Privacy Policy
Open Service Animal Registry, Inc.
Effective Date: Not set
Last Updated: Not set
Open Service Animal Registry, Inc. (“OSAR,” “we,” “us,” or “our”) respects the privacy of handlers, registrants, trainers, working-dog organizations, visitors, and others who interact with our services.
Privacy and data minimization are fundamental principles of OSAR. Our goal is to operate a useful, transparent registry without collecting more personal information than is reasonably necessary to provide that service.
This Privacy Policy explains how OSAR collects, uses, discloses, stores, and protects personal information when you use:
- openserviceanimalregistry.org;
- OSAR account and registry services;
- OSAR public verification pages;
- OSAR QR credentials;
- Apple Wallet or Google Wallet credentials issued through OSAR;
- optional identity-verification services;
- optional training-verification services;
- contact, support, and other OSAR services; and
- other websites, applications, or services that link to this Privacy Policy.
This Policy should be read together with OSAR’s Terms of Use and applicable registry policies.
1. OUR PRIVACY PRINCIPLES
OSAR is designed around the following principles.
Data minimization
We seek to collect only information that is reasonably necessary to operate the registry, verify information when requested, protect the platform, and fulfill OSAR’s nonprofit mission.
Handler control
Handlers control significant aspects of what information is displayed publicly through an OSAR record.
Separation of public and private information
Information necessary for account administration, identity verification, payments, communications, or internal security is not automatically included in a public registry record.
No sale of registrant data
OSAR does not sell personal information.
No behavioral advertising business model
OSAR does not use handler or registry information to build advertising profiles or sell targeted advertising.
No unnecessary medical information
OSAR does not require a handler to disclose a medical diagnosis in order to create an ordinary service-animal registry record.
Third-party identity verification
Where practical, highly sensitive identity information is processed by a specialized identity-verification provider rather than being copied into OSAR’s own application database.
Transparency
OSAR distinguishes between information supplied by a registrant and information independently confirmed by OSAR or another party.
2. A SPECIAL NOTE ABOUT SERVICE-ANIMAL INFORMATION
Registering a service animal may indirectly reveal or suggest information about a handler that could be considered sensitive, including the possibility that the handler has a disability.
OSAR therefore treats service-animal registry information with heightened care even when the information does not include a medical diagnosis.
OSAR does not require ordinary registrants to disclose:
- a specific medical diagnosis;
- medical records;
- physician records;
- medical-treatment history;
- prescription information;
- health-insurance information; or
- other detailed medical information.
Please do not submit medical records or diagnostic information unless OSAR specifically requests particular information for a clearly disclosed purpose and provides an appropriate process for doing so.
Where applicable law requires affirmative or explicit consent before processing sensitive personal information, OSAR will seek that consent separately rather than relying solely on general acceptance of our Terms of Use.
3. INFORMATION WE COLLECT
The information OSAR collects depends on how you use the Service.
3.1 Account Information
When you create an OSAR account, we may collect:
- name;
- email address;
- authentication credentials or authentication-provider information;
- account settings;
- communication preferences;
- account status;
- security information associated with the account; and
- records of account creation, verification, access, and significant changes.
We do not store plaintext passwords.
4. HANDLER INFORMATION
If you register an animal, we may collect information about the handler, including:
- name;
- relationship to the registered animal;
- preferred public-display format;
- contact information;
- registry attestations;
- identity-verification status;
- verification dates;
- privacy preferences;
- account and record history; and
- other information voluntarily supplied through the registration process.
OSAR does not require the handler’s medical diagnosis as part of ordinary registration.
5. INFORMATION ABOUT REGISTERED ANIMALS
Information concerning a registered animal may include:
- animal name;
- photograph;
- species;
- breed or type;
- sex;
- birth date or approximate age;
- service-animal or working-dog classification;
- work or task categories;
- working discipline;
- training source;
- trainer or training-organization information;
- registry status;
- training-verification status;
- animal-identity verification;
- microchip information;
- assessment information, where applicable;
- record history;
- handler attestations; and
- other information voluntarily submitted by the registrant.
Although information about an animal is not necessarily personal information by itself, OSAR treats it as personal information when it is linked or reasonably linkable to an identifiable handler or other individual.
6. MICROCHIP INFORMATION
Handlers may optionally associate an animal’s microchip with an OSAR record.
OSAR does not ordinarily display a full microchip number on a public verification page.
Where displayed, OSAR may show only a masked or partial identifier, for example:
Microchip ending ••••4739
The full identifier may be retained privately when reasonably necessary to support animal-identity verification.
7. HANDLER IDENTITY VERIFICATION
OSAR may offer optional independent handler-identity verification.
OSAR currently intends to use Stripe Identity or a comparable specialized identity-verification provider.
Depending on the verification method used, the provider may request information such as:
- government-issued identification;
- name;
- date of birth;
- government identification number;
- photographs of identity documents;
- a selfie or live image;
- device information;
- IP address; and
- biometric information used to compare the individual with an identification document.
OSAR’s approach
OSAR’s application is designed so that government-identification images, selfies, and biometric templates are not copied into OSAR’s ordinary registry database.
Instead, the identity provider performs the verification and OSAR records information reasonably necessary to document the result, such as:
- identity provider;
- provider verification reference;
- verified or unverified status;
- verification date;
- limited verification-result information;
- name-match result, where necessary;
- fraud or exception status, where appropriate; and
- redaction or deletion status.
Depending on the provider’s platform, authorized OSAR personnel may technically have limited access to identity-verification information through the provider’s administrative tools. OSAR’s policy is to access such information only when reasonably necessary for verification, fraud prevention, troubleshooting, legal compliance, or security.
OSAR intends to request deletion or redaction of identity-verification information held by the provider when appropriate and supported by the provider’s services, subject to legitimate fraud-prevention, legal, security, and recordkeeping requirements.
Identity-verification providers maintain their own privacy practices and retention requirements. Individuals completing identity verification should review the provider’s privacy disclosures presented during the verification process.
A failed or incomplete identity verification:
- does not determine whether an animal legally qualifies as a service animal;
- does not determine whether a handler has a disability;
- does not automatically invalidate a basic OSAR registry record; and
- is not itself a determination of any legal right.
8. TRAINER AND TRAINING-ORGANIZATION INFORMATION
If a handler requests training verification, OSAR may collect information concerning a trainer or training organization, including:
- trainer or organization name;
- business name;
- professional email address;
- professional telephone number;
- website;
- business address;
- publicly available professional information;
- relationship to the animal or handler;
- approximate training dates;
- training categories;
- verification responses;
- confirmation status;
- communications concerning the verification request; and
- appropriate audit records.
OSAR may independently locate publicly available professional contact information rather than relying exclusively on information supplied by the handler.
If you are a trainer or organization representative who receives an OSAR verification request, the information you provide will be used to evaluate and document the verification request and for related fraud-prevention, compliance, and recordkeeping purposes.
OSAR will not publicly disclose private correspondence with trainers or organizations unless disclosure is authorized, required by law, or otherwise expressly stated.
9. PAYMENT INFORMATION
OSAR may charge small one-time fees for optional services that create direct third-party or administrative costs, such as identity verification or training verification.
OSAR may also accept voluntary donations.
Payments may be processed by Stripe or another payment processor.
The payment processor may collect information such as:
- name;
- billing address;
- email address;
- payment-card information;
- bank or payment-account information;
- transaction information;
- fraud-prevention information; and
- device or network information.
OSAR does not intend to store complete payment-card numbers or card security codes in its application database.
OSAR may retain transaction information such as:
- amount;
- date;
- payment-provider reference;
- transaction type;
- payment status;
- refund status;
- billing identity information where necessary; and
- accounting and tax records.
Payments for optional verification services are separate from charitable donations.
10. PUBLIC REGISTRY INFORMATION
OSAR is a voluntary registry, and part of the Service is designed to permit third parties to verify records.
Handlers should therefore understand that information designated for inclusion on a public verification record is public information.
Depending on the handler’s selections and the record type, a public verification page may display:
- animal name;
- animal photograph;
- OSAR record number;
- classification;
- working or task categories;
- record status;
- handler-attestation status;
- training source;
- independent verification statuses;
- partial or masked animal identifiers;
- last-confirmed date; and
- handler identity according to the handler’s selected privacy setting.
Handler-name options may include, where available:
- full name;
- first name and last initial; or
- no publicly displayed handler name.
Private information such as account email, telephone number, home address, payment information, complete microchip number, identity-document information, or medical records is not intended to appear on an ordinary public verification page.
11. PUBLIC VERIFICATION DOES NOT MEAN PUBLIC DIRECTORY
OSAR does not intend to operate an unrestricted public directory through which users can browse handlers or search broadly for individuals with service animals.
Public verification is intended primarily to occur through:
- a QR credential;
- a secure verification link; or
- an exact OSAR record number.
OSAR may use rate limiting, anti-automation controls, search-engine directives, and other measures intended to reduce bulk enumeration, scraping, or indexing of registry records.
However, no technical measure can guarantee that information made publicly accessible will never be copied, photographed, cached, archived, indexed, or redistributed by another person.
Handlers should therefore treat any information they choose to make public as information that may be seen or retained by third parties.
12. QR CODES
OSAR QR codes are designed to contain a verification URL or token rather than embedding sensitive personal information directly in the QR code.
Scanning the QR code generally directs the user to the corresponding OSAR verification page.
Do not assume that possession of a QR code is confidential. A person who receives or photographs the QR code may be able to access the associated public verification record.
13. APPLE WALLET AND GOOGLE WALLET
OSAR may provide digital credentials compatible with Apple Wallet and Google Wallet.
When you choose to add an OSAR credential to a digital wallet, certain credential information must be provided to Apple, Google, or their respective services in order to generate, store, update, or display the credential.
Credential data may include:
- animal name;
- OSAR record number;
- record status;
- credential artwork;
- verification URL or QR code; and
- other limited information selected for the credential.
Apple and Google process information according to their own terms and privacy policies.
OSAR seeks to minimize the amount of information included in a digital-wallet credential.
14. CONTACT AND SUPPORT INFORMATION
When you contact OSAR, we may collect:
- name;
- email address;
- topic;
- message;
- attachments you voluntarily provide;
- prior correspondence;
- support history; and
- information necessary to investigate or respond to your inquiry.
Please do not send medical records, government identification documents, payment-card information, passwords, or other highly sensitive information through ordinary support forms or email unless specifically requested through an approved secure process.
15. INFORMATION COLLECTED AUTOMATICALLY
When you access OSAR websites or applications, we may automatically receive limited technical information, including:
- IP address;
- browser type;
- device type;
- operating system;
- pages requested;
- referring page;
- date and time of access;
- session information;
- approximate region derived from IP address;
- security and fraud indicators;
- error information; and
- application-performance information.
We use this information primarily to:
- operate the website;
- maintain sessions;
- protect accounts;
- detect fraud and abuse;
- prevent automated scraping;
- investigate technical problems;
- maintain system reliability;
- understand general usage patterns; and
- improve accessibility and performance.
16. COOKIES AND SIMILAR TECHNOLOGIES
OSAR may use cookies and similar technologies that are necessary for functions such as:
- authentication;
- session management;
- security;
- fraud prevention;
- user preferences;
- load balancing; and
- accessibility.
OSAR may also use limited analytics to understand website performance and usage.
If OSAR introduces optional analytics, advertising, or other nonessential technologies requiring consent under applicable law, OSAR will provide appropriate notice and consent controls.
OSAR does not intend to use registry information for cross-site behavioral advertising.
17. GLOBAL PRIVACY CONTROL AND UNIVERSAL OPT-OUT SIGNALS
OSAR does not currently sell personal information or use personal information for targeted advertising in a manner that would ordinarily require an opt-out mechanism.
If OSAR’s practices change in a manner subject to applicable universal opt-out requirements, OSAR will recognize legally required mechanisms, including Global Privacy Control where applicable.
18. HOW WE USE INFORMATION
OSAR may use personal information to:
Operate the registry
- create and maintain accounts;
- create and maintain registry records;
- issue OSAR record numbers;
- provide public verification;
- generate QR credentials;
- provide digital-wallet credentials;
- manage record statuses; and
- provide handler dashboards.
Perform requested verification
- verify handler identity;
- contact trainers or training organizations;
- validate training relationships;
- associate animal identity information;
- perform or document future assessments; and
- display accurate verification statuses.
Communicate with users
- provide account notices;
- send verification requests;
- send security notifications;
- respond to inquiries;
- provide service updates;
- notify handlers about record status;
- request re-attestation; and
- provide legally required notices.
Protect OSAR and its users
- prevent fraud;
- investigate abuse;
- detect duplicate or suspicious activity;
- protect account security;
- prevent unauthorized access;
- enforce OSAR policies;
- maintain audit records; and
- investigate security incidents.
