1.Our role in your data
CentralCore is workforce and patrol management software operated by Security USA, Inc. (“we,” “us,” or “our”). It is sold to organizations — security companies, property managers, and facilities teams — and used by their personnel. That means we handle information in two distinct roles, and your rights differ depending on which one applies.
- As a service provider (processor). Almost everything inside the application — employee records, sites, tours, checkpoint scans, shifts, and field reports — belongs to the organization that subscribes to CentralCore. We process it on that organization’s instructions and under our agreement with them. They decide what is collected, who may see it, and how long it is kept.
- As a controller. We independently determine how we handle information relating to the operation of the service itself — account provisioning, billing and subscription records, support correspondence, and security and diagnostic logs.
If you are an employee using this app at work
Your employer, not Security USA, Inc., decides what is recorded about your work and who inside the organization can see it. Requests to access, correct, or delete your records should go to your employer first. If you contact us directly, we will refer you to them and assist them in responding.
2.Scope
This policy covers the CentralCore web application at centralcoreusa.com (including organization-specific subdomains) and the CentralCore mobile app for iOS and Android.
It does not cover third-party websites or services we link to, or your employer’s own privacy practices, which are governed by their policies.
3.Information we collect
Account and profile information
Accounts are created by your organization’s administrators, not by us and generally not by you. The following may be recorded:
- Name (first, last, and display name)
- Work email address and phone number
- Employee ID (a 1–8 digit identifier assigned by your employer)
- Role, permissions, and the sites you are assigned to
- Profile photo, if one is uploaded
- Account status, and the date the account was created and last updated
Sign-in credentials for field personnel are generated by the system and issued by your employer. Passwords are stored only as salted hashes by our authentication provider; we never see them in readable form.
Operational records you create in the app
- Patrol tours and checkpoint scans — which tour was started and completed, which checkpoints were scanned, and the date and time of each scan
- Shifts and site visits — scheduled and recorded attendance at the sites you are assigned to
- Field reports — the answers you submit on your employer’s report forms, which may include free-text descriptions, photographs taken in the app, drawn signatures, checkboxes, dates and times, and transcripts produced by voice-to-text
- Activity and audit records — a log of significant actions taken in the application (for example creating, editing, or deleting a record) together with the user and timestamp
Device and technical information
- Push notification token, along with the device name and platform (iOS or Android), so alerts can be delivered to the right device. Removed when you disable notifications or the device is deregistered.
- Installed site — the site the mobile app is configured for, used to target notifications and scope what the app displays
- Server logs — IP address, request path, user agent, timestamps, and response timings, generated automatically and retained for security, abuse prevention, and troubleshooting
- Session cookies — see Cookies and similar technologies
Information from your employer
Administrators may import employee and site records in bulk, and may add information about your role, certifications, required uniform, and site assignments. We receive this information from them.
4.What we do not collect
Some things are worth stating plainly, because comparable products do collect them:
- No continuous or background location tracking. The app does not request location permission and does not follow your movements. Checkpoint verification works by physically tapping an NFC tag at the checkpoint — the record is that a tag was scanned at a given time, not where your device was. Latitude and longitude are stored for sites (property addresses supplied by your employer), never for people.
- No biometric data. Optional fingerprint or face unlock is handled entirely by your device’s operating system. Your biometric data never leaves your device and is never transmitted to or stored by us — the app receives only a pass or fail result.
- No advertising, tracking, or analytics SDKs. We do not use advertising identifiers, do not build advertising profiles, and do not embed third-party marketing or behavioural analytics trackers in the applications.
- No sale of personal information. We do not sell personal information and do not share it for cross-context behavioural advertising.
5.Device permissions
The mobile app requests the following permissions. Each is used only for the stated purpose, is requested at the point of use, and can be denied or withdrawn in your device settings — declining a permission disables the related feature but not the rest of the app.
| Permission | Why it is used |
|---|---|
| NFC | Reading checkpoint tags during a patrol tour. Used only while a scan is in progress. |
| Camera | Attaching photographs to field reports. Some report fields are configured by your employer to require a live capture rather than a library upload. |
| Photo library | Selecting an existing image to attach to a report, where your employer's form permits it. |
| Microphone and speech recognition | Optional voice-to-text when filling in report fields. Audio is transcribed by your device's operating system; we store only the resulting text, not the recording. |
| Notifications | Delivering alerts about assignments, missed tours, and reports. |
| Biometric unlock | Optionally unlocking the app with Face ID, Touch ID, or a fingerprint. Handled entirely on-device. |
6.How we use information
- To provide the service — authenticate users, display sites and assignments, record tours and scans, accept and distribute field reports, and generate report exports and PDFs
- To send operational notifications — email and push alerts for missed or late tours, submitted reports, and scheduled summaries, as configured by your organization
- To keep the service secure — authenticate sessions, enforce permissions and organization isolation, detect abuse, and investigate incidents
- To support and maintain the service — respond to support requests, diagnose faults, and monitor reliability and performance
- To improve the service — understand which features are used and where the product falls short, working from aggregated or de-identified information wherever it is sufficient
- To meet legal obligations — comply with applicable law, enforce our agreements, and respond to lawful requests
We do not use the operational content your organization stores in CentralCore to train machine learning models for other customers or for our own general-purpose models.
