Privacy Policy
Effective date: August 4, 2026
Last updated: August 5, 2026
1. Who we are
Let Loose is operated by Baracuna, LLC, a Washington limited liability company (“Baracuna,” “Let Loose,” “we,” “us,” or “our”). Let Loose is an overnight-stay marketplace connecting owners of reactive and anxious dogs with private, fenced properties for stays with their dog. This policy covers our mobile app (guest and host experience), our host web portal, our admin systems, and our website at letloosestays.com (together, the “Services”).
If you have questions about this policy or want to exercise any of the rights described below, contact us at [email protected].
2. Information we collect
We collect the following categories of information. Some of it you give us directly; some is generated by using the Services.
Sensitive information, at a glance. Several categories below are treated as sensitive under state privacy law (e.g., California's CPRA) or warrant extra care given who Let Loose serves: precise geolocation (host property location), your dog's bite/near-bite history and trigger profile, government ID and biometric verification data (if you complete identity verification), and criminal background check results (hosts). We collect these only for the specific purposes in Section 3, never use them for advertising, and apply narrower internal access than the rest of your account data (see Section 7).
| Category | Examples | Collected from | Shared with |
|---|---|---|---|
| Account information | Name, email, phone, password (hashed) | You, at signup | Service providers (Section 4); counterpart sees only your first name |
| Location | Host property address & coordinates; guest search location | You; your device (with permission) | The other party to a booking; Mapbox, Google Places |
| Dog trigger/bite-history profile | Triggers, stress signals, comfort protocol, vet contact, bite/near-bite disclosure | You | The host of a requested/confirmed booking; our team |
| Host property & vetting | Fence/gate details, lot size, resident-animal info, photos, video walkthrough, internal vetting notes | You; our vetting team | Guests see property details; vetting notes are admin-only |
| Identity verification | Government ID photo, live selfie, verified/not-verified result | You, via our verification vendor | Verification vendor (holds the underlying images); we store only the result |
| Background check (hosts) | Criminal history check status/outcome | You, via our screening vendor | Screening vendor (holds the report); we store only the outcome |
| Payment | Booking amounts, fees, payout status, Stripe identifiers | You; Stripe | Stripe |
| Damage claims | Incident description, evidence photos/video, amounts | Host, guest | The claim's host and admin; insurer if a policy is in place |
| Messages, reviews, reports | Message text, review text/ratings, report content | You | Your conversation counterpart; admins; automated content filter |
| Device & usage | Device/OS, app version, crash diagnostics, IP address, push token | Your device | Service providers who host our infrastructure |
2.1 Account information (all users)
Name, email address, phone number, password (stored as a salted hash, never in plain text), and your role on the platform (guest, host, or admin).
2.2 Location information
Host property address and precise geolocation (latitude/longitude) for listings, so guests can search and get directions. Guest search location, if you search near a place or allow location access, to show nearby listings. Precise geolocation is sensitive information under some state privacy laws (including California's CPRA) — we collect it only for the purposes described here and do not sell it.
2.3 Dog profile and trigger/bite-history information
To match guests with appropriate properties and give hosts the information they need to safely host, we collect a profile for each dog you bring, including: known triggers, early stress signals, comfort protocols, routine notes, an emergency veterinary contact, and a required disclosure of any bite or near-bite history. This is sensitive personal information. Unlike some comparable platforms, Let Loose does not exclude dogs with a bite/near-bite history — we require disclosure instead, so hosts can make an informed decision before accepting a booking. This information is shared with the host of a confirmed or requested booking and with our team for safety and insurance purposes; it is never sold or used for advertising.
2.4 Host property and vetting information
If you're a host, we collect information about your property as part of our vetting process and your listing: fence height and material, gate/latch security details, lot size, whether other dogs or pets reside on the property, sightline/privacy details, photos, and (once implemented) a short video walkthrough of the fenced area. We also collect internal vetting notes and, for identity confirmation, a photo ID during our vetting visit. Internal vetting visit notes are never visible to you as the applicant — see Section 7.
2.5 Identity verification and biometric information
[Planned, not yet live] We plan to offer identity verification (government ID photo plus a live selfie) through our payment processor's identity-verification product. This process derives biometric information — facial-geometry data used to match your selfie to your ID photo — which several states regulate as a distinct, sensitive category. If enabled for your account: the verification result (verified/not verified, plus a timestamp) is stored on your Let Loose profile; the underlying ID images and biometric data are collected, processed, and retained by our verification vendor under their own privacy policy and with your consent at the time of verification — we do not receive or store the raw images or biometric template ourselves. See our Biometric Data Retention and Destruction Policy for the full details.
