Privacy Policy
Version 1.4 · Effective April 10, 2026
1. Information We Collect
We collect information you provide directly, including:
- Account information — name, email address, and password when you create an account (farmer or consumer).
- Farm & operational data — animal records, health events, breeding records, financial transactions, egg production logs, pasture and grazing data, feed and hay inventory, equipment records, beekeeping and apiary data, and other information you enter into the Service.
- Marketplace profile data — farm name, address, city, state, phone number, email, website, social media links, photos, farming practices, product categories, operating hours, payment methods, delivery options, and farmers market locations that you add to your public farm profile.
- Livestock listing data — animal breed, species, sex, age, registration number, registry name, genetic traits (A2 status, polled, chondro, PHA), pedigree information (sire and dam names), color, photos, and pricing that you include in livestock-for-sale listings.
- Invoice data — customer names, line item descriptions, amounts, and payment status included in invoices you create. Invoices shared via public link are accessible to anyone with the link.
- Team member data — email addresses of users you invite to your organization, their assigned roles, and membership status.
- Consumer account data — if you create a consumer account, we collect your saved farm favorites, order history, product interest preferences, and any information you provide when signing up through a farm’s customer signup link or QR code (including the signup source for analytics purposes).
- AI interaction data — when you use AI-powered features (farm assistant, receipt scanning, pedigree extraction, CSV import mapping), we store your queries, uploaded images, and the AI-generated responses. Conversation history for the farm assistant is stored to maintain context across sessions.
- Billing information — payment details are processed and stored by Stripe; we do not store your full credit card number.
- Banking data (Plaid) — if you connect a bank account via Plaid, we receive transaction data (amounts, dates, merchant names). Access tokens are AES-256 encrypted at rest.
- Email signup data — if you submit your email address through a blog signup form, farm customer signup page, or other email capture form, we store your email address along with the signup source and referrer URL for analytics purposes.
- Notification preferences — your per-notification-type settings, lead times, push notification subscription data (browser endpoint URL and encryption keys), and email digest preferences.
We also collect standard usage data such as IP address, browser type, pages visited, and session duration through server logs and analytics.
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service.
- Process billing and manage your subscription.
- Generate reports (e.g., Schedule F summaries, cost analytics, financial comparisons) that you request.
- Power AI features — send limited portions of your farm data to AI providers to generate receipt extractions, assistant responses, pedigree extractions, smart insights, and import mappings.
- Display your public farm profile, product listings, and livestock listings to prospective buyers on the Howdy Ag marketplace and search results.
- Deliver notifications via in-app alerts, email digests, and browser push notifications based on your preferences.
- Send transactional emails (account verification, password resets, billing receipts).
- Communicate product updates or changes to these policies (you may opt out of non-essential emails).
- Detect and prevent fraud or abuse.
3. Public Profiles & Marketplace Data
Certain data you provide is intentionally made public through the marketplace. This section explains what is public and how it is used.
- Public farm profiles. When you create a marketplace profile, your farm name, location (city, state, and approximate geographic coordinates), contact information you provide (phone, email, website, social media), photos, farming practices, product categories, and other profile details are visible to anyone on the internet, including users without a Howdy Ag account. Public profiles may also be indexed by external search engines.
- Geocoding. We use the Google Maps Geocoding API and the U.S. Census Bureau Geocoder to convert your farm address into geographic coordinates (latitude and longitude). These coordinates are stored in our database and used to show your farm in location-based search results (e.g., “farms within 50 miles”). Coordinates are approximate and do not pinpoint your exact address. You may update or remove your address at any time.
- Livestock listings. Animal details you include in livestock listings (breed, genetics, pedigree, registration, pricing) are publicly visible. If you link a listing to a private animal record, only the fields relevant to the listing are published — your full herd management data remains private.
- Order data. When a buyer places an order through your marketplace listings, their name, email address, and any shipping information they provide will be shared with you to fulfill the order. You are responsible for handling buyer data in accordance with applicable privacy laws.
- Customer signup links & QR codes. If you generate a public signup link or QR code for customer registration, consumers who sign up through that link are associated with your farm. We track the signup source (e.g., “farm-stand” or “website”) for your analytics but do not share individual consumer data with other farms.
- Public invoice links. Invoices shared via token-based URLs are viewable by anyone with the link. Invoice details (farm name, customer name, line items, amounts, payment status) are visible without authentication. Links can be deactivated by deleting or cancelling the invoice.
- Removal. You may unpublish your farm profile or delete individual listings at any time, which will remove them from our search results. Cached versions may persist in external search engine indexes for a period outside our control.
4. Marketplace Analytics
We collect analytics data about how the marketplace is used to help sellers understand their visibility and improve the Service. This includes:
- Impressions. When your farm profile or livestock listing appears in search results, we record that it was shown, along with the search query and approximate geographic area of the search.
- Page views. When someone visits your public farm profile, we record the visit.
- Contact clicks. When a visitor clicks your phone number, email, website, or directions link, we record the action type (but not the visitor’s identity).
- Search data. We record search queries and the approximate geographic coordinates of searches to improve search relevance. Search data is not linked to individual user accounts for anonymous (non-logged-in) visitors.
Sellers can view aggregate analytics (impression counts, page views, contact rates) for their own farm through the marketplace analytics dashboard. We do not share individual seller analytics with other sellers or third parties.
