1. Introduction
The Equine Directory ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect when you use The Equine Directory mobile app, website, and related services (collectively, the "Platform"), how we use it, who we share it with, and how you can exercise your rights.
We serve two types of users: Riders (horse owners who search for and book equine services) and Providers (equine professionals who list and offer services). We collect and use data differently depending on your role, and this Policy explains both.
By using the Platform, you consent to data practices described in this Policy. If you do not agree, please do not use the Platform. You may withdraw consent at any time by deleting your account — see Section 10.
Our Platform is currently available in the United States. We are headquartered in Kentucky, USA.
2. Information We Collect
2.1 Information You Provide Directly
| Data Category | Examples | Who Provides It |
|---|---|---|
| Account details | Name, email address, password, profile photo | All users |
| Horse information | Horse name, breed, age, health notes relevant to a service | Riders (optional) |
| Business details | Business name, service category, credentials, service area, pricing, availability | Providers |
| Listing content | Service descriptions, photos, business hours | Providers |
| Reviews & ratings | Star ratings, written reviews, review photos | Riders (post-booking) |
| Messages | In-app messages and photos shared with Providers or Riders | All users |
| Payment information | Card type, last 4 digits, billing address (full card data processed by payment processor) | All users who transact |
| Support communications | Emails, chat messages, attachments sent to our support team | All users |
2.2 Information Collected Automatically
When you use the Platform, we automatically collect:
- Device information: Device type, operating system version, unique device identifiers, app version;
- Usage data: Features accessed, screens viewed, search queries, time spent, taps and interactions;
- Location data: Precise GPS location (with your permission) or approximate location derived from IP address — see Section 4;
- Log data: IP address, access timestamps, error logs, crash reports;
- Analytics data: Session duration, referral sources, in-app events (e.g., "booking confirmed", "review submitted").
2.3 Information from Third Parties
We may receive information about you from:
- Sign-in providers: If you register with Apple Sign In or Google Sign In, we receive your name and email as authorized by you;
- Payment processors: Transaction status, fraud signals, and payment method metadata;
- Credential verification services: Confirmation of professional certifications for Providers (e.g., farrier certification, veterinary licensing);
- App stores: Apple and Google may share aggregated usage and crash data with us.
3. How We Use Your Information
We use your information to operate and improve the Platform. Specifically:
3.1 Service Delivery
- Create and manage your account;
- Display Provider listings to Riders based on location and search criteria;
- Process and confirm Bookings and facilitate messaging between Riders and Providers;
- Process subscription payments and commissions;
- Send Booking confirmations, reminders, and service-related notifications;
- Enable Providers to manage their listings, availability, and analytics.
3.2 Safety & Trust
- Verify Provider credentials and listing accuracy;
- Detect and prevent fraud, abuse, and violations of our Terms;
- Investigate complaints and disputes;
- Enforce our Community Rules and Acceptable Use Policy.
3.3 Platform Improvement
- Analyze usage patterns to improve features and fix bugs;
- Conduct internal research and analytics (using aggregated or de-identified data);
- Test new features with a subset of users.
3.4 Communications
- Send transactional emails (booking confirmations, receipts, password resets);
- Send service updates and important policy changes;
- Send optional marketing emails and push notifications about new features, providers in your area, or promotional offers — only with your consent, and you can opt out at any time.
3.5 Legal & Compliance
- Comply with applicable laws and regulations;
- Respond to lawful government requests and legal proceedings;
- Enforce our Terms and protect our legal rights.
3.6 Legal Basis (EEA/UK Users)
If you are in the European Economic Area or United Kingdom, we rely on the following legal bases:
- Contract performance: To create your account, process Bookings, and handle payments;
- Legitimate interests: To improve the Platform, prevent fraud, and send transactional communications;
- Consent: For marketing emails, push notifications, and precise location access;
- Legal obligation: To comply with tax, financial, and regulatory requirements.