2.6 Background check information (hosts only)
[Planned, not yet live] As part of host vetting, we plan to run a criminal background check through a third-party screening vendor before a host is approved. We store the check's status and outcome (e.g., clear/flagged) on your host application; the underlying report is held by our screening vendor under their own privacy policy and applicable background-check law, and is used solely to inform our approval decision.
2.7 Payment information
We use Stripe to process payments and payouts. We do not store your full payment card number on our servers — Stripe collects and stores that directly. We store booking amounts, platform fees, payout amounts and status, and Stripe identifiers needed to reconcile a transaction.
2.8 Damage claims and insurance-related information
If a host files a damage claim after your stay, or if you're a host filing one, we collect the incident description, requested/approved amounts, and any evidence (e.g., photos) submitted to support the claim. This information is shared with the claim's host, our admin team reviewing it, and, once a host-protection insurance policy is in place, our insurer or claims administrator if the claim is escalated to a covered loss.
2.9 Messages, reviews, and reports
Messages you send through in-app messaging, reviews you post after a completed stay, and any reports you or others file about a listing, host, guest, or message (including the reported content and your stated reason). Messages and reviews are not fully private between you and your counterpart: they pass through an automated content filter before being posted (see Section 3.1), and our team can access them to investigate a report or a Trust & Safety concern. Reviews are shown publicly once posted; see the visibility summary in Section 2.11.
2.10 Device and usage information
Device type and operating system, app version, crash and error diagnostics, IP address, and general usage data (e.g., which screens you visit) to help us operate, secure, and improve the Services. If you enable push notifications, we store a device push token so we can deliver booking, message, and account notifications to your device. We do not currently respond to browser “Do Not Track” signals, as no common industry standard for honoring them exists yet.
2.11 What's public, what's shared with your counterpart, and what stays internal
- Public (visible to anyone browsing the app): your listing's photos, description, and amenities (if you're a host); your posted reviews and their star ratings, tied to your first name only.
- Visible to your specific booking counterpart only: your first name (never your last name, phone number, or email, unless you choose to share it directly in a message); your dog's trigger/bite-history profile (guest → host, for a requested/confirmed booking only); messages in your shared conversation thread.
- Internal only, never shown to the other party: a host applicant's internal vetting visit notes; a guest's or host's raw background-check report or identity-verification images (held by our vendors, not us); admin moderation notes on a report.
Cookies and similar technologies (website): our marketing website at letloosestays.com may use cookies or similar technologies for basic site functionality and aggregate analytics. The mobile app and host portal do not use advertising cookies or third-party ad trackers.
We do not knowingly collect more than the categories above, and we do not collect sensitive information (like the dog trigger profile, precise geolocation, or biometric verification data) for advertising purposes.
3. How we use your information
We use the information above to: create and manage your account; operate the booking marketplace (matching, booking, payment, and payout); enable in-app communication between guests and hosts; vet and approve hosts; verify guest and host identity where applicable; run background checks on host applicants where applicable; provide customer support; investigate and act on reports of abuse, safety issues, or policy violations; process and support damage claims; send transactional notifications (booking confirmations, new messages, application status); detect and prevent fraud and platform abuse; and comply with legal obligations (including tax, insurance, and dispute recordkeeping).
3.1 Automated content filtering
Messages, review comments, and listing descriptions are checked against an automated content filter before they're posted. A message, review, or listing description containing prohibited content is rejected outright and never posted — this happens automatically, without a person reviewing it first, though you can contact us at [email protected] if you believe something was blocked in error.
We do not sell your personal information, and we do not use your dog's trigger/bite-history profile, your precise location, or your host vetting details for advertising or share them with data brokers.
4. How we share your information
We share information in these circumstances only:
- With the other party to a booking. A host sees the guest's relevant booking details and dog profile (including bite-history disclosure) for a request or confirmed stay; a guest sees the host's listing, property, and relevant vetting-derived details. See Section 2.11 for the exact breakdown of what's shared vs. kept internal. This exchange is the core of how the marketplace functions and can't be turned off for an active booking.
- With service providers who process data on our behalf, under contract and only for the purposes we specify:
- Stripe — payment processing, host payouts (Stripe Connect), and (once enabled) identity verification (Stripe Identity).
- Supabase — our database, authentication, file storage, and real-time messaging infrastructure. Nearly all data described in Section 2 passes through or is stored in Supabase.
- Mapbox — map display.
- Google Places — address autocomplete during listing creation. [Not yet integrated as of this writing.]
- Resend — transactional email delivery (booking confirmations, application status, account notices).
- Certn (or our then-current background-check vendor) — host criminal background screening. [Planned, not yet live.]
- [Host-protection insurer/claims administrator, once a policy is in place] — damage claim evidence and incident details, if a claim is escalated to a covered loss.
