Privacy Policy — Canada
This is the Canada edition. It applies to shops and pet owners in Canada.Read the United States edition →
Last updated: September 4, 2026
VaxCheck is operated by Vital Brands Inc., 363 N Sam Houston Pkwy E, Suite 125, Houston, TX 77060, USA. This policy explains what we collect, why, who we share it with, and what you can do about it. It is written for people and businesses in Canada and follows the ten fair information principles of the Personal Information Protection and Electronic Documents Act (PIPEDA), and the private-sector privacy laws of Quebec, Alberta and British Columbia where they apply instead.
It covers three groups: Facilities (groomers, daycares, kennels who hold accounts), Pet Owners (consumers who submit records through a Facility's link, and who may also use the records portal at vaxcheck.app/my-pets), and prospective customers we contact by email.
Who is responsible for your data
Accountability. Vital Brands Inc. is accountable for the personal information in its custody or control, including information handled on its behalf by the providers listed below. Our Privacy Officer can be reached at privacy@vaxcheck.app (or hello@vaxcheck.app) or at the postal address at the foot of this page, and is responsible for this policy, for answering access requests, and for receiving complaints.
This matters, because it determines who you ask.
If you are a Pet Owner, the Facility you gave your records to is the controller — it decided to collect them and why. We are its processor: we store and process the data on its instructions, under a written agreement. If you want your data corrected or deleted, ask that Facility first. You can also email us and we will help.
We are the controller for Facility account data, billing records, security logs, and the business contacts in our own sales outreach.
For the features you use directly in the records portal — the pet photo, the public verify link, wallet passes, the Document Vault, the travel folder, and a VaxCheck Plus subscription — we are the controller, because you, not a Facility, decided to use them. Ask us directly about those.
What we collect
From Facilities: your email address, business name, optional phone number, optional logo and booking link, your reminder settings, and your plan and billing status. Payments run through Stripe; we never see or store full card numbers.
From Pet Owners: your name, and your email address and/or mobile number; if you ever opt in to a future text-reminder channel, or accept a Facility's own agreement on its intake form, the consent record needed to prove it (date, time, IP address, browser and the exact wording or agreement version shown); your pet's name, species, breed and any notes you add, such as allergies, behavior or your vet's name; vaccine names, dates administered and expiry dates you type in; and any certificate photo or PDF you upload.
From Pet Owners using the records portal: a photo of your pet, if you add one; the files you place in the Document Vault and any name or expiry date you give them; which pets you turned sharing on for, the share link itself, and a count of how often it was opened; messages and contact details strangers send through the lost-pet relay, if you turn it on; a record of which wallet passes you created; and, if you subscribe to VaxCheck Plus or order a printed card, your Stripe customer reference, plan status and — for a printed card only — the shipping address you give Stripe. We never see or store your full card number.
A note about certificates. A certificate photo often shows your veterinarian's name, clinic and license number, and sometimes their signature. We store the image as you uploaded it. We do not index it or use it for anything but showing it to the Facility and to you — unless you or the Facility ask VaxCheck to read it, which is described in its own section below.
From veterinary clinics: when a Facility or a Pet Owner asks a clinic to confirm records, we store the clinic's name and email address as typed from the certificate, whether the clinic confirmed or disputed the records and when, any note it added, and a one-day hash of the responding connection's IP address used only to limit abuse. When a clinic emails a certificate to a pet's records address, we store the sender address, subject and attachments as described under forwarding below.
From businesses a pet owner hands records to: when a Pet Owner sends one pet's records to a business using the feature described under Handing your records to a business below, we store the business name and email address the owner typed, the country the owner said the business is in, whether we emailed that address or the owner sent the link themselves, whether and when the link was opened and how many times, and — if that business later signs up with the same address — the fact that it claimed the records. We also count how many different owners currently have records waiting for that address, and show that count to the business and to the owners. If you are a business reading this because an owner sent you a link: you do not need an account to read it, we did not get your address from a list, and the message we sent (if we sent it) carries a one-click unsubscribe that stops every email from us permanently. You can also write to privacy@vaxcheck.app and we will delete what is held against your address.
