacts you about your delivery by email, text message or phone. When handing over the box, it may ask for a code we text you, a signature or an ID document, or take a photo at your door. It may also send you a short satisfaction survey. Your orders and contact details sit in the same Shopify account as the Breto shop, which is the same company.

Transfers outside the EU. Some providers are outside the EU or can reach data from there. We only use them with a safeguard the law recognises: an EU adequacy decision (the EU–US Data Privacy Framework, or Canada), binding corporate rules, or the European Commission's standard contractual clauses. The table shows which. Ask us for a copy at legal@bfc.dog.

How long we keep it

DataHow long
Accounts that never bought anythingDeleted 12 months after the last activity
Your account and your dogs' data, including plans and reportsWhile your account is open. When you close it, we delete what we no longer need and lock the rest away, only for a possible claim, until 5 years after your last order, consultation or message
Orders and invoices6 years from the end of the year of the order, as Spanish accounting law requires. After you close your account they are locked away, with your identity removed where the law allows
Chats5 years after the last message. If you close your account, they are locked away until then, only for a possible claim
Postcode checks24 months, without your identity; an email you left to be told about your area until we tell you, or 12 months
WaitlistUntil you ask us to remove you, or 24 months
Your yes to offersUntil you unsubscribe. We keep a record of when you said yes and when you unsubscribed for 3 years after, to show we had your consent
Sign-in codes, links and sessions24 hours for codes, 4 days for single-use links, up to 60 days for a session
Our internal alert emails12 months
Security logsAbout an hour

Your rights

You can ask to see your data, correct it, delete it, limit or object to how we use it, or get a copy to take elsewhere. You can object at any time to our use of your data for marketing, and we'll stop. You can withdraw consent at any time, and unsubscribe with the link in any marketing email.

Email legal@bfc.dog from the address on your account. We reply within one month. Some data we must keep, such as invoices, even after you ask us to delete your account. We lock that data away. Only the person in charge of data at BFC can open it, and only for a court, a tax or data protection authority, or a legal claim. We delete it when the legal period ends.

If you think we have handled your data wrongly, you can complain to the Spanish Data Protection Agency (AEPD), www.aepd.es (online at sede.aepd.es), Calle Jorge Juan 6, 28001 Madrid.

Age

BFC is for adults. You must be 18 or over to join.

Security

Connections are encrypted, staff sign in with two-step verification, and card data stays with Stripe.

Changes

We'll post any change here with a new date. If a change matters, we'll email you before it applies.