Privacy Policy
Last updated: May 2026
BarnPage ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our multi-tenant equestrian barn management platform. BarnPage is a Software-as-a-Service (SaaS) product hosted on Microsoft Azure.
1. Information We Collect
Account Information
When you create an account we collect your name, email address, and password (hashed). You may optionally provide a profile photo. Your account may be associated with one or more barns, each with a specific role (e.g., Owner/Admin, Barn Manager, Head Trainer, Assistant Trainer, Groom/Staff, Student Rider, Parent/Guardian, Horse Owner/Leaser, or Read-Only Family Guest).
Barn & Membership Data
Barn name and settings, your role within each barn, assigned horses, lesson history, group memberships, and parent / guardian linked-account relationships.
Lesson & Scheduling Data
Lesson bookings, schedule preferences, arena assignments, cancellations, waitlist entries, and attendance records.
Media & Videos
Photos and other gallery media you upload, plus lesson video recordings used for manual review and MEGAN analysis. All media is stored in Azure Blob Storage with SAS-based (Shared Access Signature) access control.
Community & Progress Data
Posts and comments in the community feed, rider progress records, lesson evaluations, highlights, and leaderboard participation.
2. How We Use Your Information
- Service delivery: Operating your barn's scheduling, community feed, progress tracking, horse management, member management, and other core features.
- MEGAN video analysis: On Standard and Premium plans, lesson video frames are sent to the OpenAI API for analysis. MEGAN generates draft feedback that a trainer must review and approve before it is shared. See Section 3 for details.
- Manual lesson reviews: On Starter plans and above, trainers can write and publish lesson evaluations and feedback directly.
- Progress tracking: Aggregating lesson data and evaluations to display rider progress over time.
- Communication: Sending transactional emails (booking confirmations, schedule changes, invitations, and supported notifications) via Azure Communication Services when enabled.
- Platform improvement: Analyzing anonymized usage patterns to improve features and performance.
3. MEGAN Video Analysis
BarnPage offers MEGAN (Machine Equestrian Guidance & Analysis Network), an AI-assisted video analysis feature, on Standard and Premium plans. When a trainer requests MEGAN analysis of a lesson video:
- Selected frames from the video are sent to the OpenAI API with vision-capable models for processing.
- The MEGAN-generated analysis results are stored in our database, associated with the lesson and barn.
- BarnPage does not opt in to sharing API data for model training, and MEGAN analysis is handled under the API terms applicable to our account.
- MEGAN output is always presented as a draft. A qualified trainer must review and approve all MEGAN-generated feedback before it is visible to riders or parents.
- Standard plans include a monthly MEGAN analysis quota (currently 150). Premium plans have unlimited analysis.
4. Data Sharing
We never sell your personal data.
- Within your barn: BarnPage is multi-tenant with tenant-scoped barn isolation. Your data is shared only within the barn you belong to, governed by role-based access controls set by your barn owner or manager.
- MEGAN processing: Video frames and related metadata are sent to OpenAI for analysis when a trainer initiates a MEGAN review (Standard and Premium plans only). No other user data is shared with OpenAI.
- Service providers: We use Microsoft Azure (hosting, PostgreSQL database, Blob Storage, Communication Services) and OpenAI (MEGAN video analysis) as data processors under strict data protection agreements.
- Legal requirements: We may disclose information if required by law or to protect rights, safety, or property.
5. Media & Video Privacy
- Secure storage: All uploaded media is stored in Azure Blob Storage. Access is controlled via time-limited SAS tokens - files are never publicly accessible.
- General media visibility: Gallery media can be visible to the barn, limited to trainers and staff, or kept private to the uploader and staff depending on barn settings and upload context.
- Media approval: Barns can require staff approval before non-staff gallery uploads become visible to other members.
- Strict rider privacy: Rider-linked gallery media without photo consent is kept private when strict rider privacy is enabled.
- Lesson video access: Lesson videos are accessible only to appropriate staff, tagged or primary riders, and linked parents / guardians after review and publishing rules allow access.
6. Minor Privacy Protections
BarnPage takes the privacy of minor riders seriously. The following protections are available:
- Configurable barn settings: Barn owners can configure whether minors appear on leaderboards via the barn settings page.
- Consent tracking: BarnPage provides a consent management system where parents or guardians can record consent preferences for photo sharing, video sharing, leaderboard participation, and progress sharing. Barn staff are expected to respect recorded consent preferences.
- Media privacy controls: Barns can use media approval, default visibility, and strict rider privacy settings to reduce unnecessary exposure of minor rider media.
- Leaderboard filtering: When the barn's "minors in leaderboard" setting is disabled, minor riders are excluded from leaderboard rankings unless a guardian has explicitly granted leaderboard consent.
- Linked accounts: Parent / guardian accounts can be linked to their minor's account, giving guardians visibility into their child's schedule, progress, and consent settings.
- Minimal data collection: We collect only the data necessary to provide the service for minor users.
7. Consent Management
BarnPage provides granular consent controls. Barn staff and guardians can record and manage four consent types for riders:
- Photo sharing: Whether photos featuring the rider may be shared within the barn community.
- Video sharing: Whether lesson videos may be shared beyond the immediate lesson participants.
- Leaderboard participation: Whether the rider appears on barn leaderboards and highlights.
- Progress sharing: Whether progress records and evaluations may be visible to other members beyond the rider's trainers and guardians.
Consent preferences can be updated at any time from your account settings.
8. Cookies
BarnPage uses only essential session cookies managed by NextAuth.js to keep you signed in. We do not use any third-party tracking cookies, advertising cookies, or analytics cookies.
9. Third-Party Services
- Microsoft Azure: Cloud hosting, PostgreSQL database, Blob Storage (media), and Azure Communication Services (email delivery).
- OpenAI: MEGAN video analysis on Standard and Premium plans. Video frames are processed via the OpenAI API under the API terms applicable to BarnPage.
10. Data Retention & Deletion
- Active accounts: We retain your data for as long as your account is active and you are a member of at least one barn.
- Post deletion: Community feed posts are soft-deleted (hidden from view) and may be permanently removed during routine data maintenance.
- Media deletion: Uploaded gallery media and lesson videos can be permanently deleted by the uploader or a barn manager at any time when permitted. Barn owners can also configure retention for gallery media. Deleted media is removed from Azure Blob Storage.
- Account deletion: You may request full deletion of your account and associated data by contacting us at [email protected].
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data.
- Export your data in a portable format (by request).
- Withdraw consent for optional data processing (photo sharing, video sharing, leaderboard, progress sharing) at any time.
- Object to processing of your data in certain circumstances.
To exercise any of these rights, contact us at [email protected].
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how your information is handled, please contact us at [email protected].