Privacy Policy

Effective Date: December 13, 2025

Your Privacy Matters

We protect your personal information and handle your data responsibly. We do not sell your personal data to third parties. This policy applies globally to all users of Wagabond Pets.

1. Information We Collect

Account Information

  • Email address and name (via Clerk authentication)
  • Profile photo (optional)
  • Location (city/country for service optimization)
  • Subscription and payment information (via Stripe or Apple In-App Purchase)

Pet Information

  • Pet profiles: name, breed, age, weight, microchip ID
  • Medical records: vaccinations, medications, diagnoses, appointments
  • Uploaded documents: vet records, lab results, prescriptions
  • Health tracking: weight history, medication schedules

Usage Information

  • Features used and interaction patterns
  • Device information and browser/app type
  • IP address and approximate location
  • Shared record access logs
  • Error reports and crash logs

Information We Do NOT Collect

  • Precise GPS location (we only collect city/region level)
  • Contacts from your device
  • Photos beyond what you explicitly upload
  • Data from other apps on your device

2. How We Use Your Information

To Provide Our Service

  • Store and organize pet health records
  • Process and extract data from your documents using AI
  • Send medication and vaccination reminders
  • Generate secure sharing links
  • Process payments and manage subscriptions

To Improve Our Service

  • Analyze usage patterns to enhance features
  • Debug issues and improve performance
  • Develop new features based on user needs
  • Train AI models using anonymized, aggregated data only

To Communicate With You

  • Send important service updates and new feature announcements
  • Notify you of security alerts and critical bug fixes
  • Provide account and billing notifications
  • Share tips for using Wagabond Pets effectively

You can unsubscribe from non-essential emails via your account settings, but will continue to receive critical service and security notifications.

We process your personal data based on the following legal grounds:

Processing ActivityLegal Basis
Account creation and managementContract performance
Storing and organizing pet recordsContract performance
Processing paymentsContract performance
Document processing with AI (OCR)Contract performance + Consent
Security monitoring and fraud preventionLegitimate interest
Service improvement analyticsLegitimate interest (with opt-out)
Marketing communicationsConsent (with opt-out)
Crash reports and error trackingLegitimate interest

4. Automated Processing & AI

AI Document Processing

When you upload veterinary records, we use AI (Azure Document Intelligence) to automatically extract information like vaccination dates, medication names, and dosages. This is automated decision-making that affects how your data is organized.

How Automated Processing Works

  • Documents are processed by Microsoft Azure AI services
  • Extracted data is presented for your review and correction
  • You can edit or delete any extracted information
  • Original documents are always preserved

Your Rights Regarding Automated Processing

  • You can request human review of automated decisions
  • You can contest and correct any extracted data
  • You can opt out of AI processing (manual entry only)
  • Contact us to exercise these rights

5. Data Storage & Security

  • Data encrypted at rest and in transit (TLS 1.3+)
  • Stored on secure Google Cloud Storage with signed URLs
  • Database hosted on Neon PostgreSQL with automatic backups
  • Access controls and audit logging for all data access
  • Regular security audits and vulnerability assessments
  • SOC 2 compliant infrastructure providers

Data Location

Your data is primarily stored in the United States. We use globally distributed infrastructure for performance, but personal data remains in US data centers unless otherwise specified for your region.

6. Data Sharing

We Do Not Sell Your Data

Your personal data is never sold to third parties. This includes your name, email address, payment details, pet information, and any data that identifies you. We do not share data for third-party advertising purposes.

