Privacy Policy

Last updated: 1 July 2026

1. Who we are

SentinelTag is a safeguarding and emergency information platform operated by Marc Busby (trading as SentinelTag)("we", "us", "our").

We are the data controller for personal data processed through the SentinelTag mobile application and website. We are registered with the Information Commissioner's Office (ICO) as a data controller.

Contact us about privacy matters: privacy@sentineltag.com

2. What data we collect and why

We collect the following categories of personal data:

Data typePurpose
Account data (name, email, password hash)Account creation and authentication
Emergency profile data (name, date of birth, photo)Identifying the profile subject in an emergency
Health and medical information (conditions, medications, allergies)Providing critical information to authorised responders
Emergency contact numbersEnabling immediate contact with designated contacts
Profile photographsVisual identification of the profile subject
GPS location (recorded when an authorised app user scans a tag)Audit trail for safeguarding accountability
Scan history (who scanned, when)Security monitoring and audit logging
Payment informationProcessing credit purchases (handled by Stripe — we do not store card details)
Device tokens (FCM)Push notifications when your tag is scanned

3. Special category data

Health and medical information is "special category data" under UK GDPR Article 9. We process this data only where:

  • You have given explicit consent (by creating and populating a profile); and/or
  • Processing is necessary to protect the vital interests of the data subject or another person where the subject is physically or legally incapable of giving consent (Article 9(2)(c)).

Health data is never used for marketing, profiling, research, or any purpose other than displaying it to authorised responders in the circumstances you have configured.

4. Legal basis for processing

Processing activityLegal basis (UK GDPR Art 6)
Account creation and managementContract (6(1)(b))
Displaying profile to authorised responderVital interests (6(1)(d)) / Consent (6(1)(a))
Displaying public emergency number to any finderVital interests (6(1)(d))
Scan audit log with locationLegitimate interests (6(1)(f)) — safeguarding accountability
Push notificationsConsent (6(1)(a))
Payment processingContract (6(1)(b))
Security monitoring and unauthorised scan loggingLegitimate interests (6(1)(f))

5. Children's data

SentinelTag is designed to protect children. A parent or legal guardian must create and manage any profile for a child under 13. By creating a child's profile, you confirm you have parental or guardian authority to do so and consent to the processing of that child's personal data on their behalf.

We comply with the ICO's Children's Code (Age Appropriate Design Code). Children's data is processed only for the safeguarding purposes described in this policy. It is never used for advertising, profiling, or any commercial purpose.

6. How we share your data

Your data is shared only in the following circumstances:

  • Authorised responders: users you explicitly grant access to a profile can view that profile when they scan the tag.
  • Group members: if you share a profile with a group, all current and future members of that group gain access.
  • Public emergency number: if you enable this feature, the phone number and display name you specify are written to the NFC tag as plain, unencrypted text and can be read by anyone who holds the tag and has an NFC-capable device — not only registered SentinelTag users, and without signing in. You should treat this information as effectively public.
  • Scans by people without the app: if someone taps a tag with a phone that does not have the SentinelTag app, they are shown a web page with the public emergency number (if enabled). We record this as an unauthorised scan in the tag owner’s audit log for safeguarding accountability. For these public scans we log only the date and time and a basic browser identifier — we do notcollect the finder’s location, and these records are deleted after 90 days.
  • Data processors: we use Google Firebase (infrastructure), Stripe (payments), and Gmail (transactional email). Each operates under a Data Processing Agreement with appropriate safeguards.

We do not sell your data, share it with advertisers, or disclose it to any third party beyond those listed above.

7. Data retention

Data typeRetention period
Tag and profile dataUntil deleted by the owner. If an account becomes inactive (no credit spent), tag data is automatically and permanently deleted 90 days after the subscription expiry date.
Account dataAccount lifetime plus 30 days post-closure
Scan audit logs12 months from the date of each scan
Payment records7 years (legal obligation — HMRC)
Unauthorised scan logs90 days

We will send you email warnings at 30 days and 7 days before any scheduled automatic deletion. You can cancel the deletion at any time by spending a credit to reactivate your account. The lawful basis for the 90-day retention period after subscription expiry is the performance of a contract (UK GDPR Article 6(1)(b)) — we retain data for a reasonable period to allow users to reactivate without data loss.

8. Security

We protect your data using:

  • AES-256 encryption of profile data fields at rest
  • Firestore security rules enforcing access control at the database level
  • Multi-factor authentication (email OTP + optional biometrics)
  • Screenshot prevention on Android; app-switcher privacy overlay on iOS
  • Full audit logging of all profile accesses
  • TLS encryption for all data in transit

9. International transfers

Your data is stored in Google Firebase infrastructure. We configure our Firebase project to use EU/UK regions where possible. Any transfers to the United States (for example, via Google's global infrastructure) are covered by Standard Contractual Clauses under the UK International Data Transfer Agreement (IDTA).

10. Your rights

Under UK GDPR you have the right to:

  • Access — request a copy of the data we hold about you
  • Rectification — correct inaccurate data (you can do this directly in the app)
  • Erasure — request deletion of your data
  • Restriction — ask us to limit how we use your data
  • Objection — object to processing based on legitimate interests
  • Portability — receive your data in a structured, machine-readable format

To exercise any of these rights, email privacy@sentineltag.com. We will respond within 30 days.

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113.

11. Cookies

The SentinelTag website uses only essential session cookies required for authentication. No advertising, tracking, or analytics cookies are set.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email and by a prominent notice on the website. The "Last updated" date at the top of this page always reflects the most recent version.

13. Contact us

Data controller: Marc Busby (trading as SentinelTag)
Email: privacy@sentineltag.com