Operate the organization
- process payments;
- process donations;
- maintain accounting records;
- administer nonprofit activities;
- evaluate services;
- improve accessibility;
- develop features;
- conduct quality assurance; and
- comply with legal obligations.
Research and transparency reporting
OSAR may create aggregated or deidentified statistics concerning registry usage, such as the number of active records or broad categories of registered working animals.
OSAR will take reasonable measures designed to prevent such reports from identifying individual handlers.
19. HOW WE SHARE INFORMATION
OSAR does not sell personal information.
We may disclose personal information in the following circumstances.
Service providers
We may use service providers to perform functions such as:
- hosting;
- database services;
- secure file storage;
- authentication;
- transactional email;
- payment processing;
- identity verification;
- security;
- fraud detection;
- error monitoring;
- website performance;
- accessibility;
- customer support; and
- professional services.
Providers receive information reasonably necessary to perform their services and are expected to process information consistently with applicable contractual and legal requirements.
At your direction
We disclose information when you intentionally make it public or direct us to share it.
Examples include:
- activating a public registry record;
- sharing your QR credential;
- adding a credential to Apple Wallet or Google Wallet;
- requesting trainer verification; or
- authorizing a third party to receive information.
Trainers and organizations
When you request training verification, OSAR may disclose limited information necessary to allow the trainer or organization to identify the relevant animal-handler relationship and respond to the request.
Legal requirements
OSAR may disclose information where reasonably necessary to:
- comply with applicable law;
- respond to lawful court orders, subpoenas, warrants, or governmental requests;
- establish, exercise, or defend legal claims;
- protect the rights or safety of OSAR, our users, or others;
- investigate suspected fraud or unlawful conduct; or
- respond to an emergency involving a credible threat of serious harm.
OSAR will seek to limit disclosure to information reasonably necessary under the circumstances.
Organizational changes
If OSAR undergoes a merger, restructuring, consolidation, dissolution, transfer of programs, or similar organizational transition, information may be transferred as part of that process where permitted by law.
Because OSAR is intended to operate as a nonprofit public-interest organization, any such transfer should remain subject to applicable nonprofit, privacy, contractual, and legal restrictions.
20. INFORMATION WE DO NOT SELL
OSAR does not sell registrant personal information in exchange for money.
OSAR also does not intend to share personal information for cross-context behavioral advertising or comparable targeted-advertising activities.
OSAR does not sell:
- handler information;
- registry information;
- trainer information;
- identity-verification data;
- service-animal information;
- working-dog information;
- email lists; or
- public-verification activity.
If this practice ever materially changes, OSAR will update this Policy and provide any notices, choices, or consent mechanisms required by applicable law.
21. IDENTITY-VERIFICATION PROVIDERS
Identity verification involves particularly sensitive information.
When Stripe Identity or another provider performs identity verification, the provider may operate as an independent controller of certain information or may have its own legal obligations regarding data retention, fraud prevention, biometric processing, and regulatory compliance.
OSAR does not control every aspect of a third-party provider’s data practices.
Before completing identity verification, users should review the privacy disclosures provided by the identity-verification provider.
OSAR will not publicly display:
- driver's-license numbers;
- passport numbers;
- Social Security numbers;
- identity-document images;
- selfies used for identity verification; or
- biometric identifiers.
22. AUTOMATED IDENTITY VERIFICATION
A third-party identity provider may use automated systems, artificial intelligence, computer vision, biometric comparison, fraud detection, or manual review in evaluating an identity-verification request.
OSAR may receive the resulting verification status and limited supporting information.
OSAR does not use the result of identity verification to determine:
- whether a person has a disability;
- whether an animal qualifies under the ADA;
- whether a handler possesses public-access rights; or
- whether a registered animal is legally a service animal.
Where appropriate, OSAR may provide alternative or manual review processes when automated verification cannot be completed.
23. TRAINING VERIFICATION
OSAR training verification is designed to verify factual claims, not to create legal certification.
For example, OSAR may seek confirmation that:
- a particular trainer worked with the animal-handler team;
- a particular organization trained the animal;
- training occurred during a stated period;
- particular general training categories were provided; or
- a particular assessment or qualification occurred.
OSAR may retain confirmation responses and related audit information to support the integrity of the registry.
OSAR will not publicly publish private trainer correspondence merely because the resulting status appears on a public record.
