Privacy Policy
Last updated: May 3, 2026
1. About this policy
This Privacy Policy applies to the GuardChek platform hosted at app.guardchek.com and the related public pages, including the job-applicant intake form at app.guardchek.com/apply.
GuardChek is a multi-tenant Software-as-a-Service (SaaS) product. That means individual security guard companies (each a “Customer”) license the platform from us and use it to operate their business. When you submit information through the platform — for example, by applying for a job at a Customer’s firm, by being employed as a guard whose schedule is tracked here, or by signing in as an administrator — some of that information is processed by us as the operator of the platform, and some is processed by the Customer as an independent data controller.
In plain terms: we run the software and the servers; the Customer (your employer or prospective employer) decides what to ask of you and what to do with your information inside their account. Where the law requires it, we act as a service provider to the Customer; the Customer is responsible for obtaining your consent and for honouring your requests about their copy of your data. For information we collect on our own behalf (e.g. account credentials, payment data, platform telemetry), we are the data controller.
2. Who we are
GuardChek Corp. is incorporated in Ontario, Canada. You can contact our privacy team at any time:
- Email: privacy@cnsssecurity.ca
- Mailing address: 160 Tycos Dr, Ground Floor, Unit 130, North York, ON M6B 1W8, Canada
For purposes of the Personal Information Protection and Electronic Documents Act (PIPEDA), our designated Privacy Officer can be reached at the email above.
3. Information we collect
The categories of personal information we collect depend on how you interact with the platform:
3.1 Information you provide directly
- Account credentials: name, email, hashed password, role assignment, MFA configuration.
- Job application data (when submitted via /apply): full legal name, date of birth, residential address, phone number, email, employment history, security guard licence details, driver’s licence, First Aid certification, Social Insurance Number (SIN), banking information for direct deposit, references, criminal background disclosure, and uploaded copies of supporting documents.
- Employee records(for guards, supervisors, dispatch staff, and administrators on a Customer’s account): everything in the application above, plus emergency contacts, vacation requests, training records and quiz results, shift clock-in/clock-out events with optional GPS coordinates, field reports filed during shifts, dispatch communications, and internal messages.
- Client records(information about a Customer’s own clients): business name, billing address, site addresses, point-of-contact name and contact details, contractual rates, and invoice history.
- Suspect / incident records:when authorized users file a suspect report (e.g. trespass, theft suspect), the report may include the suspect’s description, photograph, and circumstances of the incident. Customers are responsible for ensuring their use of these records complies with applicable laws, including provincial trespass and privacy legislation.
3.2 Information collected automatically
- Authentication and session data: IP address, browser fingerprint, login timestamps, session tokens, MFA attempts.
- Activity logs: a record of meaningful actions taken in the platform (e.g. who archived which guard, who published a schedule, who deleted a record). Used for security investigation, compliance, and audit purposes.
- Error and performance telemetry: when an error occurs, the system collects the stack trace, the URL, and a small set of contextual identifiers (user ID, browser version) so engineering can diagnose and fix the issue. This telemetry is processed by Sentry on our behalf.
- Location data — one-off events: when a guard clocks in or out via the mobile app, when an SOS is triggered, or when guard tour NFC scans are recorded, GPS coordinates are captured at that moment to verify the action.
- Location data — on-shift continuous tracking: while a guard is clocked in to a scheduled shift, the CNSS mobile app shares the device’s location with the employer’s dispatch / supervisor team approximately once per minute. Tracking starts automatically when the guard taps Clock In and stops automatically when they tap End shift. We do not track guards outside their scheduled shifts. The purpose is to enable dispatch to respond if a guard needs help, to support SOS routing, and to verify shift attendance for payroll. Guards are informed of this tracking by an in-app consent screen the first time they clock in, and may revoke location permission at any time via their device’s OS settings (which will prevent further clock-ins until permission is restored).
- Device telemetry collected during shifts: while tracking is active, the app also reports the device model, operating system + version, app version, battery percentage, charging status, and network type (Wi-Fi / cellular / offline). This helps dispatch and administrators verify that a guard is reachable (e.g. flag low battery before it becomes a problem). No other device contents (contacts, photos, browser history, etc.) are accessed or transmitted.
3.3 Sensitive information
We collect Social Insurance Numbers, banking information, and government-issued identification documents (driver’s licence, security guard licence) because they are required for employment, payroll, and security industry licensing verification under provincial law. These items are stored in access-controlled tables and uploaded files are stored in a permission-restricted bucket. Only authorized administrators and HR personnel within the relevant Customer’s account can view them.
