Loading page
Preparing the latest SaddleSync information.
Effective: August 15, 2026
Help improve SaddleSync by sharing pseudonymous feature usage and narrowly triggered diagnostic recordings. Names, emails, rider information, payment details, and form entries are excluded.
This setting controls future collection only; changing it does not automatically delete historical analytics. It applies to this browser across SaddleSync barn subdomains.
This Privacy Policy explains how SaddleSync collects, uses, shares, and protects your personal information. It applies to all users of saddlesync.app and all barn subdomains operated on the platform.
Account Data: When you create an account, we collect your name, email address, phone number, and a hashed version of your password.
Child and Rider Data: Parents and guardians provide information about their children, including name, date of birth, skill level, emergency contact name and phone number, and optional medical notes or allergies. This data is provided with parent or guardian consent.
Barn Data: Barn owners provide their barn name, subdomain, timezone, logo, and administrative settings.
Financial Data: Payment information is processed and stored by Stripe. SaddleSync does not store credit card numbers or full bank account details.
Waiver Data: Digital signatures, typed legal names, and agreement timestamps are collected and stored when parents sign liability waivers.
Usage Data: We collect session data, login timestamps, and notification preferences to operate the platform.
Product Analytics Data: When usage analytics is enabled, we use pseudonymous account and barn identifiers, role categories, sanitized page paths, feature and outcome codes, aggregate counts, bounded performance measurements, and privacy-restricted interaction data. We configure analytics to exclude names, email addresses, rider information, payment details, waiver content, form entries, URL query strings, and access tokens.
Push Device Data: If you choose browser push notifications, we store an encrypted browser-provided subscription endpoint and keys, a non-reversible endpoint fingerprint, a random installation identifier, a device label you may edit, a broad device platform category, permission and subscription status, and last-seen timestamps for that SaddleSync origin.
We use your information to provide the core SaddleSync service: lesson scheduling, enrollment management, makeup token tracking, payment processing (via Stripe), optional browser push plus email and SMS notifications, calendar synchronization (via Google Calendar API, when enabled by a barn administrator), and platform administration and support.
With Barn Administrators: Parent and child data is shared with the administrators of the barn where the family is enrolled. Barn administrators can view rider details, enrollment history, and payment records for their barn only.
With Payment Processors: Stripe receives payment-related data necessary to process transactions between parents and barns.
With Communication Providers: Resend receives email addresses for transactional email delivery. Twilio receives phone numbers for SMS notifications, when enabled.
With Browser Push Services: If you opt in, your browser selects an external push service and provides SaddleSync a subscription capability used to send encrypted, generic notifications to that browser. The selected service may be operated by the browser or operating-system provider. Lock-screen display and delivery timing are controlled by your browser, device, and operating system.
With Cloud Storage: Vercel Blob stores uploaded barn logos, horse photos, waiver PDFs, and related document assets.
With Google: Calendar event data is shared with Google Calendar when a barn administrator enables calendar synchronization.
With Analytics and Monitoring Providers: PostHog receives pseudonymous, privacy-restricted usage data to help us improve the platform. Qualifying friction events on reviewed safe screens may trigger a sampled, masked diagnostic recording; restricted account, rider, billing, waiver, roster, authentication, and tokenized screens are excluded. Sentry receives error telemetry for application monitoring. Upstash processes request metadata for rate limiting and security purposes.
With Accounting Providers: When a barn administrator connects QuickBooks Online or Xero, invoice and payment data is synced to the connected accounting platform for that barn's records.
We do not sell your personal data to third parties. We do not share your data with advertisers.
SaddleSync does not collect personal information directly from children under 13. All child data is provided by a parent or legal guardian during the registration process.
Child data collected is limited to what is necessary for lesson management: name, date of birth, skill level, emergency contacts, and medical notes.
Parents may request access to, correction of, or deletion of their child's data at any time through their dashboard or by contacting support.
We use industry-standard security measures to protect your data, including HTTPS encryption for all data in transit, hashed passwords, and role-based access controls.
Payment data is handled by Stripe, which is PCI DSS compliant. SaddleSync does not process or store raw payment card data.