From prospective business customers: business name, city, state, website and a business email address, published publicly by that business. We record where we found it. Every message includes a one-click unsubscribe, and we honour it permanently.
Automatically: standard server logs — IP address, browser type, pages requested — kept for up to 30 days for security and debugging. Our hosting provider tells each page the country of the connection (never a city or an address); we use it only to show the United States or Canada edition of the site and do not store it. We use no advertising trackers, no analytics cookies, and no tracking pixels.
How we use it
To show a Facility the vaccination status of pets in its care; to send vaccine-expiry reminders to Pet Owners on that Facility's behalf; to run the service — sign-in, billing, support, fraud and abuse prevention; and to meet our legal obligations.
We do not sell or share your personal information, we do not rent it, we do not give it to data brokers, and we do not use it for advertising or profiling. We do not sell personal information as that term is defined by the California Consumer Privacy Act.
Pet vaccination data is not human health data. A pet's vaccination record is not your medical information. VaxCheck is not subject to HIPAA and we do not describe ourselves as HIPAA-compliant. We do treat the record as your personal information, because it is linked to you.
Cookies
We set only the cookies the service needs to work: one to keep a Facility signed in, one to keep a Pet Owner signed in to the portal, and small ones that remember the country edition you picked, which of your locations you are viewing, that you dismissed the cookie notice, and — for 30 days — that you arrived from a pet card or a door-policy page. No advertising cookies, no analytics cookies, no tracking pixels, no third-party trackers. Because every cookie is strictly necessary, none requires consent, and the notice you see once at the bottom of the page is a notice, not a consent form. Every cookie is listed by name, purpose and lifetime at vaxcheck.app/cookies. We use no technology that identifies, locates or profiles you within the meaning of Quebec's Law 25, so there is nothing to activate or deactivate.
Email and text messages
Reminder emails go to Pet Owners on behalf of the Facility holding the record. Each one identifies the Facility, carries our postal address, and includes a link to stop receiving reminders. Stopping reminders does not delete your records — contact the Facility for that.
Text reminders are not currently offered. If we introduce them, they will go only to Pet Owners who expressly opt in, STOP will always stop them permanently, and this policy will be updated first.
Our own marketing email to businesses is identified as an advertisement, carries our postal address, and includes a one-click unsubscribe we honour immediately and permanently.
Reading documents with AI — optional, and always checked by a person
A Facility or a Pet Owner can ask VaxCheck to read a vaccination certificate or another pet document so the dates do not have to be typed. This is a choice made each time — by tapping “Read the certificate” or by forwarding an email to a pet's records address — and never happens to a file that was simply uploaded and stored.
- What is sent. The document exactly as we received it, plus the pet's name and species so the reader knows whose certificate it is. A certificate carries whatever is printed on it — typically the owner's name and address, the animal's description, and the veterinarian's name, clinic, licence number and signature — and all of that travels with the image. When a certificate arrives as a forwarded email, the sender's address, the subject line and the message body go too, because they are often where the pet's name is. The subprocessor table below says the same thing; this list used to say the opposite.
- Who processes it. Anthropic, PBC (United States), through its commercial API. Under the terms we hold with Anthropic, the content is not used to train its models and is retained only briefly to operate the service. The provider and its terms are listed in the table below.
- What comes back. A transcription: vaccine names, dates as printed, the clinic block, and a confidence grade for each line. It is shown to the person who asked, who checks it against the document and saves, edits or discards it. Nothing is filed without a person looking at it first, and every saved record carries a mark that it was read from a certificate and checked by a person.
- What we keep. The transcription you approve, the document itself, and a log entry (which account, when, how many pages) used to enforce daily limits. We do not keep the provider's raw response beyond the fields you saw.
- Limits. Reading is a transcription aid, not a verification: it cannot tell a genuine certificate from an altered one, and it may misread a handwritten date. That is why a person checks every line, and why nothing on VaxCheck is ever described as “verified by VaxCheck”.
