Legal information
Privacy Policy
Hisani ("Hisani", "we", "us", or "our") operates the Hisani platform, including Authentication, My Horses, Stopwatch, Planner, Marketplace, Stable, Dashboard, Admin, and related platform services (together, the "Service"). This Privacy Policy explains what information we collect, how we use and share it, and the choices you have.
This Policy applies to everyone who uses the Service, whether browsing public content or using a registered Horseman account. It does not apply to third-party websites or services we link to.
1. Information we collect
We collect information you provide directly, information created as you use the Service, and limited technical information collected automatically.
- Account and identity information: your name, Contact Points such as email address or phone number, profile details, verification state, account status, authentication-method information, and account-security events. Passwords and one-time codes are handled only through the trusted authentication flow and are not stored in browser-readable storage.
- Marketplace content: listings, listing photographs and documents, messages exchanged about a listing, bookmarks, reports, and seller actions.
- My Horses content: the private horse names and optional breed, date-of-birth, sex, Sire, and Dam facts you save to your account. A My Horses record is a convenience record and is not proof of legal title or registration.
- Stopwatch data: unfinished timing work, completed history, comments, and related timing values stored locally on your device. If you use the optional conditions bar, your browser requests your device location and sends the coordinates directly to BigDataCloud to derive a city name. Hisani does not receive or store these coordinates. Hisani sends only that city name through its public Stopwatch API to Open-Meteo and stores the latest resolved city, timezone, weather, and humidity on your device. If device location is unavailable or you decline it, BigDataCloud may return an approximate city from your network address. Current Stopwatch timing data is not synchronized to a Hisani server account.
- Planner activity: races you save or privately assign to a horse name, exports you generate, and public catalogue or reference data stored on your device for repeat visits and approved offline use. On a fresh Planner visit, if you already granted browser location access, your coordinates are sent directly to BigDataCloud to identify your country and select a matching jurisdiction filter. Hisani does not receive or store these coordinates. Your detected country may remain on your device for up to 24 hours so repeat Planner visits can apply the jurisdiction immediately; it is cleared when expired or when location permission is no longer granted. The selected jurisdiction appears in the shareable filter URL and can be removed. Planner does not request new location permission or use IP location for this default.
- Location defaults: when you have already granted browser location access, Marketplace, My Horses and Stable may send your device coordinates directly to BigDataCloud to prefill unanswered location fields or fresh location filters. Hisani does not receive or store these coordinates. Supported country and state values, and an optional city for Stable creation, remain editable; saved locations and your manual choices take precedence. Form locations are saved only when you submit the form, and Marketplace location filters can appear in the shareable URL. These defaults do not request new permission or use IP location if device lookup fails.
- Stable content: the Stables you own or hold a position in, staff membership and positions, invitations you send or receive, roster entries recording the name and positions of people who work at a yard without a Hisani account, Horse Owner profiles and the per-horse links that grant an owner read access, and the horses held at Stable level with the photographs uploaded for them. Stable records are visible only to Horsemen whose staff position or Horse Owner link grants access to them.
- Administrative and support information: authorized administrative actions, audit records, reports, support messages, and records of actions taken to protect accounts and the Service.
- Usage and device data: log data, approximate location inferred from IP address, browser and device type, connectivity and error information, and the session cookie described below.
2. How we use your information
We use the information described above to:
- provide, maintain, and secure the Service, including authenticating you and enforcing account, ownership, privacy, moderation, and administrative permissions;
- operate the Products you use, such as storing your private My Horses list, preserving local Stopwatch work, synchronizing Planner Saved races and race assignments, generating Planner exports, and matching Marketplace conversations to the correct listing and participants;
- communicate with you about your account, security events, support requests, and material changes to the Service;
- detect, investigate, and prevent fraud, abuse, unauthorized access, and violations of our Terms of Service;
- comply with legal obligations and respond to lawful requests from public authorities; and
- improve the reliability, safety, and usability of the Service.
3. AI-assisted document processing
Marketplace and My Horses may let you submit a horse passport, name-plate, or similar document or photograph so that an AI model can suggest structured horse data. The output is always an unverified, editable draft. You must review it before saving a horse, using it in a listing, or relying on it for another purpose.
We do not use AI-generated extraction output to make a decision that produces legal or similarly significant effects concerning you without human review.
4. Legal bases for processing
Where applicable data-protection law requires a legal basis, we rely on one or more of the following: your consent where requested; processing necessary to provide the Service you use; our legitimate interests in operating, securing, supporting, and improving the Service; and compliance with a legal obligation.
6. International data transfers and data residency
The Service is currently hosted on Amazon Web Services infrastructure in the United States (us-east-1), under a documented temporary exception adopted after a regional service disruption prevented deployment to our intended United Arab Emirates region. We intend to migrate hosting to the United Arab Emirates (me-central-1) and will update this Policy when that migration completes.
Where we transfer personal information across borders, we take steps designed to ensure that it continues to receive an appropriate level of protection consistent with applicable law.
7. Data retention
We keep account and Product information for as long as your account is active and as needed to provide the Service. A passport image used only to prefill My Horses is not attached to the saved horse and becomes eligible for automatic deletion after 24 hours; Hisani does not retain its raw AI provider response. Marketplace listing scans follow the separate listing-evidence lifecycle described by that Product. After account closure, a Stable Hire application, its status, and its listing-scoped conversation remain as the yard's record, but the applicant name and the closing Horseman's sender name are removed, the resume is deleted, and the application text is replaced with "Application content removed." We otherwise retain information only as long as necessary for legal obligations, security, fraud prevention, dispute resolution, enforcement, moderation, audit integrity, and other legitimate purposes permitted by law. Device-local Stopwatch and Planner cache data may remain on a device until you remove the relevant site data, the Service clears it under its account-lifecycle rules, or the browser or operating system removes it.
9. Your rights and choices
Subject to applicable law, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. You can exercise available account controls from Account settings or contact us using the details below.
Some information may be retained or excluded from deletion where applicable law permits or requires it, including for account security, fraud prevention, legal claims, moderation, or audit integrity. We will explain any material limitation that applies to a request.
10. Data security
We use safeguards including encryption in transit and at rest, access controls, account-isolation rules, and redaction of sensitive fields from operational logs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children's privacy
The Service is intended for users who are at least 18 years old, or the age of legal majority in their jurisdiction. We do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, please contact us and we will take appropriate action.
12. Changes to this policy
We may update this Policy from time to time. If we make material changes, we will provide reasonable notice, such as an in-product notice or an update to the effective date, before the changes take effect.
13. Contact us
If you have questions about this Policy or want to exercise your privacy rights, contact us at privacy@hisani.app.

