Privacy Policy
Effective Date: April 21, 2026
1. Regulatory Compliance
Pawdara is committed to protecting user privacy in accordance with applicable data protection laws including:
- PIPEDA (Personal Information Protection and Electronic Documents Act) for Canadian users.
- CalOPPA (California Online Privacy Protection Act) for California users.
- Applicable US federal and state privacy laws for all US users.
Pawdara is not subject to HIPAA as it handles veterinary records only, not human medical records.
2. Data We Collect
We collect the following categories of information:
- Account Information: Name, email address, phone number, and password hash.
- Pet Health Records: Species, breed, date of birth, vaccination history, medical notes, weight logs, and uploaded documents or photos.
- Clinic Information: Clinic name, address, license number, contact person, and number of veterinarians.
- Usage Data: Device type, operating system, app version, and interaction patterns to improve our services.
- Payment Information: Processed securely through our payment partner (Stripe). Pawdara does not store full credit card numbers.
3. How We Use Your Data
Your data is used to:
- Provide and maintain the Pawdara platform and its features.
- Facilitate communication between pet owners and veterinary clinics.
- Send appointment reminders and health notifications.
- Process subscription payments.
- Improve our services through aggregated, anonymized analytics.
- Comply with legal obligations.
4. Data Storage & Security
All data is stored on secure, encrypted servers hosted by Supabase (backed by AWS). We implement industry-standard security measures including:
- TLS/SSL encryption for all data in transit.
- Encryption for data at rest in accordance with our hosting provider's security standards.
- Data is isolated per account — only you and your authorized clinics can see your records.
- Periodic security reviews and vulnerability assessments.
5. Your Rights
Depending on your jurisdiction, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Deletion: You can delete your account at any time directly in the Pawdara app under Profile → Delete Account, or by contacting privacy@pawdara.com. Your personal data will be permanently removed within 30 days of your request.
- Portability: Export your data in a structured format. Export options available depend on your current subscription plan.
- Opt-Out: Unsubscribe from marketing communications at any time.
To exercise any of these rights, contact us at privacy@pawdara.com.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Pet health records are retained for as long as your account is active to preserve your pet's complete medical history. Upon account deletion, personal information is removed within 30 days, though anonymized analytics data may be retained.
7. Third-Party Services
We share data with the following categories of third parties:
- Supabase: Database hosting, authentication, file storage, and edge functions.
- Stripe: Payment processing for premium subscriptions.
- Apple / Google: In-app purchase processing, social sign-in, and push notification delivery (APNs / FCM).
- Expo: Mobile app build pipeline and push-notification relay.
- Resend: Transactional email delivery for notifications, reminders, and account communications.
- Cloudflare: Bot protection (Turnstile) on signup, contact, and password-reset forms.
- Vercel: Hosting for the web, clinic portal, and admin panel.
- Sentry: Application error monitoring and performance tracing (PII scrubbed before upload).
We do not sell your personal data to third parties. Data shared with service providers is limited to what is necessary to deliver our services.
All data is stored on servers located in the United States. Canadian users acknowledge that their data is stored and processed in the United States.
8. Do Not Track
Pawdara does not currently respond to browser Do Not Track signals as there is no industry standard for how to respond to such signals. We will update this policy if we implement Do Not Track support in the future.
9. Children's Privacy
Pawdara is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal data, we will delete it promptly.
10. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify affected users within 72 hours via email and in-app notification. We will also notify:
- The Office of the Privacy Commissioner of Canada as required by PIPEDA.
- Applicable US state authorities as required by state breach notification laws.
11. Contact Us
For questions or concerns about this Privacy Policy, please contact us at:
- Email: privacy@pawdara.com
- Support: support@pawdara.com
Mailing address: To be updated upon company incorporation. Canadian and US users may contact us at privacy@pawdara.com for all privacy-related inquiries.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify users via email or in-app notification and update the "Effective Date" at the top of this page. Continued use of Pawdara after changes constitutes acceptance of the updated policy.