KyndGuard Privacy Policy

Version 1.3 · Last updated August 9, 2026

KyndGuard ("we", "us", "our") provides a guard-management software-as-a-service platform used by security agencies to schedule guards, track activity at client sites, file regulatory reports, and communicate with clients. This policy explains what personal information KyndGuard collects, why we collect it, how we share and store it, and the choices you have over your data.

KyndGuard is operated from Canada. Personal information may be processed in Canada or the United States. By using KyndGuard you agree to the practices described here. If you do not agree, do not use the service.

1. Who this policy applies to

This policy covers three classes of users:

  • Agency staff — administrators, supervisors, and dispatch personnel of a security agency that has licensed KyndGuard.
  • Security guards — field staff employed or contracted by a licensed agency, using KyndGuard to clock in, log activity, and file reports during their shifts.
  • Clients — businesses and property managers who receive security services from a licensed agency and view reports + activity at their own sites through KyndGuard's client portal.

2. Information we collect

2.1 Information you provide directly

  • Identity: first and last name, email address, phone number, role assigned by your agency, language preference.
  • Authentication: hashed password (we never see the plaintext), session tokens, optionally a recovery email.
  • Onboarding profile (guards): emergency contact name and phone, uniform sizes (shirt, pants, boots, jacket), face photograph for shift identification, regulatory licence number (PSISA in Ontario or equivalent), licence expiry date, hire date.
  • Documents you upload: regulatory certifications, government-issued ID images, employment contracts, training certificates, signed direct-deposit forms, and similar employment documents.
  • Operational entries: shift log notes, incident reports, use-of-force reports, trespass notices, vehicle inspection results, banned-persons records, welfare check-in responses, end-of-shift summaries, expense receipts, time-off requests, and AI-chat transcripts you initiate with our shift-assistant tool.
  • Communications: messages you send to or receive from your agency, your client, or other guards through the platform; feedback and bug reports you submit through the in-app Report-a-Problem flow.

2.2 Information collected automatically

  • Location: when a guard clocks in or out, files a log entry, files an incident or use-of-force report, or triggers an SOS, we record the device's GPS coordinates and accuracy radius (within a few metres). Location is collected only when the guard is actively using the app and only when the device has granted location permission. We do not collect location in the background. Because these recorded positions are retained as part of the operational record, a guard's most recently recorded position remains visible to authorised administrators at their agency after the action that captured it — including after the shift has ended. Guards are not re-notified when an administrator views a previously recorded position.
  • Photos and media: when a guard or client uploads a photo (for example a face photo at onboarding, evidence on an incident report, or a vehicle damage photo), we store the image file.
  • Device + technical data: browser type, operating system, IP address, the page or URL the user was on when they submitted a report, app version. This information is logged for security, debugging, and audit purposes.
  • Activity timestamps: every action that affects schedule, payroll, or evidentiary records (clock events, edits to incident reports, alert acknowledgements, document uploads) is timestamped and attributed to the user who performed it.

3. Why we collect this information

We collect personal information for the following purposes only:

  • To provide the service — schedule shifts, record clock events, accept and display reports, deliver notifications to the right people, generate invoices.
  • To meet regulatory and contractual obligations — Ontario's Private Security and Investigative Services Act (PSISA) requires contemporaneous documentation of incidents and use of force for at least two years; client contracts require evidentiary records.
  • To maintain platform safety — detect fraud, prevent abuse, surface safety incidents (SOS, welfare check-ins overdue) to the right people quickly.
  • To improve the platform — analyse aggregate usage patterns, identify bugs, plan new features. We do not sell or rent personal information to third parties for advertising.
  • To communicate with you — service notifications, invitations to join the platform, password resets, and (where required) safety alerts about your shift.

4. How we share information

4.1 Within your agency

Personal information you submit to KyndGuard is visible to authorised staff of the security agency that employs or contracts you. Agency administrators and supervisors can view all guards' profiles, schedules, reports, and activity within their agency. Guards can view their own data only. Clients can view security reports, schedules, and impact metrics for the sites they own — and only those sites.

