← Let Loose

Privacy Policy

Effective date: August 4, 2026

Last updated: August 5, 2026

1. Who we are

Let Loose is operated by Baracuna, LLC, a Washington limited liability company (“Baracuna,” “Let Loose,” “we,” “us,” or “our”). Let Loose is an overnight-stay marketplace connecting owners of reactive and anxious dogs with private, fenced properties for stays with their dog. This policy covers our mobile app (guest and host experience), our host web portal, our admin systems, and our website at letloosestays.com (together, the “Services”).

If you have questions about this policy or want to exercise any of the rights described below, contact us at [email protected].

2. Information we collect

We collect the following categories of information. Some of it you give us directly; some is generated by using the Services.

Sensitive information, at a glance. Several categories below are treated as sensitive under state privacy law (e.g., California's CPRA) or warrant extra care given who Let Loose serves: precise geolocation (host property location), your dog's bite/near-bite history and trigger profile, government ID and biometric verification data (if you complete identity verification), and criminal background check results (hosts). We collect these only for the specific purposes in Section 3, never use them for advertising, and apply narrower internal access than the rest of your account data (see Section 7).

CategoryExamplesCollected fromShared with
Account informationName, email, phone, password (hashed)You, at signupService providers (Section 4); counterpart sees only your first name
LocationHost property address & coordinates; guest search locationYou; your device (with permission)The other party to a booking; Mapbox, Google Places
Dog trigger/bite-history profileTriggers, stress signals, comfort protocol, vet contact, bite/near-bite disclosureYouThe host of a requested/confirmed booking; our team
Host property & vettingFence/gate details, lot size, resident-animal info, photos, video walkthrough, internal vetting notesYou; our vetting teamGuests see property details; vetting notes are admin-only
Identity verificationGovernment ID photo, live selfie, verified/not-verified resultYou, via our verification vendorVerification vendor (holds the underlying images); we store only the result
Background check (hosts)Criminal history check status/outcomeYou, via our screening vendorScreening vendor (holds the report); we store only the outcome
PaymentBooking amounts, fees, payout status, Stripe identifiersYou; StripeStripe
Damage claimsIncident description, evidence photos/video, amountsHost, guestThe claim's host and admin; insurer if a policy is in place
Messages, reviews, reportsMessage text, review text/ratings, report contentYouYour conversation counterpart; admins; automated content filter
Device & usageDevice/OS, app version, crash diagnostics, IP address, push tokenYour deviceService providers who host our infrastructure

2.1 Account information (all users)

Name, email address, phone number, password (stored as a salted hash, never in plain text), and your role on the platform (guest, host, or admin).

2.2 Location information

Host property address and precise geolocation (latitude/longitude) for listings, so guests can search and get directions. Guest search location, if you search near a place or allow location access, to show nearby listings. Precise geolocation is sensitive information under some state privacy laws (including California's CPRA) — we collect it only for the purposes described here and do not sell it.

2.3 Dog profile and trigger/bite-history information

To match guests with appropriate properties and give hosts the information they need to safely host, we collect a profile for each dog you bring, including: known triggers, early stress signals, comfort protocols, routine notes, an emergency veterinary contact, and a required disclosure of any bite or near-bite history. This is sensitive personal information. Unlike some comparable platforms, Let Loose does not exclude dogs with a bite/near-bite history — we require disclosure instead, so hosts can make an informed decision before accepting a booking. This information is shared with the host of a confirmed or requested booking and with our team for safety and insurance purposes; it is never sold or used for advertising.

2.4 Host property and vetting information

If you're a host, we collect information about your property as part of our vetting process and your listing: fence height and material, gate/latch security details, lot size, whether other dogs or pets reside on the property, sightline/privacy details, photos, and (once implemented) a short video walkthrough of the fenced area. We also collect internal vetting notes and, for identity confirmation, a photo ID during our vetting visit. Internal vetting visit notes are never visible to you as the applicant — see Section 7.

2.5 Identity verification and biometric information

[Planned, not yet live] We plan to offer identity verification (government ID photo plus a live selfie) through our payment processor's identity-verification product. This process derives biometric information — facial-geometry data used to match your selfie to your ID photo — which several states regulate as a distinct, sensitive category. If enabled for your account: the verification result (verified/not verified, plus a timestamp) is stored on your Let Loose profile; the underlying ID images and biometric data are collected, processed, and retained by our verification vendor under their own privacy policy and with your consent at the time of verification — we do not receive or store the raw images or biometric template ourselves. See our Biometric Data Retention and Destruction Policy for the full details.

2.6 Background check information (hosts only)

[Planned, not yet live] As part of host vetting, we plan to run a criminal background check through a third-party screening vendor before a host is approved. We store the check's status and outcome (e.g., clear/flagged) on your host application; the underlying report is held by our screening vendor under their own privacy policy and applicable background-check law, and is used solely to inform our approval decision.