Account data is retained for as long as your account is active. Waiver records are retained in accordance with legal requirements. Payment records are retained per Stripe's data retention policies.
Upon account deletion, your personal data will be removed within a reasonable processing period, except where retention is required by law.
Removing a notification device clears its stored subscription capability immediately. The revoked device tombstone is retained for up to 30 days for security and cleanup. Notification center items and delivery summaries are retained for up to 90 days, and individual delivery-attempt records for up to 30 days.
Each barn on SaddleSync operates as an independent tenant. Barn administrators can only access data for users enrolled at their barn. Data from one barn is not visible to administrators of another barn.
Platform administrators have limited access to barn and user data for the purposes of support, billing, and enforcing these terms.
You may access and update your personal information through your SaddleSync dashboard at any time. You may request a copy of your data or request that your account and data be deleted by contacting support@saddlesync.app.
You may opt out of non-essential notifications through your notification preferences. Transactional notifications (such as booking confirmations) cannot be fully disabled while your account is active.
Browser push is optional and device-specific. You may change notification types, turn notifications off for the current device, or revoke browser permission. Turning notifications off stops future push to that device but does not change independent email settings. Push is best-effort and may be delayed or not delivered; your SaddleSync notification center remains the durable source of truth.
Notifications may appear on a device lock screen. SaddleSync uses generic reviewed lock-screen text, but anyone with access to a shared device may still see that a SaddleSync notification arrived. Remove the device or sign out when you are finished using a shared device.
You may turn Usage analytics off in Account Settings. This account-wide preference stops future eligible browser analytics, diagnostic recordings, identification, and user-linked server analytics on every device after the preference is saved. Anonymous visitors may use the control on this Privacy page. Turning analytics off does not automatically delete historical data; you may contact support@saddlesync.app about applicable access or deletion rights.
SaddleSync uses session cookies for authentication purposes. We use Sentry for error tracking and application monitoring. When Usage analytics is enabled, PostHog uses first-party local storage and cookies across SaddleSync barn subdomains for pseudonymous product analytics, privacy-restricted autocapture and heatmaps, and narrowly triggered diagnostic replay.
Diagnostic replay is not continuous. A recording is eligible only after a reviewed dead-click, rage-click, or safe action-failure trigger on an approved route and a deterministic sample. Inputs and dynamic text are masked, and network bodies, request headers, console logs, canvas contents, and embedded iframe contents are not recorded.
We do not use third-party advertising trackers or sell data to ad networks.
Account data is retained for as long as your account is active. Upon account deletion, personal data is removed within 30 days, except as noted below.
Financial and payment records are retained for 7 years in accordance with tax and accounting regulations. Waiver records (including digital signatures) are retained for a minimum of 3 years after the last activity date, or longer as required by applicable law. Notification logs are retained for 90 days. PostHog product analytics events are retained for 12 months and eligible diagnostic recordings for 30 days, subject to applicable legal preservation requirements and data rights.
SaddleSync's services are hosted in the United States. If you access the platform from outside the United States, your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
By using SaddleSync, you consent to the transfer of your data to the United States. We rely on industry-standard security measures to protect your data during transfer and storage.
In the event of a data breach that compromises your personal information, SaddleSync will notify affected users via email within 72 hours of confirming the breach. Notification will include the nature of the breach, the types of data affected, steps we are taking to address it, and recommended actions you can take to protect yourself.
We will also notify applicable regulatory authorities as required by law.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
Right to Delete: You may request deletion of your personal information, subject to certain exceptions (such as legal retention requirements).
Right to Correct: You may request correction of inaccurate personal information.
Right to Opt Out of Sale or Sharing: SaddleSync does not sell or share your personal information for cross-context behavioral advertising. No opt-out is necessary.
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To submit a request, contact us at support@saddlesync.app. We will verify your identity before processing your request and respond within 45 days.
We may update this Privacy Policy from time to time. Material changes will be communicated via email. Continued use of SaddleSync after changes take effect constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or your data, please contact us at support@saddlesync.app.