ZeroBadge Privacy Policy
Version 1.0 · Effective October 6, 2026
This Privacy Policy explains how ZeroBadge ("ZeroBadge," "we," "us") handles personal information in connection with our websites, applications, worker portal, and hardware badges (the "Service"). The Service is offered only in the United States, for business and workforce use.
1. Two roles
When we act for a Customer. Companies that subscribe to ZeroBadge ("Customers") deploy badges to their workers ("Workers"). For information about Workers and about a Customer's administrators that is processed through the Service, the Customer is the business or controller and we are its service provider or processor. We handle that information on the Customer's behalf and under its instructions. The Customer decides whether and how badges are used, and the Customer is responsible for giving Workers legally required notices and obtaining their consent. If you are a Worker, your employer's own privacy notice also applies, and you should direct questions and requests to your employer first.
When we act for ourselves. We are responsible for information we collect for our own purposes, such as information from visitors to our website, people who contact us or request a demo, and our Customers' billing and account contacts.
2. Information we collect
From badges (on behalf of Customers), while a badge is switched on:
- Location information, including precise location, estimated from nearby cell towers, WiFi access points, Bluetooth signals, and satellite positioning, collected about every 5 minutes
- Identifiers of nearby WiFi access points, Bluetooth devices, and cell towers used to estimate location
- Motion information, such as whether the badge is moving or still
- Timestamps, button presses, alerts, battery level, signal information, and device and SIM identifiers
About Workers (on behalf of Customers): name, email address or phone number, employer, role or crew, badge assignment, portal login and activity, and records of notices acknowledged, including time, IP address, and device information.
About Customers and Admins: name, business contact details, company information, account credentials, billing details (payment card data is collected and stored by our payment processor, not by us), support communications, and dashboard activity.
From website and app use: IP address, browser and device type, pages viewed, referring pages, and information from cookies and similar technologies described in our Cookie Policy.
Derived information: Events such as arrivals, departures, time on site, transit periods, and alerts.
What we do not collect: Badges do not record audio, video, or photos. We do not collect biometric identifiers such as fingerprints, face scans, or voiceprints. We do not knowingly collect information from anyone under 18. When a badge is switched off, it does not collect or transmit information.
3. How we use information
- To provide, operate, secure, and support the Service for Customers
- To estimate location and generate Events
- To create and manage accounts, send login, onboarding, and service messages, and provide support
- To bill Customers and collect payment
- To detect and prevent fraud, misuse, and security incidents
- To maintain and improve the Service, including by creating aggregated or de-identified information
- To comply with law and to establish, exercise, or defend legal claims
- For our own information only (not Worker badge data): to market our Service to businesses
We do not use Worker information for advertising, and we do not use precise location or other sensitive personal information to infer characteristics about a person.
4. How we disclose information
- To the Customer. A Worker's Events and related information are available to authorized people at the Worker's employer.
- To service providers. Companies that help us run the Service, listed in Section 6, under contracts that limit their use of the information.
- For legal reasons. When we believe disclosure is required by law, subpoena, court order, or government request, or is needed to protect the rights, safety, or property of any person or of ZeroBadge, or to investigate fraud or misuse.
- In a business transfer. In connection with a merger, acquisition, financing, or sale of all or part of our business, subject to this Policy's protections.
- With consent or at direction. When a Customer or individual directs us to.
- Aggregated or de-identified information, which does not identify any person or Customer. We do not attempt to re-identify it.
5. No sale or sharing
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16.
6. Service providers
| Purpose | Provider |
|---|---|
| Application hosting | Vercel |
| Database and storage | Supabase |
| Authentication | Supabase |
| Device messaging and IoT infrastructure | Amazon Web Services |
| Cellular connectivity | Hologram |
| Network-based location estimation | Google (Geolocation API); Hologram |
| Maps and location display | Mapbox |
| Address lookup | Mapbox |
| Payments | Stripe |
| Resend | |
| Text messaging | Twilio |
| Error monitoring | Sentry |
We may also use providers for network-based location estimation, email, and text messaging. This list may change as our Service changes.
7. How long we keep information
- Raw badge data, including raw location readings: deleted or irreversibly de-identified within 90 days after collection.
- Events, badge assignment history, and Worker acknowledgment records: kept for 4 years from creation, then deleted or irreversibly de-identified.
- Customer account, contract, and billing records: kept for the life of the account and up to 7 years afterward for tax, accounting, and legal purposes.
- Website and support information: kept for as long as needed for the purposes above.
We may keep information longer when required by law, legal process, or a legal hold, or to establish or defend legal claims. Copies in backups are overwritten in the ordinary course after these periods. Aggregated or de-identified information may be kept indefinitely.
8. Your choices and rights
Workers. You can stop collection at any time by switching your badge off. Because we handle your badge information on your employer's behalf, requests to access, correct, or delete it should go to your employer, who is responsible for responding. If you contact us, we may refer your request to your employer and will assist your employer as required by law.
Rights under state law. Depending on where you live and on whether the law applies to the company responsible for your information, you may have the right to know what personal information is collected and how it is used and disclosed, to access it, to correct it, to delete it, to limit the use of sensitive personal information, and to not be retaliated against for exercising these rights. California residents have these rights under the California Consumer Privacy Act where it applies. Some state privacy laws do not apply to information collected in an employment or business context. You may use an authorized agent where the law allows.
How to make a request to us. For information we are responsible for, email support@zerobadgetechnologies.com. We will take reasonable steps to verify your identity and will respond as required by applicable law.
Sensitive personal information. Precise location is treated as sensitive personal information under some laws. We use it only to provide the Service, for security, and for the other purposes that those laws permit without offering a right to limit.
Marketing. You can unsubscribe from our marketing emails using the link in any of them. Reply STOP to opt out of text messages.
Browser signals. We do not sell or share personal information, so there is nothing to opt out of in response to "Do Not Track" or Global Privacy Control signals.
9. Security and location of data
We use reasonable administrative, technical, and physical safeguards, including encryption in transit and access controls. No method of transmission or storage is completely secure, and we cannot guarantee security. Information is processed and stored in the United States.
10. Children
The Service is not directed to children and may not be used by anyone under 18. If you believe a minor's information has been provided to us, contact support@zerobadgetechnologies.com.
11. Third-party links and services
Our Service may link to or rely on third-party services that have their own privacy practices. We are not responsible for them.
12. Changes
We may update this Policy. We will post the new version with a new effective date and, for material changes, give notice through the Service or by email.
13. Contact
ZeroBadge. Privacy: support@zerobadgetechnologies.com.
D6 · version 1.0 · sha256 3b39d455895fc3c6827a39e1a150418c61560d996911198ba26ae0d2504057d7