When We Share Information

  • With your consent: Via time-limited sharing links you create
  • Service providers: Essential third parties who help us operate:
    • Clerk (authentication)
    • Stripe (payment processing)
    • Apple (in-app purchases, iOS only)
    • Google Cloud (file storage)
    • Microsoft Azure (document processing)
    • Neon (database hosting)
    • Sentry (error monitoring)
    • SendGrid (email delivery)
  • Legal requirements: If required by law, court order, or government request
  • Business transfers: In connection with a merger, acquisition, or sale of assets (with notice)

Service Provider Requirements

All service providers are contractually required to:

  • Process data only for specified purposes
  • Maintain appropriate security measures
  • Delete data upon termination of services
  • Not use data for their own purposes

7. International Data Transfers

Your data may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards for international transfers through:

  • Standard Contractual Clauses (SCCs): EU-approved data transfer agreements
  • Data Processing Agreements: Binding contracts with all processors
  • Adequacy decisions: Transfers to countries with adequate protection where applicable
  • Supplementary measures: Additional technical and organizational protections

Transfer Impact Assessments

We conduct transfer impact assessments to evaluate the legal framework in recipient countries and implement additional safeguards where necessary.

8. Your Rights

Universal Rights (All Users)

  • Access: View all data we have about you and your pets
  • Correction: Update or correct inaccurate information
  • Deletion: Delete your account and all associated data
  • Portability: Export your data in standard formats (JSON, PDF, CSV)
  • Withdraw consent: Revoke consent for optional processing
  • Opt-out: Unsubscribe from marketing communications

How to Exercise Your Rights

  • In-app: Settings → Privacy → Your Data Rights
  • Email: privacy@wagabondpets.com
  • Mail: Wagabond Pets, Privacy Team, P.O. Box 304, San Angelo, TX 76901

We respond to all requests within 30 days. Complex requests may take up to 45 days with notice.

9. Regional Privacy Rights

European Union & EEA (GDPR)

Additional Rights for EU/EEA Residents:

  • • Right to restrict processing
  • • Right to object to processing based on legitimate interests
  • • Right not to be subject to automated decision-making with legal effects
  • • Right to lodge a complaint with your local Data Protection Authority

Supervisory Authority: You may contact your local Data Protection Authority. A list is available at edpb.europa.eu

United Kingdom (UK GDPR)

UK Resident Rights:

  • • Same rights as GDPR (access, correction, deletion, portability, objection)
  • • Right to lodge a complaint with the Information Commissioner's Office (ICO)
  • • UK-specific Standard Contractual Clauses (International Data Transfer Agreement) apply

Contact ICO: ico.org.uk | 0303 123 1113

Brazil (LGPD)

Direitos dos Residentes Brasileiros:

  • • Confirmação da existência de tratamento de dados
  • • Acesso, correção e exclusão de dados pessoais
  • • Portabilidade de dados para outro fornecedor
  • • Informação sobre compartilhamento com terceiros
  • • Revogação do consentimento
  • • Direito de peticionar à ANPD

Autoridade Nacional: Autoridade Nacional de Proteção de Dados (ANPD) - gov.br/anpd

California, USA (CCPA/CPRA)

California Resident Rights:

  • • Right to know what personal information is collected, used, and shared
  • • Right to delete personal information
  • • Right to correct inaccurate personal information
  • • Right to opt-out of sale/sharing (Note: We do not sell or share your data)
  • • Right to limit use of sensitive personal information
  • • Right to non-discrimination for exercising your rights

Do Not Sell or Share: We do not sell or share personal information for cross-context behavioral advertising.

Canada (PIPEDA)

Canadian Resident Rights:

  • • Right to access your personal information
  • • Right to challenge accuracy and have it corrected
  • • Right to know how your information is being used
  • • Right to withdraw consent (subject to legal restrictions)
  • • Right to complain to the Privacy Commissioner of Canada

Privacy Commissioner: priv.gc.ca | 1-800-282-1376

Australia (Privacy Act 1988)

Australian Resident Rights:

  • • Right to know what information we hold about you
  • • Right to access your personal information
  • • Right to request correction of inaccurate information
  • • Right to complain about privacy breaches
  • • Right to opt-out of direct marketing

OAIC: Office of the Australian Information Commissioner - oaic.gov.au | 1300 363 992

Japan (APPI)

日本居住者の権利:

  • • 保有個人データの開示請求権
  • • 内容の訂正、追加、削除の請求権
  • • 利用停止・消去の請求権
  • • 第三者提供の停止請求権
  • • 利用目的の通知請求権

