Privacy

What we collect, and why


Plainly: today this site collects an email address if you give us one, and runs the analytics and advertising tools described below. When the product opens, it will hold the records of your practice — and those are yours. This page is written to be true the day it publishes and honest about what changes at launch.

Last updated 23 August 2026

This page is a draft. It is published so the structure exists, and it will be replaced before Roost opens to the founding cohort.

Who we are

Roost is back-office software for independent relief veterinarians, operated by [ENTITY — the LLC being formed to run Roost; named here once it exists]. The site is not yet open to the public and the product has not launched, so this policy is written to be accurate today and to say honestly what changes when it opens.

You can reach a person any time at hello@roost.vet.

What we collect on this site today

Right now this is a marketing site with one form. If you ask to join the founding cohort, we store the email address you type, which page you submitted it from, the date you submitted it, and the two-letter country your request came from (read from a Cloudflare header, which we use to spot bot floods). We do not store your IP address, and no account or password exists yet.

We use your email address to write to you about the founding cohort — when it opens, what changed, and what we would like your opinion on. Ask us to delete it and we will, without a retention argument.

Analytics and advertising on this site

This site runs two different kinds of measurement, and the difference matters:

PostHog is our own, first-party product and web analytics. It records pseudonymous usage — page views, which links you follow, and properties like which plan you land on — so we can see how the site is used. It does not record your screen: there is no session replay or session recording of any kind, on this site or anywhere in Roost. If that ever changes, it will require a change to this policy, not language broad enough to already permit it.

Meta and Google advertising tags are third-party trackers, not our own analytics. They let us measure and target advertising. What they receive is limited to a hashed version of your identity, the stage you reached in our signup, and the Roost subscription price — never anything about your practice.

How we handle consent: being met by a stack of consent modals and popups while you are trying to read is exactly the experience Roost exists in opposition to, so our approach is notice and opt-out. This policy tells you what runs, a dismissible banner points you to it, and nothing blocks the page. We are reviewing with counsel whether visitors in the EU and UK should instead be asked to opt in before any non-essential tag fires; if so, we will build that.

What the product will collect when it opens

Roost is back-office software for your practice, so when you create an account it holds the operating record of your business: your name, email, a hashed password and phone; the clinics you work for, with their contacts and rate cards; the shifts you schedule and complete; the invoices, payments, mileage, expenses and bookkeeping that make up your finances; messages with clinics and any source emails you forward in for us to read into the system; and documents you upload while moving your records in. Payment and bank details are handled by Stripe and go straight to them — Roost does not store your card or bank numbers.

This is the sensitive set. It is the whole financial picture of a small business, and often a veterinarian’s entire livelihood. Two things follow, and we hold to both: your business data is yours — you can export all of it, on any plan including the free one, at any time, as a button and not a support request — and it never leaves the product to feed our own business systems.

The sub-processors we use

We rely on a small set of third-party services to run Roost, and we list them by name rather than by vague category. The ones marked “live now” are used by this marketing site today; the rest come into use when the product opens.

  • Cloudflare — DNS, site hosting, and the form that takes your email (live now)
  • Zoho CRM — our waitlist and contact records (live now)
  • PostHog — first-party product and web analytics; no session recording (live now)
  • Meta and Google — advertising measurement and targeting (live now)
  • Supabase — the database, authentication and file storage that holds your account and business records (at launch)
  • Stripe — subscription billing and Roost Payments; holds card, bank and identity-verification details directly (at launch)
  • Zoho Billing — subscription management and billing (at launch)
  • Zoho Marketing Automation — our newsletters and lifecycle email (at launch)
  • Zoho Desk — support tickets and help center (at launch)
  • Zoho Bookings — scheduling onboarding calls (at launch)
  • Zoho Flow — automated syncs between the tools above; carries whatever the specific sync moves (at launch)
  • Postmark — transactional email, including the invoices you send to clinics (at launch)
  • Twilio — text messages and our published phone line (at launch)
  • Sentry — error tracking, which may incidentally include identifiers (at launch)

Lines we don’t cross

A few commitments are unusual enough, and central enough to what Roost is, that we state them as promises rather than leave them to inference:

Your business records never enter our own business systems. Our company’s books and your practice’s books are separate systems by design — the two never touch. Your clinics, shifts, rates, invoices, mileage and books are never synced to our CRM, our accounting, or any marketing tool.

Advertising platforms never receive your business data. What we send an ad platform is limited to hashed identity, signup stage, and the Roost subscription price — never your clinics, shifts, rates, invoices, mileage or earnings. A conversion we report is worth the price of a subscription, never a number derived from what you make.

Your card and bank details never touch our servers. Card entry happens only on Stripe’s own pages, and we keep a deliberately minimal payments posture so those numbers never reach us. Documents you upload go to access-controlled product storage, never a general company file store.

And the one that needs care rather than a flat promise: we do not sell your data. Here is the single caveat, named plainly instead of hidden behind “we use cookies”: to advertise Roost, we upload the email addresses on our list — including waitlist addresses — to Meta, which uses them to find similar audiences to show our ads to. That is a real use of an email you gave us for a different reason. We are still confirming with counsel whether it requires your consent rather than notice, including for people who joined the waitlist before this page said so.

Keeping, exporting and deleting your data

Export is full and self-serve on every plan, including the free one, at any time.

Deletion: ask us to delete your data and we will, and confirm it. We are still defining exactly what “deleted” means where backups and Stripe’s own legal record-keeping outlast the request — we would rather get that honest than say something tidy that isn’t quite true. [Retention periods for the database and for backups are being set with counsel — TBD.]

Closing your account is self-serve, with no retention tricks, and your data is exported for you on the way out. On the free plan past its grace period, the account becomes read-and-export only — nothing is deleted, and export keeps working.

Clinics who receive your invoices

When you send an invoice through Roost, the clinic receives it by email — and most clinics never create a Roost account or become our users. Their contact details were entered by you, not collected by us. We are confirming with counsel exactly what our role is for that data and whether anything needs to be shown to the clinic; this section will say plainly where that lands. [Open — under legal review.]

Changes to this policy, and getting in touch

This page is a draft, and it will change as the product does — materially before Roost opens to the founding cohort. When we make a material change we will update the date at the top and, once you have an account, tell you.

Questions about any of this, or a request to see or delete what we hold: write to hello@roost.vet and a person will answer.