This Privacy Policy describes how the operator of Sanctuary Protected handles information in connection with Sanctuary Protected. It covers our websites and the hosted Service. It does not cover websites or cameras operated solely by your Organization outside the Service.
1. Introduction
Sanctuary Protected is a software platform Organizations use to manage security operations, incidents, notifications, training, and related records. When you use the Service as a member of an Organization, much of the information you enter is Customer Content that Organization administrators can access according to roles and permissions. Our Terms of Service (/terms) and Billing Policy (/billing) describe the commercial relationship.
2. Organizations and Our Role
Organizations decide what operational records to keep, whom to invite, and which roles those people receive. We process that information to host and operate the Service for the Organization. Requests to correct or delete incident files, safety-concern profiles, or other Organization records should generally be directed first to that Organization. We process Account authentication data, security logs, and platform telemetry to operate, secure, and bill the Service.
Whether we act as a “service provider,” “processor,” or another legal role can depend on the information type and applicable law. That characterization should be confirmed in a customer agreement where required.
3. Information We Collect
The categories below reflect features that exist in the product today. Your Organization may not use every module.
- Account information: name, email address, password (stored by our authentication provider, not in recoverable plain text in application tables), optional profile phone, profile photo, and user identifiers.
- Organization information: Organization name, slug, addresses, campus records, branding, emergency-contact fields, and settings.
- Security and authentication: sign-in events, MFA challenge metadata, whether a verified backup phone exists, trusted-device records, MFA session cookies, IP addresses collected for audit and security, and similar logs.
- Incident information: reports, categories, locations, timestamps, notes, team assignments, and photographs or attachments when the plan allows.
- Safety-concern information: profiles, notes, and photos when the plan allows.
- Training, certification, scheduling, hardware inventory, medical-supply inventory, and policy-document files when those modules are used.
- Communication information: notification contents and delivery status, enrolled email or Text/SMS endpoints, and consent records for Text/SMS operational alerts where the product collects them.
- Billing information: plan, subscription status, and billing history in our application database. We do not currently operate a connected card checkout. We do not store payment-card numbers in the application. If a payment processor is connected later, card data would be handled by that processor.
- Technical information: browser and device characteristics needed to run the site, cookies described below, and application logs.
- Support communications: messages you send to support mailboxes or through in-product help feedback.
4. Sensitive Information
Customers may enter information that is sensitive in context: incident narratives, safety concerns, notes that mention medical events, information about minors that appears in Organization records, building or camera details, and photographs. We do not claim that the Service is HIPAA compliant, and these Terms and this Policy are not a Business Associate Agreement. Do not treat the Platform as a medical-records system.
5. How Information Is Collected
- Directly from you when you register, update a profile, or submit records.
- From Organization administrators who invite or provision you and configure the tenant.
- Automatically when you use the Service (logs, cookies, security events).
- From email and (where configured) Text/SMS providers that report delivery status.
- From a payment processor if one is connected in the future.
- From support requests.
6. How We Use Information
- Provide Platform features you and your Organization request.
- Authenticate Users, enforce MFA and trusted-device rules, and prevent unauthorized access.
- Send operational notifications your Organization configures and Account security messages.
- Maintain incidents, inventory, schedules, and similar modules.
- Operate subscriptions, show plan limits, and (when a processor is connected) process payments.
- Provide support, troubleshoot, prevent fraud and abuse, and improve reliability.
- Comply with law and enforce our Terms.
7. Notifications and Communications
We use email for Account security codes, invitations, and many operational notices. Text/SMS may be used for MFA backup to a verified number and for Organization alerts where the plan includes Text/SMS and an endpoint is enrolled. In-app notices may appear in the product. Push notifications are not generally enabled. Operational and security messages are distinct from marketing. We do not use Account creation alone as marketing-text consent.
9. Organization Access
Owners, administrators, security leaders, and other roles may see different slices of Organization data. Access can also depend on group membership, campus assignment, and temporary permissions. Platform operators (our internal administration tools) may access tenant data as needed to support, secure, or operate the Service, subject to internal controls.
