Privacy Policy
Last updated August 5, 2026
This policy explains how PatrolOS handles personal information on patrolos.org and in the PatrolOS platform. For data your employer submits about you as an officer, dispatcher, or client contact, your employer is the controller and PatrolOS acts as its processor.
Who is responsible for your data
- Marketing site, demo requests, and account signups: PatrolOS is the controller.
- Operational data inside a customer workspace (shifts, patrols, incidents, GPS, media): the subscribing company is the controller; PatrolOS processes it on their instructions.
- If you are an officer or client contact with questions about your data, contact the company that gave you access first.
Information we collect
- Account data: name, email address, organization, role, and authentication identifiers.
- Demo and contact requests: name, business email, company, headcount, preferred time, and anything you type in the notes field.
- Operational data: shifts and time punches, breaks, checkpoint scans, patrol tours, incident reports, notes, photos, video, and voice recordings you submit.
- Location data: GPS coordinates, accuracy, and timestamps captured from an officer's device while they are on shift or using location-dependent screens.
- Device and technical data: browser and device type, battery and connectivity status used for field diagnostics, IP address, and log data.
- Billing data: plan, subscription status, and billing identifiers. Card details are collected and stored by Stripe, not by us.
How location data is used
Location is used only inside PatrolOS: to show officers on the live operations map, verify on-site arrival and departure, stamp time punches and checkpoint scans, and support incident review. We do not sell location data, use it for advertising, or share it with data brokers. Location is only requested when the officer's browser or device grants permission.
How we use information
- To provide, secure, support, and improve the platform.
- To authenticate users and enforce role-based access.
- To process payments and manage subscriptions.
- To respond to demo requests and support enquiries.
- To detect abuse, investigate security incidents, and keep audit logs.
- To meet legal obligations and enforce our Terms.
We do not sell personal information and we do not use Customer Data to train third-party AI models.
AI processing
When you use AI features (report drafting, summaries, transcription, copilot), the relevant content is sent to our AI model provider to generate a response. Output is a draft that requires human review. AI providers act as subprocessors under contract and are not permitted to use the content to train their models.
Subprocessors
- Supabase — database, authentication, and file storage.
- Cloudflare — application hosting and network delivery.
- Lovable — platform hosting and AI gateway used for AI features.
- Stripe — payment processing and subscription billing.
- Google Maps Platform — map tiles, geocoding, and address autocomplete.
- OpenStreetMap / Nominatim — fallback address lookup.
Retention
- Operational data is retained for as long as the customer's subscription is active, then for 30 days after termination to allow export.
- Audit logs are retained on an append-only basis for security and compliance review.
- Demo requests are retained until acted on and then archived for our sales records.
- Backups roll off on the managed provider's standard schedule.
Security
Traffic is encrypted with TLS, data at rest is encrypted by our managed providers, row-level security scopes every read and write to the signed-in user's organization and role, and sensitive actions are written to an audit log. See the Trust Center for details. No system is perfectly secure, so we cannot guarantee absolute security.
Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to withdraw consent. Email angel18almanza@gmail.com and we will respond within the time required by applicable law. If your data sits in a customer workspace, we will refer the request to that customer as controller.
International transfers
Our providers may process data in the United States and other countries. Where required, we rely on appropriate transfer mechanisms such as standard contractual clauses in our agreements with subprocessors.
Children
The platform is for business use and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
We will post updates to this policy here and update the “last updated” date. Material changes will be announced in-app or by email.
Questions about this document? Contact PatrolOS at angel18almanza@gmail.com.
