Who we are
Pawdentity, LLC (“Pawdentity”, “we”, “us”) provides management software for pet-care businesses — boarding, daycare, grooming and training facilities. This policy explains what personal information we handle, why, and what you can do about it.
It covers pawdentity.com, the Pawdentity staff application, and the customer portal your facility offers to pet owners.
Two different roles
Which rights apply to you depends on how your information reached us, so this distinction matters more than it might appear:
- For facility accounts, we are the controller. When a business signs up and its staff use Pawdentity, we decide how that account information is handled, and this policy governs it directly.
- For the records a facility keeps, we are a processor. Client and pet records, bookings, payments and messages belong to the facility. We store and process them on that facility’s instructions and do not decide what is collected or how it is used.
If you are a pet owner, the facility you booked with is your first point of contact for access, correction or deletion of your records. We will help them act on your request; we will not unilaterally alter or delete their business records at the request of someone who is not the account holder.
What we collect
Facility staff accounts
- Name, email address, and optionally a mobile number and profile photo
- A password, stored only as a salted cryptographic hash — we never store, log, or have any way to read the password itself
- Your role and permissions within the facility, and an optional job title
- Employment details the facility records for payroll and scheduling, such as pay rate, pay type and time-clock entries
- Appearance preferences, such as your chosen theme
- Sign-in activity: session records, and a log of sign-in attempts against an email address used to throttle password guessing
Records a facility keeps in Pawdentity
- Client contact details and additional emergency or authorized contacts
- Pet profiles — name, breed, weight history, photos, feeding and medication needs, care notes and behavioral notes
- Bookings and stays, check-in and check-out records, and care events logged during a stay
- Documents uploaded by or for a client, including veterinary and vaccination records
- Orders, invoices, payment records and stored payment method references
- Messages exchanged between facility staff and clients, including attachments
- Signed agreements and waivers
Applications and inquiries
If you apply for a Pawdentity account, we keep the business and contact details you submit — business name, your name, email, phone, business type, address, website, and the scale information you provide — so we can assess and respond to the application. If you send us a message through the contact form we keep the message, your contact details, and a record of the consent wording you agreed to and when.
What we do with it
- Provide the service: run bookings, records, payments, messaging and reporting
- Authenticate you and keep accounts secure, including verifying your email address, throttling repeated failed sign-ins, and checking chosen passwords against known breach lists
- Send transactional email — verification codes, account notices, and booking reminders
- Support you when you contact us
- Meet legal, tax and accounting obligations
We do not sell personal information. We do not use the records a facility keeps in Pawdentity to advertise to its clients, and we do not share them between facilities.
Who else touches it
We use a small number of providers to run the service. Each receives only what it needs:
| Provider | Purpose | What it receives |
|---|---|---|
| Convex | Application database and backend hosting | Data stored in the service |
| Stripe or FluidPay | Card processing, depending on the facility’s configured provider | Payment details and transaction amounts. Card numbers are handled by the provider — we store a reference, never the full card number |
| Resend | Transactional email delivery | Recipient address and message content |
| Google Places | Address suggestions as you type an address | Only the partial address being typed, and only while an address field is in use. This also applies on our public application form, before any account exists |
We may also disclose information where legally required, or as part of a merger or acquisition, in which case we will give notice before your information becomes subject to a different policy.
Cookies and measurement
We use cookies for signing in and for remembering a preference. We do not use advertising cookies, and nothing on our sites follows you to another company’s website.
- better-auth.session_token — keeps you signed in. It is marked HTTP-only, so page JavaScript cannot read it, and it is not sent on cross-site requests.
- better-auth.convex_jwt — a short-lived credential, good for fifteen minutes, that lets the page load your data. Also HTTP-only.
- paw_theme and paw_mode — remember the appearance you chose. Nothing else.
On this marketing site we count how pages are read using our own software, and it deliberately cannot identify anyone: a record is the name of an event, the moment it happened, and at most the path of the page — no cookie, no advertising identifier, and nothing that links one page view to another or to a person. We honor the “Do Not Track” setting in your browser and record nothing at all when it is switched on. We do not run any third-party analytics or advertising script.
How we protect it
These are the specific measures in place, not general assurances:
- Passwords are hashed with PBKDF2-SHA256 at 100,000 iterations with a random per-user salt. Plain passwords are never written to storage or to logs.
- Sessions use an HTTP-only cookie that browser JavaScript cannot read. Application code holds only a short-lived token that expires within the hour, so a cross-site scripting flaw cannot capture a durable credential. Signing out revokes the session and every token derived from it.
- Verification codes and activation links are stored only as cryptographic hashes, are single-use, expire, and are never written to logs.
- New passwords are screened against a public breached-password list using a method that never transmits your password or its full hash.
- Facilities are isolated from one another at the data-access layer: every request is resolved against the signed-in user’s membership before any record is read.
- Sensitive actions are recorded in an audit log.
- Traffic is encrypted in transit.
No system is perfectly secure, and we make no guarantee that it is. We do not currently hold a SOC 2, ISO 27001 or equivalent certification.
How long we keep it
- Facility records are kept for as long as the account is active, because they are the facility’s operating history. On account closure we will delete or return them on request, subject to any legal retention we are under.
- Sessions expire after 14 days; expired tokens are removed automatically.
- Sign-in attempt logs are pruned after 24 hours.
- Verification codes expire within minutes and are deleted once used.
- Financial records are retained as long as tax and accounting rules require, which typically outlasts the account.
Your choices
Depending on where you live you may have the right to:
- Ask what personal information we hold about you and get a copy
- Correct information that is wrong
- Ask us to delete information, where we are not required to keep it
- Object to or restrict certain processing
- Withdraw consent where processing relies on it
Staff of a facility can update most of their own details in the app directly. For anything else, or if you are a pet owner, contact your facility first — or write to us at support@pawdentity.com and we will route the request appropriately.
Transactional messages — verification codes, security notices, booking confirmations — are part of the service and cannot be switched off while an account is open.
Children
Pawdentity is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us and we will delete it.
Where your information is held
Pawdentity is operated from the United States and information is processed there. If you use the service from elsewhere, you are transferring information to the United States, where privacy laws may differ from those in your own country.
Changes to this policy
We may update this policy. The current version always appears on this page, and we will give notice of material changes through the service before they take effect.
Contact us
Questions about this policy, or about information we hold — support@pawdentity.com. Our Terms & Conditions govern use of the service alongside this policy.