4. Location Data
Location is central to how The Equine Directory works — it powers our live map view and helps Riders find the nearest equine professionals.
4.1 Types of Location Data
- Precise GPS location: Collected in real time when you use the map, search nearby services, or allow "always on" location access. This is only collected if you grant the app location permission on your device.
- Approximate location: Derived from your IP address when you browse on the web or when GPS is unavailable.
- Provider service area: Providers set a geographic service area (e.g., "50-mile radius of Lexington, KY") that is displayed publicly on their listing.
4.2 How We Use Location Data
- Surface nearby Providers on the map and in search results;
- Calculate distances between Riders and Providers;
- Show real-time availability of Providers in your area;
- Help Providers set and manage their service radius;
- Improve search relevance and regional coverage planning.
4.3 Your Controls
You control location access through your device settings:
- iOS: Settings → Privacy & Security → Location Services → The Equine Directory. Choose "Never", "While Using the App", or "Always".
- Android: Settings → Apps → The Equine Directory → Permissions → Location. Choose "Deny", "Allow only while using the app", or "Allow all the time".
Denying location access will limit the map view and "near me" search features, but you can still use the Platform with a manually entered location.
4.4 Background Location
We do not collect your location when you are not actively using the app unless you have expressly granted "Always" location permission, in which case we may use background location to pre-load nearby Providers for a faster map load. You can change this permission at any time in your device settings.
4.5 Location Data Retention
Precise GPS coordinates used for a search are not stored beyond the current session. Booking-related location data (e.g., a Provider's service address) is retained as part of the booking record per Section 8.
5. Payment Information
We take payment security seriously. All card transactions are processed by our PCI-DSS-compliant payment processor. The Equine Directory never stores your full card number, CVV, or PIN.
5.1 What We Store
We store:
- A tokenized reference to your payment method (provided by our payment processor);
- Last 4 digits of your card and card type, for display purposes;
- Billing address for tax and fraud prevention purposes;
- Transaction records (amount, date, Booking reference) for accounting, dispute resolution, and legal compliance.
5.2 App Store Subscriptions
When you purchase a Subscription through Apple's App Store or Google Play, payment is processed entirely by Apple or Google. We receive only a confirmation of the purchase and your subscription status; we never receive or store your payment credentials in these cases. Apple's and Google's respective privacy policies govern their handling of your payment data.
5.3 Provider Payouts
To disburse earnings to Providers, we collect bank account or payout details (such as routing and account numbers or PayPal email). This data is stored securely and used solely for payout purposes. Providers may be required to complete identity verification (KYC) as required by financial regulations.
5.4 Fraud Prevention
We use automated fraud detection tools that analyze transaction patterns. These tools may use your account history, device fingerprint, IP address, and behavioral signals to flag potentially fraudulent transactions. Flagged transactions may be reviewed by our team before processing.
8. Data Retention
We retain your data for as long as necessary to provide the Platform and fulfill the purposes described in this Policy. The following retention periods apply:
| Data Type | Retention Period |
|---|---|
| Account data (name, email, profile) | Duration of account + 30 days after deletion |
| Booking records & receipts | 7 years (tax & financial compliance) |
| Payment transaction records | 7 years (legal/financial obligation) |
| In-app messages | Duration of account + 30 days after deletion |
| Reviews (anonymized) | Indefinitely (part of public provider record) |
| Usage & analytics data | Up to 24 months (aggregated after 12 months) |
| Support communications | 3 years after resolution |
| Crash logs | 90 days |
| Location data (session GPS) | Not stored beyond the session |
When data is no longer required, we delete it or anonymize it so it can no longer be linked to you.
9. Your Rights & Choices
Depending on where you live, you have certain rights over your personal data. We honor these rights for all users globally to the extent technically and legally feasible.
