1. Who we are & scope
VetVero is operated by Eskaris LLC, a Florida limited liability company (“VetVero,” “we,” “us”). This policy explains how data is handled on the VetVero practice-management platform and our public website (together, the “Service”).
VetVero is a business-to-business service: our customers are veterinary practices in the United States and Canada, and the people who use the Service day to day are their staff. This policy covers both — and explains where a practice’s own clients (pet owners) fit in.
2. Our two roles
For clinic and staff data, we are the business. For the account data your practice gives us — staff accounts, clinic profile, billing status, and the technical data in Section 3 — Eskaris LLC decides how and why it is processed, acting as the “business” under the CCPA (and the equivalent role under PIPEDA).
For patient and pet-owner records, your clinic is the business. The practice controls the veterinary records it keeps — patient records, pet-owner contact details, medical notes. VetVero processes that data solely on the clinic’s instructions to provide the Service, as a “service provider” under the CCPA and the equivalent under PIPEDA. We do not use it for our own purposes. These roles are formalized contractually in our Data Processing Addendum.
Pet owners: if a veterinary practice holds records about you or your animal in VetVero, direct privacy requests to that practice — it is the custodian of its records. We support the clinic in fulfilling such requests (Section 9).
3. Information we collect
Account & clinic data (provided by you at registration and in settings):
- your name, email address, and sign-in credentials;
- your clinic’s name, address, phone number, timezone, and locale preferences;
- your clinic’s tax ID, which is printed on the invoices you generate;
- staff details entered by your practice or by each staff member: names, email addresses, an optional phone number and profile photo, roles (administrators, veterinarians, and staff), and — for prescribers — license and DEA numbers;
- subscription status. Payment card details are collected and processed by Paddle (Section 5), never stored by us.
Practice data (entered by your clinic in the course of care): pet-owner names and contact details, patient records, medical notes, vaccination histories, appointments, prescriptions, invoices, and uploaded photos and files. Pet owners may also submit some of this themselves — a clinic’s public online-booking page collects the owner’s name and contact details on that clinic’s behalf. Your clinic controls this data either way (Section 2).
Inquiries: if you contact us — through the contact form or our mailboxes — we collect the name, clinic, email address, and message you submit, and use them to respond.
Technical data: IP addresses and request logs generated by our hosting infrastructure; the IP address recorded alongside certain audited actions (for example, prescription events); IP and interaction signals processed for rate limiting and bot protection on our public contact form; and error logs. We do not run analytics or tracking scripts, and we build no usage profiles. The small set of cookies we use is described in our Cookie Policy.
4. How we use information
We use the data above to:
- provide, support, secure, and improve the Service;
- send transactional email — account, security, and billing messages about your own account;
- send appointment and vaccine reminders to your clinic’s clients, on your clinic’s behalf and at its direction;
- detect and prevent fraud, abuse, and security incidents; and
- comply with law and enforce our Terms.
What we never do: we do not sell personal information, we do not share it for cross-context behavioral advertising, we show no ads, and we do not use clinic data to train AI models.
5. Sub-processors
These providers process data on our behalf to deliver the Service. Each is bound to process it only for the purpose shown. We may update this list as the Service evolves and will give notice of material changes (Section 12).
Supabase
Database, authentication, and file storage for all Service data.
Data location: United States · supabase.com/privacy
Vercel
Application hosting and request logs.
Data location: United States · vercel.com/legal/privacy-notice
Resend
Transactional and reminder email delivery.
Data location: United States · resend.com/legal/privacy-policy
Twilio
SMS delivery from your clinic’s dedicated number, once messaging activates for your clinic.
Data location: United States · twilio.com/legal/privacy
Paddle
Merchant of Record for subscription billing — payment card data is collected and processed by Paddle, never by us.
Data location: United Kingdom & United States · paddle.com/legal/privacy
Cloudflare
Turnstile bot protection on our public contact form — processes IP address and browser interaction signals to tell people from bots.
Data location: Global edge network (US company) · cloudflare.com/privacypolicy
Google Workspace
Business email for our support, legal, and privacy mailboxes — messages you send to those addresses are stored there.
Data location: United States · policies.google.com/privacy
6. SMS & consent
Once messaging activates for a clinic, reminders are sent from the clinic’s own dedicated number, in the clinic’s name. The clinic is responsible for obtaining its clients’ consent to receive messages, as required by the TCPA in the United States and CASL in Canada.
Recipients can opt out at any time: reply STOP to any message — we stop sending and confirm the opt-out — reply HELP for help, and reply START to resubscribe. We maintain opt-out records. Message frequency varies with appointment and vaccine schedules, and message and data rates may apply. Reminder emails sent on a clinic’s behalf carry an unsubscribe link.
Mobile opt-in data — phone numbers and consent status collected for messaging — is not shared with third parties for their own marketing or any other purpose; it is used solely to deliver the clinic’s messages (Section 5).
7. Security
Protection is layered:
- Tenant isolation. Row Level Security scopes every database query to the authenticated clinic — no clinic can reach another’s data.
- Encryption. TLS for data in transit; encryption at rest for stored data.
- Private files. Patient photos and documents live in private buckets, served only through short-lived signed URLs.
- Role-based access. Staff permissions are enforced at the database policy level, by role.
- Audit logs. Clinical, financial, and account-security actions are logged with the acting user and timestamp.
No system is 100% secure. Keep your credentials confidential, and tell us promptly if you suspect unauthorized access to your account.
8. Retention & deletion
While your subscription or trial is active, we retain your data to run the Service. After your subscription or trial ends, your data is retained for 90 days — during which you can still export it — and is then permanently deleted. Copies may persist briefly in encrypted backups until those backups are rotated out; backups are used only for disaster recovery.
You can export your clinic data as CSV files at any time. Your practice is the custodian of its medical records and is responsible for retaining them as its state or provincial rules require — see Terms §7. Export before the 90-day window closes.
9. Your rights
United States (CCPA/CPRA). California residents — and residents of states with similar laws — may request to know and access the personal information we hold about them, correct it, delete it, or receive it in a portable format, and will never be discriminated against for exercising those rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of and no “Do Not Sell or Share” link is required.
Canada (PIPEDA). You may request access to your personal information, ask us to correct it, and withdraw consent to its processing (which may limit our ability to provide the Service). You may also complain to the Office of the Privacy Commissioner of Canada.
How to exercise these rights: email privacy@vetvero.com or use the contact form. We verify identity before acting on a request and respond within the timelines the applicable law requires. If your data is held in a clinic’s records, we will refer you to that clinic and assist it (Section 2).
10. Data location & international transfer
Service data is hosted in the United States (Section 5). For Canadian practices this means personal information is transferred to, stored in, and processed in the United States, where it is subject to US law.
By using the Service, a Canadian practice consents to that transfer and is responsible for its own PIPEDA transparency — telling its clients that records are processed by a US-based service provider.
11. Children
The Service is a professional tool for veterinary practices and their staff, who must be at least 18 (Terms §1). It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor’s information has been entered into the Service, contact us and we will help remove it.
12. Changes to this policy
We may update this policy as the Service and the law evolve. For material changes we will give notice by email or in-app notice before the new policy takes effect, and we always update the “Last updated” date above. Continued use of the Service after the effective date constitutes acceptance.
13. Contact
Questions, concerns, or privacy requests: