Effective Date: September 8, 2026
CanOS ("we," "our," or "us") is a kennel and animal care business management platform operated by ODIN Consulting LLC. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the CanOS mobile application and web platform (collectively, the "Service"). By using the Service, you agree to the practices described here.
When a staff member connects Gmail, CanOS receives the connected email address and OAuth access and refresh credentials. We encrypt stored Gmail credentials and use the requested Gmail permissions only to read messages and attachments shown in the Gmail Center, read the selected sending identity/signature, apply message labels, move messages to or from Gmail Trash when a staff member directs it, and send email on the connected account's behalf. CanOS does not permanently delete Gmail messages or change Gmail account settings. Personal Gmail inbox content is read live and is not copied into CanOS; we retain the connection credential and short-lived Gmail message identifiers used to avoid duplicate inbox notifications.
For an account-level Gmail connection, CanOS may copy an incoming email that matches a CRM contact into that contact's communication history. The copied record can include sender, subject, message body, Gmail message/thread identifiers, and the resulting in-app notification. We retain these copies only while the account-level Gmail connection remains active or until the business deletes the associated CRM record.
Connecting a financial institution through Plaid is optional. The connection begins only when an authorized CanOS user chooses to open Plaid Link, selects an institution and accounts, and authorizes Plaid to share information with CanOS. CanOS currently requests Plaid's Transactions product. Depending on what the institution makes available, CanOS receives account-identifying details such as the institution and account name and Plaid identifiers, together with transaction information such as transaction and pending-transaction identifiers, dates, amounts, currency, merchant or description information, pending or posted status, and transaction categories. CanOS uses this information for finance review, expense handling, reconciliation, financial analytics, and business reporting.
Plaid Link handles the institution sign-in and authorization process. CanOS does not receive or store the username, password, PIN, or other sign-in credentials you enter for your financial institution in Plaid Link. Plaid and the connected financial institution also process information under their own terms and privacy notices. Please review Plaid's End User Privacy Policy and the privacy notice of your financial institution.
After authorization, CanOS stores an encrypted Plaid connection credential so the Service can request transaction updates, as well as institution/account labels and identifiers needed to identify the connection. Imported transaction records are stored in the applicable CanOS business account or franchise unit and are protected by the same access controls and safeguards described in this Policy. No method of storage or transmission is completely secure, and we do not guarantee absolute security.
We use the information we collect to:
CanOS is a multi-tenant platform. Each business account ("tenant") operates in an isolated data environment. Staff members, client data, and operational records belonging to one account are not accessible to other accounts. Tenant isolation is enforced at both the application layer and the database layer. We do not use one tenant's data to train models or improve outcomes for other tenants.
You can remove a personal Gmail connection at any time from Gmail → Accounts. An account administrator can remove the shared account-level Gmail connection from the same screen. Disconnecting revokes the Google credential where Google accepts the revocation request, deletes the local OAuth credentials immediately, stops future Gmail access and notification delivery, and removes Gmail-synced CRM email copies and Gmail-derived in-app notifications from the active database. A completion record containing only the time, request scope, and deletion counts is retained so support can verify the request; it does not contain Gmail credentials, message content, subjects, or email addresses.
Backups are access-restricted and are retained for up to 30 days for disaster recovery. Deleted Gmail data is removed from active systems immediately and is not restored from a backup except as required for disaster recovery; if a backup restoration is necessary, the next deletion sweep removes the Gmail data again. You may also request deletion through our data-deletion page or by emailing support@canos.app. We verify the requester and complete eligible requests within 30 days.
An authorized user can disconnect an account-level Plaid connection from the account integrations settings or a unit-level Plaid connection from the applicable K9 Metrics unit connection settings. Disconnecting removes the local Plaid access credential and stops CanOS from requesting future transaction updates for that connection. It does not automatically delete transaction records already imported into CanOS, and it may not by itself end every relationship you have with Plaid or your financial institution.
Previously imported financial records remain subject to the retention terms below, including retention needed for business records, accounting, dispute resolution, legal obligations, and other legitimate business needs. An ordinary disconnect does not purge those records. An authorized user may request deletion of the local Plaid credential and eligible imported Plaid records by emailing support@canos.app; the request must be authenticated before we act. Account closure or expiration of the approved purpose also triggers deletion of eligible Plaid records. We verify the requester and scope before acting. Some imported financial records may be retained where required by law or a documented hold; backup copies expire under our disaster-recovery schedule.
We do not sell your personal information. We may share information in the following limited circumstances:
We work with trusted third-party providers who process data on our behalf, including:
We may disclose information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of CanOS, our users, or others.
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify affected users before any such transfer takes effect.
We may share information with third parties when you have explicitly authorized us to do so.
CanOS sends appointment reminders and general operational messages to users who opt in by checking the SMS-consent box on one of our public sign-up forms (see our SMS Consent page). Message frequency varies. Message and data rates may apply. Reply STOP to opt out at any time, or HELP for help. For full SMS terms see the Terms of Service.
No mobile information, phone numbers, or SMS opt-in consent will be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers are only shared with our SMS provider (Twilio) strictly for the purpose of delivering the messages the user opted in to receive.
Dog owners who access the CanOS Client Portal do so at the invitation of a kennel or trainer that uses CanOS. The business that invited you is the primary controller of your data within their account. We process that data on their behalf in our capacity as a data processor. For questions about how a specific business uses your data, please contact them directly.
Your data is stored in encrypted databases hosted in secure cloud infrastructure. Files and media are stored in private object storage with access controlled via expiring signed URLs. Stored third-party connection credentials, including Plaid access credentials, are encrypted. We implement role-based access controls, JWT-based authentication, and audit logging to protect against unauthorized access. Passwords are never stored in plain text.
While we take industry-standard precautions, no system is completely immune to security risks. We encourage users to use strong passwords and notify us immediately at support@canos.app if they suspect unauthorized access.
We retain your data for as long as your account is active or as needed to provide the Service. Retention can vary by data type and purpose. Deleted records may remain in a recoverable state for a limited period before permanent removal, and access-restricted disaster-recovery backups are retained for up to 30 days. If you close your account, we will delete or anonymize your data within a reasonable timeframe, except where retention is required by law or a documented legitimate business need, such as maintaining financial or transaction records. Plaid connection credentials and imported records follow the specific disconnection and deletion terms in Section 3B.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at support@canos.app. We may need to verify your identity, authority, and the account or records covered by the request. Rights and exceptions vary by jurisdiction, and certain financial records may need to be retained as described above.
The CanOS platform is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has submitted information to us, please contact us at support@canos.app.
The CanOS web application uses session storage and local storage to maintain authentication state and user preferences. We do not use third-party advertising trackers or behavioral profiling cookies. Anonymous usage analytics may be collected to help us improve the platform.
The Service may include optional integrations with third-party platforms, including Google, Facebook, Stripe, Twilio, and Plaid. Information handled by a connected provider is also subject to that provider's privacy policy and, where applicable, the privacy policy of the institution you connect. We encourage you to review those notices before authorizing an integration. For connected financial accounts, see Section 3B and Plaid's End User Privacy Policy.
We may update this Privacy Policy from time to time. When we do, we will revise the Effective Date at the top of the page. For material changes, we will provide notice via the app or by email. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
ODIN Consulting LLC
CanOS Platform
support@canos.app
https://canos.app