This is a draft template. It must be reviewed and approved by a licensed attorney before the product goes live.

It is not legal advice and cannot be used as-is. Privacy obligations differ by state and depend on the practice's size, revenue and client base. Do not publish this page while any bracketed field remains unfilled.

21 fields still to fill: Legal entity name, Entity type and state of formation, Registered mailing address, General contact email, Effective date, Last updated, Privacy request channel, Second privacy request method, Clinical record retention, Financial record retention, Consent record retention, Log retention, Data storage region, Fees and billing terms, Refund policy, Backup policy, Limitation of liability, Post-termination export window, Dispute resolution mechanism, Governing law, Venue for disputes

Privacy Policy

Effective date: [EFFECTIVE DATE] · Last updated: [LAST UPDATED]

1. What this policy covers

This policy describes how personal information is handled in the E-Vet veterinary practice management software: information about pet owners ("clients"), about the animals treated by the practice, and about the clinic staff who use the application.

A note on a common misunderstanding: HIPAA governs protected health information about people. Veterinary medical records are not covered by HIPAA. They are governed instead by state veterinary practice acts and state medical-records rules, which differ from state to state on record ownership, minimum retention, and what must be released to a client on request. Nothing in this product should be read as a HIPAA compliance claim.

2. Who is responsible for your information

The veterinary practice that uses E-Vet decides what client and animal information is collected and why. For US state consumer privacy laws, the practice is the business / controller.

[LEGAL ENTITY NAME], which provides the software, hosts and processes that information only on the practice's instructions and only to deliver the service. In that role it acts as a service provider / processor.

This distinction determines who answers a consumer rights request. If you are a pet owner, direct your request to the veterinary practice that holds your records. If a request reaches the software provider directly, it will be forwarded to the relevant practice rather than actioned independently.

Practices with California clients should execute a CCPA service-provider addendum / data processing agreement with the software provider before going live. Request one at [GENERAL CONTACT EMAIL].

3. Who to contact

The fields below must be completed before this page is published. Until they are, this is not a usable privacy notice.

  • Legal entity: [LEGAL ENTITY NAME]
  • Mailing address: [REGISTERED MAILING ADDRESS]
  • Privacy contact: [GENERAL CONTACT EMAIL]
  • Rights request channel: [PRIVACY REQUEST CHANNEL]
  • Alternate request method: [SECOND PRIVACY REQUEST METHOD]

4. Categories of information collected

  • Client identity and contact information: name, phone number, email address, mailing address and city.
  • Animal and medical records: species, breed, date of birth, microchip and registration numbers, examination notes, diagnoses, treatment plans, vaccination and prescription history, laboratory results and hospitalization records. These records describe an animal, but because they are linked to an identifiable owner they are treated as that owner's personal information.
  • Payment and billing information: invoice line items, amounts, payment status, payment method and account balance. Full card numbers are not stored in the application; card processing is handled by the payment processor named below.
  • Staff account information: a staff member's name, role, email address and the record of actions taken under their account.
  • Session and technical information: authentication session state and the audit trail of changes made to records.

The application is not designed to collect sensitive personal information about clients beyond what is listed above. If a practice types such information into a free-text field, that choice and its consequences rest with the practice.

5. Why the information is used

  • To schedule, manage and remind clients about appointments.
  • To record examinations, treatments, vaccinations and prescriptions, and to make that history available to the treating veterinarian.
  • To manage laboratory requests and results.
  • To track hospitalized patients and treatment tasks.
  • To invoice, collect payment and maintain account balances.
  • To meet record-keeping obligations under state veterinary practice acts and tax law.
  • To secure the service, detect unauthorized access and investigate misuse.

6. Information is not sold or used for advertising

Client and animal information is not sold. It is not shared for cross-context behavioral advertising, and it is not used to build advertising or marketing profiles. The application contains no advertising pixels, no analytics scripts and no third-party tracking code — see section 9.

7. How long information is kept

Information is kept for as long as it is needed for the purpose it was collected for, and never for less than the minimum period the law requires.

  • Veterinary medical records: state veterinary practice acts set a minimum retention period, and it varies by state. Period applied by this practice: [CLINICAL RECORD RETENTION]
  • Invoices and financial records: retained for the period required by tax and accounting rules. Period applied: [FINANCIAL RECORD RETENTION]
  • Messaging consent records: retained while consent is active and afterwards for as long as needed to evidence that consent was given and honored. Period applied: [CONSENT RECORD RETENTION]
  • Session and audit logs: [LOG RETENTION]

A statutory retention period can outlast a deletion request. Where a veterinary practice act, tax rule or other law requires a record to be kept, a deletion request cannot be honored for that record until the required period expires. Deletion requests are honored for everything not subject to such a requirement, and the retained record is deleted or de-identified once the period ends. If a request is refused on this basis, the reason is given.

