Privacy Policy
Last Updated: July 3, 2026
1. Introduction
VigilGuard is a professional guard deployment and patrol monitoring platform. We value the privacy of guards, supervisors, and administrators. This Privacy Policy describes how we collect, process, and protect your information when utilizing our dashboard and mobile apps.
2. Information Collection & Purpose
We collect information necessary to verify patrol fulfillment, confirm guard alertness, and schedule shifts:
- Location Data (Shift-Only): The VigilGuard mobile application tracks coordinates only when a guard is clocked into an active shift. This coordinates data is processed to update the supervisor live map and verify checkpoint scans. Location tracking is completely disabled once the guard clocks out of their shift.
- Patrol Checkpoint Logs: We log checkpoint scans, including NFC tag IDs, QR code values, and timestamps.
- Alertness Test Diagnostics: We store test completion statuses, response times, and scores to ensure on-duty guards remain awake and alert.
- Account & Profile Information: We store roster data, including name, email, phone number, and national ID, provided by your company admin.
3. Biometrics Security
When guards enable biometric authentication (fingerprint or face login) on the Android application, all biometric data is handled locally by the Android operating system's secure element. VigilGuard does not transmit or store biometric keys on our remote servers.
4. Data Access & Sharing
Location records, patrol scans, and alertness test results are visible only to authenticated supervisors and company administrators belonging to your specific security agency. We do not sell guard tracking or personal data to third parties or marketing platforms.
5. Security
We use industry-standard encryption protocols (HTTPS/SSL) to secure data transmitted from mobile devices and the web dashboard, ensuring shift logs and telemetry remain protected from unauthorized access.
6. Annex II: Technical & Organisational Measures (TOMs)
To ensure the security, confidentiality, integrity, and availability of personal and operational data, we implement the following technical and organisational measures:
- Data Encryption: All data in transit is protected using TLS 1.3 encryption. Data at rest in our databases is encrypted using AES-256 standards.
- Access Controls & Multi-Tenancy: Strict logical separation of tenant data is enforced via company-based query partitioning. Access is restricted using Role-Based Access Control (RBAC) and secure JWT session handling.
- Mobile Device Hardware Security: Guard biometric templates for fingerprint/face login are processed exclusively on the secure hardware enclave of the mobile device (FIDO2/WebAuthn), ensuring no biometric keys are sent to the cloud.
- Strict GPS Limiting: Geolocation coordinates are gathered only during active shift assignments and are automatically disabled upon shift completion.
- Audit Logging: Detailed security logs are maintained for administrative actions, SOS events, and API access requests to detect and investigate unauthorized access attempts.