Privacy Policy
Introduction
ESPR Creative Lab Private Limited ("Barnaby", "we", "us", or "our") operates the Barnaby mobile application and website. This Privacy Policy explains what information we collect, why we need it, who we share it with, and how you can ask us to correct, export, or delete it.
Animal health information is personal and sensitive. We use it to run consultations, records, reminders, orders, and support; we do not sell your personal or animal-health data for advertising.
Information We Collect
We collect information you give us directly, including:
- Account information: Name, email address, phone number, and profile photo
- Pet/animal information: Species, breed, age, weight, photos, and health records
- Payment information: Processed by Razorpay - we store payment/order references, not raw card details
- Consultation records: Chat messages and prescriptions. Video/audio calls are transmitted live via Agora and are not recorded or stored
- Communications: Messages with veterinarians, customer support interactions, and feedback
- Device information: Device type, operating system, unique device identifiers, and IP address
- Usage data: Features used, time spent in app, and interaction patterns
- Location information: With your permission, coarse and precise device location, used only to find nearby veterinary clinics, vets, and emergency services. We do not share your location with third parties for advertising.
How We Use Your Information
We use your information to:
- Provide, maintain, and improve our services
- Facilitate veterinary consultations and connect you with appropriate veterinarians
- Process one-time payments for consultations and marketplace orders
- Send appointment reminders, vaccination alerts, and important notifications
- Personalize your experience, such as showing relevant reminders and saved animal profiles
- Respond to your inquiries and provide customer support
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations and regulatory requirements
- Analyze usage patterns to improve our platform
Information Sharing
We share only the information needed to provide the service with:
- Veterinarians: Your pet's health information and consultation history are shared with veterinarians you consult with
- Marketplace sellers: Shipping address and contact information for order fulfillment
- Payment processors: Razorpay processes payments and eligible refunds
- Service providers: Cloud hosting, analytics, and communication services that assist our operations
- Legal authorities: When required by law or to protect rights and safety
We never sell your personal data to third parties for advertising or marketing purposes.
Third-Party Service Providers / Sub-processors
To operate Barnaby, we use a limited set of third-party processors. These providers act on our instructions under confidentiality and data-protection obligations, and may only process the data necessary to deliver their service. The current sub-processors are:
- Supabase: Database, authentication, and file storage hosting — stores your account, animal, health-record, consultation, and marketplace data.
- Razorpay: Payment processing — receives payment and transaction details to process one-time consultation and order payments, and refunds. Card details are handled by Razorpay; we do not store them.
- Agora: Real-time video and audio consultations — handles the live audio/video media stream during a consultation.
- Google Firebase (Phone Authentication, Cloud Messaging, and Analytics): Phone-number verification, push-notification delivery, and app usage analytics — receives your mobile number and one-time-password (OTP) content for sign-in, plus device tokens, app event and usage data, and device/diagnostic identifiers.
- Google Firebase Crashlytics: Crash and stability reporting — receives device information, crash logs/stack traces, and a Crashlytics user identifier (see "Crash and Diagnostic Reporting" below).
- Hostinger (email hosting): Transactional and account email delivery — receives your email address and the content of transactional messages (for example, receipts and account notifications).
We review our sub-processors periodically and will update this list as our service providers change.
Crash and Diagnostic Reporting
To keep the app stable and to diagnose problems, we use Firebase Crashlytics to collect crash and diagnostic information. When the app encounters an error or crash, we may collect:
- Device information: Device model, operating system version, app version, language, and similar technical attributes.
- Crash details: Crash logs, stack traces, and the app state leading up to the crash.
- A crash-reporting user identifier: A pseudonymous identifier set by Crashlytics that lets us correlate multiple crash reports from the same installation so we can investigate and fix recurring issues.
This data is used solely to identify, prioritise, and fix stability and security issues, and is not used for advertising.
Data Security
We implement industry-standard security measures including:
- SSL/TLS encryption for all data in transit
- Encrypted storage for sensitive data at rest
- Regular security audits and vulnerability assessments
- Access controls and role-based permissions
- Secure data centers located in India (ap-south-1 region)
No internet service can promise absolute security. What we can promise is that we keep improving our protections, limit access, and respond seriously when something looks wrong.
Data Retention
We retain your personal data for as long as your account is active or as needed to provide you services. Specifically:
- Account data: Retained until you delete your account
- Health records: Retained as per regulatory requirements (minimum 3 years after last consultation)
- Payment records: Retained for 7 years as per Indian tax regulations
You may request deletion of your data at any time, subject to our legal obligations to retain certain information.
Your Rights
Under applicable data protection laws, you have the right to:
- Access: Request a copy of your personal data we hold
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your account and associated data
- Export: Request your data in a portable format
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing for direct marketing
- Withdraw consent: Withdraw consent for data processing at any time
To exercise these rights, contact us at hello@barnaby.in. We will respond within 30 days.
Cookies and Tracking
Our website (barnaby.in) is a static informational site. It does not set cookies and does not load analytics, advertising, or third-party tracking scripts.
Our mobile app uses diagnostic and analytics tools (such as Firebase Analytics and Crashlytics) to understand usage patterns, diagnose crashes, and improve the service. We do not use these technologies for advertising purposes. You can control them through your device settings.
Children's Privacy
Under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"), any individual under 18 years of age is a child. Barnaby is intended for use by adults aged 18 and above. We do not knowingly create accounts for, or knowingly collect personal data from, children (persons under 18) without the verifiable consent of a parent or lawful guardian.
A child may use Barnaby only under the supervision of, and with verifiable consent provided by, a parent or lawful guardian who holds the account. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you are a parent or guardian and believe a child has provided us personal data without your consent, please contact us immediately at hello@barnaby.in, and we will take steps to verify and delete such information.
International Data Transfers
We aim to store and process Indian users' data in India and use the Mumbai (ap-south-1) region for our primary database hosting. However, some of our third-party processors operate globally and may process certain data on servers located outside India. In particular, Google Firebase and Crashlytics, Razorpay, Agora, Hostinger, and Supabase may process or transit data through infrastructure outside India in the course of delivering their services.
Where personal data is transferred or processed outside India, we do so in a manner consistent with the Digital Personal Data Protection Act, 2023 and applicable Indian law, and we rely on appropriate contractual safeguards (such as standard contractual clauses and data-processing agreements that impose confidentiality and security obligations on the processor). We do not transfer personal data to any jurisdiction restricted by the Government of India for such transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting the new policy on this page with an updated date
- Sending you an email notification
- Displaying a notice in the app
Your continued use of Barnaby after changes constitutes acceptance of the updated policy.
Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made thereunder, the name and contact details of the Grievance Officer are provided below:
Name: Grievance Officer, ESPR Creative Lab Private Limited
Email: hello@barnaby.in
Address: ESPR Creative Lab Private Limited,
India
The Grievance Officer shall acknowledge your complaint within 24 hours and resolve it within 15 days of receipt (and, for data-protection requests under the DPDP Act, within 30 days).
Contact Us
For privacy-related questions or to exercise your data rights, contact our Data Protection Officer:
Email: hello@barnaby.in
Address: ESPR Creative Lab Private Limited,
India