For Shelters, Rescues & Their IT Reviewers

Data Access & Security

Exactly what we access when you connect your shelter software, what we store, what we never touch, and how to turn it off. If someone at your organization reviews vendors before an API key is shared, this page is for them.

The Short Version

Read-only

We only fetch your adoptable listings. We never write to your system.

Public listing data only

The same pet profiles you already publish. No adopter, medical, or financial records.

Revocable anytime

Remove your key in the Hub or rotate it in your software. Syncing stops.

No credential required at all

Prefer not to share a key? List pets directly in the Hub instead.

What We Access

When you connect your shelter management software, our sync service periodically fetches your adoptable animal listings — the roster of pets you make available for adoption, and for each pet the profile you publish:

  • Name, species, breed, age group, sex, and similar listing attributes
  • Photos and the adoption description
  • Adoption status (so adopted pets come down promptly)

That's the whole list. All requests are read-only: we pull data from your system's adoption feed, and we never create, modify, or delete anything in it.

What we never access or collect

  • Adopter or applicant personal information
  • Medical records beyond what you publish in a pet's public listing
  • Intake, outcome, or case history
  • Lost & found reports
  • Donor, payment, or financial data
  • Staff or volunteer records

Where your data appears

Synced listings are published to werescue.pet, the WeRescue iOS and Android apps, and — for participating shelters — the Clear The Shelters pet search. In other words: adopter-facing pet search, the reason you connected in the first place. We don't sell or share your feed with data brokers.

How Your Credentials Are Handled

  • You enter your key on hub.werescue.pet over HTTPS, and it's stored in our production database on AWS.
  • Within the Hub, your key is visible only to your own shelter's account users, so your team can manage or replace it. WeRescue staff can access it for support and to operate the sync; our review screens show only the last four characters.
  • Our sync service uses the key for one thing: fetching the adoptable listings described above.
  • You can replace or remove the key at any time in your shelter profile. Our importer only touches accounts with a saved key, so removing it stops syncing. Rotating the key inside your own software has the same effect immediately.

Worth knowing: for most supported systems, the "API key" grants access to a vendor-published adoption feed — the same feed that powers your own website's adoptable page. Treat it with care, but know it is not your master login.

Specifics by Data Source

Different systems expose data differently, so here is what we use for each, and — where it matters — how to scope what we can see from your side.

PetPoint / Petango

What you share
Your Petango Web Services auth key and, for multi-site accounts, a site ID.
What we call
Only the public Petango adoption web service: the adoptable-animal search and the per-animal detail lookup. We never call the lost & found, adoption-list, medical, or any other methods.
How to scope it
Which animals reach that feed is controlled inside PetPoint by your administrator — the stage settings under Admin Options and each site's listing checkbox. Whatever your feed returns is what every consumer of it receives (including your own website widget), so it's worth reviewing those settings whether or not you connect with us. We can additionally scope our pull to specific sites on request.

ShelterLuv

What you share
A ShelterLuv API key, which you can generate and revoke in your ShelterLuv account settings.
What we call
The ShelterLuv API's animal endpoints, read-only, to fetch your publishable adoptable animals and their photos.
How to scope it
ShelterLuv controls which animals are marked adoptable/publishable in your account. Revoking the key in ShelterLuv cuts off access instantly.

RescueGroups.org

What you share
Usually nothing — we read the adoptable listings your organization already syndicates through RescueGroups' pet data services.
How to scope it
Your RescueGroups export settings control what is syndicated, to us and to every other adoption site they feed.

Adopt-a-Pet

What you share
Your Adopt-a-Pet shelter ID and partner API key.
What we call
The Adopt-a-Pet partner API, read-only, to fetch the listings you already publish publicly on Adopt-a-Pet.com.

WeRescue Hub direct listings

What you share
Nothing. You add pets in the Hub yourself and we access no external system. This option is always available, including alongside a feed, and it's the right choice if your organization can't share credentials at all.

Using something else — Chameleon, ShelterBuddy, Animal Shelter Manager, or another system? Ask us; support varies by system and we'll tell you plainly what is and isn't available.

Animals That Must Never Be Published

Some shelters care for animals whose whereabouts must stay confidential — safe-haven programs for the pets of domestic-violence survivors, protective custody cases, and similar. We take this seriously. If this applies to you, do one of the following before connecting a feed:

  • Verify your feed first. Confirm with your software administrator that protected animals are excluded from your adoptable feed. Every consumer of that feed receives whatever it returns — us, your website, and anyone else — so this is the setting that actually protects those animals.
  • Or skip the feed. List adoptable pets directly in the Hub and share no credential at all. Confidential records never touch our systems in any form.
  • Or ask us for a scoped sync. For some systems we can restrict our pull server-side to specific sites, locations, or stages, so protected records are never in the response we receive. Contact us and we'll tell you what's possible for your setup.

If you ever find an animal on WeRescue that should not be public, email [email protected] with the listing and we will remove it right away.

Agreements & Security Reviews

This page, together with our Terms and Privacy Policy, is our standard commitment to every organization on the platform. It's public on purpose: every shelter gets the same answers, and your reviewer can check them without a meeting.

We don't execute per-organization MOUs or data-use agreements for free listing syndication — with hundreds of participating organizations, one clear public standard protects your animals better than a filing cabinet of negotiated variations. If your organization's policy requires a signed agreement before any API access is granted, use the Hub's direct listing option: your pets reach adopters and no system access is involved at all.

Genuine security questions are always welcome, though — technical reviewers can reach us at [email protected] and will get answers from the people who run the platform.

Leaving is easy too

Remove your key (or your whole account) whenever you like. Syncing stops, and if you want previously synced listings taken down, tell us and we'll remove them.