Last updated 4 September 2026

Privacy Policy

What we collect, why we collect it, who else touches it, and how to get it back or have it deleted.

1. What we collect

  • Account details — your name or farm name, email address, and the password you set (stored only as a hash, by our authentication provider).
  • Your records — animals, weights, feed and costs, treatments and vet visits, breeding and pedigree, show entries and results, photos, documents and notes.
  • Orders and shipping — what you ordered and the address to send it to.
  • Device taps — when a tag is tapped, which animal it resolved to, the outcome, and the IP address and browser of the tap. This is the audit trail that makes a verified record meaningful.
  • Support messages — what you send us, so we can answer it.

We do not take or store card numbers. Payments go directly to Stripe, which holds the card details; we only ever see the last four digits and the result.

2. What we use it for

  • Running the service — showing your records, fulfilling device orders, processing payments.
  • Verification — proving that an entry was made by a tap of the right tag by the right account.
  • Service email — confirmations, receipts, reminders you asked for, and account notices.
  • Occasional product email about ShowStat. Every one has an unsubscribe link that works.
  • Keeping the service secure and preventing abuse.

We do not sell your records, and we do not sell your email address.

3. Analytics and advertising cookies

Our own analytics store no personal data. We record which page was viewed and how long it was open. No IP address, no user agent, no cookies, and no query strings — a page view cannot be traced back to a person, which is why it runs without a consent banner.

Advertising pixels are different, and you should know they are here. We run the Meta (Facebook) pixel and the TikTok pixel so we can tell whether our ads work. These are set by Meta and TikTok, they do use cookies and device identifiers, and they report activity back to those companies — including a signal when someone completes a signup. Under California law this may count as “sharing” personal information for cross-context behavioural advertising. You can opt out by using your browser's tracking protection or a content blocker, and by adjusting your ad settings with Meta and TikTok directly.

4. Who else processes your data

  • Supabase — database, file storage and authentication.
  • Fly.io — application hosting.
  • Stripe — payments, subscriptions and payouts.
  • Resend — sending our email.
  • Meta and TikTok — advertising measurement, as described above.
  • Anthropic — powers the AI Helper. Content you send to it is processed to generate a reply.

Each is used only to provide the service, and is bound by its own agreement with us.

5. Children

ShowStat accounts are for adults. Where a 4-H or FFA member is using ShowStat, the account belongs to a parent, guardian, leader or advisor, who is responsible for what is entered. We do not knowingly collect personal information from children under 13. If you believe we have, email us and we will delete it.

6. Your choices

  • Get a copy — export any animal's record from the app, or ask us for everything we hold.
  • Correct it — edit your records directly, or ask us.
  • Delete it — close your account and we delete your records within 30 days, apart from transaction records we must keep for tax purposes.
  • Stop the email — unsubscribe from any product email. Service email about your account and orders will continue.
  • Opt out of ad sharing — as described in section 3.

California residents have these rights under the CCPA/CPRA and we will not discriminate against you for using them. Email support@showstat.live and we will respond within 45 days.

7. How long we keep things

  • Your records: for as long as your account is open, then 30 days.
  • Tap audit log: 12 months, because it is what makes a record verifiable after the fact.
  • Anonymous page analytics: 12 months.
  • Orders and invoices: seven years, for tax and accounting.

8. Security

Data is encrypted in transit and at rest. Access to the production database is restricted to a service credential held by the application, and edit-session tokens are stored only as hashes so a database copy cannot be used to forge one. No system is perfectly secure; if a breach affects you we will tell you promptly.

9. Changes

We will post any update here with a new date at the top, and email you if the change is significant. See also our Terms of Service.

Questions about this document? Email support@showstat.live or use the support page.