9.1 Summary of Rights
- Access: Request a copy of the personal data we hold about you;
- Correction: Ask us to correct inaccurate or incomplete data;
- Deletion: Request deletion of your personal data (see Section 10 for the account deletion process);
- Portability: Receive your data in a structured, machine-readable format;
- Restriction: Ask us to limit how we use your data in certain circumstances;
- Objection: Object to processing based on legitimate interests, including for direct marketing;
- Withdraw Consent: Where processing is based on your consent, withdraw it at any time without affecting prior processing.
9.2 Marketing Opt-Out
You can opt out of marketing communications at any time by:
- Clicking "Unsubscribe" in any marketing email;
- Going to Profile → Settings → Notifications → Marketing in the app;
- Contacting privacy@equinedirectory.com.
Opting out of marketing does not affect transactional notifications (booking confirmations, payment receipts, account security alerts), which are required for the Platform to function.
9.3 Push Notifications
You can disable push notifications at any time through your device settings (iOS: Settings → Notifications → The Equine Directory; Android: Settings → Apps → The Equine Directory → Notifications).
9.4 How to Submit a Data Request
To exercise any of the above rights, email privacy@equinedirectory.com with "Privacy Rights Request" in the subject line. We will verify your identity and respond within 30 days (or 45 days if the request is complex). We will not charge a fee for reasonable requests.
10. How to Delete Your Account
You have the right to delete your account and associated data at any time. This is a core requirement of our platform and complies with Apple App Store and Google Play guidelines.
Account deletion is permanent. Once confirmed, your account, profile, and personal data cannot be recovered. Download any data you need before proceeding.
10.1 Steps to Delete Your Account In-App
- Open The Equine Directory app and sign in;
- Tap your Profile icon (bottom right);
- Go to Settings (gear icon, top right);
- Scroll to Account and tap "Delete Account";
- Review the confirmation information and type "DELETE" to confirm;
- Tap "Permanently Delete My Account."
10.2 Delete via Email
If you cannot access the app, email privacy@equinedirectory.com from the email address registered to your account with the subject "Account Deletion Request." We will verify your identity and process the deletion within 10 business days.
10.3 What Is Deleted
- Your profile, photos, and personal information;
- Your listing data (if you are a Provider);
- Your saved favorites and Booking history (visible to you);
- Your in-app messages;
- Your marketing preferences and notification settings.
10.4 What May Be Retained
- Transaction and payment records for up to 7 years (required by US tax law and financial regulations);
- Anonymized reviews — your written review content remains but your name and profile are removed;
- Fraud and safety records if we are required to retain them to protect other users;
- Legal hold data if a legal proceeding requires us to preserve certain records.
10.5 Subscriptions & Active Bookings
Deleting your account cancels any active Subscription at the end of the current billing period. If you have active or upcoming Bookings, please cancel or complete them before deleting your account. For App Store subscriptions, also cancel your subscription directly in Apple's Settings or Google Play to stop future charges.
11. Children's Privacy
The Equine Directory is not directed at children under the age of 13 (or 16 in the EEA/UK), and we do not knowingly collect personal data from children. If we learn that we have collected data from a user under the applicable minimum age, we will promptly delete that data and terminate the account.
If you are a parent or guardian and believe your child has created an account on our Platform, please contact us immediately at privacy@equinedirectory.com and we will take swift action.
Users between the ages of 13–17 may use the Platform only with verifiable parental or guardian consent. We do not allow users under 18 to create Provider accounts or engage in payment transactions.
12. Third-Party Services
The Platform may contain links to third-party websites, services, or map providers (such as Apple Maps or Google Maps used to display service locations). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you interact with.
12.1 Apple & Google Integrations
Our app integrates with Apple and Google services including:
- Apple Maps / Google Maps: For the live map view. Your location query is sent to the respective mapping service per their privacy policy;
- Apple Sign In / Google Sign In: Authentication via these services shares your name and email with us as you authorize;
- Apple Push Notification Service / Firebase Cloud Messaging: Used to deliver push notifications to your device.
