Kennelflow

Privacy policy

Last updated 21 September 2026.

This policy explains what personal data Kennelflow holds, why we hold it, and what you can ask us to do with it.

Who is who

For the account holder's own details (your name, email, facility name, billing record) we are the data controller. For the records you enter about your customers and their animals, you are the controller and we are your processor: we hold and process that data only to provide the service to you.

What we hold

What we do not do

We do not sell personal data, we do not use your facility data to train models, and we do not serve third-party advertising or advertising trackers. The app sets one cookie, kf_session, which keeps you signed in; it is HttpOnly and carries no tracking identifier. There is no analytics script on this site.

Processors we use

How long we keep it

Facility data is kept while your account is open and deleted within 30 days of closure. Billing records are kept as long as tax law requires. Logs are kept for up to 30 days.

Your rights

You can export everything yourself at any time from Import / export. You can also ask us to correct or delete data, to restrict processing, or to provide a copy; write to us via the support page and we will answer within 30 days. If you are in the UK or EU you may complain to your data protection authority.

Security

Traffic is served over HTTPS. Passwords are stored as scrypt hashes with a per-password salt. Sessions are HttpOnly cookies. Billing webhooks are signature-verified and rejected outright if the signature is missing or wrong. The database volume is snapshotted nightly.