5. Search Placement & Ranking
Search results on the farm discovery page and livestock search are influenced by several factors including geographic proximity, subscription tier, recent account activity, and administrative boosts. Paid-tier farms with recent management activity may appear higher in search results than free-tier farms. We do not accept payment specifically for search placement outside of the subscription tier structure.
6. Data Sharing & Third Parties
We do not sell your personal information. We share data only with the following categories of service providers, each under contractual data-protection obligations:
- Supabase — database hosting, authentication, and file storage (including marketplace profile photos, animal photos, and receipt images).
- Vercel — application hosting and deployment.
- Stripe — subscription billing and marketplace payment processing via Stripe Connect. When you enable online sales, you create your own Stripe Connected Account subject to Stripe’s terms. Buyer payment data flows through Stripe and is not stored in our systems.
- Plaid — bank account connectivity (only if you opt in).
- Google Maps — we use the Google Maps Geocoding API to convert farm addresses into geographic coordinates for location-based search. Only your farm address is sent to Google for this purpose. We also use Google Maps to display farm locations on the discovery map.
- U.S. Census Bureau — we use the Census Geocoder as an alternative geocoding service for address-to-coordinate conversion.
- National Weather Service (NWS) — we send your farm’s geographic coordinates to the Weather.gov API to retrieve current conditions, forecasts, and historical weather data for dashboard widgets and grazing management features. No personally identifiable information beyond coordinates is sent.
- Anthropic (AI provider) — certain features send limited data to Anthropic’s Claude AI for processing:
- Receipt scanning: receipt images and extracted text.
- Farm assistant: your chat messages and relevant farm data summaries (animal counts, financial totals, grazing status) needed to answer your questions.
- Pedigree extraction: uploaded pedigree screenshots.
- Smart insights: aggregate farm metrics used to generate operational insights.
- CSV import: column headers and sample rows from uploaded files.
Data sent to Anthropic is used solely to generate your results and is not used to train AI models. We do not send your full database or personally identifiable information beyond what is necessary for the specific feature you are using. Anthropic’s data handling is governed by their privacy policy.
We may also disclose information if required by law, subpoena, or court order, or to protect the rights and safety of Howdy Hills LLC and its users.
7. Push Notifications
If you opt in to browser push notifications, we store the following data to deliver notifications to your device:
- Your browser’s push subscription endpoint URL.
- Encryption keys (p256dh and auth) required by the Web Push protocol.
This data is used solely to deliver push notifications and is deleted when you unsubscribe. We do not share push subscription data with third parties. You may revoke push notification permissions at any time through your browser settings.
8. Data Storage & Security
Your Data is stored on Supabase-managed PostgreSQL databases with row-level security enabled. All data is encrypted in transit (TLS) and at rest. Plaid access tokens receive additional AES-256-GCM encryption. Marketplace photos are stored in Supabase Storage buckets with access controls. AI conversation history is stored in our database and is accessible only within your organization. We implement industry-standard security practices but cannot guarantee absolute security.
9. Data Breach Notification
In the event of a security breach that compromises your personal data, we will notify affected users via email within 72 hours of becoming aware of the breach, in accordance with applicable state and federal notification laws. We will also notify relevant regulatory authorities as required.
10. Data Retention
We retain Your Data for as long as your account is active. If you delete your account, you may request an export of Your Data within 30 days. After that window, we will begin deleting Your Data from production systems. Residual copies in encrypted backups may persist for up to 90 days before being fully purged. Some data may be retained longer where required by law (e.g., tax records).
Marketplace-specific retention: When you delete your account or unpublish your farm profile, your public profile and listings are removed from our search results immediately. Marketplace analytics data (impression counts, page views, search queries) may be retained in anonymized, aggregate form for service improvement purposes. Completed marketplace order records may be retained as required by applicable tax and commerce regulations.
AI data retention: AI conversation history is retained as long as your account is active and is deleted when your account is deleted. Receipt scan images are retained until you delete them or your account is closed.
Email signup retention: Email addresses collected through signup forms are retained until the subscriber requests removal or unsubscribes. You may request deletion by emailing support@howdyag.farm.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data and receive a copy.
- Correct inaccurate or incomplete data.
- Delete your account and associated data.
- Export your data in a standard format.
- Object to certain types of processing.
- Unpublish your marketplace profile and remove your data from public search results at any time.
- Opt out of non-essential notifications, email digests, and push notifications at any time through your account settings.
To exercise any of these rights, email support@howdyag.farm. We will respond within 30 days.
12. Cookies & Analytics
We use essential cookies for authentication and session management. We do not currently use third-party analytics services for general page tracking. We do not use advertising cookies or sell data to advertisers. Marketplace analytics (Section 4) are collected server-side and do not use cookies or client-side tracking scripts.
13. State Privacy Rights (U.S.)
If you are a resident of California, Virginia, Colorado, Connecticut, or another state with a consumer privacy law, you may have additional rights including the right to know what personal information we collect, the right to delete it, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as defined under the California Consumer Privacy Act (CCPA) or the Virginia Consumer Data Protection Act (VCDPA). Marketplace analytics data collected about anonymous visitors (search queries, approximate search locations) is not linked to identifiable individuals and is used solely for service improvement. To exercise your rights, email support@howdyag.farm. We will respond within 30 days (or sooner if required by your state’s law).
14. Children’s Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect information from children. If we learn that we have collected data from a child, we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or an in-app prompt, update the version number and effective date above, and require you to affirmatively accept the updated policy before continuing to use the Service. For non-material changes, your continued use of the Service after the effective date constitutes acceptance.
Questions? Contact us at support@howdyag.farm.