Privacy Policy: What We Collect and Why
Last updated: September 5, 2026
ESA Card (esacard.com) sells instant registration kits for emotional support animals. Registration at /register takes about 3 minutes and asks no health questions, so the most sensitive category of personal data never enters our systems at all. This policy explains what we do collect, how we use it, who sees it, and the choices you have. We wrote it in plain English on purpose. A privacy policy you can't read protects no one.
What we collect
- Contact and account details. Your name, email address, and where you live: your city plus your state if you are in the US, or your country if you are not. Your name and location appear on your card; the verification listing shows the location but not your name. A phone number, with its country code. The country code starts on the country your connection appears to come from, which we read from the request rather than store, and you can change it; the country the number is finally saved under, and whether it came from your connection or your own choice, goes to the product analytics described below along with the form steps. The number leaves your browser only when you press the pay button, and once you have paid it is saved on your customer record with Stripe, our payment processor, beside your email address, so a person can reach you if something about your order needs sorting out, such as a kit email that bounced. We do not send text messages.
- Pet details. Species, name, breed, and a photo of the one animal on the registration, so your Certificate of Registration and wallet ESA Card describe and picture the right animal.
- Payment information. Payments are processed by Stripe. Your card number goes directly to Stripe and we never see or store it. We keep only the order record: what you bought, when, and for how much.
- Usage data. Standard website logs: pages visited, referring link, IP address, device and browser type, and cookies that keep your session together and help us understand how the site is used.
- Advertising identifiers. If you arrive from an ad, the click identifier in the link and the cookies the ad platform sets in your browser. These, and what we send back to those platforms, are described under Advertising, analytics and cookies below.
What we don't collect: health information
We ask no health questions and collect no health data of any kind. No diagnosis, no medical history, no evaluations, no appointments. That's by design: registration is a convenience product, and we're honest that a card or certificate carries no legal weight. What a housing provider will ask for is an ESA letter from a licensed healthcare provider, and we don't sell those. Because we never collect health data, there is no health data here to breach, sell, or subpoena.
How we use your information
- To deliver what you paid for: generating your Certificate of Registration and wallet ESA Card as print-ready PDF files, emailing them to you instantly, and publishing your verification listing at /verify.
- To run the verification page: anyone with your registration number can confirm it's active. The lookup shows less than the card does. It returns the registration number, your pet's name and breed, the city and state (or country) on the registration, the date it was issued, and whether the registration is active. Your name is never returned by the lookup, and neither is your email address or anything about your order.
- To send transactional messages: your order confirmation and the PDF files you bought. Registration is a one-time payment.
- To send occasional marketing email, which you can unsubscribe from with one click at any time.
- To process refunds under our 30-day money-back guarantee, prevent fraud, and meet legal obligations.
What we never do
- We never sell your personal data for money. Nobody pays us for your details: not data brokers, not list buyers, not anyone. What we do send to advertising platforms, we send to run and measure our own ads, and we describe it in full below rather than hiding it behind the word "sell".
- We never collect health data, so there is none to share, lose, or use for marketing. Ever.
- We never publish more than the card shows. Your verification listing displays less than the card itself does, and never your name, your email address, or your payment history.
Service providers we work with
A small number of companies help us run ESA Card. Each receives only what it needs to do its job, is bound by contract to use your data solely to provide services to us, and is prohibited from selling it.
- Payment processor (Stripe): handles your card details end to end. We never store card numbers.
- Email provider: receives your email address and order status to send the messages described above.
- Live chat (Crisp): the chat widget loads on our marketing pages whether or not you use it, so from your first page view Crisp receives the page address, your browser and device details, an approximate location derived from your IP, and a cookie it sets to recognize you on later visits. If you write to us, it also receives your message and your email address, so a person can reply.
- Product analytics (Mixpanel): receives the pages you view and how you interact with them (clicks, scrolling, form steps, and the stages you complete in the registration funnel) along with a random visitor id. It does not record the text of what you click or type; we turned that setting off. When you start checkout, it also receives your email address, name, city, state and country, and your phone number, so one profile shows one customer instead of three anonymous devices. It never receives your pet photo, and there is no health data anywhere to send it.
- Error and performance monitoring (Sentry): receives crash reports and, for a sample of ordinary sessions, performance traces: page addresses, browser and device details, and the technical stack behind an error. We configure it not to send personal data, and it strips session ids, gift codes and email addresses before anything leaves your browser.
- Internal alerts (Slack): our own order and support notifications go to a private Slack channel and include your email address and a link to your Stripe record, so the person on support can find your order. Nothing about you is posted anywhere public.
Advertising, analytics and cookies
We buy ads, and ads only work if the platform can tell which clicks turned into orders. That means information about your visit (and, if you buy, about your order) goes to the advertising platforms we use. Calling that anything other than sharing would be dishonest, so here is exactly what happens.
Google Analytics runs on every page of this site. The Meta, TikTok and Reddit tags run only where we have an active account configured with that platform, so the list below describes the maximum rather than a guarantee that every one of them is live on the day you read this.
- Google (Google Analytics and Google Ads): receives the address of each page you view, the product views and checkout steps you complete, and the value and currency of a purchase along with your registration number as the transaction id, together with your IP address, browser and the cookies its tag sets. We do not send Google your email address or your name.
- Meta (Facebook and Instagram): its browser pixel receives your page views, the product and checkout steps you complete, and, on the confirmation page, the purchase itself with its value and your registration number as the order id, along with the two Meta cookies it sets in your browser. When you buy, our server also sends Meta a purchase event containing your email address, phone number, first and last name, city, state and country, each individually SHA-256 hashed before it leaves us, plus a hashed customer id derived from your registration number. The same event carries, in the clear, your registration number as the event and order id, the address of the page you bought from, those two cookie values, and your browser's user-agent string. Meta matches the hashes against its own users to credit the sale to an ad.
