Legal
Privacy Policy
Last updated: September 1, 2026
1. Introduction
RescueSphere is a US-based software platform built for animal rescue organizations. This policy describes what information we collect when you use RescueSphere, how we use it, who we share it with, and what control you have over it. We've written it in plain English on purpose. If anything is unclear, email us at [email protected].
This policy applies to the RescueSphere service itself. It does not cover separate privacy practices of your rescue organization. See Section 8 for how that works.
2. What we collect
We collect the minimum needed to run the service:
- Account information. Your name, email address, organization name, and password (hashed) when you sign up. Phone number if you choose to provide it.
- Records you create. Information about animals, adopters, fosters, volunteers, and donors that you enter into your RescueSphere tenant.
- Donation and payment data. Donation amounts and metadata. Payment card numbers are handled by Stripe. We never see or store them ourselves.
- Usage analytics. Basic information about how you use RescueSphere (pages visited, features used, browser type, IP address) so we can fix bugs and improve the product.
- Support communications. Anything you email us or submit through our contact form.
3. How we use it
We use the information we collect to:
- Provide and operate the RescueSphere service.
- Send transactional emails (account confirmations, password resets, billing receipts, important service notices).
- Send text messages (SMS) through Twilio when you use the messaging features. Recipients can opt out any time by replying STOP; see the SMS section of our Terms of Service.
- Improve the product: diagnose problems, understand which features get used, prioritize what to build next.
- Prevent fraud and abuse, and protect the security of accounts.
- Respond to support requests and other communications you initiate.
We do not use your data to train external AI models or to build advertising profiles. We do not sell your data, and we do not share it with advertising or data-broker partners. Inside RescueSphere, access is limited to your own team, by the roles you assign, and to a small number of our staff, only when you ask us for support or while we keep the service running.
4. Who we share it with
We share data only with third-party service providers we use to run RescueSphere, and only the minimum each one needs:
- Stripe: payment processing for subscriptions and donations.
- Twilio: SMS/text messaging, when you use the messaging features.
- Object storage: a file/media storage provider for photos, documents, and other uploads.
- Our hosting provider: the infrastructure that runs the application (subject to change; we keep this list current).
- Email delivery: a transactional email provider so that account emails reach you.
- Error monitoring: a service that captures application errors so we can fix them.
For organizations that need it, the current list of sub-processors and their roles is maintained in our Data Processing Agreement, available on request at [email protected]. We impose data-protection obligations on each sub-processor.
We do not sell or "share" (as defined by California law) your data. We do not share your data for advertising. We may disclose information if required by valid legal process, but we'll push back on overbroad requests.
5. Where it's stored and international transfers
RescueSphere data is primarily stored on infrastructure located in the United States. Some sub-processors (such as Stripe and Twilio) may process limited data in other regions under their own terms. Where personal data protected by the GDPR or UK GDPR is transferred to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (or another lawful mechanism), as described in our Data Processing Agreement.
6. Security
We take reasonable steps to protect your data:
- TLS encryption for all data in transit.
- Encryption at rest for databases, uploaded files, and backups.
- Role-based access controls inside the product, and limited engineer access to production systems.
- Continuous automated database backups, retained for 30 days. Uploaded files are stored redundantly, but do not yet have point-in-time version history.
To be straightforward with you: we are an early-stage company. We do not currently hold SOC 2 or other formal third-party certifications. As we grow, we plan to pursue them. If your organization needs documented controls today, please reach out and we'll share what we have.
7. Your rights
You can:
- Export the data in your tenant at any time as CSV or JSON.
- Correct inaccurate information. Most fields are editable directly in the product.
- Delete your account and request deletion of your tenant data.
- Ask us what we have on file about you and how it's being used.
California residents (CCPA/CPRA) have additional rights, including the right to know, the right to delete, the right to correct, the right to opt out of sale/sharing (we do neither), and the right not to be discriminated against for exercising those rights.
EU/UK residents (GDPR/UK GDPR) have the rights of access, rectification, erasure, restriction, data portability, and objection, and the right to lodge a complaint with a supervisory authority. Where your information sits in a rescue's tenant, the rescue is the controller and you should contact them first; we will assist them as their processor.
To exercise any right, email [email protected]. We won't discriminate against you for exercising your rights.
8. Adopter and donor data on your tenant
This part is important if you run a rescue: when your organization collects information about adopters, fosters, volunteers, or donors through RescueSphere, your organization is the data controller for that information and RescueSphere is the data processor.
That means you decide what to collect and why, and you are responsible for providing your own privacy notice to the people whose information you're collecting. We handle the data on your behalf according to this policy, our Terms of Service, and a Data Processing Agreement that sets out our obligations as your processor (and "service provider" under California law). The Data Processing Agreement is available on request.
Retention. You can export your tenant data at any time. After your account is cancelled or terminated, we retain your tenant data for 30 days so you can return or pull a final export, then delete it from active systems; encrypted backups age out on their normal rolling schedule.
9. Children
RescueSphere is not directed at children under 13, and we do not knowingly collect information from anyone under 13. If you believe a child has provided us information, contact us and we'll delete it.
10. Cookies
Essential cookies. The RescueSphere app and adopter/foster/volunteer portals use only strictly-necessary cookies to keep you signed in (session) and protect forms (CSRF). These are required for the service to work and cannot be switched off. We do not use advertising trackers, retargeting pixels, or cross-site tracking in the app.
Analytics on rescue websites. A rescue can connect its own Google Analytics account to the public website it builds with RescueSphere. When enabled, that public site shows a cookie banner and loads Google Analytics (which sets its own cookies) only after the visitor accepts. Declining keeps those cookies off.
Payments. Donation and payment pages load Stripe, our payment processor, which sets cookies it needs for fraud prevention and to complete the transaction. See Stripe's privacy policy for details.
11. Changes
If we make material changes to this policy, we'll notify you in-app and by email before they take effect. Smaller wording or clarity edits will be reflected by an updated "Last updated" date at the top of this page.
12. Contact
Privacy questions, requests, or concerns: [email protected].