← Back to home

Privacy Policy

Last updated: 18 May 2026

1. Who We Are

Fetch Veterinary Ltd ("Fetch", "we", "us", or "our") operates the Fetch platform at fetchvet.co and associated mobile applications. Fetch is a UK-based marketplace that connects veterinary practices with locum veterinarians and veterinary nurses for shift cover.

We are the data controller for the personal data processed through our platform. This means we determine the purposes and means of processing your personal data and are responsible for ensuring that processing complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

If you have any questions about this Privacy Policy or our data practices, please contact us at [email protected].

2. Personal Data We Collect

We collect different categories of personal data depending on whether you are a locum veterinary professional or a veterinary practice representative.

2.1 Account and Identity Data

  • Full name, email address, and password (hashed with bcrypt)
  • Phone number and contact details
  • Profile photograph
  • Third-party sign-in identifiers, if you register or sign in via a supported OAuth provider (currently Google, Apple, and Microsoft; legacy LinkedIn identifiers may be retained on accounts created before LinkedIn sign-in was retired). We store only the provider-issued user ID and the email address associated with that account.
  • Passkey credentials (WebAuthn public keys) if you register a passkey. The private key never leaves your device.
  • Two-factor authentication (2FA) secrets (encrypted) and one-time recovery codes, if you or your practice administrator enable 2FA
  • Device fingerprints (IP address and User-Agent) attached to each refresh token to detect anomalous re-issuance — when both the network and the device class change at once between a token issue and its refresh, we email the account owner and write a security audit-log entry (described in Section 2.5)

2.2 Professional Data (Locum Users)

  • RCVS registration number (7-digit number verified against the RCVS public register)
  • Profession type (veterinarian or veterinary nurse)
  • Business structure (sole trader or limited company) and VAT registration status
  • Years of experience and specialisations
  • Professional indemnity insurance documents
  • Right to work documentation
  • RCVS registration certificates
  • Identity verification documents and CV
  • AI-generated document analysis results (e.g., extracted expiry dates, readability flags, consistency checks)

2.3 Practice Data

  • Practice name, address, and postcode
  • Practice phone number and contact details
  • Animal types treated and practice specialisations
  • Multiple location details (for multi-site practices), including proof-of-address documentation for location verification
  • Default hourly and daily rates
  • Team membership records (names, email addresses, and roles for invited staff)
  • IR35 status determinations and practice-locum relationship notes

2.4 Financial Data

  • Bank account details for locum profiles (encrypted at rest)
  • Subscription billing information (processed and stored by Stripe; we do not store full card numbers)
  • Shift rates and booking financial summaries

2.5 Technical and Usage Data

  • Device information (device type, operating system, app version)
  • IP address and approximate location derived from it
  • Geolocation data (with your explicit consent, for nearby shift search and shift check-in)
  • Device fingerprint records attached to refresh tokens (IP address and User-Agent), retained for the lifetime of the refresh token and compared on each refresh — a substantial mismatch in both network and device class triggers an email alert to the account owner
  • Push notification tokens (Expo push tokens on mobile, Web Push subscriptions on web)
  • Authentication tokens stored in browser local storage (web) or the OS keychain / encrypted secure storage (mobile)
  • Product analytics events via PostHog (for example, page views and feature-usage events)
  • Error and crash data (collected via Sentry for debugging purposes)

2.6 Communications Data

  • Messages exchanged between users through the in-app messaging system
  • Notification preferences and history
  • Support correspondence

2.7 Booking and Shift Data

  • Shift details (dates, times, locations, rates, requirements)
  • Booking history and status records
  • Check-in timestamps and location data
  • Hours worked confirmations
  • Reviews and ratings
  • Cancellation records and reliability metrics

3. How We Collect Your Data

We collect personal data through the following means:

  • Directly from you: When you register an account, complete your profile, post or apply for shifts, send messages, upload documents, refer a friend, invite team members, or contact us for support.
  • Automatically: When you use our platform, we automatically collect technical data such as device information, IP addresses, and usage patterns. Geolocation data is collected only with your explicit consent.
  • From third parties: We may receive payment confirmation data from Stripe, authentication data from a supported OAuth provider (currently Google, Apple, and Microsoft) if you use third-party sign-in, and registration status data from the RCVS public register to verify professional credentials.

Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following legal bases:

4.1 Performance of a Contract (Article 6(1)(b))

Processing necessary to provide our marketplace services, including account management, shift matching, booking management, messaging between users, and processing subscription payments.

4.2 Legitimate Interests (Article 6(1)(f))

Processing necessary for our legitimate interests, provided those interests are not overridden by your rights. This includes platform security and fraud prevention, service improvement and analytics, error monitoring and debugging, and enforcing our terms of service (including the cancellation policy and reliability ratings).

4.3 Legal Obligation (Article 6(1)(c))

Processing necessary to comply with our legal obligations, including financial record-keeping requirements (six-year retention), responding to law enforcement requests, and compliance with employment and tax reporting regulations.

