Privacy Policy
Last updated: April 24, 2026
This Privacy Policy explains how MF Automations LLC d/b/a Pay Vets Now ("we", "us") collects, uses, shares, and protects personal information when you use payvetsnow.com and related services.
1. Information we collect
- Account information: email, full legal name.
- Intake information you provide: branch of service, approximate service dates, discharge type, claimed conditions, state, description of evidence.
- Documents you generate: pre-filled PDF forms derived from your intake.
- AI Concierge conversations: messages you send and the AI's responses.
- Payment information: handled by Stripe. We never store your card number or CVV. We store subscription status and the Stripe customer/subscription IDs.
- Technical information: IP address, user agent, timestamps for security and audit purposes.
2. How we use your information
Only to: provide the service (generate your VA forms, run the AI Concierge, maintain your dashboard), process payments, communicate about your account, improve the product in aggregate form, and comply with legal obligations. We never sell your data.
3. Sharing
We share minimum-necessary data with these sub-processors:
- Cloudflare (hosting, DNS, rate limiting, Turnstile bot check) — United States
- Stripe (payment processing) — United States
- Google (email delivery via Gmail API from our sending domain) — United States
- Anthropic (AI inference for the AI Concierge) — United States
We do not share your data with anyone else without your consent, except as required by law.
4. Data retention
Account and intake data is retained while your account is active and for up to 90 days after account deletion (except audit logs and subscription records, which are retained longer for legal and tax compliance). You may request deletion at any time (see Section 8).
5. Security
TLS 1.3 in transit. Encrypted at rest by Cloudflare D1 infrastructure. Session cookies are HttpOnly, Secure, SameSite=Lax. Authentication is by email-based magic link — we do not use passwords. Rate limiting and Cloudflare Turnstile protect against abuse. Every sensitive action is written to an append-only audit log.
6. Cookies
We use a minimal set of cookies: a session cookie (pvn_session) for authentication, a consent preference cookie, and Stripe's payment cookies during checkout. We do not currently run marketing cookies. See our cookie banner on first visit to choose your preferences. We honor the Global Privacy Control signal.
7. Your rights under state privacy laws
If you are a resident of a state with a comprehensive privacy law — including California (CCPA/CPRA), Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa (ICDPA), Texas (TDPSA), Oregon (OCPA), Tennessee (TIPA), Indiana (CDPA), Delaware, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Rhode Island, Montana — you have the right to:
- Know what personal information we hold about you
- Access / download that information (request via the Export tool in your dashboard)
- Delete your information (self-service via dashboard or by emailing privacy@payvetsnow.com)
- Correct inaccurate information
- Opt out of the sale or sharing of personal information (we do not sell or share for cross-context advertising)
- Non-discrimination for exercising these rights
8. How to exercise your rights
- Access / download: sign in and click "Export my data (JSON)" on your dashboard, or download directly.
- Delete: POST to
/api/dsar/deletewith body{"confirm":"DELETE MY DATA"}while signed in, or email privacy@payvetsnow.com from your registered address. Subscription and tax records are retained as required by law. - Correct: email privacy@payvetsnow.com or update via your dashboard.
- Appeal: if we decline a request, you have the right to appeal — email privacy@payvetsnow.com with "Appeal" in the subject.
We will respond within 45 days (some laws allow 60 days with a notice of extension).
9. HIPAA
When you upload medical records or service treatment records, we treat them as protected health information. We will sign a Business Associate Agreement with any provider that requires one before transmitting PHI. Do not upload medical records until we notify you that the encrypted evidence vault is live.
10. Children
Pay Vets Now is not directed to children under 13 and we do not knowingly collect personal information from children under 13.
11. Changes to this Policy
Material changes will be communicated by email and posted here with an updated date.
12. Contact
MF Automations LLC d/b/a Pay Vets Now · 233 NE 27th St, Miami, FL 33137
privacy@payvetsnow.com