- Cloud hosting and infrastructure providers (Cloudflare) for our web applications.
- With our own team (Baracuna, LLC personnel) as needed to operate the Services, vet hosts, moderate content, and respond to reports or support requests.
- With law enforcement or government authorities, if legally required (e.g., a subpoena or court order) or if we believe in good faith that disclosure is necessary to protect the safety of a person or the public — for example, cooperating with an investigation into a dog-bite incident or a safety report.
- For other legal reasons, if we believe disclosure is necessary to comply with a legal obligation, protect the rights, property, or safety of Let Loose, our users, or the public, or investigate potential violations of our terms.
- In connection with a business transaction, such as a merger, acquisition, or sale of assets — we'll require any successor to honor the commitments in this policy, and will notify you of any material change in how your information is handled.
We do not sell your personal information, and we do not share it with third parties for cross-context behavioral advertising. If that ever changes, we'll update this policy first and provide a “Do Not Sell or Share My Personal Information” opt-out before it takes effect.
5. Data retention
We retain personal information for as long as your account is active and as needed to provide the Services, plus the periods below for specific categories:
- Account and booking records: retained for the life of your account and for [7 years] after account closure, to satisfy tax, accounting, and dispute-resolution obligations.
- Dog trigger and bite-history profile: retained for as long as your account is active, and for [3 years] after your last completed stay or account closure, to support insurance and safety recordkeeping in case a dispute or claim arises from a past stay.
- Host property and vetting information, including video walkthroughs: retained for as long as the host's listing is active, and for [3 years] after a listing is deactivated or the host account is closed, for the same insurance/dispute-recordkeeping reason.
- Identity verification results: retained for as long as your account is active; underlying documents are held by our verification vendor per their own retention schedule.
- Background check results: retained per our screening vendor's retention schedule and applicable background-check law.
- Damage claim records (incident descriptions, evidence): retained for [7 years] after resolution, matching our general insurance/dispute-recordkeeping period.
- Messages and reviews: retained for as long as your account is active, to preserve the record for both parties and for trust-and-safety purposes; a message or review we've removed for a policy violation is retained internally (marked hidden, not publicly visible) for recordkeeping. Reviews and messages you've shared with a booking counterpart may remain visible to that counterpart, or in our records, even after you close your account.
- Reports: retained for [3 years] after resolution, for pattern-of-abuse detection and recordkeeping.
- Device/usage diagnostics: retained for [12–24 months], then aggregated or deleted.
6. Your privacy rights
Regardless of where you live, you may ask us to:
- Access the personal information we hold about you.
- Correct inaccurate information (most account and listing fields can also be edited directly in the app or portal).
- Delete your personal information, subject to what we're legally required or permitted to retain (see Section 5).
- Receive a copy of your information in a portable, machine-readable format (“data portability”).
- Opt out of non-essential communications (transactional notifications tied to your bookings and account can't be turned off while you have an active booking, for safety reasons).
To exercise any of these rights, email [email protected]. We'll verify your identity before acting on a request and will respond within [30 days]. If you'd like someone else to submit a request on your behalf, we'll need written authorization from you before acting on it. If we can't fulfill a request in whole or in part, we'll explain why.
If you are a California resident, you have rights under the California Consumer Privacy Act as amended by the CPRA once those rights apply to us; if you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the GDPR/UK GDPR once we are subject to them. We're extending the same core rights (access, correction, deletion, portability) to all users voluntarily today, ahead of any legal requirement to do so.
7. Data security
We use industry-standard technical and organizational measures to protect your information, including encryption in transit, database-level access controls (row-level security scoping every user to only their own and their counterparty's relevant data), and restricted internal access to sensitive fields (for example, internal host-vetting visit notes are never visible to the applicant, and raw background-check reports and identity-verification images are held by our vendors, not stored on our own systems). No system is perfectly secure, and we cannot guarantee absolute security.
If we experience a data breach that affects your personal information, we will notify affected users and, where legally required, relevant regulators, without undue delay and in line with applicable breach-notification law.
8. Children's privacy
Let Loose is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from children. If we learn we've collected information from someone under 18, we'll delete it.
9. International users
Let Loose currently operates in the San Francisco Bay Area and the northern California weekend-trip corridor only, and we don't target users outside the United States. If that changes, we'll update this section to describe any international data transfer safeguards that apply.
10. Changes to this policy
We may update this policy as the Services evolve. If we make a material change, we'll notify you (by email and/or an in-app notice) at least [14] days before it takes effect. The “Last updated” date at the top of this page always reflects the current version.
11. Contact us
Baracuna, LLC (operating as Let Loose)
Baracuna, LLC — 522 W Riverside Ave, Ste N, Spokane, WA 99201
Email: [email protected]
General support: [email protected]