4.4 Consent (Article 6(1)(a))

Where we rely on your consent, such as for geolocation data collection, push notifications, non-essential analytics (PostHog), and marketing communications (if applicable). You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

4.5 Special-Category Data (Article 9)

Some verification documents you upload — in particular, right-to-work documents such as passports and residence permits — may reveal data from which racial or ethnic origin could be inferred. Where such documents contain special-category data, we rely on Article 9(2)(b) UK GDPR(processing necessary for the purposes of carrying out the obligations of, and exercising specific rights of, the controller or of the data subject in the field of employment, social security, and social protection law, as authorised by the Data Protection Act 2018). As required by Schedule 1, Part 4 of the DPA 2018, we maintain an Appropriate Policy Document setting out our procedures for compliance with the data-protection principles and our retention and erasure policies for this category of data. A copy is held internally and is available to the Information Commissioner's Office on request. We do not use right-to-work data for any purpose other than verifying eligibility to work and compliance with UK immigration law.

We do not currently carry out criminal-record checks or process criminal-offence data (Article 10 UK GDPR). If we ever introduce them (for example, DBS checks), we will update this policy and, where required, obtain the additional lawful basis and consents required by section 10 and Schedule 1, Part 3 of the DPA 2018.

5. How We Use Your Data

We use your personal data for the following purposes:

  • Account management: Creating and maintaining your account, authenticating your identity (including passkey registration, 2FA verification, and session security via device fingerprints), and managing your profile.
  • Password security: When you set or change a password, we check its SHA-1 hash prefix against the Have I Been Pwned breach database (using their anonymised k-anonymity API) to prevent re-use of known-compromised passwords. The full password is never transmitted.
  • Marketplace operations: Matching locum professionals with shift opportunities, facilitating bookings and rate negotiations, enabling in-app messaging between practices and locums, and processing post-shift hours confirmations.
  • Verification: Verifying RCVS registration status in real time via the RCVS public register, analysing uploaded documents with Anthropic's Claude Vision model to check document type, readability, expiry, and consistency, and validating professional documentation to maintain platform trust and safety.
  • Geospatial matching: Using your location (with consent) to show nearby shifts, calculate distances for shift search results, and record your check-in location when you arrive at a shift.
  • Billing: Processing practice subscription payments through Stripe, managing Free, Starter and Pro tier entitlements, tracking per-location shift quotas, and issuing invoices.
  • Notifications: Sending push notifications (mobile via Expo, web via VAPID Web Push) and emails (via Resend) about booking updates, shift reminders, check-in reminders, new messages, urgent shift alerts, team invites, and document-expiry warnings.
  • Team and referral features: Enabling practices to invite staff members by email, tracking referral codes between users, and calculating practice-locum relationship tiers based on completed bookings.
  • Safety and integrity: Enforcing our cancellation policy, calculating reliability ratings, detecting fraud or misuse (including suspicious session activity flagged by device fingerprinting on refresh), moderating reviews under Terms §15, and rate-limiting requests to prevent abuse.
  • Service improvement: Monitoring errors and crashes via Sentry, analysing usage patterns via PostHog (in aggregate), and improving platform performance and user experience.

6. Data Sharing and Third-Party Processors

We do not sell your personal data. We share personal data only as described below and only to the extent necessary for the stated purposes.

6.1 Between Platform Users

When a booking is made, relevant profile information (name, contact details, practice location, professional qualifications) is shared between the practice and the locum to facilitate the engagement. Messages sent through our platform are visible to conversation participants.

6.2 Third-Party Data Processors

We use the following third-party service providers who process personal data on our behalf under data processing agreements:

ProcessorPurposeLocationSafeguard
NeonPostgreSQL database hostingUnited StatesUK-US Data Bridge
StripeSubscription billing and payment processingUnited StatesUK-US Data Bridge
Cloudflare R2File storage (documents, profile images)Global (edge locations)Standard contractual clauses
SentryError tracking and crash reportingUnited StatesUK-US Data Bridge
ExpoPush notification delivery (mobile)United StatesUK-US Data Bridge
ResendTransactional email deliveryUnited StatesUK-US Data Bridge
UpstashRate limiting (Redis)United StatesUK-US Data Bridge
InngestBackground job processingUnited StatesUK-US Data Bridge
AnthropicAI-powered verification document analysis (Claude Vision)United StatesUK-US Data Bridge
PostHog (EU)Product analytics and feature-usage eventsEuropean Union (Frankfurt)UK adequacy decision for the EEA
RailwayWeb and API application hostingUnited StatesUK-US Data Bridge
RCVS public registerReal-time verification of RCVS registration number (we send the number, not personal data)United KingdomN/A (UK)
Have I Been PwnedAnonymised password-breach check (k-anonymity: only a SHA-1 hash prefix is sent)United Kingdom / Global CDNN/A (anonymised)
Apple Push Notification servicePush notification delivery to iOS devices (via Expo)United StatesUK-US Data Bridge
Google (Firebase Cloud Messaging)Push notification delivery to Android devices (via Expo)United StatesUK-US Data Bridge

6.3 Legal Disclosures

We may disclose your personal data if required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

