Privacy Policy
Last updated September 18, 2026
This Privacy Policy describes how Houndtrust LLC (“Houndtrust,” “we,” “us”) handles personal information in connection with the Houndtrust software and websites (the “Service”). It applies to Providers (the independent dog-care professionals who use Houndtrust to run their business), to Clients (a Provider's customers, who use the Service at the Provider's invitation to share information, sign documents, or view updates), and to Visitors who use our public course, care-request, community, chat, or card-making features without a Provider account.
Our role: who controls the data
For a Provider's own account information, Houndtrust is the controller. For the Client and pet information a Provider collects through the Service (for example through an intake link or the owner portal), the Provider is the controller and Houndtrust acts as the Provider's service provider/processor - we process that information to provide the Service under our agreement with the Provider and the Provider's use and configuration of the Service. We also use limited data for a few narrow operational purposes of our own - keeping the Service secure, monitoring errors, understanding how it's used so we can improve it, and managing accounts and billing - and for those we act as our own controller. We never use your pet's care information to advertise to you, and we never sell it. If you are a Client with questions about your information, contact the dog-care professional you work with; we will help them respond. Houndtrust is the controller of information a Visitor gives us directly through a public Houndtrust feature.
For a Client card payment, the Provider is the merchant of record and controls the underlying care transaction and customer relationship. Stripe provides payment processing under its agreements with Houndtrust and the Provider. Stripe may act as a processor for the merchant and may also use payment data for its own legal, security, fraud-prevention, and service purposes as described in the Stripe Privacy Policy. Houndtrust acts as its own controller when it uses limited payment and risk information to secure the Service, enforce payment limits, and investigate misuse.
Information we collect
Before signup: when you submit the setup questionnaire, we save your email, selected services, business name if provided, progress, and reminder choice. We use these details to help you finish setup. If you opt in, we may send up to two signup reminders, at least seven days apart. Each includes an unsubscribe link. Saved pre-signup contacts expire after 30 days and are removed by our daily cleanup. Completing an account stops signup reminders; ordinary account records follow the retention rules below.
Provider account information: name, email, password (stored only as a secure hash), business details (business name, address, contact info), and subscription status.
Information entered into the Service: the client, pet, booking, service, and money information a Provider enters or that a Client submits through an intake link. This can include an owner's name, email, phone, and ZIP; a pet's care notes, medications, allergies, and veterinarian; emergency-contact details; and - because the Service is built for real-world care - security-sensitive details such as home-access or lockbox codes (which are stored for the Provider only) and signed waivers and authorizations.
Photos and files: update photos, logos, profile images, public care or community photos, card photos, and any documents a Client uploads (such as vaccination records or a photo of a form) are stored in our file storage. Client documents are private to the Client and Provider. Other images may appear through a unique shared link, on a published Provider profile, or publicly when the person submitting them chooses a public community or card feature.
Payment information: Stripe handles Provider subscriptions and optional Client card payments made to a Provider's connected account. Card details and the billing address are entered on Stripe's hosted checkout and pass directly to Stripe. Houndtrust does not receive or store full card numbers or card security codes. We receive transaction identifiers, amounts, tips, application fees, payment status, refund status, dispute status, payer contact details, Stripe risk results, and a one-way hash of Stripe's card fingerprint when available. We use that information to reconcile payment requests, show receipts, limit card testing, detect possible self-payments or stolen-card use, and review fraud reports.
Technical and audit information: standard server logs to keep the Service running and secure, and - for intake submissions and electronic signatures - an IP address and timestamp recorded as part of the audit trail for that record.
Public features: if you join the free course, make a card, post a care request, submit community content, or send feedback, we collect the information shown in that form. Depending on the feature, that may include an email address, phone number, name, ZIP or neighborhood, pet details, dates, a photo, and the words you submit. We also use limited IP, referral, and device information for security, rate limits, confirmation, and attribution.
Text-message information: if you choose text messages, we record the phone number, the wording you agreed to, when and where you agreed, and later STOP, START, or HELP requests. We also receive message identifiers, delivery status, and error codes from our text provider. We do not use Client phone numbers for Houndtrust marketing. We do not sell or share mobile phone numbers or text-message opt-in data with third parties or affiliates for marketing or promotional purposes. We disclose mobile information only to service providers needed to deliver and secure the text-message service, such as Twilio, as described below.
Walk location data: when a Provider chooses to track a walk, the browser records the walk's GPS route, distance, and duration on the Provider's device, only while tracking is on, and saves it with that update so the owner can see the route on their Stay Card. Location permission is asked for by the browser and can be declined - updates work fine without a walk. We never track location in the background or outside an active walk.
Attribution cookie: when you arrive from a referral or campaign link, we store a first-party cookie (for about 30 days) noting where the visit came from, so we can understand which channels bring people to Houndtrust. See “Cookies” below.
Your owner portal
If a Provider invites you, you can create a Houndtrust owner account to manage your pet's care in one place. When you do, we store your email address, whether it has been confirmed, and the secure sign-in tokens that keep you logged in. The account stays active between bookings so you can return to it; you can ask us or your Provider to close it at any time.