12.2 Analytics & Crash Reporting
We use third-party analytics and crash reporting tools (such as Firebase Analytics, Mixpanel, or Crashlytics) that collect device and usage data. These services process data under their own privacy policies. We configure them to minimize personal data collection and, where possible, to anonymize data before transmission.
13. Data Security
We implement industry-standard security measures to protect your personal data from unauthorized access, disclosure, alteration, and destruction, including:
- Encryption in transit: All data transmitted between the app/website and our servers is encrypted using TLS 1.2 or higher;
- Encryption at rest: Sensitive data (including payment tokens and credentials) is encrypted at rest using AES-256;
- Access controls: Employee access to user data is restricted on a need-to-know basis and protected by multi-factor authentication;
- Regular security audits: We conduct periodic vulnerability assessments and penetration tests;
- PCI-DSS compliance: Our payment processing environment is maintained to PCI-DSS standards.
Despite these measures, no system is perfectly secure. In the event of a data breach that affects your rights, we will notify you as required by applicable law, including within 72 hours of discovery where required by GDPR.
If you discover a security vulnerability, please report it responsibly to security@equinedirectory.com.
14. International Data Transfers
The Equine Directory is based in the United States. If you access our Platform from outside the US, your data will be transferred to and processed in the United States, where data protection laws may differ from those in your home country.
For users in the European Economic Area (EEA) or United Kingdom, we rely on the following safeguards for international transfers:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to countries without an adequacy decision;
- UK International Data Transfer Agreements (IDTAs) for transfers from the UK;
- Transfers to countries with an adequacy decision from the European Commission or UK government.
You may request a copy of the applicable transfer safeguards by contacting our Data Protection Officer (see Section 17).
15. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you additional rights over your personal information.
15.1 Categories of Personal Information Collected
In the past 12 months, we have collected the following categories of personal information from California consumers (as defined by the CCPA):
- Identifiers (name, email, device ID, IP address);
- Personal information categories listed in the California Customer Records statute (billing address);
- Commercial information (transaction records, subscription history);
- Internet or other electronic network activity information (usage data, crash logs);
- Geolocation data (with permission);
- Inferences drawn from the above to create a user profile (e.g., preferred service categories).
15.2 We Do Not Sell or Share Your Personal Information
The Equine Directory does not sell your personal information and does not share it for cross-context behavioral advertising purposes. You do not need to submit an opt-out request.
15.3 Your California Rights
California residents have the right to:
- Know what personal information we collect, use, disclose, and share;
- Delete personal information we have collected;
- Correct inaccurate personal information;
- Opt out of the sale or sharing of personal information (not applicable — we don't sell or share);
- Limit the use and disclosure of sensitive personal information;
- Non-discrimination for exercising your CCPA rights.
To exercise your rights, email privacy@equinedirectory.com with "California Privacy Request" in the subject. You may also designate an authorized agent to make requests on your behalf, provided they present signed authorization.
15.4 Shine the Light
California Civil Code § 1798.83 ("Shine the Light") permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes, so no such disclosure has occurred.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our data practices, or our services. When we make material changes, we will:
- Update the "Last updated" date at the top of this page;
- Send an in-app notification to all users;
- Email the address associated with your account for significant changes.
Your continued use of the Platform after the effective date of the updated Policy constitutes your acceptance of the changes. If you disagree with a material change, you may delete your account.
17. Contact Us & Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Privacy & data requests: privacy@equinedirectory.com
- General support: support@equinedirectory.com
- Security disclosures: security@equinedirectory.com
Data Protection Officer (EEA/UK)
For users in the European Economic Area or United Kingdom, you may contact our designated Data Protection Officer at dpo@equinedirectory.com. You also have the right to lodge a complaint with your local data protection supervisory authority (for example, the ICO in the UK or your national DPA in the EU).