個人情報保護委員会: ppc.go.jp

South Korea (PIPA)

대한민국 거주자의 권리:

  • • 개인정보 열람권
  • • 개인정보 정정·삭제권
  • • 개인정보 처리정지권
  • • 개인정보 이동권
  • • 자동화된 결정에 대한 거부권

개인정보보호위원회: pipc.go.kr | 118

Singapore (PDPA)

Singapore Resident Rights:

  • • Right to access your personal data
  • • Right to correct errors or omissions
  • • Right to withdraw consent at any time
  • • Right to request data portability
  • • Right to complain to PDPC about breaches

PDPC: Personal Data Protection Commission - pdpc.gov.sg

Other Regions

For users in other countries, we apply GDPR-equivalent protections as our baseline standard. If your country has specific data protection laws, please contact us and we will accommodate your rights under applicable law.

10. Children's Privacy

Age Requirements

Wagabond Pets is not intended for children. Minimum age requirements vary by region.

RegionMinimum AgeParental Consent
United States13 yearsRequired for ages 13-17
European Union16 years (varies by country)Required below threshold
United Kingdom13 yearsRequired for ages 13-17
South Korea14 yearsRequired under 14
Other Regions13 years (default)Recommended for minors

We do not knowingly collect personal information from children below the applicable age. If we discover we have collected data from a child without proper consent, we will delete it promptly. Parents or guardians may contact us to request deletion of their child's data.

11. Data Retention

Data TypeRetention PeriodAfter Account Deletion
Account informationWhile account is activeDeleted within 30 days
Pet records & filesWhile account is activeDeleted within 30 days
Payment records7 years (legal requirement)Retained for tax/legal
Server logs90 daysAuto-deleted
Analytics data1 yearAnonymized immediately
Backups30 days rollingPurged within 90 days

Inactive Accounts

Accounts inactive for 3 years may be scheduled for deletion. We will send email warnings at 2 years and 2.5 years before any action is taken.

12. Cookies & Tracking

We use minimal cookies for essential functions. See our full Cookie Policy for details.

Summary

  • Essential cookies: Required for login and security (cannot be disabled)
  • Functional cookies: Remember your preferences (can be disabled)
  • Analytics: Help us improve the service (opt-out available)
  • Advertising: We do not use advertising cookies

App Tracking (iOS)

Our iOS app does not track you across other companies' apps or websites for advertising purposes. We do not use the IDFA (Identifier for Advertisers).

13. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms:

  • Regulatory notification: Within 72 hours to relevant authorities (as required by GDPR, LGPD, etc.)
  • User notification: Without undue delay if high risk to individuals
  • Notification method: Email to your registered address and in-app notification
  • Information provided: Nature of breach, data affected, steps taken, recommendations for you

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will notify you via email at least 30 days before changes take effect
  • We will display a prominent notice in the app
  • We will update the "Effective Date" at the top of this policy
  • Previous versions will be archived and available upon request

Continued use of the service after changes take effect constitutes acceptance of the updated policy.

15. Contact Us

Privacy Team

For privacy questions, data requests, or to exercise your rights:

Data Protection Representative

For EU/EEA residents, our data protection matters can be addressed to our Privacy Team at the email above. We will respond within the timeframes required by GDPR.

Response Times

  • General inquiries: 5 business days
  • Access/portability requests: 30 days
  • Deletion requests: 30 days
  • Complex requests: Up to 45 days with notice

Privacy Summary

  • ✓ We do not sell your personal data to anyone
  • ✓ You can export or delete your data anytime
  • ✓ Your data is encrypted and stored securely
  • ✓ You control who sees your pet's records
  • ✓ We comply with global privacy laws (GDPR, LGPD, CCPA, PIPEDA, and more)
  • ✓ Contact privacy@wagabondpets.com for any privacy concerns

Document Version: 2.0 | Last Updated: December 13, 2025 |Previous Version: January 1, 2025

This policy is available in additional languages upon request. Para español, português, 日本語, 한국어, or other languages, please contact us.