Privacy Policy
Last updated: 1 July 2026
1. Who we are
SentinelTag is a safeguarding and emergency information platform operated by Marc Busby (trading as SentinelTag)("we", "us", "our").
We are the data controller for personal data processed through the SentinelTag mobile application and website. We are registered with the Information Commissioner's Office (ICO) as a data controller.
Contact us about privacy matters: privacy@sentineltag.com
2. What data we collect and why
We collect the following categories of personal data:
| Data type | Purpose |
|---|---|
| Account data (name, email, password hash) | Account creation and authentication |
| Emergency profile data (name, date of birth, photo) | Identifying the profile subject in an emergency |
| Health and medical information (conditions, medications, allergies) | Providing critical information to authorised responders |
| Emergency contact numbers | Enabling immediate contact with designated contacts |
| Profile photographs | Visual identification of the profile subject |
| GPS location (recorded when an authorised app user scans a tag) | Audit trail for safeguarding accountability |
| Scan history (who scanned, when) | Security monitoring and audit logging |
| Payment information | Processing credit purchases (handled by Stripe — we do not store card details) |
| Device tokens (FCM) | Push notifications when your tag is scanned |
3. Special category data
Health and medical information is "special category data" under UK GDPR Article 9. We process this data only where:
- You have given explicit consent (by creating and populating a profile); and/or
- Processing is necessary to protect the vital interests of the data subject or another person where the subject is physically or legally incapable of giving consent (Article 9(2)(c)).
Health data is never used for marketing, profiling, research, or any purpose other than displaying it to authorised responders in the circumstances you have configured.
4. Legal basis for processing
| Processing activity | Legal basis (UK GDPR Art 6) |
|---|---|
| Account creation and management | Contract (6(1)(b)) |
| Displaying profile to authorised responder | Vital interests (6(1)(d)) / Consent (6(1)(a)) |
| Displaying public emergency number to any finder | Vital interests (6(1)(d)) |
| Scan audit log with location | Legitimate interests (6(1)(f)) — safeguarding accountability |
| Push notifications | Consent (6(1)(a)) |
| Payment processing | Contract (6(1)(b)) |
| Security monitoring and unauthorised scan logging | Legitimate interests (6(1)(f)) |
5. Children's data
SentinelTag is designed to protect children. A parent or legal guardian must create and manage any profile for a child under 13. By creating a child's profile, you confirm you have parental or guardian authority to do so and consent to the processing of that child's personal data on their behalf.
We comply with the ICO's Children's Code (Age Appropriate Design Code). Children's data is processed only for the safeguarding purposes described in this policy. It is never used for advertising, profiling, or any commercial purpose.
6. How we share your data
Your data is shared only in the following circumstances:
- Authorised responders: users you explicitly grant access to a profile can view that profile when they scan the tag.
- Group members: if you share a profile with a group, all current and future members of that group gain access.
- Public emergency number: if you enable this feature, the phone number and display name you specify are written to the NFC tag as plain, unencrypted text and can be read by anyone who holds the tag and has an NFC-capable device — not only registered SentinelTag users, and without signing in. You should treat this information as effectively public.
- Scans by people without the app: if someone taps a tag with a phone that does not have the SentinelTag app, they are shown a web page with the public emergency number (if enabled). We record this as an unauthorised scan in the tag owner’s audit log for safeguarding accountability. For these public scans we log only the date and time and a basic browser identifier — we do notcollect the finder’s location, and these records are deleted after 90 days.
- Data processors: we use Google Firebase (infrastructure), Stripe (payments), and Gmail (transactional email). Each operates under a Data Processing Agreement with appropriate safeguards.
We do not sell your data, share it with advertisers, or disclose it to any third party beyond those listed above.
7. Data retention
| Data type | Retention period |
|---|---|
| Tag and profile data | Until deleted by the owner. If an account becomes inactive (no credit spent), tag data is automatically and permanently deleted 90 days after the subscription expiry date. |
| Account data | Account lifetime plus 30 days post-closure |
| Scan audit logs | 12 months from the date of each scan |
| Payment records | 7 years (legal obligation — HMRC) |
| Unauthorised scan logs | 90 days |
We will send you email warnings at 30 days and 7 days before any scheduled automatic deletion. You can cancel the deletion at any time by spending a credit to reactivate your account. The lawful basis for the 90-day retention period after subscription expiry is the performance of a contract (UK GDPR Article 6(1)(b)) — we retain data for a reasonable period to allow users to reactivate without data loss.
8. Security
We protect your data using:
- AES-256 encryption of profile data fields at rest
- Firestore security rules enforcing access control at the database level
- Multi-factor authentication (email OTP + optional biometrics)
- Screenshot prevention on Android; app-switcher privacy overlay on iOS
- Full audit logging of all profile accesses
- TLS encryption for all data in transit
9. International transfers
Your data is stored in Google Firebase infrastructure. We configure our Firebase project to use EU/UK regions where possible. Any transfers to the United States (for example, via Google's global infrastructure) are covered by Standard Contractual Clauses under the UK International Data Transfer Agreement (IDTA).
10. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the data we hold about you
- Rectification — correct inaccurate data (you can do this directly in the app)
- Erasure — request deletion of your data
- Restriction — ask us to limit how we use your data
- Objection — object to processing based on legitimate interests
- Portability — receive your data in a structured, machine-readable format
To exercise any of these rights, email privacy@sentineltag.com. We will respond within 30 days.
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
11. Cookies
The SentinelTag website uses only essential session cookies required for authentication. No advertising, tracking, or analytics cookies are set.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email and by a prominent notice on the website. The "Last updated" date at the top of this page always reflects the most recent version.
13. Contact us
Data controller: Marc Busby (trading as SentinelTag)
Email: privacy@sentineltag.com