24. RECORDING CONSENT AND ATTESTATIONS
OSAR maintains records of important user choices and attestations.
These may include:
- acceptance of Terms;
- acknowledgement of registry limitations;
- handler attestations;
- consent to public disclosure;
- consent to sensitive-data processing where required;
- trainer-contact authorization;
- privacy selections;
- verification authorizations; and
- withdrawal of consent.
Records may include the version of the disclosure or policy accepted, date and time, user ID, and appropriate technical audit information.
25. DATA RETENTION
OSAR retains personal information only for as long as reasonably necessary for the purposes described in this Policy, subject to legal, accounting, fraud-prevention, security, dispute-resolution, and nonprofit recordkeeping requirements.
Retention periods vary by category.
Active accounts and registry records
Information is generally retained while the account or record remains active and for a reasonable period afterward as necessary to administer deletion, disputes, fraud prevention, audits, or legal obligations.
Public registry information
Public information remains available while the corresponding record is active or otherwise designated for public display.
When a public record is archived or removed, OSAR will remove it from ordinary public access, subject to technical caching and limited lawful retention.
Identity-verification information
OSAR seeks to retain only the verification result and minimum audit information necessary for the registry.
Raw identification documents, selfies, and biometric data processed by the identity provider are subject to the provider’s retention practices and any deletion or redaction requests OSAR can appropriately initiate.
Payment and donation records
Transaction records may be retained for the periods reasonably necessary for accounting, tax, audit, fraud-prevention, dispute, and legal purposes.
Training-verification records
Confirmation responses and appropriate supporting audit information may be retained while the related registry record remains relevant and afterward for a reasonable period necessary to protect registry integrity and resolve disputes.
Security records
Security and access logs may be retained for a limited period appropriate for security monitoring, fraud investigation, incident response, and system integrity.
Backups
Deleted information may persist temporarily in encrypted or restricted backups until those backups are overwritten or expire according to OSAR’s backup lifecycle.
Information retained solely for backup, legal, fraud-prevention, or security purposes may be isolated from ordinary operational use.
26. DELETING OR ARCHIVING A REGISTRY RECORD
Handlers may archive a record or request deletion through available account controls or by contacting OSAR.
Removal of a record from public access does not necessarily require immediate destruction of every associated internal record.
OSAR may retain limited information where reasonably necessary to:
- complete transactions;
- comply with tax or accounting obligations;
- investigate fraud;
- enforce agreements;
- maintain security;
- document prior verification activity;
- prevent abuse;
- resolve disputes;
- establish or defend legal claims; or
- comply with applicable law.
Where continued retention is unnecessary, information will be deleted, anonymized, or deidentified according to OSAR’s retention practices.
27. YOUR PRIVACY RIGHTS
Depending on where you live, applicable law may provide rights concerning your personal information.
These may include the right to:
- know whether OSAR processes your personal information;
- access your personal information;
- correct inaccurate personal information;
- delete personal information;
- obtain a portable copy of certain information;
- withdraw consent;
- restrict certain processing;
- object to certain processing;
- opt out of sale of personal information;
- opt out of targeted advertising;
- opt out of certain profiling;
- appeal a decision concerning a privacy request; and
- lodge a complaint with an applicable privacy regulator.
Because OSAR does not sell personal information or use registry information for targeted advertising, some statutory opt-out rights may not be relevant to OSAR’s current practices.
OSAR intends, where reasonably practicable, to provide core access, correction, and deletion controls to registered users regardless of whether a particular privacy statute requires those rights in the user’s jurisdiction.
28. HOW TO EXERCISE YOUR RIGHTS
Where available, many privacy choices can be managed directly through your OSAR account.
You may also submit a privacy request to:
privacy@openserviceanimalregistry.org
OSAR may need to verify your identity before completing a request.
Verification will be proportionate to the nature and sensitivity of the information involved.
OSAR will not require substantially more personal information than reasonably necessary to verify a privacy request.
Authorized agents may submit requests where permitted by applicable law. OSAR may require appropriate evidence of the agent’s authority.
OSAR will respond within the period required by applicable law.
If applicable law gives you a right to appeal OSAR’s decision regarding a privacy request, appeal instructions will be provided with the response.
29. CORRECTION OF PUBLIC REGISTRY INFORMATION
OSAR encourages handlers to maintain accurate records.
Handlers may update eligible registry information through their account.