- No automated decisions. VaxCheck makes no decision about a pet, a person or an account automatically. The status colors are arithmetic on dates a person entered or approved; whether a pet is admitted is decided by the Facility.
- Opting out. Do not use the reader — type the dates instead, or ask the Facility to. A Facility can switch off its pets' records addresses in Settings.
Asking a clinic to confirm
A Facility, or you as a Pet Owner, can ask the veterinary clinic named on a certificate to confirm that the records on file match theirs. We email the clinic a one-click page showing the pet's name and the vaccine names and dates in question — nothing about you beyond your name as the owner, so the clinic can find the right file, and never your contact details. The clinic's answer (confirmed or does not match, with any note) is stored with the record and shown to the Facility and to you. Requests are limited to one per clinic per pet per week. A clinic can ignore the request; after 30 days the link expires.
Forwarding certificates by email
Each pet has a private records address (for example cooper-x7k2m@in.vaxcheck.app) shown in the portal and on the Facility's pet page. Anything sent to it — by you or by your clinic — is received by our email provider, Resend, which keeps the message for 30 days; we store the sender address, subject, the attachments, and the transcription described above, and file the resulting records as unverified for the Facility to check. When the sender is a clinic rather than the owner, the record says so. Mail to an address that matches no pet is answered with a short note; our log of it (sender, subject, and that it matched nothing) is deleted within 7 days, and any attachment is never stored. Do not forward anything to a records address that is not about that pet.
Where your data lives, and who we share it with
All records, including Document Vault files and pet photos, are stored in the United States. Two providers, Google and Apple, receive pet data only when you choose to add a wallet pass. QR codes are drawn by VaxCheck itself and no third party is involved in them. These are all of our subprocessors:
Your information leaves Canada. Vital Brands Inc. is a United States company and every provider above stores and processes data in the United States. Information stored in the United States is subject to United States law and may be accessible to United States courts, law enforcement and national-security authorities under that law. We use it there for the purposes in this policy and no others, protect it with the safeguards described below, and hold each provider to contractual terms at least as protective as this policy. Questions about our providers outside Canada go to our Privacy Officer at privacy@vaxcheck.app.
Quebec. Before personal information about people in Quebec is communicated outside the province we carry out a privacy impact assessment as the Act respecting the protection of personal information in the private sector requires, and we will not use a provider where that assessment concludes the information would not receive adequate protection.
| Provider | What it does | What it gets |
|---|---|---|
| Supabase | Database and file storage | All records, encrypted at rest |
| Vercel | Application hosting | Traffic in transit; server logs |
| Stripe | Payments | Facility and VaxCheck Plus billing details, and the shipping address for a printed card; card data goes straight to Stripe |
| Resend | Email delivery, and receiving certificates you forward to a pet’s records address | Recipient address and message content; for forwarded mail, the sender address, subject, body and attachments, which Resend keeps for 30 days |
| Anthropic | Reads a vaccination certificate you or your shop upload or forward, so the dates can be filled in for a person to check. Not switched on today — no document has been sent to Anthropic, and nothing will be until this line changes. | The document exactly as it was given to us, and the pet’s name. A certificate is not a form we crop: the image typically also carries the owner’s name and address, the animal’s description, the veterinarian’s name, clinic, license number and signature, and any handwriting on the page — all of which travel with it. For a certificate that arrives by forwarded email, the sender’s address, the subject line and the message body go too, because the clinic often writes the dates in the message rather than only on the attachment. Anthropic processes it to return the transcription and does not use it to train models. We keep the transcription a person approves, and the document itself stays with us either way. |
| Cloudflare | Bot protection on the sign-in form (Turnstile) | IP address and a challenge token |
| Google (Google Wallet) | Holds a pet card pass on Android, only if you add one | Pet name, species, breed, photo, vaccine names/dates/statuses, shop name and logo, and the verify link if sharing is on. Never your name, email, phone or address. |
| Apple (Apple Wallet) | Holds a pet card pass on iPhone, only if you add one | The same pet data as Google, minus the photo, plus a device token so the pass can update |
| Twilio | Text-message delivery, where a Facility has it enabled and a Pet Owner has opted in | The mobile number and the message text. Nothing else — no pet record, no account data |
| Sentry (Functional Software, Inc.) | Records application errors so faults are found and fixed | The error and where in the code it happened, plus the account id or address involved where that is what identifies the fault. Never a certificate, a document or a pet record |
Each receives only what it needs, under its own terms. We will post changes to this list here before a new provider starts processing your data.
