Privacy policy
Breto Dog Concepts, S.L.U. is responsible for the personal data you give Breto Food Club. We use it to run your account, feed your dogs and deliver your boxes, and we never sell it. Last updated: 4 October 2026.
Who is responsible
BRETO DOG CONCEPTS, S.L. (Sociedad Unipersonal), NIF B21659651, Carrer de Badajoz 65, local 2, 08005 Barcelona. Write to legal@bfc.dog about anything in this policy. We have no Data Protection Officer; at our size and activity the law doesn't require one.
Consultations are given by independent veterinarians (see the Terms). Every consultation, first or follow-up, is between you and the veterinarian. When you book one, or ask us something in the chat that we pass to them, we share your name, contact details, your question and your dog's details with the veterinarian so they can answer, and you ask them to share their plans and reports with us. The veterinarian is responsible for the data they hold, including their own notes, under their own privacy notice. We are responsible for the copies of their plans and reports we keep in your club account. We use them to show them to you and to build your boxes.
What we collect
| What | Examples | When |
|---|---|---|
| You | first name, surname (optional), email, phone | sign-up, checkout, your account page |
| Delivery and billing | address, postcode, delivery slot, billing address; your tax ID only if you ask for a full invoice | postcode check, checkout |
| Your dogs | name, breed, photo, age, weight, activity, allergies, health conditions, body condition, feeding plans and reports | sign-up questions, consultations, your dog pages |
| Orders and payments | what you bought, prices, delivery status, payment status | checkout and each renewal |
| Bookings | date, time, which dogs, status | when you book a consultation |
| Messages | your chats with the BFC team | when you tap "Ask us" |
| How you found us | the invite code or campaign link you arrived with | sign-up |
| Out-of-area interest | postcode, and your email if you ask us to tell you when we deliver there | postcode check |
| Waitlist | landing page | |
| Technical | IP address (used for security checks and kept only in disguised form), server logs kept for about an hour | every visit |
Card details go straight to Stripe. We never see or store them.
Data we get from others. The veterinarian gives us the plans and reports they write. Calendly tells us about consultations you book, Stripe whether a payment went through, couriers how your delivery went. If you also buy at breto.store with the same email, we show those orders in your club account: Breto Dog Concepts runs both.
Information about your dog is not "health data" under data protection law, but we treat it carefully. Please don't put details of your own health in notes or chats.
Why we use it
| Purpose | Legal basis |
|---|---|
| Create your account and sign you in with email codes | Our contract with you |
| Sell and deliver your boxes, run your subscription, take payments | Our contract with you |
| Service emails: sign-in codes, order confirmations, renewal reminders, payment problems, delivery changes | Our contract with you |
| Estimate your dog's daily energy needs and portion sizes from your answers | Our contract with you |
| Arrange consultations and keep the plans and reports the vet writes for you | Our contract with you |
| Answer your messages and requests | Our contract with you, or our legitimate interest in helping you |
| Invoices, accounting and tax | Legal obligation |
| Tell you when there's room (waitlist) or when we deliver to your postcode | Your consent: you asked us to |
| Marketing emails, such as offers or reminders about a plan you haven't ordered | Your consent. If you are a customer, our legitimate interest in telling you about similar products, with an unsubscribe link in every email |
| Security: bot checks, rate limits, fraud prevention | Our legitimate interest in keeping the service safe |
| Seeing which invite batches and campaigns bring people, from the invite code or campaign tag in your link. We only look at totals | Our legitimate interest in knowing which campaigns work. You can object |
| Handling claims | Our legitimate interest in defending ourselves |
The portion estimate is an automatic calculation, but it decides nothing about you: it suggests amounts you can change at any time. We make no automated decisions with legal or similarly significant effects.
We need your name, email, address, phone and payment to sell and deliver. Your dogs' names and the sign-up questions are needed to join, because we build your box and plan from them. Health details beyond those are optional.