Certain independently verified fields may not be directly editable because changing them could invalidate the underlying verification.
If verified information is inaccurate, the handler should request correction or re-verification rather than altering the verification result directly.
30. SECURITY
OSAR uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, destruction, alteration, disclosure, or misuse.
Depending on the system and information involved, safeguards may include:
- access controls;
- least-privilege permissions;
- multifactor authentication for privileged accounts;
- secure session management;
- encryption in transit;
- appropriate encryption or protected storage;
- audit logging;
- secure software-development practices;
- vulnerability and dependency management;
- rate limiting;
- anti-abuse controls;
- secure backups;
- separation of public and private information;
- third-party security review; and
- incident-response procedures.
No Internet service or storage system can guarantee absolute security.
Users are responsible for protecting their account credentials and should notify OSAR promptly if they suspect unauthorized access.
31. SECURITY INCIDENTS
If OSAR determines that a security incident involving personal information requires notification under applicable law, OSAR will provide required notifications in accordance with applicable legal requirements.
OSAR may also take steps such as:
- securing affected systems;
- revoking sessions or credentials;
- requiring password resets;
- notifying service providers;
- investigating affected records; and
- cooperating with appropriate authorities.
32. CHILDREN AND MINOR HANDLERS
OSAR recognizes that a legitimate service-animal handler may be a child.
However, OSAR accounts are intended to be created and managed by adults.
Individuals under 18 years of age should not independently create or administer an OSAR account.
A parent or legal guardian may create and manage a registry record on behalf of a minor handler where permitted by OSAR policies.
OSAR will seek to minimize information collected about minor handlers.
For records involving minors:
- public display of the minor handler’s identity should be limited by default;
- medical diagnoses should not be collected through ordinary registration;
- a parent or guardian should control privacy settings;
- verification processes may be modified or restricted; and
- additional safeguards may apply.
OSAR is not directed to children under 13 and does not knowingly permit children under 13 to independently create accounts or submit personal information.
If OSAR learns that personal information was collected directly from a child contrary to these requirements, OSAR will take appropriate steps consistent with applicable law.
Parents or guardians may contact OSAR regarding a child’s information at:
privacy@openserviceanimalregistry.org
33. EMAIL AND OTHER COMMUNICATIONS
Certain communications are necessary for operation of the Service.
These may include:
- email-verification messages;
- password or security notices;
- registry-status notices;
- verification communications;
- trainer-confirmation requests;
- transaction receipts;
- privacy or legal notices; and
- other administrative communications.
Users generally cannot opt out of communications necessary to administer an active account.
If OSAR sends optional newsletters, fundraising messages, or promotional communications, recipients will be provided an appropriate way to unsubscribe.
34. INTERNATIONAL USERS
OSAR is based in the United States.
If you access OSAR from another country, your information may be processed in the United States or other jurisdictions where OSAR’s service providers operate.
Those jurisdictions may have privacy laws different from those in your home country.
Where applicable law requires a particular mechanism for an international transfer of personal information, OSAR will use an appropriate mechanism or service provider arrangement.
35. USERS IN THE EUROPEAN ECONOMIC AREA, UNITED KINGDOM, OR OTHER GDPR-STYLE JURISDICTIONS
Where the General Data Protection Regulation, UK GDPR, or similar law applies to OSAR, OSAR will process personal information using an appropriate legal basis.
Depending on the processing, this may include:
Performance of a contract
For processing reasonably necessary to:
- create an account;
- provide registry services;
- maintain credentials;
- respond to requests; or
- perform requested services.
Consent
For processing requiring consent, which may include:
- certain sensitive personal information;
- certain public disclosures;
- optional identity verification;
- optional cookies; or
- other processing for which applicable law requires consent.
Where explicit consent is required for sensitive information, OSAR will seek explicit consent.
Legitimate interests
Where permitted, OSAR may process information for legitimate interests such as:
- preventing fraud;
- protecting account security;
- improving the Service;
- enforcing policies;
- maintaining registry integrity; and
- administering the organization,
provided those interests are not overridden by applicable individual rights.
Legal obligations
OSAR may process information where necessary to comply with applicable law, accounting rules, legal process, or regulatory obligations.
Where legally required, individuals may have additional rights to object, restrict processing, withdraw consent, or complain to a supervisory authority.
Withdrawal of consent does not affect processing lawfully performed before the withdrawal.