We also disclose data if the law requires it, to enforce our Terms, to protect someone's safety, or to a buyer in a merger or sale of assets — in which case this policy continues to apply until you are told otherwise.
Security
How it is protected. Every connection uses TLS. Data is encrypted at rest in our database and file storage. Certificate photos and vault files live in private storage buckets that are never publicly listable and are served through short-lived links. Row-level security in the database, enforced by the database itself and not only by our code, means one Facility can never read another's data; the columns a signed-in account can read are granted one by one. Sign-in is by one-time code or link, with no password to steal, protected by Cloudflare Turnstile; the pet-owner portal and every emailed link use signed, expiring tokens.
Who can get in. Production access is limited to the people who run the service, uses the providers' own multi-factor sign-in, and is logged. Facility staff see only the location they were invited to; the owner can suspend or remove a staff login at any time and sees an activity log of what staff did. VaxCheck staff access to records is limited to support, abuse and security cases and is logged.
How it is tested and kept. Every change runs an automated suite before it ships, including checks that one account cannot reach another's rows. Our database provider takes daily backups. Deleted data is removed from live storage immediately and ages out of backups on the provider's schedule. Rate limits sit on every public form and link.
How it is disposed of. When you delete a pet, a document or a photo, the file is deleted from storage at that moment; when an account is closed, its rows are deleted within 30 days and its files with them.
A fuller description, including what we do not claim (no SOC 2 report of our own, no HIPAA), is at vaxcheck.app/security.
About owner update links. The link in a reminder email is a private web address that opens that owner's records without a password. Anyone with the link can use it, so treat it like a password and do not forward it.
No system is completely secure. If we discover a breach of security safeguards involving your information that creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada — and to the Commission d'accès à l'information for people in Quebec, and to the Information and Privacy Commissioner of Alberta where Alberta's Act applies — and notify you, as soon as feasible, with what happened, what information was involved, what we are doing and what you can do. We keep a record of every breach for two years, as PIPEDA requires. If you are a Facility, we will tell you without undue delay so you can meet your own obligations.
Who can see records
Vaccine records and certificate photos are visible only to the Facility account they were submitted to. Pet Owners get a private link showing only their own pets. No Facility can ever see another's data.
If you turn on a pet's public verify link, anyone with that link can see that pet's card — the pet's name, species, breed, photo, vaccine statuses and dates as entered, the name of the Facility that verified each record (its logo too, where it is a paying Facility), a clinic's name and answer where a clinic was asked to confirm a record, and the last-updated date. Never your name or contact details. The link is off by default and you can switch it off or replace it at any time; the old link then stops working immediately. Document Vault files are visible only to you; no Facility, no share link and no wallet pass ever exposes them.
A Facility's public door-policy page (vaxcheck.app/s/its-name) shows only what the Facility requires and any note it wrote. It shows no pet and no person. If you are signed in to the portal, it can check your own pets against that policy on your screen only; nothing about that check is sent to the Facility.
VaxCheck staff can access records where needed to provide support, investigate abuse or security incidents, or comply with the law. Access is limited to people who need it, and we log it.
Your records portal, and sending records to another facility
If you are a Pet Owner, you can sign in at vaxcheck.app/my-pets using the email address you gave a Facility. There is no password: we email you a link, which proves you control the mailbox. The portal shows every pet and vaccination record held for that address, across every Facility that uses VaxCheck.
