Privacy Policy
What we collect when you build a pet care plan, who processes it on our behalf, how long we keep it, and how to exercise your privacy rights.
Last updated September 1, 2026
Scope of this policy
This policy explains how Paws & Visits, Inc. ("Paws & Visits", "we", "us") collects and uses personal information across three connected products: the pawsandvisits.com website, the Paws & Visits browser extension, and the in-home veterinary and training visits we coordinate for you. It applies to prospective customers, account holders, Plus subscribers, and anyone who contacts support. It does not apply to the independent veterinary practices, trainers, insurers, or retailers we connect you with; each handles your information under its own policy.
Paws & Visits, Inc. is the controller of the information described here. Our registered office is 1420 Ridgeway Ave, Suite 210, Asheville, NC 28801, USA.
Information we collect
Account information
Name, email address, password hash, ZIP or postal code, and (optionally) a mobile number for appointment reminders. ZIP code is required because our in-home network covers 38 states and we need to tell you honestly whether a visit is available before you plan around it.
Pet profile information
To generate a first-30-days plan we collect your pet's name, species, breed or breed mix, estimated date of birth, adoption or homecoming date, sex, spay/neuter status, weight, known vaccination history, and any notes you enter about diet, medication, or behavior. Breed and date of birth drive the entire care schedule, so they are functionally required for the product to work.
Extension activity
The browser extension activates only on adoption and breeder listing pages you visit — for example Petfinder, Adopt-a-Pet, and participating shelter and rescue sites. On those pages it reads the visible listing attributes (breed, approximate age, listing location, shelter name) so it can build a matching checklist. We record that a checklist was generated, which listing domain it came from, and which items you opened. The extension does not read page content on unrelated sites, does not log your browsing history, and never collects form fields, passwords, or payment details.
Appointment and payment information
Booking a vaccination visit, wellness check, or trainer session creates a record containing the service address, requested time window, access notes (gate codes, parking), the assigned provider, and the provider's visit summary. Stripe processes card payments and Plus billing; we receive the last four digits, card brand, expiry, billing postal code, and the result. We never receive or store full card numbers.
Support and communications
We keep email threads, chat transcripts, and call notes from support interactions, plus your marketing and transactional message preferences.
Device, analytics, and marketing identifiers
We collect IP address, user-agent, device and viewport characteristics, referring URL, pages and events viewed, and identifiers set by our analytics and advertising tools — including Google Analytics 4 client IDs, PostHog distinct IDs, and Google Ads click identifiers (gclid) appended to inbound ad traffic. Where consent is required, these are set only after you grant it.
How and why we use information
- To deliver the service — generating breed-specific plans, scheduling visits, dispatching reminders, fulfilling starter-kit orders, and providing support.
- To take payment — processing one-time orders, Plus subscriptions, and refunds.
- To improve the product — measuring which checklist items are completed, where onboarding flows are abandoned, and which care plan formats are actually used.
- To market responsibly — sending onboarding email sequences you can unsubscribe from in one click, and measuring the performance of our advertising.
- To keep the service safe and lawful — fraud prevention, abuse investigation, accounting, tax, and legal process.
Legal bases (EEA, UK, and Switzerland)
- Contract — account creation, care plan generation, appointment booking, order fulfilment, and billing.
- Consent — analytics and advertising cookies and similar identifiers, SMS reminders, and optional marketing email.
- Legitimate interests — service security, fraud prevention, aggregate product analytics where consent is not required, and defending legal claims.
- Legal obligation — tax records, accounting records, and responses to lawful requests.
Where we rely on consent you may withdraw it at any time; withdrawal does not affect processing already completed.
Consent Mode v2
For visitors in the EEA, the UK, and Switzerland, all Google advertising and analytics tags on our site load through Google Consent Mode v2. Until you make a choice in our consent banner, analytics_storage, ad_storage, ad_user_data, and ad_personalization are denied by default and only cookieless pings are sent. Your choice is stored and applied to every subsequent page view until you change it using the "Cookie preferences" link in the footer. Consent Mode v2 signals govern those tags; they do not affect strictly necessary cookies.
