Legal

Privacy Policy

Effective January 1, 2024

1. Who We Are

Uniguard Pro is a cloud-based security monitoring and dispatch platform. We act as the data controller for information about our direct account holders (operators, dealers, tenant administrators) and as a data processor for information that our customers upload about their own end users (callout contacts, site occupants, video subjects captured by customer-owned cameras).

Questions about this policy or any of the rights described below can be sent to [email protected]. For general support, contact [email protected] or (833) 486-0846.

2. Information We Collect

We collect the minimum information required to operate the security-monitoring service:

Account information

  • Name, business or property name, email address, phone number
  • Password hash (Argon2id with a library-generated random salt; older accounts keep a bcrypt hash until their next sign-in — we never store plaintext passwords)
  • If you enable two-factor authentication: an encrypted authenticator secret, hashed single-use recovery codes, and the time-step of the last accepted code (so a code can’t be replayed)
  • Role (operator, dealer staff, tenant administrator, tenant operator)
  • For dealers and commercial customers: business address, billing email, contact phone

Site information

  • Physical address of monitored premises, geocoded coordinates
  • Names and phone numbers of designated emergency contacts (the account holder is responsible for obtaining contact consent — see our SMS & Voice Notification Terms)
  • SIA DC-09 account identifiers and encryption keys used to authenticate signals from your alarm panel

Security event data

  • Alarm signals received from your panel: timestamp, event code (burglary, fire, panic, supervisory, etc.), zone, raw SIA frame
  • Camera detections from UniFi Protect alarm rules: trigger type, device, timestamp, thumbnail image
  • Cancelled-alarm audit records (when you disarm during the entry-delay countdown)
  • Operator dispatch and resolution actions (acknowledgement timestamps, dispatch decisions, notes)

Notification logs

  • SMS and voice messages we send: recipient phone number, message body, delivery status from the carrier
  • Email notifications: recipient, subject, delivery status
  • Dispatcher communications: which alarm was escalated, which dispatch outcome (police dispatched, customer cancelled, false alarm)

Billing information

  • For direct customers: Stripe Customer ID, subscription status, plan tier, add-ons, metered usage counts
  • Payment card data is collected, stored, and processed by Stripe — it never touches Uniguard Pro’s servers
  • Invoice history and metered-usage reports

Technical & security data

  • Login timestamps, IP addresses, and a per-user audit log of administrative actions
  • Bot-challenge results from Cloudflare Turnstile on auth forms
  • HTTP access logs at the Cloudflare edge and at our origin nginx (truncated client IP, request path, status code)
  • Live-chat support: the messages you send, replies (AI or human), any name, email or phone number you choose to leave, any screenshot you attach, and a random per-browser conversation identifier held in a cookie (see Section 8). Website visitors can use the chat without an account; if you later create an account or leave your email, the conversation is attributed to you so support has the history.

3. How We Use Your Information

We process the information above strictly to:

  • Deliver the security monitoring service — receive panel signals, evaluate rules, escalate to dispatchers, notify your designated contacts
  • Operate the customer, dealer, and operator portals so you can manage your sites, view alarm history, and respond to events
  • Bill direct customers, calculate metered usage, send receipts and dunning emails
  • Detect and block abusive activity (credential stuffing, account enumeration, signal injection)
  • Maintain an audit trail of administrative actions for regulatory compliance and forensic review
  • Communicate operational changes (planned maintenance, security advisories, policy updates) to active customers

We do not sell or rent personal information to third parties. We do not use account or event data for advertising, profiling, or machine-learning model training. We do not share data with third parties except as described in Section 4 below.

4. Sub-Processors We Share Data With

We rely on the following third-party processors to operate the service. Each is bound by a data processing agreement limiting them to the purpose described:

Sub-processorPurposeData
CloudflareCDN, WAF, bot challenge (Turnstile), DDoS mitigation, DNSAll HTTP traffic to our public origins; truncated IP for rate limiting
StripeSubscription billing, payment card processingCustomer name, email, payment card (handled entirely by Stripe), invoice + usage data
TwilioSMS notification deliveryRecipient phone number, message body, delivery receipts
ResendTransactional email delivery (signup, password reset, billing receipts)Recipient email, subject, HTML body, delivery receipts
NoonlightProfessional dispatcher escalation for pro-monitored customersSite address, signal details, callout contact info, and for video-monitored cameras (including cameras the customer linked to the sensor that alarmed) a still image, a short recorded clip and a live-view link for the alarm (only for alarms that meet the dispatch or verification policy)
UniFi Cloud (Ubiquiti Inc.)Camera roster sync, snapshot retrieval, and recorded clips, live video and detection events from cameras the customer switched on for video monitoringCustomer-issued UniFi API key, device identifiers, snapshot images, short video clips, live video, detection and arm/disarm events
MapboxAddress autocomplete and geocoding during site setupAddress strings typed during onboarding
HaveIBeenPwnedPassword breach check at account creation / password resetFirst 5 characters of the SHA-1 hash of the password (k-anonymity API — your full password never leaves our servers)
IONOSVPS hosting for our application servers and databaseAll data stored at rest on the platform server

This list is updated when a sub-processor is added or removed. Material additions are communicated to active customers via email at least 30 days in advance.

