NATAO Privacy Policy
Last updated: 5/1/2026
The National Association of Therapy Animal Organizations (referred to in this policy as “the Association,” “we,” “us,” or “our”) respects the privacy of the members, volunteers, donors, and visitors who interact with us. This Privacy Policy explains what personal information we gather through our website and related services (together, the “Services”), why we gather it, how we use and safeguard it, and the choices available to you.
By visiting our website, becoming a member, subscribing to our communications, or otherwise using the Services, you acknowledge the practices described here. If any part of this policy is not acceptable to you, please discontinue use of the Services. If you have questions after reading it, the section titled “How to Contact Us” explains how to get in touch.
Information We Collect
Information you give us directly
In brief: We collect the details you choose to share with us.
When you become a member, sign up for a newsletter, complete a form, make a payment or donation, or otherwise communicate with us, you may provide information such as your name, organization or affiliation, information about your organization and services it provides, email address, mailing address, telephone number, professional credentials, account login details, and any message content you send. You are responsible for keeping this information current, and you agree that the details you supply are accurate and belong to you or to someone you are authorized to represent.
We do not seek out or knowingly gather sensitive categories of information — such as health conditions, racial or ethnic background, religious views, or precise financial account numbers — beyond what is reasonably needed to operate the Association. Where payment is required, card and banking details are handled by our payment processors rather than stored on our own systems (see “Payments and Donations”).
Information collected automatically
In brief: Some technical data is recorded by our systems whenever you visit.
Like most websites, ours records certain technical details automatically when you browse. This can include your device type, browser, operating system, approximate region derived from your network address, the pages you view, the links you follow, and the dates and times of your visits. On its own this information does not identify you by name; we rely on it mainly to keep the site secure and running properly and to understand how visitors use our pages.
We gather this kind of data through cookies and similar technologies. The Association does not maintain a separate cookie policy — our use of these technologies is described within this document, in the section titled “Cookies and Tracking Technologies.”
How We Use Your Information
In brief: We use your information to provide you Association benefits, communicate with you, process payments, keep our Services secure, and meet our legal obligations.
Depending on how you interact with us, we may use the personal information we collect for the following purposes:
• Providing and maintaining your account. To create and manage member accounts, verify your identity at login, and give you access to resources and benefits restricted to our members.
• Communicating with you. To respond to your inquiries, send administrative messages about your account or membership, and other communcations
• Processing payments and donations. To handle membership dues, event fees, contributions, and related receipts or confirmations.
• Improving our Services. To analyze how the website is used so we can fix problems, refine content, and make the experience more useful.
• Security and fraud prevention. To protect the Association, our members, and our Services against misuse, unauthorized access, and other harmful activity.
• Legal and compliance purposes. To meet recordkeeping, tax, accounting, and other obligations, and to enforce our terms or respond to lawful requests.
Where we rely on your consent for a particular use — for example, sending marketing emails — you may withdraw that consent at any time, as described in “Your Choices.”
When and With Whom We Share Information
In brief: We share information only with others in the very limited circumstances described below. We do not sell your personal information.
The Association will never sell your personal information, and we do not rent or trade it to outside parties for their own marketing. We may share information in these situations:
• Service providers. We work with trusted vendors who perform functions on our behalf — such as email delivery, payment processing, and analytics. These providers may access personal information only to perform their tasks for us and are expected to safeguard it.
• With Other Association Members. We share limited information about you with other members through our member directory, , forums, articles and other mechanisms to meet the goals of the Association. If you would like to opt out of the member directory, please contact us.
• Legal requirements. We may disclose information when we reasonably believe it is necessary to comply with a law, regulation, court order, or valid governmental request, or to protect the rights, property, or safety of the Association, our members, or others.
• Organizational changes. If the Association undergoes a merger, reorganization, or transfer of operations, personal information may be passed to a successor entity, which would remain bound by the commitments in this policy.
Cookies and Tracking Technologies
In brief: We use cookies and similar tools to operate the site and understand how it is used. We do not maintain a separate cookie policy.
Cookies are small files placed on your device that help a website function and remember your preferences. We use essential cookies to keep you signed in to your account and maintain the security of your session. Most web browsers let you refuse or delete cookies through their settings; if you block them, you may not be able to stay signed in.
We do not use cookies for tracking or advertising purposes. Instead, we use cookieless technologies to gather aggregate anonymous statistics about how visitors use our pages, and we honor Do Not Track signals from your browser.
Because our cookie and tracking practices are explained here, we do not publish a stand-alone cookie notice.
Payment and Donation Processing
In brief: Payment details are handled by third-party processor, not stored by us.
When you pay membership dues, register for an event, or make a donation, your payment is processed by Stripe, a PCI-DSS compliant payment processor. Stripe collects the card or banking information needed to complete your transaction and processes it under its own privacy policy. If you set up recurring membership dues, Stripe securely stores your payment method to process automatic renewals.
We receive confirmation of each transaction, including the amount, date, transaction ID, and your name and email address. We do not store full payment card numbers or banking details on our systems. Transaction records we receive are retained for as long as needed for financial recordkeeping and membership administration.
Email Communications and Your Choices
In brief: You control the messages you receive from us.
If you subscribe to, or opt in to, our communications, we will send communications to the email address you provide. Every marketing message includes a way to unsubscribe, and you can opt out at any time by following that link or by contacting us directly. Even after you opt out of marketing email, we may still send necessary administrative messages — for example, confirmations related to your account, membership, or payments — since these are part of providing the Services. When you become a NATAO member, you’re automatically subscribed to our newsletter. You can unsubscribe at any time using the link at the bottom of every email.
How We Protect Your Information
We maintain reasonable administrative, technical, and physical safeguards designed to protect the personal information in our care against loss, misuse, and unauthorized access. No method of transmitting or storing data can be guaranteed completely secure, so we cannot promise absolute security. You also play a role: please keep your account password confidential and notify us promptly if you believe your account has been compromised.
How Long We Keep Your Information
In brief: We keep personal information only as long as we reasonably need it.
We retain personal information for as long as your account or relationship with the Association is active and for a reasonable period afterward to fulfill the purposes described in this policy — including to provide the Services, resolve disputes, maintain records, and comply with legal, tax, and accounting obligations. When we no longer have a legitimate need to keep information, we take steps to delete it or render it anonymous. Where deletion is not immediately practical — for instance, when data resides in secure backups — we isolate it from active use until it can be removed.
Children’s Privacy
In brief: Our Services are intended for adults and are not directed to children under 18.
The Association does not knowingly collect personal information from, or direct its Services toward, anyone under 18 years of age. By using the Services you represent that you are at least 18. If we discover that we have collected information from a person under 18 without proper authorization, we will deactivate the associated account and take reasonable steps to delete the information. If you believe a minor has provided us with personal information, please contact us using the details in “How to Reach Us.”
Geographic Scope
The Association operates within the United States, and the Services are intended for users located in the United States. We do not direct our Services to, or knowingly market to, individuals in the European Economic Area, the United Kingdom, or other regions governed by foreign data protection regimes such as the GDPR, and this policy is not designed to address those laws. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with any local laws that apply to you.
Updates to This Policy
In brief: We may revise this policy from time to time.
We may update this Privacy Policy periodically to reflect changes in our practices, our Services, or applicable law. When we do, we will revise the “Last updated” date at the top of the document, and for significant changes we may provide additional notice, such as a prominent posting on our website or a direct message. We encourage you to review this policy from time to time so you stay informed about how we handle your information.
How to Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, you can contact us.
We will review and respond to your request in accordance with applicable law.