2.7 Payment information

We use Stripe to process payments and payouts. We do not store your full payment card number on our servers — Stripe collects and stores that directly. We store booking amounts, platform fees, payout amounts and status, and Stripe identifiers needed to reconcile a transaction.

2.8 Damage claims and insurance-related information

If a host files a damage claim after your stay, or if you're a host filing one, we collect the incident description, requested/approved amounts, and any evidence (e.g., photos) submitted to support the claim. This information is shared with the claim's host, our admin team reviewing it, and, once a host-protection insurance policy is in place, our insurer or claims administrator if the claim is escalated to a covered loss.

2.9 Messages, reviews, and reports

Messages you send through in-app messaging, reviews you post after a completed stay, and any reports you or others file about a listing, host, guest, or message (including the reported content and your stated reason). Messages and reviews are not fully private between you and your counterpart: they pass through an automated content filter before being posted (see Section 3.1), and our team can access them to investigate a report or a Trust & Safety concern. Reviews are shown publicly once posted; see the visibility summary in Section 2.11.

2.10 Device and usage information

Device type and operating system, app version, crash and error diagnostics, IP address, and general usage data (e.g., which screens you visit) to help us operate, secure, and improve the Services. If you enable push notifications, we store a device push token so we can deliver booking, message, and account notifications to your device. We do not currently respond to browser “Do Not Track” signals, as no common industry standard for honoring them exists yet.

2.11 What's public, what's shared with your counterpart, and what stays internal

Cookies and similar technologies (website): our marketing website at letloosestays.com may use cookies or similar technologies for basic site functionality and aggregate analytics. The mobile app and host portal do not use advertising cookies or third-party ad trackers.

We do not knowingly collect more than the categories above, and we do not collect sensitive information (like the dog trigger profile, precise geolocation, or biometric verification data) for advertising purposes.

3. How we use your information

We use the information above to: create and manage your account; operate the booking marketplace (matching, booking, payment, and payout); enable in-app communication between guests and hosts; vet and approve hosts; verify guest and host identity where applicable; run background checks on host applicants where applicable; provide customer support; investigate and act on reports of abuse, safety issues, or policy violations; process and support damage claims; send transactional notifications (booking confirmations, new messages, application status); detect and prevent fraud and platform abuse; and comply with legal obligations (including tax, insurance, and dispute recordkeeping).

3.1 Automated content filtering

Messages, review comments, and listing descriptions are checked against an automated content filter before they're posted. A message, review, or listing description containing prohibited content is rejected outright and never posted — this happens automatically, without a person reviewing it first, though you can contact us at [email protected] if you believe something was blocked in error.

We do not sell your personal information, and we do not use your dog's trigger/bite-history profile, your precise location, or your host vetting details for advertising or share them with data brokers.

4. How we share your information

We share information in these circumstances only:

We do not sell your personal information, and we do not share it with third parties for cross-context behavioral advertising. If that ever changes, we'll update this policy first and provide a “Do Not Sell or Share My Personal Information” opt-out before it takes effect.

5. Data retention

We retain personal information for as long as your account is active and as needed to provide the Services, plus the periods below for specific categories:

6. Your privacy rights

Regardless of where you live, you may ask us to:

To exercise any of these rights, email [email protected]. We'll verify your identity before acting on a request and will respond within [30 days]. If you'd like someone else to submit a request on your behalf, we'll need written authorization from you before acting on it. If we can't fulfill a request in whole or in part, we'll explain why.

If you are a California resident, you have rights under the California Consumer Privacy Act as amended by the CPRA once those rights apply to us; if you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the GDPR/UK GDPR once we are subject to them. We're extending the same core rights (access, correction, deletion, portability) to all users voluntarily today, ahead of any legal requirement to do so.

7. Data security

We use industry-standard technical and organizational measures to protect your information, including encryption in transit, database-level access controls (row-level security scoping every user to only their own and their counterparty's relevant data), and restricted internal access to sensitive fields (for example, internal host-vetting visit notes are never visible to the applicant, and raw background-check reports and identity-verification images are held by our vendors, not stored on our own systems). No system is perfectly secure, and we cannot guarantee absolute security.

If we experience a data breach that affects your personal information, we will notify affected users and, where legally required, relevant regulators, without undue delay and in line with applicable breach-notification law.

8. Children's privacy

Let Loose is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from children. If we learn we've collected information from someone under 18, we'll delete it.

9. International users

Let Loose currently operates in the San Francisco Bay Area and the northern California weekend-trip corridor only, and we don't target users outside the United States. If that changes, we'll update this section to describe any international data transfer safeguards that apply.

10. Changes to this policy

We may update this policy as the Services evolve. If we make a material change, we'll notify you (by email and/or an in-app notice) at least [14] days before it takes effect. The “Last updated” date at the top of this page always reflects the current version.

11. Contact us

Baracuna, LLC (operating as Let Loose)

Baracuna, LLC — 522 W Riverside Ave, Ste N, Spokane, WA 99201

Email: [email protected]

General support: [email protected]