This Privacy Policy describes how ZendPaw (operated by CardoCore) collects, uses, and protects your personal information. Reviewed against LFPDPPP 2025 (Mexico), CCPA/CPRA (United States), and GDPR (European Union).
Privacy Policy
1. Who We Are
ZendPaw is a SaaS platform for pet service businesses, operated by CardoCore, based in the Yucatán Peninsula, Mexico.
Data Controller (for data we collect directly from you):
Company: CardoCore / ZendPaw
Email: hello@zendpaw.com
Website: www.zendpaw.com
Data Processor (for personal data you upload about your clients):
ZendPaw acts as a data processor on behalf of you, the business owner, who acts as the data controller for your clients' data. Your obligations as a data controller toward your clients are described in our Terms of Service.
2. What Data We Collect
We collect personal data in the following categories.
| Data Category | Specific Data | How Collected | Why We Need It |
|---|---|---|---|
| Account Data | Full name, business name, email address, phone number, business type, country | Registration form | To create and manage your account |
| Billing Data | Name on card, billing address, subscription plan | Stripe checkout (we do not store card numbers) | To process payments and issue invoices |
| Business Operations Data | Appointment records, service history, staff schedules | You enter it in the app | To provide the core platform functionality |
| Client & Pet Data | Names, contact details, pet names, breeds, vaccination records, service notes entered about your clients | You enter it in the app | To power pet profiles and appointment management features |
| Usage Data | Pages visited, features used, session duration, browser type, device type, IP address | Automatically collected | To improve the platform and diagnose issues |
| Communications Data | Emails you send us, support requests | You send them to us | To provide customer support |
| Cookie & Tracking Data | Cookie consent status, session tokens, analytics events | Automatically via cookies | See our Cookie Policy at www.zendpaw.com/cookies |
We do not collect: government ID numbers, social security numbers, financial account numbers, health insurance information, biometric data, or racial/ethnic origin data.
3. How We Use Your Data
We use your personal data for the following purposes and on the following legal bases:
| Purpose | Data Used | Legal Basis (GDPR) | Legal Basis (LFPDPPP) |
|---|---|---|---|
| Providing the Service | Account, billing, operations data | Performance of contract | Consent / contractual necessity |
| Processing payments | Billing data, forwarded to Stripe | Performance of contract | Contractual necessity |
| Sending transactional emails (confirmations, receipts, alerts) | Email address | Performance of contract | Contractual necessity |
| Customer support | Communications data | Legitimate interest | Legitimate purpose |
| Platform improvement using anonymized analytics | Anonymized usage data | Legitimate interest | Legitimate purpose |
| Security and fraud prevention (CAPTCHA, rate limiting) | IP address, device data | Legitimate interest | Legitimate purpose / legal obligation |
| Legal compliance | As required | Legal obligation | Legal obligation |
| Marketing emails (only if you opt in) | Email address | Consent | Consent |
We do not use your data for:
- Selling personal information to third parties
- Targeted advertising
- Automated decision-making that produces legal effects without human review
- Building profiles for resale or data brokerage
4. Client and Pet Data - Your Responsibility
ZendPaw is a tool you use to manage your own clients' data. When you enter your clients' names, contact details, pet health records, or any other personal information into ZendPaw, you are the data controller for that data under applicable privacy laws.
As the data controller, you are responsible for:
- Having a lawful basis to collect and store your clients' personal data (e.g. consent, contract performance)
- Informing your clients about how their data is used
- Responding to your clients' data access or deletion requests
- Complying with LFPDPPP 2025, CCPA, GDPR, or other laws applicable to your jurisdiction and your clients' jurisdictions
ZendPaw processes this data only on your behalf and according to your instructions. We do not use your clients' data for our own purposes beyond what is necessary to operate the platform.
Pet health records (vaccinations, medical notes) may constitute sensitive personal data under some jurisdictions. You are responsible for handling these records with appropriate care and obtaining consent from your clients where required.