4.2 Service providers (sub-processors)

We rely on a small set of trusted third-party services to operate the platform. Each is contractually bound to protect your information and to process it only for the purposes we direct.

  • Supabase (database, authentication, file storage) — United States.
  • Vercel (web hosting + serverless compute) — United States.
  • Resend (transactional email delivery) — United States.
  • Anthropic (Claude AI model for the in-app shift assistant and auto-generated shift handoffs) — United States. Conversation transcripts are sent for processing but are not used to train Anthropic's models, per our enterprise-grade API agreement.
  • Google / Apple (push notifications, app distribution) — for the Android and iOS mobile apps.

Cross-border transfers to the United States are protected by contractual data-processing terms with each sub-processor. We do not transfer personal information to jurisdictions outside Canada or the United States.

4.3 Disclosures required by law

We may disclose personal information to law enforcement, regulators (including PSISA's investigative arm), insurers, or courts when compelled by valid legal process. We do not disclose more than is strictly required.

4.4 No sale or advertising

We do not sell, rent, or trade personal information. We do not use the platform for behavioural advertising. We do not allow any third party to do so through KyndGuard.

5. How long we keep your information

  • Active account data: retained for as long as your agency or client relationship with KyndGuard is active.
  • Evidentiary records (incident reports, use-of-force reports, trespass notices, vehicle inspections, body-worn camera logs, banned-persons lists): retained for a minimum of two years from creation, in line with PSISA's regulatory record-keeping floor. Many agencies retain longer for civil-litigation defence — your agency sets the retention period in their KyndGuard organisation settings.
  • Employment documents (contracts, signed forms, identity copies): retained for seven years after the employment relationship ends, in line with Ontario labour-record retention standards.
  • Authentication + audit logs: retained for one year for security and abuse-detection purposes.
  • Deleted accounts: when you request account deletion, your profile is removed from the active platform within thirty (30) days. Evidentiary records that name you remain retained for the regulatory period above, with your identifying details anonymised where law allows.

6. Security measures

  • All connections to KyndGuard use HTTPS / TLS 1.3 encryption in transit.
  • Database storage is encrypted at rest by our hosting provider.
  • Row-level security policies in the database enforce that each user can only access their own data and the data their agency role permits, even if a software bug attempts to bypass application-layer checks.
  • Authentication uses industry-standard bcrypt-style password hashing; we never store or transmit your password in plaintext.
  • Critical actions (privileged role changes, payment-rate edits, evidentiary report edits) generate immutable audit-trail rows that survive even if the original record is later deleted.
  • Access by KyndGuard staff to underlying database records is logged.

No system is perfectly secure. We will notify affected users and the relevant regulators without undue delay if we discover a personal-data breach affecting your information.

7. Your rights

Under PIPEDA, Canada's federal privacy law, you have the right to:

  • Know what personal information we hold about you.
  • Request a copy of that information in a portable format.
  • Correct information that is inaccurate.
  • Withdraw consent for non-essential processing (we will tell you what becomes unavailable as a result).
  • Request deletion of your account and your information, subject to the regulatory retention exceptions in Section 5.
  • Complain to the Office of the Privacy Commissioner of Canada if you believe we have mishandled your information.

To exercise any of these rights, contact us using the details in Section 10.

8. Children

KyndGuard is a workplace tool for licensed security guards, agency staff, and the clients of those agencies. Eligibility to work as a guard under PSISA requires the user to be at least eighteen years old. We do not knowingly collect personal information from anyone under eighteen. If you believe a minor's information has been provided to us, contact us and we will remove it.

9. Changes to this policy

We may update this policy as the service evolves or as regulatory obligations change. Material changes will be announced in-app at least fourteen days before they take effect. Minor clarifications and grammatical fixes do not require advance notice. The "Last updated" date at the top of this page reflects the most recent revision.

10. Contact

For any privacy question, deletion request, complaint, or right exercise, contact us at:

KyndGuard
Email: team@kyndguard.com


This policy is provided in English; if you require a translation, contact us. In case of conflict between the English original and any translation, the English version governs.