Privacy Policy

This policy explains what information the CentralCore web application and mobile app collect, why we collect it, who it is shared with, and the choices available to you.

Effective
August 3, 2026
Last updated
August 3, 2026

1.Our role in your data

CentralCore is workforce and patrol management software operated by Security USA, Inc. (“we,” “us,” or “our”). It is sold to organizations — security companies, property managers, and facilities teams — and used by their personnel. That means we handle information in two distinct roles, and your rights differ depending on which one applies.

  • As a service provider (processor). Almost everything inside the application — employee records, sites, tours, checkpoint scans, shifts, and field reports — belongs to the organization that subscribes to CentralCore. We process it on that organization’s instructions and under our agreement with them. They decide what is collected, who may see it, and how long it is kept.
  • As a controller. We independently determine how we handle information relating to the operation of the service itself — account provisioning, billing and subscription records, support correspondence, and security and diagnostic logs.

If you are an employee using this app at work

Your employer, not Security USA, Inc., decides what is recorded about your work and who inside the organization can see it. Requests to access, correct, or delete your records should go to your employer first. If you contact us directly, we will refer you to them and assist them in responding.

2.Scope

This policy covers the CentralCore web application at centralcoreusa.com (including organization-specific subdomains) and the CentralCore mobile app for iOS and Android.

It does not cover third-party websites or services we link to, or your employer’s own privacy practices, which are governed by their policies.

3.Information we collect

Account and profile information

Accounts are created by your organization’s administrators, not by us and generally not by you. The following may be recorded:

  • Name (first, last, and display name)
  • Work email address and phone number
  • Employee ID (a 1–8 digit identifier assigned by your employer)
  • Role, permissions, and the sites you are assigned to
  • Profile photo, if one is uploaded
  • Account status, and the date the account was created and last updated

Sign-in credentials for field personnel are generated by the system and issued by your employer. Passwords are stored only as salted hashes by our authentication provider; we never see them in readable form.

Operational records you create in the app

  • Patrol tours and checkpoint scans — which tour was started and completed, which checkpoints were scanned, and the date and time of each scan
  • Shifts and site visits — scheduled and recorded attendance at the sites you are assigned to
  • Field reports — the answers you submit on your employer’s report forms, which may include free-text descriptions, photographs taken in the app, drawn signatures, checkboxes, dates and times, and transcripts produced by voice-to-text
  • Activity and audit records — a log of significant actions taken in the application (for example creating, editing, or deleting a record) together with the user and timestamp

Device and technical information

  • Push notification token, along with the device name and platform (iOS or Android), so alerts can be delivered to the right device. Removed when you disable notifications or the device is deregistered.
  • Installed site — the site the mobile app is configured for, used to target notifications and scope what the app displays
  • Server logs — IP address, request path, user agent, timestamps, and response timings, generated automatically and retained for security, abuse prevention, and troubleshooting
  • Session cookies — see Cookies and similar technologies

Information from your employer

Administrators may import employee and site records in bulk, and may add information about your role, certifications, required uniform, and site assignments. We receive this information from them.

4.What we do not collect

Some things are worth stating plainly, because comparable products do collect them:

  • No continuous or background location tracking. The app does not request location permission and does not follow your movements. Checkpoint verification works by physically tapping an NFC tag at the checkpoint — the record is that a tag was scanned at a given time, not where your device was. Latitude and longitude are stored for sites (property addresses supplied by your employer), never for people.
  • No biometric data. Optional fingerprint or face unlock is handled entirely by your device’s operating system. Your biometric data never leaves your device and is never transmitted to or stored by us — the app receives only a pass or fail result.
  • No advertising, tracking, or analytics SDKs. We do not use advertising identifiers, do not build advertising profiles, and do not embed third-party marketing or behavioural analytics trackers in the applications.
  • No sale of personal information. We do not sell personal information and do not share it for cross-context behavioural advertising.

5.Device permissions

The mobile app requests the following permissions. Each is used only for the stated purpose, is requested at the point of use, and can be denied or withdrawn in your device settings — declining a permission disables the related feature but not the rest of the app.

PermissionWhy it is used
NFCReading checkpoint tags during a patrol tour. Used only while a scan is in progress.
CameraAttaching photographs to field reports. Some report fields are configured by your employer to require a live capture rather than a library upload.
Photo librarySelecting an existing image to attach to a report, where your employer's form permits it.
Microphone and speech recognitionOptional voice-to-text when filling in report fields. Audio is transcribed by your device's operating system; we store only the resulting text, not the recording.
NotificationsDelivering alerts about assignments, missed tours, and reports.
Biometric unlockOptionally unlocking the app with Face ID, Touch ID, or a fingerprint. Handled entirely on-device.

6.How we use information

  • To provide the service — authenticate users, display sites and assignments, record tours and scans, accept and distribute field reports, and generate report exports and PDFs
  • To send operational notifications — email and push alerts for missed or late tours, submitted reports, and scheduled summaries, as configured by your organization
  • To keep the service secure — authenticate sessions, enforce permissions and organization isolation, detect abuse, and investigate incidents
  • To support and maintain the service — respond to support requests, diagnose faults, and monitor reliability and performance
  • To improve the service — understand which features are used and where the product falls short, working from aggregated or de-identified information wherever it is sufficient
  • To meet legal obligations — comply with applicable law, enforce our agreements, and respond to lawful requests

We do not use the operational content your organization stores in CentralCore to train machine learning models for other customers or for our own general-purpose models.