4. How we use your information
We use personal information to:
- provide, maintain, and improve the GuardChek platform;
- authenticate users and enforce role-based access to features and data;
- enable Customers to operate their security business (scheduling, dispatch, payroll, invoicing, compliance reporting) under their own data-controller responsibilities;
- communicate with users about their account (password resets, security alerts, schedule changes, and platform updates);
- detect and prevent fraud, abuse, and security incidents;
- comply with legal obligations including tax reporting, security industry licensing rules, and lawful requests from law enforcement or regulators;
- monitor performance, identify defects, and audit administrative actions;
- with the Customer’s consent and only at the Customer’s direction, conduct training, evaluation, or other employment-related processing.
We do not sell personal information. We do not use personal information for online behavioural advertising or for any purpose unrelated to operating the platform and supporting our Customers.
5. Service providers (sub-processors)
We rely on a small number of trusted service providers to operate the platform. Each is bound by a written agreement that requires them to use your information only to provide services to us. The current list:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | Montreal, Canada |
| Vercel | Application hosting and edge delivery | United States / global edge |
| Resend | Transactional email (password reset, notifications) | United States |
| Sentry | Error and performance telemetry | United States |
| Google Maps | Address autocomplete and map rendering | United States |
Some of these providers process data outside Canada. Where that happens, the information may be subject to the laws of those jurisdictions, including lawful access by foreign authorities. We use providers that offer industry-standard contractual and technical safeguards.
6. How long we keep your information
Retention periods vary by data category and are set primarily by the Customer who employs you (or to whom you applied). Our defaults, which a Customer may extend to meet their own legal obligations, are:
- Active employment records (guards, supervisors, admins): kept for the duration of employment plus seven (7) years thereafter, to satisfy Canada Revenue Agency record-keeping obligations and provincial security industry licensing audits.
- Successful applicant records: merged into the employee record above on hire.
- Unsuccessful applicant records: kept for one (1) year after the application is closed, then deleted, unless you ask us to delete them sooner.
- Dispatch event records, field reports, suspect reports: kept for seven (7) years for legal, insurance, and incident-history purposes.
- Activity logs and audit trail: kept for seven (7) years.
- Error telemetry:retained by Sentry per their default retention (typically 30–90 days for free tier, longer for paid).
- On-shift location pings & device telemetry: only the most recent ping per guard is retained in the live guard-app-status table (overwritten by each new ping). Historical ping data is not retained as a time series — it is used live by dispatch and then overwritten. Aggregated clock-in / clock-out events (with the GPS coordinates captured at those one-off events) follow the seven-year activity-log retention above.
7. Your rights
Under PIPEDA, you have the right to:
- Access the personal information we hold about you;
- Correct information that is inaccurate or incomplete;
- Withdraw your consent to processing, subject to legal and contractual restrictions (e.g. you cannot withdraw consent for retention of payroll records the CRA requires us to keep);
- File a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
To exercise these rights, email privacy@cnsssecurity.ca. We will respond within 30 days. Where the personal information in question is processed on behalf of a Customer, we may redirect your request to that Customer’s privacy contact and assist them in responding.
8. Security
We use a layered set of technical and organizational measures to protect personal information, including:
- encryption in transit (TLS 1.2+ for all connections);
- encryption at rest (Supabase Postgres and Storage are encrypted at rest);
- row-level security policies enforced at the database layer (so even an authenticated user cannot access another Customer’s data through the API);
- role-based permissions inside each Customer’s account;
- multi-factor authentication for administrative accounts;
- activity logging and audit trails;
- daily encrypted backups with point-in-time recovery (Supabase Pro);
- prompt incident response and breach notification procedures.
No system can be guaranteed perfectly secure. If we ever become aware of a security breach that creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner as required by PIPEDA.
9. Children
The platform is intended for adults employed (or seeking employment) in the security industry. Provincial security guard licensing typically requires applicants to be at least 18 years old. We do not knowingly collect personal information from children under 16. If you believe we have done so, contact privacy@cnsssecurity.ca and we will delete the information promptly.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top and, where the change is material, we will notify users by email or through an in-app notice. Continued use of the platform after an update constitutes acceptance of the revised policy.
11. Contact us
For privacy questions, requests, or complaints: privacy@cnsssecurity.ca.
Disclaimer.
This document is provided as a starting point. It has not been reviewed by an Ontario-licensed lawyer and does not constitute legal advice. Before relying on this policy in production, have it reviewed by privacy counsel familiar with PIPEDA, applicable provincial privacy legislation, and the security services industry.