5. Who We Share Your Data With
We share personal data only with the following trusted third-party service providers who process data on our behalf. We do not sell your data.
| Provider | Purpose | Data Shared | Their Privacy Policy |
|---|---|---|---|
| Stripe, Inc. (USA) | Payment processing | Billing name, email, subscription amount | stripe.com/privacy |
| Cloudflare, Inc. (USA) | Security, DDoS protection, bot detection (Turnstile) | IP address, browser fingerprint, request metadata | cloudflare.com/privacypolicy |
| Resend, Inc. (USA) | Transactional email delivery | Email address, email content | resend.com/legal/privacy-policy |
| Neon, Inc. (USA) | Cloud database hosting | All data stored in the platform | neon.tech/privacy |
| Vercel, Inc. (USA) | Web hosting and deployment | IP address, usage logs | vercel.com/legal/privacy-policy |
All third-party providers are contractually required to:
- Process data only for the specified purpose
- Maintain appropriate security measures
- Not sell or disclose your data to other parties
- Comply with GDPR, CCPA, and LFPDPPP as applicable
We may also disclose personal data if required to do so by law, court order, or government authority, or to protect the rights, property, or safety of ZendPaw, our users, or the public.
6. International Data Transfers
ZendPaw is operated from Mexico and serves users in Mexico, the United States, and internationally. Our infrastructure (Neon, Vercel, Resend, Stripe, Cloudflare) is located primarily in the United States.
By using ZendPaw, you acknowledge that your data may be transferred to and processed in the United States, which may have different data protection laws than your country.
For Mexican users: Cross-border data transfers are made to service providers who maintain equivalent data protection standards as required by LFPDPPP 2025.
For EU/UK users: We rely on Standard Contractual Clauses (SCCs) where applicable for transfers of EU personal data to third countries.
7. Data Retention
We retain your personal data for the following periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account and profile data | Duration of account + 30 days after deletion | To provide the service; allow data export |
| Billing records and invoices | 7 years | Tax and legal compliance (Mexican SAT requirements; US IRS guidance) |
| Client and pet data you upload | Duration of account + 30 days after deletion | Your operational data |
| Usage and analytics data (anonymized) | 24 months | Platform improvement; CCPA record-keeping requirement |
| Support communications | 2 years | Quality assurance and dispute resolution |
| Security logs (IP, access logs) | 90 days | Security monitoring and incident investigation |
After the retention period, data is deleted from active systems within 30 days and from backup systems within 90 days, unless legally required to retain it longer.
8. Your Privacy Rights
All Users
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated data
- Receive a copy of your data in a portable format
- Withdraw consent for optional processing (e.g. marketing) at any time
Mexican Users - Derechos ARCO (LFPDPPP 2025)
Under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP 2025), you have:
- Derecho de Acceso: Right to know what data we hold and how we use it
- Derecho de Rectificación: Right to correct inaccurate data
- Derecho de Cancelación: Right to request deletion of your data when no longer needed
- Derecho de Oposición: Right to object to processing of your data for certain purposes
To exercise ARCO rights:
Email: hello@zendpaw.com
Subject line: "Solicitud ARCO - [your name]"
We will respond within 20 business days as required by law.
You may also file a complaint with the Secretaría Anticorrupción y Buen Gobierno (SABG) at www.gob.mx/sabg
US Users - CCPA/CPRA Rights
California residents have the right to:
- Know what personal information is collected and how it is used
- Delete personal information (with certain exceptions)
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (we do not sell personal information)
- Non-discrimination for exercising your rights
To submit a CCPA request:
Email: hello@zendpaw.com (Subject: "CCPA Request")
We respond within 45 days as required by law.
Two methods of request submission available:
(1) Email above (2) Account Settings > Data & Privacy
EU/UK Users - GDPR Rights
EU and UK residents have the right to:
- Access, rectification, erasure ("right to be forgotten")
- Restriction of processing
- Data portability
- Object to processing based on legitimate interests
- Lodge a complaint with your national supervisory authority
To submit a GDPR request: hello@zendpaw.com
Response within 30 days.
9. Security Measures
We implement commercially reasonable technical and organizational security measures to protect your data, including:
- HTTPS/TLS encryption for all data in transit
- Bcrypt password hashing (passwords are never stored in plain text)
- Rate-limited authentication endpoints to prevent brute-force attacks
- Cloudflare Turnstile CAPTCHA on all authentication flows
- Role-based access control within the platform
- Isolated per-tenant data architecture
- Regular security reviews and dependency updates
Despite these measures, no internet transmission or electronic storage system is 100% secure. If you discover a potential security vulnerability, please report it responsibly to hello@zendpaw.com.