8.Cookies and similar technologies

The web application sets only strictly necessary cookies. These hold your authentication session and the security tokens that keep you signed in, and the application cannot function without them. We do not use advertising, marketing, or third-party behavioural analytics cookies, so there is no tracking to opt out of.

The mobile app does not use cookies; session tokens are held in the device’s secure storage (iOS Keychain or Android Keystore).

You can clear cookies in your browser settings at any time; doing so signs you out.

9.How we share information

We do not sell personal information. We share it only in the following circumstances.

Within your organization

Information is visible to other users of your organization according to the roles and permissions your administrators configure. Organizations are isolated from one another at the database level — users of one organization cannot access another organization’s records.

Service providers

We use a small number of vendors to run the service. They may process information only on our instructions and are bound by confidentiality and data protection obligations.

ProviderPurposeLocation
VercelApplication hosting, content delivery, and request loggingUnited States
SupabaseDatabase, authentication, and storage of report attachmentsUnited States
Twilio SendGridDelivery of transactional and notification emailUnited States
ExpoRouting push notifications to Apple and Google notification servicesUnited States
Google Maps PlatformMaps and address lookup for site locationsUnited States
Apple, GoogleMobile app distribution, push delivery, and on-device speech recognitionUnited States

Legal and safety

We may disclose information where we believe in good faith that it is required by law, legal process, or a lawful government request, or where it is necessary to protect the rights, property, or safety of Security USA, Inc., our customers, or the public.

Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy.

10.Visibility to your employer

CentralCore is a workforce management tool, and its purpose is to give your employer an accurate record of work performed. Depending on the permissions they configure, supervisors and administrators in your organization can see:

  • Which tours you started and completed, and which you missed
  • Each checkpoint you scanned and the time of each scan
  • Field reports you submitted, including photos, signatures, and free-text answers
  • Your shifts, site assignments, and profile details
  • An audit trail of records you created, edited, or deleted

Your employer’s own policies govern how this information is used in the employment relationship. Please direct questions about that use to them.

11.Data retention

Because your organization owns its records, it determines how long they are kept. As a general matter:

  • Operational records — tours, scans, shifts, and field reports — are retained for as long as your organization’s subscription remains active, so that they stay available for audit and compliance
  • When a user account is deleted, the profile is removed. Operational records the person created are retained for the organization’s audit trail with the author reference cleared, so the record survives without continuing to identify the individual
  • When a subscription ends, we delete or de-identify the organization’s data within a commercially reasonable period after the wind-down window in our agreement with them, except where retention is required by law
  • Server and security logs are retained on a short rolling window and then discarded
  • Backups are retained on a rolling schedule; deleted records persist in backups until those backups age out

12.Security

We use technical and organizational measures appropriate to the sensitivity of the information we handle, including:

  • Encryption in transit (TLS) and encryption at rest for stored data
  • Row-level security in the database enforcing organization isolation, so a query can only ever return the requesting organization’s rows
  • Role- and permission-based access control, checked on the server rather than only in the interface
  • Session tokens held in secure device storage on mobile
  • Audit logging of significant actions
  • Restricted administrative access on a need-to-know basis

No system can be guaranteed completely secure. If we become aware of a breach affecting your information, we will notify the affected organization and, where required, individuals and regulators, without undue delay.

13.Your privacy rights

Depending on where you live, you may have the right to request access to the personal information we hold about you, to have it corrected or deleted, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent you have given. You also have the right to lodge a complaint with your local supervisory authority.

How to exercise these rights:

  1. If you use CentralCore through an employer, contact your employer’s administrator. They control the records and can act on most requests directly within the application.
  2. Otherwise, or if your employer directs you to us, email privacy@securityusa.com. We will verify your identity before acting and respond within the period required by applicable law.

We will not discriminate against you for exercising any of these rights.

14.U.S. state privacy rights

Residents of California and other states with comprehensive privacy laws have the rights described above, including the right to know, delete, correct, and obtain a portable copy of their personal information.

We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act. We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out. You may designate an authorized agent to submit a request on your behalf; we will require proof of that authorization.

Where we handle information on behalf of a customer organization, we act as that organization’s service provider and process personal information only for the business purposes set out in our agreement with them.

15.International transfers

The service and its providers are hosted in the United States. If you access CentralCore from outside the United States, your information will be transferred to and processed there, where data protection laws may differ from those in your country. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses for these transfers.

16.Children's privacy

CentralCore is a workplace tool intended for use by employees and authorized personnel. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us at privacy@securityusa.com and we will delete it.

17.Changes to this policy

We may update this policy as the service changes or as the law requires. The “Last updated” date at the top of this page always reflects the current version. If a change is material, we will provide additional notice — for example by email to organization administrators or by a notice in the application — before it takes effect.

18.Contact us

For questions about this policy or to exercise a privacy right, contact us at:

Privacy inquiries

Security USA, Inc.

For questions about intellectual property or to report infringement, see our Copyright Notice. General information about our company is available at securityusa.com.