Your data. Your pet. Your rules.
Last updated: November 1, 2026
MediCard Pets (“we”, “us”), a venture by MAJ Medias, is built on one principle: your pet's medical information belongs to you. This policy explains, in plain language, what we collect, how we protect it, who can see it, and the rights you have over it. Questions? Email support@medicard.co.in.
1. What we collect
- Account info — email address and OAuth identifier (Google) when you sign in.
- Pet profile — name, species, breed, date of birth, color, gender, allergies, medical conditions, behavior and food preferences.
- Owner contact — owner name, phone and email used on the QR profile for lost-pet recovery.
- Medical records — vaccinations, deworming, medications, doctor visits and uploaded reports.
- Uploaded images — pet photos and scanned documents you choose to add.
- Minimal technical data — authentication tokens and error logs strictly required for security.
We do not collect precise location, advertising identifiers, contacts, or background sensor data.
2. How your data is stored
- TLS 1.2+ encryption in transit; disk encryption at rest.
- Row-level security so one account can never read another's records.
- Isolated storage buckets with per-user access policies for uploads.
- Hosted on enterprise-grade cloud infrastructure.
3. The QR profile
The QR code on your MediCard tag links to a read-only public profile of your pet. Anyone with the link (or who scans the tag) can view it — that is the purpose of a lost-pet card. Owner PII (phone/email) is only surfaced when Lost Pet Mode is enabled. You can rotate or disable the QR profile at any time.
4. Payments
Paid plans (e.g. adding additional pets at ₹399/year) are processed by our payment partner Razorpay. We do not store your card, UPI, or bank details on our servers. Razorpay's processing is governed by their own privacy policy at razorpay.com/privacy.
5. Service providers
- Managed backend, database & storage — Supabase.
- Payments — Razorpay Software Pvt. Ltd.
- OAuth — Google, only when you choose to sign in.
- Email delivery — magic links and transactional email.
Each provider is bound by a data processing agreement and acts only on our instructions.
6. Your rights
You may at any time access, correct, delete, or export your data from inside the app or by writing to us. Deleting your account permanently removes pet profiles, records and uploads within 30 days from active systems and within 90 days from encrypted backups. Under the DPDP Act (India), GDPR (EU/UK) and CCPA (California) you have additional statutory rights which we honor globally.
7. Data retention
We keep your data only while your account is active or as required by law. Inactive accounts (24 months) are permanently deleted.
8. Children
MediCard Pets is not directed to children under 13. The account holder is responsible for all data on the account.
9. Security incidents
If we discover a breach affecting your data, we notify you by email without undue delay and within 72 hours where required by law.
10. Veterinary disclaimer
MediCard Pets is an organization tool, not a veterinary device and does not provide veterinary advice. Always confirm critical health information with a qualified veterinarian.
11. Changes
Material changes are notified in-app and by email at least 14 days before they take effect.
12. Contact
MAJ Medias, Mumbai, India — support@medicard.co.in. We respond within 7 business days.
