Legal
Last updated: March 9, 2026
This Privacy Policy describes how SpruceSuite, Inc. ("SpruceSuite," "we," "us") collects, uses, and shares information when you use our platform and services. This policy applies to visitors of our website, subscribers, and the clients of businesses using our platform.
We collect information you provide directly when you create an account, request a demo, or use the Service: name, email address, phone number, business name, business address, and billing information.
When you use the Service, you may upload client records, pet records (names, breeds, weight, vaccination status, health notes, photos), appointment data, invoices, staff information, and communication logs. This data belongs to you — see our Terms of Service for data ownership details.
We automatically collect usage data when you interact with our platform and website: pages visited, features used, clicks, device type, operating system, browser type, IP address, and approximate location derived from IP address.
If you use our mobile grooming features, we may collect precise location data with your explicit consent to enable GPS tracking and route optimization. You can revoke location consent at any time through your device settings.
We use your information to provide, maintain, and improve the Service — including processing transactions, managing appointments, enabling client communication, generating reports, and delivering customer support.
We use your email to send transactional notifications (appointment confirmations, invoice receipts, account alerts) and, with your consent, product updates and feature announcements. You can opt out of non-transactional emails at any time via the unsubscribe link in any email or through your account settings.
We use aggregated, de-identified data to analyze platform usage trends and improve the Service. This data cannot be used to identify any individual user or business.
We do not use your data to train machine learning models or for any purpose unrelated to providing and improving the Service.
We do not sell your personal information. We do not share your personal information for cross-contextual behavioral advertising.
We share information with the following categories of service providers, solely to operate the Service:
Google Cloud Platform (Google LLC) — Cloud infrastructure, compute, storage, and database hosting. Data stored in the United States. Stripe, Inc. — Payment processing, invoicing, and PCI-compliant card handling. Twilio, Inc. — SMS and voice communication delivery. Sentry (Functional Software, Inc.) — Error monitoring and application performance (receives limited technical data including error traces; personal identifiers are stripped or minimized before transmission where feasible).
We may disclose information if required by law, subpoena, court order, or government request, or to protect the rights, property, or safety of SpruceSuite, our users, or the public. We will notify you of legal requests for your data unless prohibited by law or court order.
We use essential cookies required for the platform to function, including authentication tokens and session management. These cannot be disabled while using the Service.
We use analytics cookies to understand how users interact with our site and platform. You can manage your cookie preferences through the cookie settings panel accessible from the footer of our website.
We do not use advertising cookies, retargeting pixels, or third-party tracking for advertising purposes. We do not respond to Do Not Track (DNT) browser signals; we honor Global Privacy Control (GPC) signals as the successor opt-out standard.
We implement industry-standard security measures including: encryption in transit (TLS 1.2 or higher) and at rest (AES-256) for all stored data; role-based access controls with multi-tier permission levels; automatic tenant isolation at the database layer ensuring your data is never accessible to other businesses on the platform.
Our platform is hosted on Google Cloud Platform infrastructure. All data is stored in United States data centers with enterprise-grade physical security.
We maintain a vulnerability disclosure program and conduct regular security assessments. If you discover a security issue, use the contact form on our marketing site so the platform team can route it to the right reviewers.
Employee access to production data is restricted to authorized personnel, logged for audit purposes, and granted only as necessary to provide customer support or maintain the Service.
We retain your account data for as long as your account is active.
If you close your account, we delete or de-identify your personal data within 30 days, except: transactional records (invoices, payments) are retained for 7 years in accordance with tax and financial regulations; backup copies may persist for up to 90 days after deletion from production systems; and data we are required to retain by law, regulation, or legal proceeding.
You can request deletion of specific data at any time through your account settings or, if you are reaching out from the marketing site, by using the contact form so the platform team can route your request.
Regardless of where you are located, you have the right to: access the personal information we hold about you; correct inaccurate personal information; request deletion of your personal information; export your data in a portable format; and opt out of non-essential communications.
You can exercise most of these rights directly through your account settings. For requests you cannot complete through the platform, use the contact form on the marketing site and note that your message is a privacy request. We will respond within 45 days (or 30 days for Canadian residents, as required by PIPEDA).
If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act.
Categories of personal information we collect include: (A) Identifiers (name, email, phone number, IP address, account ID); (B) Commercial information (subscription records, billing history, transaction data); (C) Internet or electronic network activity (pages visited, features used, device and browser information); (D) Geolocation data (approximate location from IP address; precise location only with explicit consent for mobile grooming features); and (E) Professional or employment-related information (business name, business address, staff roles). We do not collect sensitive personal information as defined by the CPRA.
Sources of personal information include: directly from you when you create an account or use the Service; automatically through your use of the platform and website; and from payment processors in connection with transactions.
Right to know: You may request the categories and specific pieces of personal information we have collected, the sources of collection, the business purposes for collection, and the categories of third parties with whom we share information.
Right to delete: You may request deletion of personal information we have collected from you, subject to certain exceptions (legal obligations, completing transactions, security).
Right to correct: You may request correction of inaccurate personal information.
Right to non-discrimination: We will not discriminate against you for exercising your privacy rights — no price changes, service reductions, or different treatment.
We do not sell personal information. We do not share personal information for cross-contextual behavioral advertising. Accordingly, there is no need to opt out of the sale or sharing of personal information. We do not offer financial incentives for the collection of personal information.
To submit a privacy request, use the privacy request form in your account settings or the contact form on the marketing site. You may also designate an authorized agent to submit requests on your behalf. To verify your identity, we will ask you to confirm information associated with your account, such as your email address. If we cannot verify your identity, we may request additional documentation.
If you are located in Canada, your personal information is protected under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
We collect, use, and disclose your personal information only for purposes that a reasonable person would consider appropriate in the circumstances, and only with your knowledge and consent. Your personal information is stored and processed in the United States; by using the Service, you consent to this transfer, and we ensure comparable protection for your data regardless of where it is processed.
You have the right to access your personal information held by SpruceSuite, challenge its accuracy, and withdraw consent for its collection, use, or disclosure (subject to legal or contractual restrictions). We will respond to access requests from Canadian residents within 30 days, as required by PIPEDA.
If we become aware of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and report the breach to the Office of the Privacy Commissioner of Canada as required by law.
For privacy inquiries related to your Canadian privacy rights, use the contact form on the marketing site and indicate that your message is related to Canadian privacy rights.
SpruceSuite is designed for business use and is not directed to individuals under 18. We do not knowingly collect personal information from children under 13. If we discover that we have collected personal information from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, use the contact form on the marketing site so the platform team can route the report.
We may update this Privacy Policy periodically. For material changes, we will notify you via email or a prominent notice within the Service at least 30 days before changes take effect.
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy. If you do not agree to the changes, you may close your account before they take effect.
If you have questions about this Privacy Policy or our data practices, use the contact form on the marketing site so the platform team can route your message to the privacy team, or write to: SpruceSuite, Inc., Attn: Privacy Team.