Privacy notice
Last updated 12 September 2026
This is a plain-English draft written by the people who built the software, and it accurately describes what the system does. It has not yet been reviewed by a lawyer. If you need a reviewed notice before signing up, email hello@pawteli.com and ask.
The short version
Your facility owns its data. We hold it so the software can work, we never sell it, we never use it to train anything, and you can export all of it as a CSV at any moment without asking us. We never see a card number, because Pawteli does not process payments.
Who is responsible for what
If you run a boarding or daycare business using Pawteli, you decide what customer and pet information to collect and why. You are the controller of that information. We hold and process it on your instructions, as your processor, and we do not decide what to do with it independently.
If you are a pet parent who received a link from your kennel, the kennel is who holds your information. Ask them to change or delete it. We will act on their instruction, not on ours.
What we store
- Staff accounts. Name, email address, and a password stored only as a one-way hash. We cannot read your password.
- Facility details. Business name, address, phone, timezone, rates, suites and which vaccines you require.
- Pet parents. Name, email, phone, address, emergency contact and any notes staff add.
- Pets. Name, breed, sex, birthday, weight, feeding and medication notes, vet details and behaviour flags.
- Bookings. Dates, suite, add-ons, notes, and what is owed and collected.
- Vaccine records and certificates. The dates, and the image or PDF that was uploaded.
- Stay photos. Pictures staff take of pets, with the caption and who took them.
What we never store
- Card numbers or bank details. Pawteli is not a payment processor and has no payment integration. Money is taken on your own card reader and the software only records the amount you tell it you collected.
- Analytics or advertising trackers. There are none on this site or in the application. The only cookie is the one that keeps you signed in.
Who else processes it
Running the software means some data passes through other companies. These are all of them.
| Who | What for | Where |
|---|---|---|
| Cloudflare | Runs the application, stores uploaded photos and certificates, and reads the dates off vaccine certificates using a model hosted on its own infrastructure. | United States and globally |
| Neon | Hosts the database: facilities, people, pets, bookings and vaccine records. | United States |
| Anthropic | A fallback certificate reader, used only when the first reader cannot make sense of a file. Only the certificate is sent, never customer lists, bookings or photos. A facility can turn this off. | United States |
| Resend | Sends transactional email: booking confirmations, vaccine reminders and password resets. | United States |
Vaccine certificates are the only thing processed by a model, and they go for one reason: to read the dates off the page so your staff do not have to type them. By default that happens on Cloudflare, where the rest of the application already runs, so the file does not leave that infrastructure. If a certificate cannot be read there, it may be retried once with Anthropic; that fallback can be switched off for a facility on request. Certificates are not used to train models either way.
Links that work without a password
Each pet parent gets a private link to their own page. That link is the credential: anyone holding it can see that person's pets, vaccine dates and bookings, which is why it contains a long random value and why the page asks you to keep it. Photos are served from similarly unguessable addresses. A facility manager can issue a new link at any time, which immediately stops the old one working.
Because photo addresses are cached for up to a day for speed, a photo deleted from the software may remain reachable to someone who already had its exact address until that cache expires.
How long we keep it
For as long as your facility keeps its account, because a boarding history is a record you may need. Ask us to delete your facility and we will remove it and everything under it. Export first: once it is gone we cannot get it back.
Your rights
Depending on where you live you may have the right to see, correct, export or delete the information held about you. If you are a pet parent, ask your kennel first, as they hold it. If you are a facility, email hello@pawteli.com and we will act within 30 days. The export button in settings already gives you everything without waiting.
Security
Everything travels over HTTPS. Passwords are hashed and never recoverable. Access is scoped to the facility you work at, checked on every page and every action, so one facility cannot reach another's records. No system is perfect, and if we ever discover a breach affecting your data we will tell you promptly and plainly.
Changes
If this notice changes in a way that matters, we will email account holders rather than quietly editing the page. The date at the top always says when it last changed.