Sub-processors and recipients
We do not sell personal information. We share it with the following service providers under written data processing terms:
| Provider | Function | Data categories | Region |
|---|---|---|---|
| Stripe, Inc. | Payments, subscription billing, refunds | Name, email, billing address, card metadata | USA, EU |
| Twilio Inc. | Appointment SMS reminders | Mobile number, message content | USA |
| Twilio SendGrid | Transactional and marketing email | Name, email, engagement events | USA |
| Cloudflare, Inc. | CDN, WAF, DNS, bot mitigation | IP address, request metadata | Global edge |
| Google Analytics 4 | Product and site analytics | Pseudonymous identifiers, event data, truncated IP | USA, EU |
| PostHog, Inc. | Onboarding funnel analytics | Distinct ID, event data | USA |
| Google Ads | Advertising measurement and remarketing | Click IDs, hashed email for enhanced conversions, conversion events | USA |
We also disclose information to the in-home veterinarian or trainer you book (name, service address, pet profile, access notes), to insurers or brokers when you request a quote, and to authorities where law requires it. A current sub-processor list is available from [email protected].
International transfers
We are a United States company, so information about EEA, UK, and Swiss residents is transferred to the United States. Those transfers rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), supported by a transfer impact assessment and technical safeguards including encryption in transit and at rest. Where a recipient is certified under the EU-U.S. Data Privacy Framework, the UK Extension, or the Swiss-U.S. DPF, we may rely on that certification instead.
Retention
- Active account and pet profile data — for the life of the account, then 24 months after closure.
- Appointment and visit records — 84 months, to support provider quality review and liability claims.
- Payment and invoice records — 84 months, for tax and accounting.
- Extension checklist activity — 18 months, then aggregated.
- Analytics event data — 14 months in Google Analytics 4, 24 months in PostHog.
- Advertising identifiers and click data — 13 months.
- Support correspondence — 36 months.
- Consent and opt-out records — 60 months, because we must be able to prove them.
Your rights
EEA and UK GDPR
You have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent. You also have the right to lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office.
California (CCPA/CPRA)
California residents may request the categories and specific pieces of personal information we collected, the sources, the business purpose, and the categories of third parties involved; request deletion; request correction; limit the use of sensitive personal information; and opt out of sale or sharing for cross-context behavioral advertising. See our "Do Not Sell or Share My Personal Information" page to exercise the opt-out. We do not discriminate against anyone who exercises these rights.
Submit any request to [email protected] or call +1 (828) 555-0142. We verify requests by matching your email address to an existing account record and, for deletion requests, by confirming a one-time code. Authorized agents may act on your behalf with written permission. We respond within 30 days (GDPR) or 45 days (CCPA/CPRA), with one permitted extension.
Children
Our services are not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn that we hold such information we delete it promptly; a parent or guardian may report it to [email protected].
Security
We use TLS 1.2+ in transit, AES-256 encryption at rest, role-based access control with mandatory multi-factor authentication, least-privilege production access reviewed quarterly, centralized audit logging, annual third-party penetration testing, and an incident response plan with a 72-hour regulator notification path. No system is perfectly secure, so please use a unique password.
Data protection officer
Our Data Protection Officer can be reached at [email protected] or by post at the address below, marked "Attn: Data Protection Officer".
Changes to this policy
Material changes are posted here with a new revision date. If a change affects how we use information you have already given us, we email account holders at least 14 days beforehand.
Contact
Paws & Visits, Inc.
1420 Ridgeway Ave, Suite 210
Asheville, NC 28801, USA
Privacy and data requests: [email protected]
General support: [email protected]
Phone: +1 (828) 555-0142
Questions about this document? Write to [email protected] and a human will answer within one business day.
Contact us