Privacy Policy
How the IraForce Guard app and the IraForce platform handle personal information. Last updated 12 July 2026.
What the app collects, and why
These are the data-safety disclosures we file with the Apple App Store and Google Play. Every item below is linked to your identity, because IraForce is a workforce platform — your employer needs to know which guard the record belongs to.
| Data | Examples | Why we collect it |
|---|---|---|
| Contact info | Name, email address, phone number, mailing address | App functionality, account management |
| Identifiers | User ID, employee ID, device ID, session and push tokens, IP address | App functionality, security, push notifications |
| Precise location | GPS during shifts and patrols, clock-in/out location, geofence events, patrol breadcrumbs — collected in the background during an active shift | App functionality, guard safety, patrol and attendance verification |
| Photos and videos | Clock-in/out uniform photos, incident media, profile picture, credential and licence document images | App functionality |
| Audio | Voice notes attached to incident reports | App functionality |
| User content | In-app messages, incident and patrol reports, activity notes, signatures | App functionality |
| Employment info | Role, job title, site assignment, certifications and licences, shifts, timesheets, attendance | App functionality |
| App activity and diagnostics | App usage, crash logs, performance data, device model and OS version | Diagnostics, security, troubleshooting |
| Consent audit records | Timestamp, IP address and device user-agent recorded when you accept a required agreement, kept as a write-once audit record | Legal compliance and audit |
We never sell your data
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA and CPRA.
No advertising, no tracking
IraForce contains no third-party advertising and no cross-app or cross-site tracking. Your location is never used for marketing.
What we do not collect
- Biometric identifiers — Face ID, Touch ID and fingerprint unlock are performed entirely on your device by the operating system. We never receive or store your fingerprint or face data.
- Health, fitness or medical data.
- Financial or payment information.
- Your contacts address book — we never upload it.
- Browsing history or search history.
- Advertising or marketing identifiers.
Why the app tracks location in the background
IraForce Guard collects location while the app is closed or the screen is off, but only during an active work shift or patrol. It is used to verify that a guard reached each checkpoint, to record patrol routes, to trigger geofence entry and exit events, and to send your position with a panic or duress alert so help can reach you.
Background location is never used for advertising, never sold, and is not collected when you are off shift. You can revoke location permission at any time in your device settings. Doing so disables location-dependent features and may prevent you from clocking in or completing a patrol, as your employer requires.
1. Who we are
This Privacy Policy explains how IraMet ("IraForce", "we", "us", "our") collects, uses, discloses, and protects personal information in connection with theIraForce Guard mobile application (the "App") and the related IraForce security-operations platform and services (together, the "Services").
- Android package:
com.iraforce.guard - iOS bundle:
com.acmesecurity.securityGuardApp - Privacy contact: support@iramet.com
Our role: employer platform
IraForce is a workforce and security-operations platform used by employers — security companies, facilities, and similar organisations (each a "Client Organisation"). Most people who use the App are guards, supervisors, and staff of a Client Organisation.
Where we process personal information on behalf of a Client Organisation — for example, tracking a guard's patrol location, attendance, and incident reports for their employer — the Client Organisation is the data controller and IraForce acts as a data processor under that organisation's instructions. Employees should also read their employer's own privacy notice, which governs the employment relationship. Where we process information for our own purposes — operating and securing the platform, identity management, legal compliance — IraForce acts as a controller.
2. Information we collect
The full list is in the table above. What we collect depends on your role and on how your Client Organisation has configured the Services — not every user provides every category. Information reaches us from you, from your employer, and automatically from the App.
Device permissions
The App requests the permissions below. Each is optional and requested at the point of use; you may decline it or revoke it later in your device settings, though the related feature will then not work.
- Location (fine, coarse, and background) — patrol tracking, checkpoint verification, geofencing, and safety features, including while the app is in the background during an active shift.
- Camera — scanning QR codes at checkpoints, clock-in/out photos, incident media, and credential uploads.
- Microphone — voice notes and video attached to incident reports.
- Photo library — attaching existing images to reports and your profile.
- NFC — tap check-ins at NFC checkpoints.
- Biometrics — unlocking the app with Face ID, Touch ID, or a fingerprint. This is performed entirely by your device's operating system; we never receive or store biometric data.
- Notifications — shift, task, incident, and panic alerts.
Sensitive information
Your precise geolocation and account credentials are sensitive personal information under the CCPA and CPRA. We use and disclose them only for the purposes described in this Policy — operating the Services for your employer, safety, security, and compliance — and never to infer characteristics about you.