10. Children's Privacy
ZendPaw is a business management tool intended for adults operating pet service businesses. We do not knowingly collect personal data from individuals under the age of 18.
If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@zendpaw.com and we will delete it promptly.
Note: Pet data (names, breeds, vaccination records) relates to animals, not children. Client contact data entered by business owners for scheduling purposes does not constitute children's data.
11. Cookies
We use cookies and similar tracking technologies on our websites. For full details about the cookies we use, their purposes, and how to manage them, please see our Cookie Policy at www.zendpaw.com/cookies.
In summary:
- Essential cookies: always active, required for login and security
- Analytics cookies: only loaded after you accept cookies
- Security cookies (Cloudflare Turnstile): active for bot protection on authentication flows
- Third-party cookies: Stripe (payment), Cloudflare (security)
12. Marketing Communications
We may send you marketing emails if you have opted in during registration or via account settings. Each marketing email includes an unsubscribe link. You can also opt out at any time by emailing hello@zendpaw.com.
Transactional emails (receipts, appointment confirmations, security alerts, password resets) are sent as part of the Service and cannot be opted out of while your account is active.
We do not use your data for third-party advertising networks or sell your email address to any party.
13. Automated Decision-Making
ZendPaw does not make automated decisions that produce legal or significant effects about you without human review.
Our platform uses automation for:
- Sending appointment reminders (triggered by your configured settings)
- Spam and bot detection (Cloudflare Turnstile)
- Rate limiting (to protect against abuse)
None of these processes make decisions that affect your legal rights, access to services, or create legally binding obligations without human oversight.
14. Aviso de Privacidad - Resumen (LFPDPPP 2025)
🇲🇽 Para usuarios mexicanos
In compliance with Article 15 of Mexico's LFPDPPP 2025, this section serves as the simplified privacy notice (Aviso de Privacidad Simplificado).
Responsable: CardoCore / ZendPaw
Correo de contacto: hello@zendpaw.com
Domicilio: Península de Yucatán, México
Datos que recabamos:
- Nombre, correo electrónico, teléfono, nombre del negocio
- Datos de facturación (procesados por Stripe)
- Datos operativos que usted ingresa (clientes, mascotas, citas)
Finalidades:
- Proveer y mejorar la plataforma ZendPaw
- Procesar pagos de suscripción
- Enviar comunicaciones transaccionales y de soporte
- Cumplir obligaciones legales
Transferencias: Sus datos son procesados por proveedores tecnológicos (Stripe, Cloudflare, Resend, Neon, Vercel) ubicados en Estados Unidos, quienes mantienen estándares equivalentes de protección.
Derechos ARCO: Puede ejercerlos enviando un correo a hello@zendpaw.com con el asunto "Solicitud ARCO". Responderemos en un plazo máximo de 20 días hábiles.
Consentimiento: Al registrarse en ZendPaw, usted otorga su consentimiento para el tratamiento de sus datos personales conforme a este Aviso de Privacidad y los Términos de Servicio.
15. Changes to This Privacy Policy
We may update this Privacy Policy when our practices change or when required by law. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Send an email notification to registered users at least 14 days before changes take effect
- Display a notice in your account dashboard for significant changes
We encourage you to review this policy periodically. Your continued use of ZendPaw after the effective date of any changes constitutes acceptance of the updated policy.
16. Contact and Data Requests
For any privacy-related questions, data requests, or concerns:
Email: hello@zendpaw.com
Response time: within 5 business days for general inquiries; within the legally required timeframe for formal rights requests (20 business days for ARCO / 45 days for CCPA / 30 days for GDPR)
Two methods to submit data requests:
1. Email: hello@zendpaw.com with subject "Privacy Request"
2. Account Settings > Data & Privacy (for self-service export and deletion)
CardoCore / ZendPaw
Península de Yucatán, México
www.zendpaw.com
For complaints - Mexico:
Secretaría Anticorrupción y Buen Gobierno (SABG)
www.gob.mx/sabg
For complaints - EU/UK:
Contact your local data protection authority.
List of EU authorities: edpb.europa.eu/about-edpb/about-edpb/members
