Home
TenTwo Guardian

Privacy Policy

What we collect, why we collect it, what we don't do with it, and how you control it.

Draft for legal review

Sections in [BRACKETS] are placeholders for counsel to complete before public launch. This page reflects current product behavior in plain language; it is not yet a signed legal agreement.

1. Who we are and how to reach us

What this means

TenTwo is our app. Email our privacy team any time — the address is below.

TenTwo is operated by [LEGAL ENTITY NAME] ("we", "us"). Contact our privacy team at privacy@[COMPANY-DOMAIN]. A Data Protection Officer contact will be listed here after appointment: [DPO CONTACT — TO BE COMPLETED].

2. Data we collect

What this means

Your account info, your live location during a booking, Encounter recordings, your payment method through Stripe, your emergency contacts, and app usage data.

  • Account data — email, display name, phone number, and password hash.
  • Precise location — live TenTwo position while a booking is active or you have chosen to share location with family. Position is rounded until an agent has accepted a booking.
  • Encounter recordings — audio captured on your device and body-camera video captured on the responding agent's device during Encounter Mode.
  • Payment data — payment methods and billing history are stored by our payment processor (Stripe); we retain only the identifiers and last-4 digits required to display billing history.
  • Emergency contacts — the names and phone numbers you add so we can notify them during an active booking.
  • App telemetry — device type, coarse crash and error data, and product-analytics events used to improve reliability.

3. How we use the data

What this means

To get an agent to you, keep your emergency contacts informed, bill you correctly, and preserve a tamper-evident record if something goes wrong.

  • To dispatch nearby, qualified agents and calculate ETAs.
  • To create and preserve the tamper-evident evidence record associated with an Encounter, so it can be reviewed if a dispute or incident occurs.
  • To notify your emergency contacts when you activate a booking or press SOS.
  • To bill you, prevent fraud, and comply with our tax and record-keeping obligations.
  • To operate and improve the Service, and to satisfy regulatory requirements applicable to private security operations.

4. Who we share it with

What this means

Only the people who need it to help you: your agent, your emergency contacts, and our payment processor. We do not sell your data.

We share only what is necessary and only with the categories of recipient listed below. We do not sell your personal information.

  • Responding agent and their agency — pickup location, first name, and any pre-encounter notes you choose to share, so they can help you.
  • Emergency contacts — a signed tracking link showing agent name, current status, and ETA while your booking is active. The link expires when the booking ends.
  • Payment processor (Stripe) — payment method and charge details.
  • Infrastructure providers — hosting, database, and object storage vendors that operate under contract and are bound to keep data confidential. [SUB-PROCESSOR LIST TO BE COMPLETED.]
  • Law enforcement — only in response to lawful process, or when we reasonably believe disclosure is necessary to prevent imminent harm.

5. How long we keep it

What this means

Recordings default to 90 days, then delete automatically — unless a legal hold or open incident extends the timer.

Encounter recordings and evidence records are retained for 90 days by default and then automatically deleted. If an incident is filed, a footage request is opened, or a legal hold is placed, retention is extended and deletion is blocked at the database level until the hold is released. Account, booking, and payment records are retained for the period required by tax and record-keeping law. When you delete your account (see Section 8) we delete personal identifiers within 30 days and retain only what is necessary for legal, safety, or fraud-prevention purposes, in a form that no longer identifies you.

6. Security

What this means

Encrypted in transit and at rest. Every recording is hashed so tampering is detectable. Admin access is named and logged.

Data in transit is protected with TLS. Data at rest is protected with provider-managed encryption. Evidence records are hashed with SHA-256 at capture and the hash is stored alongside the file so tampering is detectable. Access to admin systems requires named accounts and is logged.

7. Your privacy rights

What this means

See, correct, export, or delete your data from Profile → Privacy & data. For anything else, email privacy@.

Depending on where you live, you may have rights to access, correct, delete, restrict, or export your personal data, and to object to certain processing. You can exercise the two most common rights directly in the app: Profile → Privacy & data. Other requests can be sent to privacy@[COMPANY-DOMAIN]. [CCPA / GDPR / STATE-SPECIFIC RIGHTS PARAGRAPHS — TO BE COMPLETED BY COUNSEL.]

8. Deleting your account

What this means

Delete from Profile → Privacy & data. Records tied to open incidents stay until those incidents are resolved.

You can delete your account from Profile → Privacy & data → Delete account. Deletion removes your login, profile, saved locations, and emergency contacts. Bookings and evidence records tied to open incidents may be retained until those incidents are resolved. Payment history retained for tax purposes is de-identified where possible.

9. Children

What this means

TenTwo is for adults. We don't knowingly collect data from anyone under 18.

The Service is not intended for anyone under 18 and we do not knowingly collect personal information from children.

10. International transfers

What this means

If your data crosses borders, we apply the safeguards the law requires.

[CROSS-BORDER TRANSFER LANGUAGE — TO BE COMPLETED BASED ON HOSTING REGION AND USER GEOGRAPHY.]

11. Changes to this policy

What this means

If we change this policy, we'll tell you in the app.

We will notify you inside the app when this policy changes materially and update the date below.

Last updated: [DATE ON REVIEW]. Effective: [DATE ON REVIEW].