Privacy Policy
Last updated: [TBD: publish date]
[TBD: …] require a real business decision before this page can be relied on.Who we are
HoofFlow is operated by [TBD: legal entity name], [TBD: registered business address]. For privacy questions or requests, contact [TBD: privacy contact email — recommend privacy@hoofflow.com once the domain is live].
What we collect
HoofFlow is a professional record-keeping tool for farriers. What we store, and why:
- Account data — your name, email, and business profile (name, phone, address, timezone), used to run your account and organization.
- Client and horse data — the professional records you create: client contact details, barn locations, horse profiles, hoof observations, visit history, and photos you take of a horse's hooves. This is your data, entered by you, about your own customers and their horses — we process it on your behalf to provide the service, not for our own purposes.
- Operational data — appointments, service catalog entries, and pricing you configure.
- Photos — hoof and horse photos you upload, stored privately per organization; never used for any purpose beyond displaying them back to you and, when you choose to attach one, an owner communication you explicitly send.
- Voice recordings — if you use voice note capture, audio is transcribed in memory and discarded immediately after — never written to storage or kept.
- Billing data — subscription status and plan. Full payment card details are collected and stored directly by Stripe, our payment processor — HoofFlow's servers never receive or store your card number, CVC, or expiry.
- Support data — anything you send us via the in-app feedback form or email, plus safe diagnostic context (app version, browser, route, timestamp) attached automatically to bug reports — never your client/horse notes, transcripts, or photos, unless you choose to attach a screenshot yourself.
- Product analytics — a small set of allowlisted events (e.g. "a visit was completed") with no client/horse names, notes, or content — used only to understand which features are actually used during the private beta, never sold or used for advertising.
AI processing
If you use voice notes or AI-drafted owner summaries, the minimum necessary text (a transcript, or a visit's service/hoof-work facts) is sent to our AI provider (OpenAI) to generate a proposal you review and explicitly approve before anything is saved. AI never writes to your records directly, and we do not send horse-owner contact details, pricing, or diagnostic language to the AI provider beyond what's needed to draft the text you asked for.
Who we share data with (subprocessors)
We use a small number of infrastructure providers to run HoofFlow — never more than necessary, and never for marketing resale:
- Supabase — database, authentication, and photo storage.
- OpenAI — voice transcription and AI-drafted text, only when you use those features.
- Google — address geocoding and route/drive-time estimates, only if your organization has location features configured.
- Resend — delivers owner communication emails you choose to send.
- Stripe — billing and payment processing; HoofFlow never receives your raw card details.
- [TBD: hosting provider] — runs the application itself.
We do not use any advertising or marketing-analytics subprocessor. See docs/SUBPROCESSORS.md in our repository for the full, current inventory.
Retention and deletion
Your professional records are never deleted for non-payment — a lapsed subscription moves your account through a Read Only state, not deletion. If you close your account, we retain your data for a limited window (target: [TBD: retention period, subject to legal review — see docs/COMMERCIAL_STRATEGY.md]) before permanent deletion, so a mistaken cancellation doesn't cost you your history. You can export a full copy of your data at any time from Settings.
Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete your personal data. Contact us at [TBD: privacy contact email] to exercise these rights. [TBD: international-transfer language once hosting region/subprocessor regions are finalized.]
Security
Every organization's data is isolated at the database layer (Row Level Security), not just by application logic. Photos are stored privately and served only via short-lived signed URLs. See our Fair Use Policy for how we protect against abuse of AI/mapping features.
Changes to this policy
We'll update this page as HoofFlow's architecture or practices change, and note the date above.