- TikTok: its browser pixel receives your page views and a hashed visitor id on every visit. As soon as you enter your email address in the registration form, whether or not you go on to buy, the pixel also receives your hashed email address and hashed first and last name. Your phone number's hash is added when you press the pay button, and not before. Our server sends the checkout and purchase events with those hashed fields plus your city, state and country in plain text (TikTok's API requires those unhashed), TikTok's own click id and cookie values, your user-agent, your language, the address of the page the event is filed against, the site that referred you, and, for the checkout event only, your IP address, which is read from that one request and never stored.
- Reddit: receives your page views and conversion events with the cookies its pixel sets. No email address and no name.
Two limits are worth stating plainly. First, we never send any of these platforms health information, because we never have any. Second, hashing is not anonymity: a hashed email is still your email to a company that already has it, which is the whole point of sending it. We are not going to pretend otherwise.
You can stop most of this from your side. Browser tracking protection, an ad blocker, or blocking third-party cookies will keep the pixels from loading at all. Ad platforms also run their own controls: Google Ads settings, Meta's Ads Preferences, TikTok's ad personalization settings, and Reddit's. And you can ask us directly, by the route described under Your rights and California residents below.
How long we keep it
We keep your account and order records while your account is active and for as long as tax, accounting, and legal requirements demand afterward. Your verification listing stays live while your registration does, and you can ask us to take it down at any time. If you ask us to delete your data, we delete everything we aren't legally required to keep and tell you what, if anything, must be retained and why. If you never finished paying, your phone number is not added to a customer record at Stripe and no one contacts you on it. The number does remain in that unfinished checkout record at Stripe and on the Mixpanel profile described above, and TikTok has its hash from the moment you pressed the pay button, sent from our server with the checkout event. Deletion and opt-out work as described under Your rights below.
How we protect it
Your data is encrypted in transit (TLS) and at rest. Access inside our team is limited to people who need it to serve you. We don't store card numbers, and we don't hold health data, which removes the two most attractive targets entirely. No system is perfectly secure, and we won't pretend ours is. But if a breach ever affects your information, we will notify you as the law requires and tell you plainly what happened.
Your rights: access, deletion, and opting out
Wherever you live, you can email contact@esacard.com, or write to us from the contact page, to request a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or tell us to stop sharing it with advertising platforms. We verify that the request really comes from you, then respond within 45 days. There is no charge and no effect on your service or pricing for exercising these rights.
We will be straight with you about how the opt-out works, because the mechanism matters more than the promise. There is no automated toggle on this site today. An opt-out request is handled by a person: we suppress your details from the server-side conversion events described above and stop sending your order to the ad platforms. What your browser has already sent to a pixel before you asked cannot be recalled by us, that part you clear by blocking the tags in your browser or using the platforms' own ad settings. If we ever add a self-service control, it will appear here first.
California residents (CCPA/CPRA) and other state privacy laws
Under the California Consumer Privacy Act, as amended by the CPRA, California residents have the right to know what personal information we collect and why, to access it, to correct it, to delete it, and to opt out of its sale or sharing. We do not sell personal information for money and have not in the preceding 12 months. But the CPRA defines "sharing" far more broadly than most people expect: disclosing personal information to a third party for cross-context behavioral advertising counts, whether or not any money changes hands. By that definition, we do share personal information, the identifiers listed under Advertising, analytics and cookies above, sent to Google, Meta, TikTok and Reddit so our ads can be targeted and measured. We would rather say so than lean on a technicality.
So: California residents have the right to opt out of that sharing, and so do residents of the other states with comparable laws, including Colorado, Connecticut, Virginia, Texas, Oregon and Montana, which give the same right over targeted advertising. To exercise it, email contact@esacard.com or use the contact page and say you want to opt out of sharing for advertising. That is the mechanism that exists today; the paragraph above explains honestly what it does and does not undo. We never share the personal information of anyone we know to be under 16, and we never knowingly collect it in the first place.
We will never discriminate against you, in price or service, for exercising any of these rights. You may use an authorized agent to submit requests; we will ask for proof of authorization to protect your account. If we deny a request, you can appeal by replying to our response, and California residents may also complain to the California Privacy Protection Agency or the state Attorney General.
Customers outside the United States
You can register from any country, so some of you are covered by the UK GDPR, the EU GDPR, or a similar law at home. Those laws give you rights of access, correction, deletion, portability, and objection, and the request address is the same one above: contact@esacard.com. Two things are worth saying plainly. First, buying a kit means your details are processed and stored in the United States, where our payment and email providers run, and placing an order is your consent to that transfer. Second, the reason we can keep this section short is that we hold so little: your name, your email, your city and country, your phone number, your pet's details, and an order record. No health data and no card numbers. The advertising platforms described above receive their share of that short list, and you can object or withdraw consent to it at the same address.
A note on consumer health data laws
Some states give consumers specific rights over health-related data, including Washington under its My Health My Data Act. Those laws barely apply to us, for a simple reason: we do not collect consumer health data. Registration asks no health questions, and we do not use geofencing around healthcare facilities. If you believe we have somehow received health information from you, email contact@esacard.com and we will delete it.
Children under 18
ESA Card is for adults. We do not knowingly collect personal information from anyone under 18. If you believe a minor has submitted information to us, email contact@esacard.com and we will delete it promptly.
Changes to this policy
When we update this policy, we change the date at the top. If a change materially affects how we handle your data, we will email you before it takes effect, not after.
Contact us
Questions about this policy or your data go to contact@esacard.com. A person reads every privacy request. You can also find answers to common questions on our FAQ page.