Legal

Privacy Policy

Effective and last updated: October 2, 2026. Applies to users in all 50 states and the District of Columbia.

1. Scope and Who We Are

This Privacy Policy explains how GuardSphere ("GuardSphere," "we," "us," or "our"), a company incorporated in the State of Delaware, collects, uses, discloses, retains and protects personal information when you visit our websites, join our waitlist, apply for a position or dealership, contact us, or use the GuardSphere security operations platform, mobile guard app and client portal (together, the "Services").

GuardSphere serves customers throughout the United States. This Policy is designed to meet the requirements of applicable federal law and the privacy laws of all 50 states and the District of Columbia, including comprehensive consumer privacy laws, data breach notification laws, biometric privacy laws, children's privacy laws and online privacy policy disclosure laws.

Business customer data: when a security company (our "Customer") uses the Services to manage its guards, sites and clients, we process that information on the Customer's behalf as a "service provider" or "processor." The Customer's own privacy notice governs that data, and requests about it should be directed to the Customer. We will assist Customers in responding to such requests.

2. Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of personal information:

  • Identifiers: name, email address, phone number, postal address, job title, company name, account username, IP address and device identifiers.
  • Professional and employment information: work history, sales and security-industry experience, licenses, education, references and other information you provide in a career or dealer application.
  • Commercial information: subscription plan interest, purchase history, invoices and billing records.
  • Workforce and operational data processed for Customers: shift schedules, time and attendance, patrol logs, post orders, incident reports, photos, messages and payroll-related information.
  • Geolocation data: GPS location used for clock-in/clock-out verification, patrol tracking and emergency alerts in the mobile guard app, only while enabled by the Customer and the user.
  • Internet and device activity: browser type, pages viewed, referring URLs, timestamps and interaction data collected through cookies and similar technologies.
  • Audio, electronic and visual information: photos, video or voice notes uploaded with incident reports.
  • Sensitive personal information (only where necessary and permitted): precise geolocation, account log-in credentials, government-issued license numbers, and, for applicants, information you voluntarily provide. We do not intentionally collect biometric identifiers; if a Customer enables a feature that uses biometrics, we will obtain any notice and written consent required by laws such as the Illinois Biometric Information Privacy Act, Texas and Washington biometric laws.
  • Inferences: AI-generated operational insights (for example, coverage-gap or incident-severity predictions) relating to sites and operations.

3. Sources of Personal Information

  • Directly from you, through forms, applications, accounts and communications.
  • From our Customers, who upload or enter information about their employees, guards, sites and clients.
  • Automatically, from your device and browser when you use the Services.
  • From service providers, business partners, references you list and publicly available sources.

4. How We Use Personal Information

  • To provide, operate, maintain and improve the Services, including scheduling, reporting, dispatch, payroll analytics and AI features.
  • To respond to waitlist, demo, sales and contact requests, and to evaluate employment and dealer applications.
  • To communicate with you about the Services, updates, security alerts and support.
  • To send marketing communications where permitted, with the ability to opt out at any time.
  • To secure the Services, prevent fraud, and detect and investigate security incidents.
  • To comply with legal obligations, enforce our terms and protect our rights and the rights of others.
  • To create de-identified or aggregated data, which we maintain in de-identified form and do not attempt to re-identify.

5. Artificial Intelligence and Automated Processing

GuardSphere uses AI to summarize reports, prioritize incidents and recommend operational actions. These features support human decision-making by supervisors and Customers. We do not use AI or automated processing to make decisions that produce legal or similarly significant effects on individuals (such as decisions about employment, credit, housing or insurance) without meaningful human review. Where state law grants a right to opt out of profiling in furtherance of such decisions, you may exercise it as described below.

6. How We Disclose Personal Information

We disclose personal information only as described here:

  • Service providers and processors that host, secure, analyze, support or deliver communications for the Services, under contracts that limit their use of the data.
  • Our Customers, regarding data processed on their behalf.
  • Authorized dealers and partners, only when you request to be connected with them.
  • Professional advisors, auditors and insurers.
  • Government authorities or law enforcement when required by law, subpoena or court order, or to protect safety.
  • A buyer or successor in connection with a merger, acquisition, financing or sale of assets, subject to this Policy.

We do not sell personal information for money. We do not "share" personal information for cross-context behavioral advertising, and we do not engage in targeted advertising based on personal data, as those terms are defined under state privacy laws. If this changes, we will update this Policy and provide the required opt-out mechanisms.

7. Cookies, Tracking and Global Privacy Control

We use essential cookies to operate the Services and may use analytics cookies to understand usage. You can control cookies through your browser settings. We honor Global Privacy Control (GPC) and similar universal opt-out signals as a valid request to opt out of sales, sharing and targeted advertising, as required in states such as California, Colorado, Connecticut, Texas, Oregon, Montana, New Jersey, Delaware, Minnesota and Maryland.

Do Not Track: as required by the California Online Privacy Protection Act (CalOPPA), we disclose that, because no uniform standard exists, we respond to GPC signals rather than browser "Do Not Track" headers.