From the portal you can review and update your pet's details (such as feeding, medications, allergies, behavior, routine, vet, and emergency contact); send and receive messages with your Provider (we store these so you both have the history, and notify you by email when there's something new); request and track a stay, including its confirmation, agreement, payment, and review status; and upload documents such as vaccination records. Documents are stored in our file storage (Supabase, on Amazon Web Services in the U.S.) and shared only with your Provider. This information is handled under the same protections described in this Policy, and your Provider remains the controller of your pet's care information.
How we use information
- to provide, secure, maintain, and improve the Service;
- to sign Providers in and manage their accounts and subscriptions;
- to let Clients complete intake, sign documents, and view updates;
- to deliver public cards, care matching, community features, and requested course emails;
- to send service and transactional messages that a Client agreed to receive;
- to process and reconcile connected-card payments, prevent card fraud, and enforce payment limits;
- to understand how people find and use the Service; and
- to comply with law and enforce our Terms.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use Client data for our own marketing.
Text messages and your choices
Text messages are optional. If you check a text-message box, Houndtrust may send automated transactional texts on behalf of your Provider about requests, bookings, reminders, account notices, and pet-care updates. Message frequency varies. Message and data rates may apply.
Reply STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, or UNSUBSCRIBE to stop Houndtrust texts to your number, START to opt back in, or HELP for help. We keep a shared suppression record so a STOP request applies across Providers who use the Houndtrust messaging service. Opting out of texts does not stop email or in-app messages. You can also ask your Provider or email hello@houndtrust.com for help with your text preference.
AI features
Some features use Anthropic (the maker of Claude) to process text:
- the AI update writer sends the Provider's rough notes and the relevant pet's stored care details (such as name, personality, and routine) to Anthropic to draft an update message; and
- the “Pip” chat assistant, available to anyone using the chat widget, sends the messages you type to Anthropic to generate a reply;
- the calendar importer may send calendar event titles and descriptions to Anthropic to suggest clients, pets, services, and stays for the Provider to review; and
- the public care-request form sends the words entered in the request to Anthropic for automated safety screening before the request can be published. A person reviews flagged requests.
When an AI feature is used, Houndtrust sends the text described above to Anthropic so it can return the requested result. Anthropic's handling and retention are governed by Houndtrust's service configuration and agreement with Anthropic. Do not include information the feature does not need. AI output can be inaccurate, so review anything before you send it.
Service providers we share with
We share personal information only as needed with providers that help us run the Service:
- Supabase - our primary application database, authentication, and file storage, hosted on Amazon Web Services in the United States;
- Stripe - Provider subscription billing, connected-account onboarding, optional Client card payments, identity and bank verification, fraud screening, application fees, refunds, and disputes. Stripe receives the card and billing information entered in its checkout and handles it under the Stripe Privacy Policy;
- Resend - email delivery for service messages, portal invitations, new-message notifications, and the client reminders a Provider enables (it receives the recipient's email plus the pet/business names and booking details needed to send the message);
- Twilio - text-message delivery and opt-out handling (it receives the recipient's phone number, message content, and delivery information needed to provide the service);
- Anthropic - the AI features described above;
- Netlify - application hosting, request handling, and operational logs;
- Backblaze - encrypted, access-restricted disaster-recovery backups;
- GitHub - restricted automation used to create and verify encrypted disaster-recovery backups;
- Sentry - error and crash monitoring, configured to avoid collecting personal details from the content of your records;
- PostHog - limited product analytics. We configure it not to receive names, contact details, pet-care content, or capability-link tokens; it may receive the pseudonymous identifiers described below; and
- ImprovMX - forwarding for email sent to our support address; and
- browser push services selected by your browser or device, such as Apple, Google, or Mozilla, when a Provider turns on push notifications. They receive the device's push endpoint and encrypted notification data needed for delivery.
We also share information if required by law, to protect the Service or people's safety, or in connection with a merger, acquisition, or sale of assets (subject to this Policy).
Cookies and device storage
We do not use advertising cookies or cross-site tracking, and anonymous visitors to our marketing pages get no persistent analytics identifier. Here is everything the Service stores in your browser:
- Sign-in session - the cookies that keep Providers and portal users signed in (up to 60 days, extended as you use the Service). Strictly necessary.
- Sign-in helpers - short-lived cookies that remember the email you asked us to send a code to (15 minutes–1 hour), a tester code you redeemed (48 hours), and a just-typed intake form so an error doesn't wipe it (10 minutes; may briefly hold the form's contents).
- Setup helpers - an HttpOnly cookie keeps completed questionnaire answers and your entered email for one day. A separate private setup reference lasts up to 30 days so we can update your saved contact. These are not analytics identifiers.
- Attribution - first-party cookies noting which page, referral, or campaign sent a Provider to signup. They last up to 30 days, help us measure signup results, and credit Founding Circle referrals. They are never shared with ad networks.
