Who is responsible for your information
The person or business operating Toe Beans Pet Care is expected to be the data controller for enquiries made through this website. The owner’s verified legal or trading identity, postal address and dedicated privacy contact have not yet been supplied. They must be added here before launch; this notice does not invent them.
While the site remains in preparation, a privacy query can be started through the website enquiry form. Please include only what is needed to identify the request and do not send identity documents unless the owner securely asks for them.
Information the website is designed to handle
Information you provide
- Your name and email address.
- An optional phone number and your preferred way to be contacted.
- The service you are interested in and the message you write.
- Your acknowledgement of the privacy notice.
Operational and security information
The service records submission and update times, enquiry status, whether an anti-spam check succeeded, and a limited deduplication value used to reduce accidental repeat submissions. Hosting and security providers may process routine request information such as IP address, browser details and diagnostic events. The application is designed not to write complete enquiry messages, contact details or secret tokens to its logs.
The enquiry form contains a hidden anti-bot field and a minimum-completion-time check. These are used only to distinguish likely automated submissions.
Why information may be used
- To read, respond to and manage a pet-care enquiry.
- To take steps requested before a possible service agreement.
- To protect the form, website and business from spam, misuse and fraud.
- To keep necessary business records and meet applicable legal duties.
The final lawful bases have not been approved. Depending on the owner’s circumstances, they may include steps before entering a contract, legitimate interests in operating and securing the service, consent for genuinely optional communications, or a legal obligation. Ticking the privacy box confirms that you have seen this notice; it should not automatically be treated as consent for every use or for marketing.
The starter website does not include a marketing mailing list, behavioural advertising or automated decisions about customers. Personal information should not be sold.
Where information is kept and for how long
Enquiries are stored in a Cloudflare D1 database with a new, read or handled status. Access is intended to be limited to authenticated administrators. Optional email notifications do not replace the database record.
A retention schedule is still required
No automatic deletion period should be assumed from this draft. Records may remain until an authorised administrator removes them under the owner’s future retention procedure. Before launch, the owner must choose and document proportionate periods for unanswered enquiries, completed work, declined enquiries, backups and any legally required records.
When information is no longer needed, the owner should securely delete or anonymise it, subject to any genuine legal need to retain a limited record.
Hosting and optional service providers
Suppliers should receive only the information needed for their role and must not be presented as active until the owner configures them. Their own infrastructure may involve processing outside the United Kingdom. The owner must confirm the actual suppliers, contracts and any required international-transfer safeguards before launch.
Cloudflare hosting and storage
Cloudflare Workers serves the website, D1 stores structured content and enquiries, and R2 may store owner-uploaded media. Cloudflare also supplies network security and may process routine connection data.
Cloudflare Turnstile
If configured, Turnstile evaluates whether a form submission appears human. Its short-lived token is verified on the server and is not intended to be retained as enquiry content. Cloudflare may process IP, browser and interaction signals for this check. If it is not configured, the local starter uses its documented development behaviour and other anti-spam checks.
Email notifications
If the owner enables the optional outbound-email adapter, enquiry details are sent to the configured email provider and recipient so the owner can respond. Copies in the recipient mailbox follow that mailbox’s security and retention settings. If email is absent or fails, the D1 record remains the source of truth.
Facebook content and links
If connected, the server may fetch public posts from the owner’s Facebook Page and cache a normalised copy. The website does not need the Facebook JavaScript SDK or a Facebook tracking iframe to display those cards. Selecting “View on Facebook” takes you to Meta’s service, where Meta’s own privacy terms apply. Without credentials, editable local cards are shown instead.
How information is protected
The planned safeguards include encrypted HTTPS transport, prepared database statements, server-side validation, restricted administrative routes, Cloudflare Access identity checks, origin and cross-site-request protections, and secret values held outside the browser and repository. No online service can promise absolute security, so access, backups and incident procedures still require ongoing owner review.
Your choices and privacy rights
Depending on the law and circumstances, you may be able to ask for access to your personal information, correction, deletion, restriction, portability, or to object to certain uses. Where a use relies on consent, you may withdraw that consent without affecting earlier lawful processing. Identity may need to be checked proportionately before fulfilling a request.
If UK data-protection law applies and a concern is not resolved, you may be entitled to complain to the Information Commissioner’s Office. Seeking an answer from the business first can sometimes resolve the issue more quickly, but it should not remove any right to contact a regulator.
Children and changes to this notice
The service is intended for adults arranging pet care and is not designed to collect children’s information. Please do not submit information about a child unless it is genuinely necessary and lawful for the requested service.
This notice should be updated when contact details, suppliers, service processes or legal requirements change. Material changes should be made clear, and the review date above should be updated.
Ask a privacy question
A verified privacy email or postal address has not yet been provided. It must replace this temporary route before public launch. For the preparation-stage site, begin through the enquiry form and write “Privacy request” at the start of the message.
Open the enquiry form