From the portal you can send a copy of your records to another Facility — for example when you start using a new groomer or kennel. This is entirely your choice and works as follows:
- Only you can start it. A Facility cannot request your records, cannot see whether you hold records anywhere else, and is never told which other Facility you use.
- You choose which pets to send. Nothing is sent until you confirm, and we email you a receipt of what was sent and to whom.
- It copies, it does not move. Your records at every other Facility are unchanged.
- What the receiving Facility gets: your name and email address, and for each pet you selected, its name, species, breed, the current vaccination dates and any certificate photos. Your phone number is not sent.
- Consent to be texted does not transfer. A Facility you send records to cannot text you unless you separately opt in with them.
- Records arrive unverified. The receiving Facility checks the dates against your certificates itself before treating them as current.
We keep a record of each transfer — the address, the destination Facility, which pets you approved and when — so that what you agreed to can be reconstructed. If a transfer happened that you did not authorise, email hello@vaxcheck.app and we will remove the copy.
Handing your records to a business
Separately from the transfer above, the portal lets you send one pet's records to any business, whether or not it uses VaxCheck — a new groomer, a kennel, a sitter, a vet. This is how it works, exactly:
- You start it, one recipient at a time. You type the business name and the email address yourself. There is no list to upload, no address book, no “send to all my shops”, and no way for a business to request this from you.
- We freeze a copy. What we store is the records for that one pet as they stood on the day you pressed send — the vaccine, the dates, and whether a certificate is on file — plus the pet's name, species and breed, your name and your email address. Your phone number is not stored on the share and is never sent. Nothing about any other pet, any other shop, or any other record travels with it.
- The link is the key. Anyone holding it can read that one pet's page for 30 days. It shows the frozen copy and the date it was taken, and it says so on the page. Treat it like a document you emailed: if it is forwarded, whoever receives it can read it too.
- Who sends the message. If you tell us the business is in the United States, we email them the link for you, from us, with a one-click unsubscribe that stops every email from VaxCheck to that address permanently. If you tell us they are anywhere else, we send nothing: we make the link and you send it yourself. Canada's anti-spam law does not permit us to introduce ourselves to a Canadian business on your behalf, and we would rather hand you the link than find an exception.
- What the message says. Your name, your pet's name, the link, why they received it, how to stop hearing from us, and a line saying it is an advertisement — because it also invites them to open a free account. It does not contain your pet's dates; those are behind the link.
- You can take it back. Revoke any link from the portal and it stops working at once, read or unread. You can see, for each one, whether it has been opened and how many times — we do our best to exclude mail scanners and browser prefetches from that count, so it under-reports rather than over-reports.
- Delete the pet and the copy goes too. A share is a copy, so deleting the pet does not automatically reach it — we delete it explicitly, at the same moment.
- If they later sign up with the address you sent to, the records you approved are waiting in their account and they can keep them. What lands is your live record at that point, not the frozen copy, and it lands unverified for them to check. Records you did not approve are not included.
Limits. Five sends a day from one account, and three a day to any one address across all senders. These exist so that nobody — including someone who got into your account — can use this to send mail. They are enforced by the database, not by the page.
Your pet card, wallet passes and share links
The portal shows a pet card for each pet. The card, and everything built from it, is a record summary as entered — not an official certificate. It shows pet data only.
- Pet photo. Optional. Stored in a storage bucket whose files are readable by anyone who has the exact unguessable address, which is what lets a wallet pass and the verify page display it. Remove it from the card at any time and we delete the file.
- Public verify link. Off by default. When you turn it on we create a random link for that pet; when you turn it off or replace it, the old link stops working. We count how many times the page was opened and when it was last opened, so you can see whether the card is being used. We do not record who opened it beyond the standard server logs described above.
- Wallet passes. Free. When you tap “Add to Google Wallet” or “Add to Apple Wallet” we send the pet data listed in the table above to that platform and keep a record of the pass so we can update it when a record changes. Deleting the pass from your phone is something only you can do; we cannot recall it. Apple sends us an anonymous device token so we can tell your phone a pass has changed; it is deleted when you remove the pass.