- Analytics - on marketing and signup pages, PostHog (our product-analytics processor, U.S.) receives limited events such as page views and signup-button clicks with a temporary identifier held only in the open browser tab. It is not saved after the tab closes. Once a Provider signs in, PostHog sets a first-party identifier (up to 365 days) so we can see which product features get used and improve them. PostHog is configured conservatively: no automatic event capture, no session recording, page URLs stripped of tokens, and analytics events are sent to PostHog without Houndtrust sign-in cookies. Pet owners browsing update links are not given a persistent analytics identifier. For limited server-side signup and payment measurement, we may use a one-way, pseudonymous customer reference instead of a name or email. This is not anonymous in the strict sense because Houndtrust can connect the event to an account in its own systems.
- On-device only - a tracked walk's route stays on the Provider's device for 24 hours (so it can be attached to the next update), and small flags remember that you opened a card pack (90 days) or saw a welcome tour. These never leave your browser.
Two related disclosures: Stay Card walk maps load map tiles from CARTO / OpenStreetMap, so the tile server receives the viewer's IP address (as with any image loaded from the web). And if a page errors, Sentry may capture a short, heavily-masked replay of the screens around the error (text and inputs are masked before they leave the browser) to help us fix it.
Public and shared links
Some features create links you can share - for example a client “update” card at a unique web address. Anyone with that link can view it, so only share it with the people you intend. A Provider's logo, avatar, and business profile may also be public when the Provider publishes a profile. Owner-made cards become viewable to anyone with the unique share link after the submitter confirms their email. They appear in Houndtrust's public Community feed only if the submitter separately chooses “Show publicly” and moderation is complete. Public care requests and Community posts appear only after the applicable public-sharing choice and confirmation or moderation. Contact information and exact locations are not displayed.
Storage, security, and retention
Data is stored with row-level security so each account can reach only its own records. We keep information while an account is active. When a Provider deletes their account in Settings, there is a 30-day window to change their mind and recover it; after that window, we delete or anonymize the account's information from active systems, except where we must keep records longer. Encrypted disaster-recovery backups are immutable and age out on their existing schedule: daily copies after 35 days, weekly copies after 180 days, and monthly copies after 400 days. Backups are not used in ordinary operations. Before restored data returns to normal use, we apply our deletion controls to records that should no longer be active. In particular, signed waivers and authorizations may be retained separately as legal records (including the signer's IP and timestamp) while reasonably needed for legal obligations or claims, and tax-relevant billing records are kept as required by law. We also keep text-message consent, opt-out, and delivery records for as long as needed to honor messaging choices, resolve delivery issues, and meet legal or carrier requirements.
We keep connected-card receipts, application-fee records, refunds, disputes, fraud warnings, and related security records while reasonably needed to operate payment features, prevent repeat abuse, answer a dispute, enforce our Terms, or meet legal and financial obligations. We limit access to payment-risk records to Houndtrust systems and staff who need them. Card numbers and card security codes are not part of those records because Stripe collects them directly.
A public care request stops appearing as an open request after 30 days. Course subscriber records remain until you unsubscribe or ask us to delete them. Owner-made cards and public care or Community submissions remain until you ask us to remove them, Houndtrust removes or closes the feature, or a legal or security need requires longer retention. Related confirmation and moderation records may be retained to document the request, protect the Service, or resolve a dispute. We keep minimal unsubscribe and text opt-out records as needed to honor those choices.
Your privacy rights (U.S. states)
Depending on where you live and whether an applicable law covers Houndtrust, you may have rights to access, correct, delete, or obtain a portable copy of personal information, and to receive equal service when you exercise those rights. We do not sell personal information or use it for targeted advertising, so we do not currently offer an opt-out for those activities. If our practices change, we will provide and honor any opt-out method required by applicable law, including applicable browser-based preference signals.
Where Houndtrust processes Client data for a Provider, we use it to provide the Service under our agreement with the Provider and the Provider's use and configuration of the Service, and we assist the Provider with applicable requests.
If you have a Houndtrust account, you can handle two of these yourself in Settings: use Download my data for a portable copy of your provider identity and account business records, and delete your account there too. The export excludes security logs and authentication secrets. For other information or requests, email hello@houndtrust.com. We may need to verify your identity and the scope of the request before acting. If we deny a request and applicable law gives you an appeal right, reply to our decision and say that you want to appeal. If you are a Client, contact the dog-care professional you work with (the controller of your information); Houndtrust will assist them. Visitors who used a public feature can contact us directly.
Children
The Service is for businesses and is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child's information has been provided to us, contact us and we will delete it.
Where data is processed
Houndtrust is based in the United States. Our primary application database and uploaded files are hosted by Supabase on Amazon Web Services in the United States. Other providers listed above may process information in locations described in their applicable terms and subprocessor disclosures.
Changes to this Policy
We may update this Policy. If we make a material change we will give reasonable notice and update the “Last updated” date above.
Contact
Houndtrust LLC
Email: hello@houndtrust.com
Mailing address: Houndtrust LLC, 7533 S Center View Ct, Ste N, West Jordan, UT 84084