Legal
Privacy Policy
Last updated: September 8, 2026
MissionReady ("MissionReady", "we", "us", or "our") provides a multi-tenant field operations and patrol accountability platform (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to our website, web application, and mobile clients.
1. Who is the controller
If you signed up for a MissionReady workspace, your employer or organization ("Customer") is the data controller for personal data processed inside that workspace, and we act as their processor. For our marketing site and account signup, MissionReady is the controller.
2. Information we collect
- Account data: name, email, password hash, workspace name, role, and billing contact.
- Operational data you submit: sites, post orders, incidents, guard tour runs, checkpoint scans, attachments, shift reports, messages, and dispatch records.
- Location data: coordinates, an accuracy figure, the capture time, and whether the reading was current or last known — recorded only at the moment of a specific work action (see Section 9), or continuously during a live patrol that your organization enables and the officer starts.
- Voice recordings & transcripts: audio you record for a Daily Activity Report or the voice assistant, plus the resulting transcript, speaker labels, timestamps, and summary (see Section 10).
- Usage data: log entries, IP address, browser, OS, referrer, performance metrics, and feature events.
- Cookies & similar: essential session cookies, security tokens, and limited analytics — see Section 8.
- Payment data: handled by our payment processor; we store only the subscription state and a billing reference.
3. How we use information
- Provide, operate, secure, and improve the Service.
- Authenticate users, enforce workspace isolation, and prevent abuse.
- Generate patrol replays, analytics, anomaly detection, and client-ready reports.
- Send transactional emails (invites, alerts, password resets, billing).
- Provide customer support and respond to your requests.
- Comply with legal obligations and enforce our Terms.
4. Legal bases (EEA / UK)
Where applicable, we rely on: (a) performance of a contract; (b) our legitimate interests in operating and securing the Service; (c) consent for optional features (e.g. marketing emails); and (d) compliance with legal obligations.
5. Sharing & sub-processors
We share personal data only with:
- Sub-processors who host, secure, or operate the Service (cloud hosting, database, email delivery, error monitoring, payment processing).
- Other members of your workspace, according to their assigned role.
- Authorities, when required by law or to protect rights, safety, and property.
- An acquirer in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal data.
6. International transfers
Personal data may be processed in countries other than where you live. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention
We retain personal and operational data for as long as the workspace is active and as needed to provide the Service. Patrol replay, GPS, and heatmap data are retained according to your subscription plan. After workspace closure, data is deleted or anonymized within a reasonable period, except where retention is required by law.
8. Cookies
We use strictly necessary cookies for authentication and security. With your consent, we also use analytics cookies (Google Analytics) to understand product usage and preference cookies to remember UI choices. You can review and change your choices any time using the center (also linked in the footer). Disabling strictly necessary cookies will break sign-in.
9. Location & GPS
Location is recorded only at the moment a signed-in user takes one of these actions: submitting a daily activity entry, filing an incident or field report, scanning a checkpoint or equipment code, clocking in or out, or activating SOS / Man Down. We do not follow anyone in the background — nothing is captured while the app is closed, off shift, or simply being browsed.
Continuous live patrol tracking is a separate feature that an organization enables and that the officer starts themselves.
Before any capture, users are shown a versioned Location & GPS disclosure and must acknowledge it; the acknowledgment is stored with the exact version and wording shown. Acknowledgment can be withdrawn at any time under Settings → Location privacy, which stops future capture but does not alter records already filed. Device-level location permission remains under the user's control.
Location attached to a report, incident, SOS alert, or checkpoint scan is part of that record and kept as long as the record. Standalone location captures that are not part of a record are deleted automatically after 90 days. If a reading was unavailable or declined, that fact is stored instead of a position — never a guessed one.
10. Voice recordings, transcription & AI
Voice Daily Activity Reports and the in-app assistant record audio only while a user is actively recording. Audio is sent to our speech provider, Deepgram, to produce a transcript with speaker labels and timestamps; AI features may also generate summaries. Recordings and transcripts belong to the workspace that created them and are visible only to authorized members of that workspace.
Original recordings and transcripts are preserved as source records for the reports built from them and are retained under your organization's retention settings. We do not use your recordings or operational content to train general-purpose AI models.
11. Security
We use encryption in transit, encryption at rest for managed databases, row-level security for workspace isolation, signed checkpoint tokens, audit logging, and least-privilege access controls. No system is perfectly secure; you are responsible for protecting your account credentials.
12. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. If your data is held inside a Customer workspace, please direct your request to that Customer; we will assist them as their processor. Otherwise, contact us using the details below.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them.
14. Changes
We may update this Policy from time to time. Material changes will be announced in-product or by email. Continued use of the Service after the effective date constitutes acceptance.
15. Contact
Questions about this Policy or our data practices? Email privacy@missionready.dev.