3. How we use information
- Provide the Services — authenticate you, run scheduling, attendance, patrols, checkpoints, incident reporting, and messaging for your Client Organisation.
- Location operations and safety — verify guard presence, track patrols and geofences, and power panic, duress, and lone-worker safety features.
- Communications — operational messages, alerts, and push notifications.
- Security — secure accounts and devices, manage sessions, detect unauthorised access, and maintain audit and consent records.
- Support and improvement — answer support requests, diagnose faults, and improve the Services.
- Legal compliance — comply with law, enforce our terms, and meet record-keeping obligations.
4. Legal bases (EEA and UK users)
Where the GDPR or UK GDPR applies, we or the Client Organisation rely on: performance of a contract; legitimate interests (platform security, fraud prevention, worker and site safety); legal obligation; consent (for device permissions, withdrawable at any time in device settings); and vital interests (panic and duress alerts).
5. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose it only:
- To your employer — administrators and supervisors at your Client Organisation can see your work data: identity, on-shift location, attendance, incidents, reports, and credentials.
- To service providers — vendors who process data on our behalf, under contract, and only on our instructions (listed below).
- For legal and safety reasons — to comply with law or lawful requests, enforce agreements, and protect the rights and safety of users and the public.
- In a business transfer — a merger, acquisition, or sale of assets, subject to this Policy.
6. Service providers
| Provider | Purpose | Data involved |
|---|---|---|
| OneSignal | Push notification delivery | Push tokens, device identifiers, notification content |
| Apple Push Notification service | iOS push delivery | Push tokens |
| Google Firebase Cloud Messaging | Android push delivery | Push tokens |
| Google Maps Platform | Maps and geocoding | Coordinates rendered on maps |
| Postmark | Transactional email | Email address, message content |
| DigitalOcean | Application and database hosting | All Services data, at rest and in transit |
7. Data retention
We keep personal information for as long as needed to provide the Services and for the periods our Client Organisations and applicable law require, then delete or de-identify it. Account data is kept for the life of your account plus a reasonable period after deactivation. Location, patrol, attendance, and incident records are kept for the period set by your employer and by applicable labour, safety, and security-licensing law. Consent and audit records are kept as tamper-evident records for the period compliance requires. Diagnostic logs are kept for a limited period. Where we act as a processor, we delete or return data on the Client Organisation's instruction, unless the law requires us to keep it.
8. International transfers
We process and store information in the United States. Where we transfer personal information out of the EEA, the UK, or another region with transfer restrictions, we rely on lawful transfer mechanisms such as the European Commission's Standard Contractual Clauses and the UK Addendum.
9. Security
We use administrative, technical, and organisational safeguards designed to protect personal information: encryption in transit (TLS), encryption of sensitive fields at rest, role-based access control, tenant isolation, secrets management, session and device controls, and audit logging. No system is perfectly secure and we cannot guarantee absolute security. Please protect your credentials and use your device's lock screen.
10. Your privacy rights
California (CCPA and CPRA)
California residents have the right to know and access the personal information we hold, to delete it, to correct it, and not to be discriminated against for exercising those rights.We do not sell or share personal information, so no opt-out is required. We use sensitive personal information only for permitted business purposes and never to infer characteristics, so no separate right to limit its use applies.
Categories collected in the last 12 months: identifiers; customer-records information; precise geolocation; audio and visual information; professional and employment information; internet and network activity; and sensitive personal information (precise geolocation and account credentials).
EEA and UK (GDPR)
You have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent, and the right to complain to your supervisory authority (in the UK, the ICO). Because we often act as a processor for your employer, we may forward your request to that Client Organisation as controller.
Other US states
Residents of states including Virginia, Colorado, Connecticut, Utah, and Texas have similar rights to access, correct, delete, and obtain a copy of their data, and to appeal a decision.
To exercise any right, or to request deletion of your data, emailsupport@iramet.com. If you work for a Client Organisation we may direct your request to your employer, or fulfil it on their behalf. We verify identity before responding, and reply within the time the law allows.
11. Children's privacy
The App is built for adults in a professional context and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
12. Your choices
- Grant or revoke camera, microphone, location, photo, and notification permissions at any time in your device settings.
- Disable location to stop location collection. This disables location-dependent work features.
- Contact your employer's administrator, or us, to update or deactivate your account.
13. Changes to this Policy
We may update this Policy. We will revise the "last updated" date and, for material changes, give additional notice in the app or by email.
14. Contact us
IraMet — Attn: Privacy
Privacy and data requests: support@iramet.com
General enquiries: iraforce.com/contact