10. Multi-Organization Accounts
If you belong to more than one Organization, your login is shared but membership, roles, and records are scoped per Organization. Switching Organizations changes which tenant data you can see. We design access controls to keep tenant data separated; you must still choose the correct Organization before acting.
11. Sale of Personal Information and Advertising
We do not sell personal information for money. We do not share personal information with third parties for their independent marketing. The Service does not currently include third-party advertising or analytics pixels. If that changes, we will update this Policy and any required notices.
13. Trusted Devices and Authentication Security
If you register a trusted device, we store a device record associated with your user identifier and issue a browser cookie so later visits can skip a repeated MFA prompt for a limited period, subject to Organization or platform policy (including requirements to complete MFA again). We may also store timestamps and coarse device or browser information for security. We do not describe token internals here.
14. Data Security
We use commercially reasonable technical and organizational measures, including encrypted connections in transit, authentication, optional and policy-driven MFA, role-based permissions, database access rules, and audit logging. No method of transmission or storage is perfectly secure. You must also protect passwords, trusted devices, and who you invite into your Organization.
15. Data Retention
Retention depends on Account status, Organization relationship, Subscription, record type, backups, and legal duties. We have not published numeric retention schedules for each table. Organization records generally remain until the Organization removes them through product workflows or we delete them after an Organization relationship ends and residual backup cycles complete. Authentication logs and security records may be kept as needed to investigate abuse.
16. Account Closure and Deletion
An individual User can update their profile name, phone, and photo. The product does not currently offer a self-service control to erase an entire personal Account across all Organizations. Organization owners and administrators can suspend or remove memberships; removal does not by itself wipe historical incident or audit records that referenced that User.
Organization owners can suspend or close an Organization in settings. Closure is an operational status change; the product states that permanent deletion of Organization history is not available through that control. Subscription cancellation is designed not to delete Customer Content. We do not currently offer a full Organization data-export package in the product, though some modules may allow limited exports based on permissions.
17. Privacy Rights
Depending on where you live, you may have rights to request access, correction, deletion, or a copy of certain personal information, to appeal a denial, or to opt out of certain processing. These rights may not apply to every record—especially Customer Content controlled by an Organization, or information we must keep for security or law. To make a request, email the privacy contact below. We may need to verify your identity and may direct Organization-record requests to your Organization.
18. California Privacy Notice
If you are a California resident, you may have additional rights under California law, including to know, delete, and correct personal information, and to opt out of “sale” or “sharing” as those terms are defined by statute. We do not sell personal information for money and do not share it for cross-context behavioral advertising. We do not currently operate a dedicated “Do Not Sell or Share” link because those activities are not part of the Service. This section is a summary, not a determination that any particular statute applies to every visitor.
19. Children’s Privacy
Sanctuary Protected Accounts are intended for adults who work for Organizations. We do not knowingly allow children to create their own Accounts. Organizations may enter information about minors in incident or safety records when they have a lawful reason to do so. That is Organization-controlled Customer Content, not a child-directed social app. If you believe a child created an Account, contact us and we will take appropriate steps.
20. International Users
The Service is designed primarily for Organizations in the United States. We do not represent that the Service is offered with GDPR-standard contracts or transfer tools. If you access the Service from outside the United States, you understand that information may be processed in the United States.
21. Law Enforcement and Legal Requests
We may disclose information when we believe it is reasonably required by law, subpoena, court order, or a lawful government request, or to protect the rights, safety, or security of our users, the public, or the Service.
22. Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy.
23. Changes to This Policy
We may update this Policy. The effective and last-updated dates and version number will change. Material changes may be announced through the Service or email when reasonably practicable.
24. Contact Information
- Privacy questions: support@sanctuaryprotected.com
- Support: support@sanctuaryprotected.com
- Mailing address: A physical mailing address has not been published in this version. Use the email contacts listed in these policies.