8. Who receives the information

Records are held in a database instance under the practice's control. Information leaves that boundary only in the following cases:

  • Hosting and database provider: Vercel Inc. (application hosting) and Supabase, Inc. (database and authentication) runs the infrastructure the application and database operate on, with access limited to what delivering the service technically requires. Data storage region: [DATA STORAGE REGION]
  • SMS / messaging provider: once appointment and vaccination reminders are switched on, only the name and phone number needed to deliver the message are passed to None — text messaging is not enabled, and no data is shared with an SMS vendor. Until that integration is enabled, no data is sent to any messaging provider — reminders are recorded in the application only.
  • Payment processor: Polar Software Inc. (polar.sh), acting as merchant of record handles card transactions where the practice has enabled payments.
  • Government authorities and legal process: disclosed where required by subpoena, court order, regulatory demand or other legal obligation, limited to the scope of the demand.

A current list of service providers is available at available on request.

9. Cookies and browser storage

The application uses no advertising or tracking cookies. What is stored in the browser is limited to the following two items:

  • Authentication session cookie: set and refreshed by the sign-in system so a signed-in user stays signed in. It is strictly necessary — the dashboard cannot be used without it.
  • evet.activeClinicId: a single entry in the browser's local storage that remembers which location a user with access to more than one clinic last selected. It holds an internal clinic identifier and no personal information.

There is no analytics, measurement, session-replay, social media or advertising code in the application. Because nothing optional is stored, no cookie consent banner or opt-out toggle is offered.

10. Text message (SMS) reminders and consent

Appointment and vaccination reminders may be sent by text message. Under the federal Telephone Consumer Protection Act (TCPA), non-emergency text messages require the recipient's prior express consent. A practice using this feature is responsible for obtaining and recording that consent before any reminder is sent, and for keeping the record of it.

  • To stop messages, reply STOP to any message. The opt-out is honored, and no further reminder texts are sent to that number.
  • Reply HELP for assistance, or contact the practice at [GENERAL CONTACT EMAIL].
  • Message frequency: Not applicable — E-Vet does not send text messages.. Message and data rates may apply.
  • Sender identity: Not applicable — E-Vet does not send text messages.
  • Opting out of text reminders does not affect the ability to book appointments or receive care, and does not stop operational communications the practice sends by other means.

11. State consumer privacy rights

Depending on where a client lives, US state consumer privacy laws may give them rights over their personal information. These include the California Consumer Privacy Act as amended by the CPRA, and comparable acts in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA) and Texas (TDPSA), among others. Whether a particular law applies to a given practice depends on that practice's size, revenue and where its clients live.

Where such a law applies, a client may request to:

  • Know and access the personal information held about them, the categories collected, the purposes, and the categories of third parties it is disclosed to.
  • Delete personal information, subject to the statutory retention limits described in section 7.
  • Correct inaccurate personal information.
  • Obtain a portable copy of their information in a readable, transferable format.
  • Opt out of sale or sharing for cross-context behavioral advertising, and of profiling that produces legal or similarly significant effects. As stated in section 6, no such sale, sharing or profiling takes place.
  • Not be discriminated against for exercising any of these rights — no denial of service, different pricing, or reduced quality of care follows from making a request.

Requests may be submitted to the practice at [PRIVACY REQUEST CHANNEL] or by [SECOND PRIVACY REQUEST METHOD]. Identity is verified before a request is actioned, so that records are not disclosed to the wrong person. An authorized agent may submit a request on a client's behalf with written proof of authorization.

Response window: requests are answered within 45 days. Where reasonably necessary, that period may be extended by a further 45 days, with notice of the extension and the reason for it given within the first 45 days. Some state laws also provide a right to appeal a refused request; where that right applies, the refusal explains how to appeal.

12. Security

Access is role-based: veterinarians, technicians, front desk staff and administrators reach only the records their role requires. These rules are enforced not only in the interface but at the database level through row-level security policies. Data in transit is encrypted. The practice is responsible for creating staff accounts, assigning the correct roles, and closing accounts when someone leaves.

No system is immune to compromise. These are the measures in place, not a guarantee against every possible incident.

13. Children

The service is a professional tool for veterinary practices. It is not directed to children, and information is not knowingly collected from children under 13. If such information is found to have been collected, it is deleted.

14. AI assistant

The assistant built into the application reads and writes clinical records in response to what a user types. It does not produce medical decisions, diagnoses or dosages. Every action it takes is shown in the conversation and can be reviewed. The data it touches is limited to records the user is already authorized to see.

15. Changes to this policy

This policy may be updated as the law or the service changes. The current version is always published on this page, and material changes are communicated to users separately.

16. Contact

Questions about this policy: [GENERAL CONTACT EMAIL] · [REGISTERED MAILING ADDRESS]

Terms of Service · Home

© 2026 E-Vet. All rights reserved.