Privacy notice

This notice describes the data used by the current SitNotes product and its account-deletion lifecycle.

Last updated July 26, 2026

Data you provide

SitNotes stores account and business settings, client and pet care profiles, owner-visible care instructions, sitter-only private access notes, bookings, checklist activity, vaccination records, report notes, report photos, and optional custom logos.

How data is used

Data is used to operate authenticated care workflows, create owner-facing confirmations and reports, apply plan access, provide support, prevent duplicate billing or reminder operations, and measure product activation using limited server-recorded event metadata.

Analytics metadata is designed not to contain client or pet names, contact details, addresses, private notes, public-link tokens, report text, or payment details.

Service providers

SitNotes uses Clerk for authentication, Supabase for application data, Cloudinary for report photos and custom logos, Resend for transactional email delivery, and Lemon Squeezy for subscription checkout, billing, and customer-portal access.

Public owner links

Public report links can be opened by anyone who has the link while the report is enabled. Owner confirmation links expire and become single-use after submission. Public responses intentionally exclude sitter-only private access notes.

Security and account isolation

Authenticated records are scoped to the signed-in sitter and protected by database access policies. No internet service can guarantee absolute security, so users should avoid placing unnecessary secrets in owner-visible fields and should share public links carefully.

Retention, downgrade, and deletion

A downgrade preserves existing account and care records and does not act as an account-deletion request. When an account is deleted, account access and shared links are disabled immediately. SitNotes retains the account data for a 30-day support recovery period. After that period ends, care data is queued for permanent deletion through our scheduled cleanup process, subject to narrowly required billing, security, and operational audit records. To request help, contact support. Third-party CDN caches may take time to expire after source assets are removed.