36. U.S. STATE PRIVACY RIGHTS
Some U.S. state privacy laws apply only after an organization reaches specified thresholds, and exemptions differ by state.
Where OSAR becomes subject to a state privacy law, OSAR will provide and honor the rights required by that law.
OSAR’s general privacy model is intended to support core rights such as:
- access;
- correction;
- deletion;
- portability;
- consent for sensitive processing where legally required;
- transparency;
- data minimization; and
- reasonable security.
OSAR does not rely on the fact that a particular privacy statute may exempt a nonprofit organization as a reason to disregard reasonable privacy practices.
37. NO HIPAA REPRESENTATION
OSAR is not a healthcare provider and is not designed to receive medical records.
Information submitted to OSAR should not be assumed to receive the protections applicable to protected health information held by a healthcare provider or health plan under the Health Insurance Portability and Accountability Act (“HIPAA”).
For this reason, handlers should not submit medical records or unnecessary diagnostic information to OSAR.
38. THIRD-PARTY WEBSITES AND SERVICES
OSAR may link to external resources, government websites, trainers, organizations, retailers, service providers, or other third parties.
OSAR does not control the privacy practices of independent third parties.
Visiting an external service is subject to that service’s own privacy policy and terms.
A link from OSAR does not, by itself, constitute an endorsement of the third party’s privacy practices.
39. FRAUD, ABUSE, AND REGISTRY INTEGRITY
OSAR may process information to identify and respond to:
- false registrations;
- duplicate records;
- impersonation;
- unauthorized use of another person’s identity;
- fabricated trainer relationships;
- falsified verification information;
- abuse of public-verification endpoints;
- automated scraping;
- compromised accounts; and
- other misuse.
Where appropriate, OSAR may suspend public access to a record during an investigation.
Internal fraud and moderation records are generally not included in public registry information.
40. DEIDENTIFIED AND AGGREGATED INFORMATION
OSAR may create information that has been aggregated or deidentified so that it is no longer reasonably linked to an identifiable individual.
OSAR may use this information for:
- research;
- transparency reports;
- program evaluation;
- public education;
- grant applications;
- statistical analysis;
- platform improvement; and
- understanding service-animal and working-dog registry trends.
OSAR will not intentionally attempt to reidentify data that has been formally deidentified except where reasonably necessary to validate the effectiveness of the deidentification process or as permitted by law.
41. ACCESSIBILITY OF THIS PRIVACY POLICY
OSAR intends for this Privacy Policy and related privacy controls to be accessible to people with disabilities.
If you encounter an accessibility issue that prevents you from understanding this Policy or exercising a privacy right, please contact:
privacy@openserviceanimalregistry.org
OSAR will work to provide the information or process in an accessible alternative format.
42. CHANGES TO THIS PRIVACY POLICY
OSAR may update this Privacy Policy as:
- the Service evolves;
- new verification methods are introduced;
- service providers change;
- laws change;
- organizational practices change; or
- additional privacy protections are implemented.
The effective date and last-updated date will appear at the top of this Policy.
If a change materially alters how OSAR uses previously collected personal information, OSAR will provide additional notice or obtain consent where required by applicable law.
Historical versions may be retained for legal, compliance, and transparency purposes.
43. CONTACT OSAR
Questions, concerns, or privacy requests may be directed to:
Open Service Animal Registry
Email: privacy@openserviceanimalregistry.org
Website: openserviceanimalregistry.org
Mailing Address:
[INSERT OSAR MAILING ADDRESS BEFORE PUBLICATION]
For general support matters unrelated to privacy, please use OSAR’s Contact Us page.
44. SUMMARY OF WHAT OSAR WILL NOT DO
For clarity, OSAR’s intended privacy model means that OSAR will not:
- sell handler or registrant information;
- sell trainer information;
- operate an advertising profile based on a handler’s service-animal record;
- require a medical diagnosis for ordinary service-animal registration;
- require submission of medical records for ordinary registration;
- place government-ID images in the ordinary OSAR registry database;
- publicly display driver's-license or passport information;
- publicly display identity-verification selfies;
- publicly display biometric information;
- publicly display full payment-card information;
- publicly display a full animal microchip number by default;
- make private account contact information public simply because an animal is registered; or
- represent a voluntary OSAR record as governmental certification.
OSAR exists to provide a useful registry with meaningful verification while collecting and exposing as little personal information as reasonably necessary to do so.