7. International Data Transfers

Several of our third-party processors are located in the United States. We ensure that any transfer of personal data outside the United Kingdom is protected by appropriate safeguards as required by UK GDPR, including:

  • UK-US Data Bridge: For US-based processors that are certified under the UK Extension to the EU-US Data Privacy Framework, providing an adequacy basis for transfers.
  • Standard Contractual Clauses (SCCs): Where the Data Bridge is not available, we use UK International Data Transfer Agreements or Addenda to EU SCCs approved by the Information Commissioner's Office (ICO).
  • Supplementary measures: Including encryption in transit and at rest, access controls, and contractual obligations regarding data security.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:

  • Active accounts: Profile data, booking history, and messages are retained for the duration of your account.
  • Account deletion: Upon requesting account deletion, we initiate a 30-day cooling-off period during which you may reactivate your account. After 30 days, personal data is permanently deleted or anonymised, except where retention is required by law.
  • Financial records: Billing and transaction records are retained for six years from the date of the transaction, as required by HMRC record-keeping obligations.
  • Verification documents: Identity documents and professional certificates are retained for the duration of your account and deleted upon account closure (subject to the 30-day cooling-off period).
  • Error logs: Crash reports and error data in Sentry are retained according to our Sentry plan's default retention (typically 90 days), after which they are deleted by Sentry.
  • Anonymised data: We may retain data indefinitely only where it has been genuinely anonymised — that is, where it cannot reasonably be re-identified by us or by any other person, including by means of combining it with other information in our possession or likely to come into our possession (the "motivated-intruder" test described in ICO guidance). Pseudonymised data that could be re-linked to you is treated as personal data and retained according to the rules above, not indefinitely.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Passwords hashed using bcrypt with 12 salt rounds. Minimum 12-character passwords are required and checked against the Have I Been Pwned breach database (NIST SP 800-63B compliant)
  • Optional passkey authentication (WebAuthn / FIDO2) using public-key cryptography — your private key never leaves your device
  • Optional two-factor authentication (2FA) via time-based one-time passwords (TOTP), which practice administrators may require for all practice team members (enforced on next sign-in)
  • JWT-based authentication with short-lived access tokens (15 minutes) and longer-lived refresh tokens (30 days)
  • Device fingerprinting on refresh tokens to detect anomalous session activity (when both the network and the device class change between issue and refresh, an alert email is sent to the account owner)
  • Bank details encrypted at rest in the database (AES-256)
  • HTTPS / TLS encryption for all data in transit
  • Private file storage on Cloudflare R2 with short-lived presigned URLs (15-minute expiry). Files are never exposed publicly.
  • Rate limiting on API endpoints (100 requests per minute general, 5 requests per minute for authentication) to prevent brute-force attacks
  • Input validation and SQL injection prevention via parameterised queries
  • CORS configuration to restrict cross-origin requests
  • Secure file uploads with type and size restrictions (10MB maximum; jpeg, png, webp, and pdf only)
  • Mobile app uses encrypted secure storage (iOS Keychain / Android Keystore) for authentication tokens

While we take all reasonable precautions, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security of your data.

9.1 Personal Data Breach Notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it, as required by Article 33 UK GDPR. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by Article 34 UK GDPR, with a description of the breach, its likely consequences, the measures we have taken or propose to take, and contact details for further information.

10. Your Rights

Under UK GDPR, you have the following rights regarding your personal data. To exercise any of these rights, please contact us at [email protected].

  • Right of access (Article 15): You have the right to request a copy of the personal data we hold about you. The fastest way is to download a self-service JSON export from Settings → Export your data (web) or the matching screen in the mobile app; alternatively, email us and we will respond within one month of receiving your request.
  • Right to rectification (Article 16): You may request correction of inaccurate personal data. You can also update most of your data directly through your profile settings.
  • Right to erasure (Article 17): You may request deletion of your personal data, subject to our legal retention obligations (e.g., six-year financial records). Account deletion includes a 30-day cooling-off period.
  • Right to restrict processing (Article 18): You may request that we restrict processing of your data in certain circumstances, such as while we verify the accuracy of contested data.
  • Right to data portability (Article 20): You may download your personal data in a structured, commonly used, machine-readable JSON format from the in-app data-export screen (see right of access above) at any time.
  • Right to object (Article 21): You may object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent: Where processing is based on consent (e.g., geolocation, push notifications), you may withdraw consent at any time through your device settings or by contacting us.

We will respond to all valid requests within one month. In complex cases, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it.

11. Cookies and Local Storage

Our web application uses browser local storage for essential functionality (authentication tokens) but does not use third-party tracking cookies. For full details, please see our Cookie Policy.

12. Children and Age Restrictions

Fetch is a professional marketplace for qualified veterinary professionals. Our platform is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that we have collected data from a person under 18, we will take steps to delete that data promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on our platform with a revised "Last updated" date. Where changes are significant, we may also notify you by email or through an in-app notification.

We encourage you to review this policy periodically. Your continued use of the platform after changes are posted constitutes acceptance of the updated policy.

14. Contact and Complaints

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF