Privacy Policy
Version 1, effective September 5, 2026
This Privacy Policy explains how ThePetSwap handles personal information under the current member-to-member pet-care model.
Who Operates the Service
ThePetSwap LLC, a California limited liability company (“ThePetSwap,” “Company,” “we,” “us,” or “our”), operates the ThePetSwap app, website, waitlist, account and profile features, community point ledger, messaging, verification, support, reporting, moderation, and related services (collectively, the “Service”).
While an account is active, privacy questions and requests may be submitted through in-app Support if available. A current contact channel is also made available at thepetswap.com for a former member or other person who cannot access the app. The Company does not publish a member-manager’s private residential address in this Policy.
Information We Collect
• Waitlist information, such as full name, email address, city, state, ZIP code, pet type, and optional referral source when you join a public waitlist.
• Account and contact information, such as name, email address, telephone number, date of birth or age-gate response, login provider, and account identifiers.
• Profile and pet information, such as profile photos, biography, neighborhood, availability, pet characteristics, care routines, behavioral history, medication information, and vaccination or health records where the Service requires or permits them.
• Private care and household information, such as home address, emergency contact, veterinarian information, keys or access instructions, handoff information, and broad household-child age bands where supplied.
• Swap and point information, including requests, offers, accepted arrangements, dates, cancellations, point credits and debits, promotions, adjustments, reversals, and related records.
• Communications and content, including member messages, support requests, safety reports, reviews, invitations, feedback, photos, documents, and related attachments.
• Verification information, which may include images of a government ID, selfie, proof of name and address, verification result, reason code, reviewer information, date, and a limited anti-abuse record.
• Device and operational information reasonably needed to operate and secure the Service, such as IP address, device type, operating system, app version, session or authentication identifiers, timestamps, security logs, crash information, and push-notification token where enabled.
• Third-party sign-in or map information received from Apple or Google when you choose or use those features, limited to information authorized for the integration.
The current Service does not use automated facial recognition, automated face matching, or biometric identification. A human reviewer may compare a submitted selfie with an identification document for identity verification.
Sources of Information
We receive information directly from you; from your activity in profiles, swaps, messages, reports, reviews, support, invitations, feedback, verification, and waitlist forms; automatically from devices and Service operations where reasonably necessary; from another member when that member submits information relevant to a swap or report; and from service providers or integrations used to operate the Service.
How We Use Information
• Create, authenticate, maintain, and secure accounts and waitlist records.
• Operate profiles, pet records, requests, offers, swaps, messages, notifications, invitations, and the point ledger.
• Conduct identity or address verification and maintain the integrity of verification status.
• Coordinate member-to-member care and provide participating members with information reasonably needed for an accepted arrangement.
• Provide support, investigate feedback, troubleshoot technical issues, and improve the Service.
• Receive and evaluate safety, fraud, animal-welfare, harassment, and Terms reports.
• Automatically filter apparent contact information before a swap is confirmed where that feature is used.
• Prevent abuse, protect members and animals, enforce rules, maintain records, and comply with law and valid legal process.
• Send transactional communications and, where required, obtain the appropriate choice for neighborhood-launch, promotional, referral, or invitation communications.
• Maintain records reasonably necessary for point administration, safety reviews, disputes, fraud prevention, support, and legal compliance.
• Meet legal-hold, dispute, security, record-integrity, and other applicable legal obligations.
What Other Members Can See
Ordinary profile and pet information designated for member visibility may be visible to signed-in members. Profile visibility is controlled through Service settings and access permissions; information designated as private is not intended for ordinary member or public visibility.
Home address, telephone number, emergency contact, veterinarian details, medical and vaccination information, microchip number or registry information, government-ID images, selfie, verification records, private messages, access codes, and private safety-report details are not public profile information. After confirmation, information reasonably necessary for the care arrangement may be made available to the confirmed participants. Reusable access credentials should be hidden or removed when the operational need ends. Company limits broad information about children in a household to the care context for which it was collected.
Service Providers and Other Disclosures
Company uses service providers for functions such as database hosting, file storage, app builds and updates, web hosting, authentication, maps, push notifications, email, support, and security. Current providers may include Supabase, Expo, Vercel, Apple, and Google, depending on the production configuration actually in use. Service providers may process information on Company’s behalf for the contracted function and under their own applicable terms.
We may also disclose information with your direction or consent; to protect members, animals, Company, or others; in a business transaction; to investigate fraud or abuse; to enforce legal rights; or in response to valid legal process or a legally permitted emergency. We do not authorize a service provider to use personal information for its own advertising merely because it processes information for Company.
Sale, Sharing, and Advertising
Company does not sell personal information and does not share personal information for cross-context behavioral advertising under the current Service model. Company does not currently use third-party behavioral advertising or ad analytics. If Company changes that model, this Policy and any legally required choices must be updated before the change is implemented.
Messages, Contact Filtering, Reports, and Administrative Access
Message text may be automatically processed to detect and restrict apparent telephone numbers, email addresses, or similar contact information before a swap is confirmed. Company does not use that processing for behavioral advertising.
Company does not represent that it routinely reads private conversations. Authorized personnel may review limited message content when reasonably necessary to address a member report, safety or fraud concern, support request, Terms enforcement, security incident, valid legal process, or other legitimate Service need. Company limits administrative access to what is reasonably necessary for the stated purpose. Company may delay or withhold notice where notice could compromise safety, privacy, fraud prevention, an investigation, security, or legal process. Company does not represent that every administrative review uses a specific approval screen, access log, or formal appeal process.
Verification Information
Verification may be optional unless the Service expressly states otherwise for a particular account or feature. Current verification may require a government-issued identification document, a selfie showing the member, and proof showing name and home address. A human comparison of an ID and selfie does not itself create a biometric template and is not automated facial recognition.
Company retains raw verification files in live storage for no more than 30 days after the verification decision, and deletes them sooner when an account is deleted while verification remains pending, unless a genuine legal or security hold applies. Company’s deletion process is intended to remove the underlying file from active storage rather than only removing a database pointer. Company may retain a minimized rejection or anti-abuse record, without the raw images, for up to 24 months where reasonably necessary to prevent repeat abuse, subject to legal holds and later reassessment.
The current verified address may be retained while a verification status tied to that address remains active. Company deletes or minimizes a superseded verified address within 30 days after replacement or expiration of the related status unless a legal, safety, fraud, or dispute reason requires longer retention.
Retention
Category
General period
Exception / purpose
Raw government ID, selfie, and proof of address
30 days after the verification decision; sooner for pending-account deletion
Longer only for a genuine legal or security hold
Daily backups
Up to 7 days
Controlled disaster recovery and legal hold as applicable
Operational logs
7 days
Longer where reasonably needed for an active security incident or legal hold
Minimized verification rejection / anti-abuse record
Up to 24 months
Longer only where justified by serious safety, fraud, or legal hold
Safety-report photos or attachments
Generally up to 24 months after report closure
Longer where reasonably necessary for a legal hold, serious safety matter, or dispute
Safety reports and material admin actions
Generally 3 years after final action
A minimized serious-safety or fraud prevention record may be longer where justified
Account, profile, swap, message, contact, and point data
While account is active; deleted or minimized after account deletion
Limited safety, fraud, legal, support, tax, dispute, and record-integrity needs
Waitlist / launch-notification record
Until launch outreach is complete or the person unsubscribes, subject to suppression records
Minimal suppression record may be retained to honor unsubscribe
Feedback and support
As reasonably needed to resolve and document the request
Minimize when no longer needed
Emergency, veterinary, vaccination, microchip, and confirmed-care information
Available for the active care arrangement; retained with account/swap records only as reasonably needed
Longer where reasonably necessary for a safety report, dispute, legal hold, or record-integrity need
Reusable access credentials (keys/codes/lockbox/alarm details)
Only while operationally necessary for the confirmed arrangement
Hide, rotate, or delete promptly after completion, cancellation, early ending, or a security concern
Account Deletion and Disaster Recovery
When Company provides self-service deletion, deleting an account removes live profile, pet, message, point, contact, and verification records as designed, subject to backup expiration and limited safety, fraud, legal, support, dispute, and record-integrity exceptions. Company may detach identity from a safety report, support record, or another member’s independent swap or point history instead of deleting a record that must remain for those purposes.
If disaster recovery restores an earlier backup, a previously deleted account or record may temporarily reappear in a controlled recovery environment. Company keeps restored deleted data inaccessible to ordinary users and reapplies the deletion ledger or equivalent deletion controls before recovery is treated as complete.
Access, Correction, Download, and Deletion
Members can use Profile and “Your data” to download available account information and delete their account, where those controls are available in the current Service. Company may also provide correction tools for available profile fields. A member may use Support for a request that cannot be completed through self-service. These tools may be offered voluntarily even when a comprehensive state privacy statute does not apply to Company.
Communications, Waitlist, and Invitations
Company may send service, security, account, swap, verification, and legal communications reasonably necessary to operate the Service. Neighborhood-launch or other promotional email includes a working unsubscribe method when required by law, and promotional push notifications respect device-level and legally required choices.
A member may use an invitation feature only where the member has a reasonable basis to contact the recipient. Company may process the destination address or telephone number to deliver the invitation, prevent abuse, honor suppression requests, and document compliance. Do not use an invitation feature for deceptive or bulk unsolicited messaging.
Cookies and Similar Technologies
The current Service does not use advertising cookies, ad analytics, behavioral advertising, or cross-site tracking. The Service may use essential or functional technologies for authentication, security, session continuity, preferences, app operation, fraud prevention, and similar internal functions. A materially different analytics or advertising practice would require an updated notice and any legally required choice before deployment.
Because the current model does not intentionally track users across third-party websites for behavioral advertising, the Service does not respond differently to browser “Do Not Track” signals on that basis. Other parties are not authorized by Company to collect personally identifiable information through the Service over time and across different websites for behavioral advertising under the current model.
Children
The Service is for adults 18 and older and is not directed to children under 13. Company does not knowingly allow children to create member accounts. If Company learns that a minor created an account, it may disable the account and delete associated information subject to limited safety, fraud, legal, and record-integrity needs. Company limits information an adult provides about children in a household to what is reasonably necessary for a care arrangement and does not treat it as a public profile field.
Data Location and International Processing
The primary Supabase database and file storage are located in Oregon, United States. Service providers may use subprocessors, personnel, or infrastructure in other locations, so personal information may be processed outside the state or country in which a user resides.
Security
Company uses administrative, technical, and organizational safeguards designed for the sensitivity of the information and the size and nature of the Service. Depending on the production configuration, safeguards may include least-privilege access, separate reviewer accounts, multifactor authentication where supported, expiring verification links, access controls, deletion jobs, incident response, secure software practices, and logging appropriate to the system. No system is completely secure, and this Policy does not promise a control that has not actually been implemented.
Security Incidents
Company maintains a separate internal breach-response plan for containment, evidence preservation, scoping, legal assessment, remediation, and legally required notice. If California breach-notification law applies, Company will assess the affected data, encryption and credential status, acquisition or reasonable belief of acquisition, affected jurisdictions, notice method, regulator obligations, and then-current statutory deadlines rather than assuming every security event requires the same response.
California Privacy Notice
California’s online privacy policy statute applies broadly to commercial websites and online services that collect personally identifiable information from California consumers. This Policy identifies the categories collected, categories of third parties with whom information may be shared, user-access and change processes where offered, the process for material Policy changes, the effective date, and current tracking practices.
Based on Company’s current scale and business model, Company does not represent that it currently meets the thresholds that define a “business” subject to the California Consumer Privacy Act. As of this Policy’s date, the principal statutory thresholds include annual gross revenue of at least $26,625,000 for the preceding calendar year, buying, selling, or sharing the personal information of 100,000 or more California consumers or households, or deriving 50% or more of annual revenue from selling or sharing California consumers’ personal information. These thresholds and Company’s scale or practices can change. Company will reassess coverage and provide any supplemental notices and rights required if the law becomes applicable.
Changes to This Policy
Company may update this Policy and will update the effective date. For a material change, Company will provide conspicuous in-app, website, or email notice as appropriate. Company will not apply a materially incompatible new use of previously collected information without any notice or consent required by then-current law.
Contact
Submit privacy questions and requests through the support channel made available in the Service while you have access to an account, or through the current contact channel at thepetswap.com if you cannot access the app. Company intentionally does not publish a member-manager’s private residential address in this Policy. Formal service of legal process is governed by applicable law and Company’s current public entity information.