Privacy

Last updated 7 September 2026

Bloomtag is an NFC tag for pets. When someone finds your pet and taps the tag, a page with your contact details opens on their phone — that is the whole product, and it means some of your information is public by design. This page says exactly what we keep, who can see it, for how long, and what you can do about it.

What you give us when you activate a tag

The profile you fill in: your pet’s name, breed, birth date (or as much of it as you know) and weight (with its unit); your name, phone number, email, city and the languages you speak; a trusted contact’s name, phone, relation to you, languages, messengers and a note; health details you choose to add (allergies, medication, rabies vaccination date, microchip number); sex, colour and marks; a vet clinic and its phone; any notes; and up to three photos. Only the pet’s name and your phone are required.

To sign in you use Google, Apple or a link sent to your email. We keep the email address that sign-in gives us and nothing else from that account.

What a finder sees

Everyone who taps the tag, or has its link, sees the profile: the pet (including sex, colour and marks), your name, phone, email, city and languages, your trusted contact’s name, phone, languages, messengers and note, the health details you added (allergies, medication and whether it is needed regularly, rabies vaccination date, microchip number), the vet, the notes, and the portrait and side-view photos. No sign-up, no app — a stranger with your dog on a lead must be able to call you at once.

The nose close-up is different. It is private: stored separately, with no public link at all, visible to you only. It exists to help confirm the pet is yours if that is ever needed.

What we record when a tag is read

  • the time, and what the reader got: a profile, an activation screen, an unknown tag, or an inactive one;
  • the country and city, as our hosting provider resolves them from the connection — we never look up an address ourselves;
  • the kind of device, from what the browser sends (roughly “iPhone or Android”);
  • a salted hash of the network address — never the address itself. The hash lets us count how many different phones read a tag; it cannot be turned back into an address.

We use this for support — “which tag did the customer actually tap?” — and to understand how often tags are used. It is not shared and not sold.

Photos

Photos are re-encoded in your browser before they are uploaded. The location your camera embeds in a picture (EXIF, including GPS) is removed in that step and never reaches us.

The portrait and side view are served from a link with an unguessable name; whoever has the link can open the picture, which is the same rule as the profile itself. The nose photo is served from a private store and can only be opened by you.

How long we keep things

  • Your profile and photos: for as long as the tag is active.
  • A deleted profile: 30 days, so you can restore it if you change your mind. During those days the tag stays yours and shows nobody anything. After 30 days the profile and its photos are erased.
  • Tag-read records: 12 months, then deleted.

What you can do

  • Change anything from your profile’s edit page, at any time.
  • Remove a photo, or all of them.
  • Delete the profile; restore it within 30 days.
  • Ask us to erase your data sooner, or to send you what we hold, at hello@bloomtag.me.

Who processes data for us

Supabase stores the database, the photos and the sign-in. Vercel hosts the site and resolves the country and city of a connection. We use no advertising trackers and no analytics beyond the tag-read records above.

Changes

When this notice changes, the date at the top changes with it. Questions and requests: hello@bloomtag.me.