Who we share it with
We use these providers to run BFC. They act on our instructions under data processing agreements, except where the table says otherwise.
| Provider | What for | Where the data is |
|---|---|---|
| Supabase | Database and staff sign-in | EU (Ireland). Supabase may reach it from the US or Singapore for support, under standard contractual clauses |
| Vercel | Hosting the website | EU (Ireland) for processing; global network for delivery. Vercel is a US company: transfers under the Data Privacy Framework and standard contractual clauses |
| Stripe (Stripe Payments Europe, Ireland) | Payments. Stripe also uses payment data as its own controller, for fraud prevention and its legal duties | EU, with transfers to the US under the Data Privacy Framework and standard contractual clauses |
| Shopify (Shopify International, Ireland) | Catalogue, stock, orders and the waitlist; one customer record shared with the Breto shop | Ireland, with transfers to Canada (EU adequacy decision) and other countries, including the US, under Shopify's binding corporate rules and standard contractual clauses |
| Resend | Sending our emails | Emails are sent from the EU (Ireland). Resend and its providers are in the US: transfers under the Data Privacy Framework and standard contractual clauses |
| Crisp | Chat | EU (servers in the Netherlands and Germany). Some of Crisp's providers are US companies, under standard contractual clauses |
| Calendly | Booking consultations | US, under the Data Privacy Framework |
| Cloudflare | The "are you human" check on sign-up, login and waitlist. Cloudflare also uses the check's signals to improve it, as its own controller | Global, including the US, under the Data Privacy Framework and standard contractual clauses |
| Apple (iCloud Mail), under Apple's own terms, not a data processing agreement | Our email inboxes | Apple's and its providers' data centres, including the US, under standard contractual clauses |
| Holded | Invoices | EU (Spain) |
| Paack (Paack Logistics Iberia, Barcelona), and sometimes other couriers | Delivering boxes | Spain. Paack says some of its IT providers may be outside the EU; ask us for details |
We also share data with the veterinarian when you book a consultation through us, and with tax authorities, courts or police when the law requires it. Our courier contacts you about your delivery by email, text message or phone. When handing over the box, it may ask for a code we text you, a signature or an ID document, or take a photo at your door. It may also send you a short satisfaction survey. Your orders and contact details sit in the same Shopify account as the Breto shop, which is the same company.
Transfers outside the EU. Some providers are outside the EU or can reach data from there. We only use them with a safeguard the law recognises: an EU adequacy decision (the EU–US Data Privacy Framework, or Canada), binding corporate rules, or the European Commission's standard contractual clauses. The table shows which. Ask us for a copy at legal@bfc.dog.
How long we keep it
| Data | How long |
|---|---|
| Accounts that never bought anything | Deleted 12 months after the last activity |
| Your account and your dogs' data, including plans and reports | While your account is open. When you close it, we delete what we no longer need and lock the rest away, only for a possible claim, until 5 years after your last order, consultation or message |
| Orders and invoices | 6 years from the end of the year of the order, as Spanish accounting law requires. After you close your account they are locked away, with your identity removed where the law allows |
| Chats | 5 years after the last message. If you close your account, they are locked away until then, only for a possible claim |
| Postcode checks | 24 months, without your identity; an email you left to be told about your area until we tell you, or 12 months |
| Waitlist | Until you ask us to remove you, or 24 months |
| Your yes to offers | Until you unsubscribe. We keep a record of when you said yes and when you unsubscribed for 3 years after, to show we had your consent |
| Sign-in codes, links and sessions | 24 hours for codes, 4 days for single-use links, up to 60 days for a session |
| Our internal alert emails | 12 months |
| Security logs | About an hour |
Your rights
You can ask to see your data, correct it, delete it, limit or object to how we use it, or get a copy to take elsewhere. You can object at any time to our use of your data for marketing, and we'll stop. You can withdraw consent at any time, and unsubscribe with the link in any marketing email.
Email legal@bfc.dog from the address on your account. We reply within one month. Some data we must keep, such as invoices, even after you ask us to delete your account. We lock that data away. Only the person in charge of data at BFC can open it, and only for a court, a tax or data protection authority, or a legal claim. We delete it when the legal period ends.
If you think we have handled your data wrongly, you can complain to the Spanish Data Protection Agency (AEPD), www.aepd.es (online at sede.aepd.es), Calle Jorge Juan 6, 28001 Madrid.
Age
BFC is for adults. You must be 18 or over to join.
Security
Connections are encrypted, staff sign in with two-step verification, and card data stays with Stripe.
Changes
We'll post any change here with a new date. If a change matters, we'll email you before it applies.