- Lost-pet relay. Off by default. If you turn it on, a person who scans the card can send you a message. We email you the message and the contact details they typed, unverified. We keep a minimal log (pet, time, and a one-day hash of the sender's IP address that cannot be turned back into an address) to enforce rate limits, and we delete the log entries after 30 days.
- Travel folder share links. Available to every Pet Owner. A share link works for 14 days and can be revoked earlier. It shows the record summary and the names of documents you chose to list — never the files themselves and never your contact details.
The Document Vault
Files you upload to the vault are stored privately in the United States on Supabase, encrypted at rest, in a bucket that is never publicly listable, and served to you through short-lived links. We do not open, review or extract anything from them ourselves. If you tap “read this document” when adding one, it is transcribed as described under Reading documents with AI above, and only then. They are visible only to you when signed in. The vault holds an unlimited number of documents for every pet owner, at no charge. If you give a document an expiry date, we email you before it expires, using the same reminder mechanism as vaccine reminders.
Documents stay until you delete them or close your account. Deletion is immediate and permanent. We do not remove documents from a quiet account on our own; if that ever changes we will say so here first.
VaxCheck Plus, printed cards and sponsored placements
VaxCheck Plus and the printed card are not currently sold. No payment is taken from any pet owner and no payment details reach Stripe through us. What follows is how they would work if either is offered again. VaxCheck Plus ($2.99 a month or $19.99 a year) and the printed card ($14.99, one-time) are paid through Stripe. Stripe gets your email address and payment details, and for a printed card the shipping address; we keep your Stripe customer reference, plan status and order status, and billing records for 7 years as tax law requires. A printed card may be produced by a printing partner who receives only the card image and the shipping address.
Sponsored placements. The portal may show a link marked “Sponsored” — for example to request a pet insurance quote. If you click it and buy, we may earn a commission. The link is outbound only: it carries a fixed reference code that identifies VaxCheck as the source and contains nothing about you or your pet, and we send the partner no data. Sponsored placements are not shown to Plus subscribers. We still do not sell or share your personal information, and we do not use it for advertising.
How long we keep it, and how to delete it
| Data | Kept for |
|---|---|
| Pet and vaccination records | While the Facility's account is active |
| Pets a Facility deletes (with all of that pet's records and photos) | Deleted immediately and permanently — not recoverable |
| All data after you ask us to close your account | Deleted within 30 days of your request |
| Data if you just stop using VaxCheck without asking | Kept until you ask us to delete it |
| Transfer receipts (which pets you sent, where, when, and a one-day hash of the connection) | 24 months, then deleted |
| Document Vault files | Until you delete them or close your account |
| Pet photo | Until you remove or replace it |
| Public verify link, its view count and wallet pass records | Until you turn sharing off / remove the pass; kept with the pet otherwise |
| Lost-pet relay rate-limit log | 30 days |
| Clinic confirmation requests and answers | With the record they concern; an unanswered request expires after 30 days |
| Emails forwarded to a records address (sender, subject, attachments) | Our log of the message for 90 days (mail that matched no pet: 7 days); the records it filed stay with the pet; the provider's copy for 30 days |
| Document-reading log (account, time, page count) | 90 days |
| Compliance reports a Facility generated (totals only) | While the Facility's account is active |
| Travel folder share links | The link works for 14 days, or until you revoke it; the row is deleted 30 days after it stops working |
| Records you handed to a business (the frozen copy and the link) | The link works for 30 days; the row is deleted 30 days after that. Revoking stops the link at once and the copy goes with the row; deleting the pet deletes it at once |
| Business name, address and country you typed when handing records over, and whether the link was opened | With the share above, and gone with it |
| VaxCheck Plus subscription and printed-card order status | While the subscription is active, then with billing records |
| Billing records | 7 years, as tax law requires |
| Server logs | Up to 30 days |
| Reminder opt-outs (the “stop these reminders” link) | Permanently — that is how we know not to email you again |
| Marketing suppression list | Permanently — that is how we make sure we never email you again |
