Back to Good Horse People

Privacy notice

How Good Horse People uses your information.

Effective September 21, 2026

Where the product stands today

Good Horse People is in an early-access research phase for routine horse care in Texas. Horse owners and caregivers can submit intake information. Matching, browsing profiles, messaging, booking, and payments are not live. We do not collect payment card or bank data.

Information both sides provide

The short early-access form collects your role as a horse owner or caregiver, first name, email address, five-digit ZIP code, and the care need or experience category you choose. It also creates a consent record with your email address, role, consent action and purpose, the consent and privacy-notice versions, source, capture method, and timestamp. If you continue into a longer intake, we also record consent history, your progress, intake status, and created, updated, and submitted times.

Horse-owner intake

The owner intake collects your first name, email address, ZIP code, routine care tasks, schedule notes, timing or urgency, and barn, property-access, or other care context you choose to provide. For each horse, it collects the horse's name, breed or type, approximate age, handling context, routine notes, and non-medical wellness notes. It also records the order in which horses appear in the intake.

Caregiver intake

The caregiver intake collects your first name, email address, ZIP code, experience category and years, barn-role history, routine responsibilities, how you heard about us, reference readiness, peer referral readiness, and willingness to complete later checks. It also collects routine tasks you would accept or decline, travel distance, availability notes, approximate visits per week, usual lead time, minimum earnings preference, and preferred price structure. We keep the application's research status and a history of status changes, including who or what made the change, the reason, and the time.

Optional caregiver research details

If you take part in later launch-preparation research, we may also collect barn roles; horse types, age groups, temperaments, and herd size; handling and property limits; weekday and weekend availability; service radius and home ZIP; a profile bio; whether you skipped a photo; training and policy acknowledgements; safety-quiz answers, score, and result; and your willingness, relationship categories, and approximate capacity for reference invitations. These are research records. They do not mean you are screened, verified, approved, insured, or available for work through Good Horse People.

Journey and funnel events

We create a random journey_id in browser session storage to connect steps from the same visit without using your name or email as the identifier. We record events such as page and step views, form starts, saves, errors, submissions, withdrawals, and resumes; the related step and time; an arbitrary event-metadata object included in the request, limited to 2,000 serialized characters and potentially including source, status, or error code; and an application ID when one exists. A journey ID can become linked to your intake when you submit it.

How you found us

Links to the site may include a source, referral value, and UTM source, medium, campaign, content, or term. We keep those values in browser session storage during your visit and save them with a signup or intake. We use them to understand which outreach brings owners and caregivers to the research program and where interest exists.

Abuse prevention

We use the network address supplied with a request, email address, journey ID, or private-link token to enforce rate limits. Those identifiers are converted to SHA-256 hashes before rate-limit buckets are stored; the rate-limit table does not store the raw address or email. Depending on the form, we may also check form timing, a hidden honeypot field, and the email domain. Honeypot submissions are not kept as intake records. Cloudflare Turnstile runs on every intake form on this site, so Cloudflare receives its response token and may receive the request's network address to perform the check.

Private continuation links

A private continuation link acts like a password for the saved intake. It can open the information in that intake and, while the intake remains editable, save changes or submit it. We store a one-way SHA-256 hash of the token, not the link itself. A newly emailed caregiver link replaces the prior link, and withdrawal disables that caregiver link. The current code does not otherwise set an automatic expiration date, so keep the link private and contact support@goodhorsepeople.com if you believe it was shared.

Re-entering the same email for a started owner research profile requests a replacement private link by email. We replace the previous link only after delivery is confirmed; the previous link then stops working. If delivery fails or is not configured, we keep the previous link. Saved answers are not shown just by entering an email address. The owner form does not save the link in browser local or session storage; it remains in the private URL while you use the profile.

Email

Starting an owner early-access research profile sends its private link immediately through Resend when email delivery is configured. Delivery is best effort. If email cannot be sent, the profile still saves and the private link is shown on screen for you to copy and keep private.

When email delivery is configured, a caregiver continuation ("resume") email is sent immediately through Resend from thenotify.goodhorsepeople.com email domain. Other operational messages, including intake receipts, are placed in an email queue. There is currently no production processor for that queue, so those messages may not be delivered yet. We store the recipient, template, limited template data, delivery status, send time, and a bounded failure reason. The private continuation URL is not stored in the email outbox or application logs. We provide an unsubscribe form without an account and keep a suppression list for optional email. Any future optional research or launch email will include an unsubscribe link; one-click unsubscribe is not currently implemented. Requested operational continuation messages are separate from that optional-email preference.

Why we use the information

We use it to operate and secure the intake forms, save and resume submissions, send requested email, measure demand for routine horse care, study caregiver supply and service-area overlap, improve the intake, answer privacy requests, and decide whether and where to develop the service. We do not sell signup or intake information.

Where information goes

Cloudflare hosts the site and Worker, stores records in its D1 database, and provides Turnstile. Resend receives the recipient, sender, reply-to address, subject, and message body needed to deliver email. Google Workspace operates the Good Horse People mailboxes that receive replies and messages sent to our support and privacy addresses. We do not list or send intake data to other vendors unless they are needed to provide the service or the law requires it.

Who can see submissions

Good Horse People's owners and authorized administrators can review submissions for research, support, safety, and operations. The admin API records caregiver-application detail reads, status-change attempts, caregiver-application exports, successful signup exports, and audit-log list requests. These records are written on a best-effort basis to an append-only audit log and include the admin actor, action, target, result, time, and limited metadata; an audit write failure does not block the admin action. Audit metadata is filtered by recognized sensitive key names and bounded by type and length, rather than inspected for sensitive content under every possible key. We aim to keep request bodies, headers, database rows, names, email addresses, private tokens, passwords, and credentials out of diagnostic logs. Many intake paths use structured redaction, but some error paths may record raw error objects.

Retention

Browser acquisition data and the journey ID use session storage and normally last for that browser session. Rate-limit buckets expire with their configured window, from one minute to 24 hours, and are deleted after expiration when the rate-limit process next runs. The current code does not enforce a general automatic retention or deletion period for signups, intake details, funnel events, email delivery records, unsubscribe records, or deletion requests. Those records remain stored unless they are manually deleted or the service changes its retention process. Consent events and admin audit events are append-only records protected by database rules that prevent them from being changed or deleted.

Your choices

You can stop optional research and launch email without signing in. This keeps a suppression record and does not delete other information. You can separately submit a deletion request using the email address you provided. A deletion request stores that address, an optional reason, inferred role when unambiguous, status, and timestamps for manual review; the request itself does not automatically delete associated records.

Contact us

For privacy questions, email privacy@goodhorsepeople.com. For help with an intake or private link, email support@goodhorsepeople.com.

See also our terms of service.