8. Your Privacy Rights

Depending on your state of residence, you may have some or all of the following rights. We extend these core rights to all U.S. users regardless of state, subject to verification and legal exceptions:

  • Right to know / access: confirm whether we process your personal information and obtain a copy, including the categories collected, sources, purposes and recipients.
  • Right to correct inaccurate personal information.
  • Right to delete personal information we collected from or about you.
  • Right to data portability: receive your data in a portable, readily usable format.
  • Right to opt out of the sale of personal information, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects.
  • Right to limit the use and disclosure of sensitive personal information, or, where required, to consent before it is processed.
  • Right to obtain a list of specific third parties to which personal data was disclosed (where provided by law, e.g., Oregon, Minnesota).
  • Right to non-discrimination and non-retaliation for exercising your rights.
  • Right to appeal our decision on your request.

9. State-Specific Disclosures

Comprehensive privacy laws. Residents of the following states have rights under their state's consumer privacy law: California (CCPA as amended by CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Delaware (DPDPA), New Hampshire, New Jersey, Nebraska, Tennessee (TIPA), Minnesota (MCDPA), Maryland (MODPA), Indiana, Kentucky and Rhode Island, as well as any other state that enacts a similar law. We apply the rights in Section 8 to residents of these states as their laws take effect.

California. In the preceding 12 months we collected the categories listed in Section 2 for the purposes in Section 4 and disclosed them for business purposes to the recipients in Section 6. We have not sold or shared personal information and have no actual knowledge of selling or sharing information of consumers under 16. California job applicants and employees receive these rights for their personnel data. Under California's "Shine the Light" law (Cal. Civ. Code §1798.83), California residents may request information about disclosures for direct marketing; we do not make such disclosures. Minors in California may request removal of content they posted (Bus. & Prof. Code §22581).

Nevada. Nevada residents may submit a request to opt out of the sale of covered information under NRS 603A. We do not sell covered information, but you may submit a request to info@guardsphere.net. GuardSphere does not collect consumer health data within the meaning of Nevada SB 370.

Washington and consumer health data. GuardSphere is not designed to collect consumer health data under Washington's My Health My Data Act or similar laws in Nevada and Connecticut. Customers should not upload health information except as needed for incident documentation, and any such data is handled under the Customer's instructions.

Biometric privacy. Illinois (BIPA), Texas (CUBI), Washington (RCW 19.375) and other state laws regulate biometric identifiers. We do not collect biometrics by default. If any biometric feature is enabled, we will provide written notice, obtain consent, publish a retention and destruction schedule, never sell biometric data, and destroy it when the initial purpose is satisfied or within the time limits required by law.

Vermont, Michigan, Massachusetts and other states. We comply with state laws governing data security (including Massachusetts 201 CMR 17.00 and New York's SHIELD Act), Social Security number protection, and employee monitoring notice requirements (including Connecticut, Delaware and New York electronic monitoring laws). Customers using location or activity tracking features are responsible for providing any required notice to their employees, and we provide tools to support that notice.

Data broker laws. GuardSphere is not a data broker under California, Vermont, Texas or Oregon data broker registration laws.

10. How to Exercise Your Rights

Email us at info@guardsphere.net with the subject line "Privacy Request," or use our Contact page. Please tell us your state of residence and the right you wish to exercise.

Verification: we will verify your identity by matching information you provide with information we hold. We may ask for additional information where needed. Authorized agents may submit requests with written, signed permission or a valid power of attorney, and we may ask you to verify your identity directly.

Timing: we will respond within 45 days, which may be extended by an additional 45 days where reasonably necessary, as permitted by law. Requests are free of charge, up to twice in a 12-month period, unless manifestly unfounded or excessive.

Appeals: if we decline your request, you may appeal by emailing info@guardsphere.net with the subject "Privacy Appeal." We will respond within the time required by your state law (generally 45–60 days). If you are not satisfied, you may contact your state Attorney General.

11. Children's Privacy

The Services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children under 13 in accordance with the Children's Online Privacy Protection Act (COPPA), and we do not knowingly sell, share or process for targeted advertising the data of consumers under 18. If you believe a child has provided us information, contact us and we will delete it.

12. Data Security

We maintain reasonable administrative, technical and physical safeguards appropriate to the nature of the data, including encryption in transit, access controls, role-based permissions, logging and employee training. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Data Breach Notification

All 50 states, the District of Columbia and U.S. territories have data breach notification laws. If a security breach involving your personal information occurs, we will notify affected individuals, Customers, state Attorneys General and other regulators as required, within the timeframes required by applicable law, and provide information about steps you can take to protect yourself.

14. Data Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain business records, comply with legal, tax and employment record-keeping obligations, resolve disputes and enforce agreements. Waitlist and contact requests are generally retained for up to 24 months; unsuccessful job and dealer applications for up to 3 years or as required by employment law; Customer data according to the Customer's instructions and contract. We then delete or de-identify the information.

15. Marketing Communications

You may opt out of marketing emails at any time by using the unsubscribe link or emailing us, consistent with the CAN-SPAM Act. We will not send marketing text messages without your prior express consent as required by the Telephone Consumer Protection Act (TCPA). Operational and security messages related to your account may still be sent.

16. Data Location

We store and process personal information in the United States. If information is transferred elsewhere, we will apply safeguards consistent with this Policy.

17. Accessibility

This Policy is available in a format accessible to people with disabilities. To request it in an alternative format, contact info@guardsphere.net.

18. Changes to This Policy

We may update this Policy to reflect changes in our practices or the law. We will post the updated Policy with a new "Last updated" date and, where the changes are material, notify you by email or through the Services before they take effect. We will obtain consent where required for material changes affecting previously collected data.

19. Contact Us

Questions or requests about this Policy or our privacy practices can be sent to GuardSphere at info@guardsphere.net.