| Business contacts we have approached (name, work address, phone, town, and the software they use) | 24 months, then deleted — except a contact who has asked us to stop, whose record is kept so we never write again |
| Our log of marketing emails we sent a business (subject, time, message id) | 24 months, then deleted |
| Replies a business sends us, and messages to our published addresses | 24 months, then deleted |
| Messaging consent and opt-out records (if any) | Kept with the owner record, to prove consent if challenged |
| Facility agreement acceptances (if a Facility requires one) | Kept with the owner record and the text of the version accepted, to prove acceptance if challenged |
Pet Owners: for vaccination records, ask the Facility that holds them, or email hello@vaxcheck.app and we will pass it on and help. For your photo, verify link, vault documents and share links, you can remove them yourself from the portal at any time. A wallet pass is removed from the phone that holds it — we cannot pull one back, and this sentence used to say you could do it from the portal, where there is no such control. For anything else, email us. Facilities: delete from your dashboard, export from Settings → Account → Import & export, or email hello@vaxcheck.app to close your account and have your data deleted within 30 days.
Because some jurisdictions require pet care facilities to retain vaccination records for a year or more, Facilities should keep their own copies. We are not your system of record.
Your rights
You have the right to know what personal information we hold about you, to be told how it is used and who it has been disclosed to, to get a copy, to have it corrected if it is inaccurate or incomplete, to withdraw consent (subject to legal and contractual limits, and with an explanation of what withdrawing means), and — under Quebec law — to have it de-indexed, to receive it in a structured, commonly used technological format, and not to be subject to a decision based exclusively on automated processing (we make none).
Write to our Privacy Officer at privacy@vaxcheck.app or hello@vaxcheck.app. We respond within 30 days; if we need more time, as PIPEDA allows in limited cases, we will tell you why and when to expect an answer. There is no charge. We may need to verify your identity, and if you are a Pet Owner we will usually need to involve the Facility that holds your records — we will tell you when we do.
If we refuse a request in whole or in part we will tell you why in writing, cite the provision we rely on, and tell you how to challenge the refusal. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376); in Quebec, to the Commission d'accès à l'information (cai.gouv.qc.ca); in Alberta, to the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca); in British Columbia, to the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).
Consent. When you enter records through a Facility's form you consent to the uses described here, which are the ones a reasonable person would expect from a pet-care business asking for vaccination records. Where a use would not be expected — a clinic confirmation request, adding a wallet pass, turning on a public link — we ask you at that moment, and you can undo it in the portal.
Marketing email to businesses. We send no unsolicited commercial email into Canada at all. Canada's Anti-Spam Legislation requires consent before a commercial electronic message is sent, so a Canadian address is refused when a prospect list is imported and refused again before any message is prepared. If you are a Canadian business and hear from us commercially, it is because you asked to; every such message identifies us, carries our postal address and includes an unsubscribe we honour immediately. We send no marketing to Pet Owners anywhere.
Children
VaxCheck is for businesses and adult pet owners. It is not directed at children and we do not knowingly collect their information; where a minor under 14 is concerned, Quebec law requires a parent's consent, which our forms do not seek because they are not for minors. If you believe a child submitted data, email hello@vaxcheck.app and we will delete it.
Connecting to other services
VaxCheck does not connect to your booking software, your accounting software or any other system, and does not pull data from them. Where a Facility gives us a booking link, we show that link in reminder emails; where you add a wallet pass, we send the pass data to Google or Apple as described above. The “arrivals check” a Facility can run matches a list of names it pastes from its own booking software against its own pets, on our server, and stores nothing from the list.
Changes
We will post material changes here and notify Facility account holders by email before they take effect.
Vital Brands Inc. · 363 N Sam Houston Pkwy E, Suite 125, Houston, TX 77060 · hello@vaxcheck.app · Privacy Officer: privacy@vaxcheck.app