7.Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases. Where we act as a processor, the controller is your employer and they are responsible for establishing the basis for the underlying processing.
- Performance of a contract — providing the service to the organization that subscribes to it
- Legitimate interests — securing the service, preventing abuse, and improving and maintaining the product, balanced against your rights and freedoms
- Legal obligation — retaining records and responding to lawful requests where required
- Consent — for optional device permissions such as camera, microphone, and notifications, which you may withdraw at any time in your device settings
10.Visibility to your employer
CentralCore is a workforce management tool, and its purpose is to give your employer an accurate record of work performed. Depending on the permissions they configure, supervisors and administrators in your organization can see:
- Which tours you started and completed, and which you missed
- Each checkpoint you scanned and the time of each scan
- Field reports you submitted, including photos, signatures, and free-text answers
- Your shifts, site assignments, and profile details
- An audit trail of records you created, edited, or deleted
Your employer’s own policies govern how this information is used in the employment relationship. Please direct questions about that use to them.
11.Data retention
Because your organization owns its records, it determines how long they are kept. As a general matter:
- Operational records — tours, scans, shifts, and field reports — are retained for as long as your organization’s subscription remains active, so that they stay available for audit and compliance
- When a user account is deleted, the profile is removed. Operational records the person created are retained for the organization’s audit trail with the author reference cleared, so the record survives without continuing to identify the individual
- When a subscription ends, we delete or de-identify the organization’s data within a commercially reasonable period after the wind-down window in our agreement with them, except where retention is required by law
- Server and security logs are retained on a short rolling window and then discarded
- Backups are retained on a rolling schedule; deleted records persist in backups until those backups age out
12.Security
We use technical and organizational measures appropriate to the sensitivity of the information we handle, including:
- Encryption in transit (TLS) and encryption at rest for stored data
- Row-level security in the database enforcing organization isolation, so a query can only ever return the requesting organization’s rows
- Role- and permission-based access control, checked on the server rather than only in the interface
- Session tokens held in secure device storage on mobile
- Audit logging of significant actions
- Restricted administrative access on a need-to-know basis
No system can be guaranteed completely secure. If we become aware of a breach affecting your information, we will notify the affected organization and, where required, individuals and regulators, without undue delay.
13.Your privacy rights
Depending on where you live, you may have the right to request access to the personal information we hold about you, to have it corrected or deleted, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent you have given. You also have the right to lodge a complaint with your local supervisory authority.
How to exercise these rights:
- If you use CentralCore through an employer, contact your employer’s administrator. They control the records and can act on most requests directly within the application.
- Otherwise, or if your employer directs you to us, email privacy@securityusa.com. We will verify your identity before acting and respond within the period required by applicable law.
We will not discriminate against you for exercising any of these rights.
14.U.S. state privacy rights
Residents of California and other states with comprehensive privacy laws have the rights described above, including the right to know, delete, correct, and obtain a portable copy of their personal information.
We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act. We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out. You may designate an authorized agent to submit a request on your behalf; we will require proof of that authorization.
Where we handle information on behalf of a customer organization, we act as that organization’s service provider and process personal information only for the business purposes set out in our agreement with them.
15.International transfers
The service and its providers are hosted in the United States. If you access CentralCore from outside the United States, your information will be transferred to and processed there, where data protection laws may differ from those in your country. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses for these transfers.
16.Children's privacy
CentralCore is a workplace tool intended for use by employees and authorized personnel. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us at privacy@securityusa.com and we will delete it.
17.Changes to this policy
We may update this policy as the service changes or as the law requires. The “Last updated” date at the top of this page always reflects the current version. If a change is material, we will provide additional notice — for example by email to organization administrators or by a notice in the application — before it takes effect.
18.Contact us
For questions about this policy or to exercise a privacy right, contact us at:
For questions about intellectual property or to report infringement, see our Copyright Notice. General information about our company is available at securityusa.com.
