Pongo
← Home

Privacy policy

Last updated: 2026-07-15

In plain words

The data about your clients, their animals, your calendar and your invoices belongs to you.

Pongo processes it solely to provide you with the service, never for its own purposes. It is never sold, never rented, and never used for advertising.

You can export all your data at any time. It always stays yours.

This page is a plain-language summary of our Data Processing Agreement (DPA). If in doubt, the full document prevails.

Download the DPA (PDF)

The parties

This policy, like our DPA, is drafted in accordance with art. 9 of the Swiss Federal Act on Data Protection (nFADP).

Controller

You — the professional who uses Pongo.

Processor

Pongo — Miguel Moor, Avenue Victor-Ruffy 54, 1012 Lausanne, Switzerland.

1. What data and why

Pongo processes the data you enter for the sole purpose of running the app — managing your clients, your schedule and your invoices:

  • Your email and password (stored encrypted).
  • Your business information: name, address, IBAN, logo, QR codes.
  • Your clients' information you add: name, contact, pets, sessions, invoices.

2. What Pongo does not do

  • Pongo never uses your data for its own purposes.
  • Never sold, never rented.
  • Never used for advertising.

3. Security

Your data is protected on several levels:

  • Account isolation: one professional's data is accessible only to them (strict isolation at the database level).
  • Encryption in transit: all exchanges use HTTPS.
  • Encryption at rest: stored data is encrypted (AES-256) by our infrastructure provider.
  • Backups: automatic daily backups are kept for 7 days.
  • Sign-in: by email and password, or via Google (your choice).
  • Certified infrastructure: our providers (Supabase, Vercel) hold recognized security certifications (SOC 2).
In normal operation, Pongo does not look at the content of your account: your clients, your pets, your invoices. What the admin panel shows me is aggregate usage statistics plus, per account, the name, the email address and a summary of activity (signup, last use, what was created — never what it contains); it does not show what you are doing in real time. The only time I would open your actual data is if you ask me for help — and always only to solve your problem.

4. Where your data is and who it's shared with

Your data is hosted in Switzerland (Zurich), with our infrastructure provider Supabase. To run the service, Pongo relies on a few technical providers:

SupabaseDatabase and storage — Switzerland (Zurich).
VercelApplication hosting (USA).
ResendSending invoices by email (USA).
StripePayment of your subscription (USA) — does not process your clients' data.
SentryError monitoring (USA) — technical diagnostics only: IP address, browser, error context and masked session recordings.
Photon / KomootAddress search (Germany) — only the typed address is transmitted.
GoogleOptional sign-in and display fonts.

Providers located outside Switzerland offer safeguards recognized by Swiss law; the US providers are certified under the Swiss-U.S. Data Privacy Framework. We comply with the Swiss nFADP and the European GDPR.

5. Your data belongs to you

  • Access: you can see all your data directly in the app.
  • Rectification: you can edit it at any time.
  • Portability: export all your data to Excel from Settings → Backup.
  • Deletion: write to us at contact@getpongo.app — we delete your account and all your data within 30 days (it may persist briefly in backups before permanent purge).

6. If something goes wrong

If a security breach affects your data, Pongo will inform you without delay. It is then up to you, as the controller, to decide whether to inform your clients or the authority (FDPIC).

7. Cookies

We only use technical cookies needed to keep you signed in. No tracking or advertising cookies.

8. Contact and governing law

Governing law: Swiss law. For any question about your personal data, write to us at contact@getpongo.app.