5. Data Retention

  • Account data — retained for the life of the account plus 12 months after cancellation (billing reconciliation + regulatory record retention).
  • Alarm events — retained for the life of the account; available for customer audit and dispute resolution.
  • Camera snapshots — retained for 90 days from the event, then automatically deleted by a background cleanup job. Snapshots from alarms cancelled-by-user are deleted immediately on cancellation.
  • Video clips — short recorded clips retrieved for an alarm are deleted automatically once the alarm has been handled. Live video is relayed for viewing and is not recorded by us.
  • Notification logs — 24 months (regulatory retention for telecom and dispatch records).
  • Audit log — retained for the life of the account; never deleted by the application (enforced at the database row-level security layer).
  • Cloudflare edge logs — retained per Cloudflare’s standard policy (~7 days at the time of writing).
  • Backups — encrypted daily DB snapshots retained 30 days then rolled off.

On account deletion, we expunge the records above on the schedule shown. If you require immediate deletion outside this schedule, contact [email protected] and we will action within 30 days unless we’re legally required to retain a specific record (e.g. an active dispatch under investigation).

6. Your Rights

Subject to the laws of your jurisdiction (GDPR, CCPA/CPRA, PIPEDA, etc.) you have the following rights regarding the personal data we hold about you:

  • Access — request a copy of the personal data we hold about you
  • Correction — update inaccurate or out-of-date data
  • Deletion — request erasure of your data subject to the retention constraints in Section 5
  • Portability — receive a machine-readable export of your account data
  • Restriction — ask us to limit how we process your data while a dispute is being resolved
  • Objection — object to specific processing (e.g. opt out of non-emergency SMS notifications)
  • Withdrawal of consent — withdraw consent previously given (note that this will disable SMS / voice security alerts; see the SMS & Voice Notification Terms)

To exercise any of these rights, email [email protected]. We respond within 30 days. If you believe we have not adequately addressed your request, you have the right to lodge a complaint with your local supervisory authority.

California residents have additional rights under the CCPA/CPRA, including the right to know what categories of personal information are collected and the right to opt out of any sale or sharing for cross-context behavioural advertising. Uniguard Pro does not sell personal information and does not share it for advertising — so no opt-out action is required from our side, but the right is preserved.

7. How We Protect Your Information

  • In transit: TLS 1.2+ on every external connection. Traffic between your browser and our origins is also routed through Cloudflare with HSTS preload.
  • At rest: Integration tokens, UniFi API keys, and SIA panel encryption keys are stored Fernet-encrypted (AES-128-CBC + HMAC-SHA256) using a key separate from the JWT signing secret.
  • Passwords: hashed with Argon2id (memory-hard, with a random salt generated by the hashing library — we do not construct salts ourselves). Accounts created before September 2026 hold a bcrypt hash (cost factor 12, over a SHA-256 pre-hash) that is transparently upgraded to Argon2id the next time the user signs in. Passwords are compared against the HaveIBeenPwned breach corpus on creation and reset.
  • Two-factor authentication: authenticator-app (TOTP) codes with single-use recovery codes; text-message codes (sent through Twilio to a phone number you verify) as an alternate; email codes for customer accounts. Required for Uniguard staff and dealer accounts, and available to every account. If you enable text codes we store the verified number for that purpose only. Sensitive actions (viewing a customer account, changing emergency contacts or integration keys, dispatching or cancelling alarms, changing a password or two-factor settings) require a recent re-confirmation of credentials.
  • Access control: layered. Every API request is authorized server-side against the signed-in user’s role, tenant and dealer; the database additionally enforces per-tenant row-level security policies on every data table, so a query that escaped application checks would still be limited to the caller’s own rows. Staff access to a customer account (“view as”) is time-limited, requires re-authentication, is shown prominently in the interface, and is recorded in the audit log.
  • Bot protection: Cloudflare Turnstile on login, signup, and password-reset forms. Direct-IP scans of our origins are silently dropped at nginx.
  • Session management: signed session tokens (8 hours for customer accounts; up to 72 hours for staff, extended only while the console is in use) with a new session identifier at every sign-in, two-factor step and re-authentication; per-user revocation (“sign out everywhere” bumps a timestamp that invalidates every prior token); HttpOnly + Secure + SameSite=Lax cookies.
  • Audit trail: All administrative actions are logged to an append-only audit table protected by row-level security policies that prevent deletion or modification by non-system roles.

No system is perfectly secure. If you believe a security issue affects Uniguard Pro, email [email protected] with the subject line “Security Report”. We triage all submissions within one business day.

8. Cookies & Similar Technologies

We use a small number of cookies, all set with the HttpOnly + Secure + SameSite=Lax attributes:

  • ugp_token — your authenticated session JWT. Cleared on sign-out.
  • ugp_impersonate — set when a dealer is viewing their customer’s portal (audit-logged on both sides). Cleared on exit.
  • ugp_impersonate_dealer — set when Uniguard support staff are viewing a dealer’s console on that dealer’s behalf (audit-logged, time-limited).
  • __Host-ugp_mfa — a short-lived (minutes) token that carries you from the password step to the two-factor code step during sign-in. Not a session; cleared as soon as sign-in completes.
  • __Host-ugp_chat — a random identifier for your live-chat conversation on this site (up to 30 days). It links the messages, any name or email you choose to leave, any discovery-call booking you make in the chat, and any screenshot you attach, to that one conversation so you can continue it. It contains no personal data itself and is never used for advertising or tracking across sites. Chat transcripts are personal data we hold under Section 2 and are retained with your support history.

Cloudflare also sets its own functional cookies for bot challenge state (e.g. cf_clearance); these are governed by Cloudflare’s privacy policy.

We do not use third-party analytics, tracking pixels, or advertising cookies anywhere on our customer-facing pages.

9. International Data Transfers

Uniguard Pro is operated from Canada. Our infrastructure (database, application servers, snapshot storage) is currently hosted in IONOS US data centers. When you use the service from outside Canada or the United States, your personal data is transferred to and processed in those jurisdictions.

Our sub-processors operate globally (Cloudflare, Stripe, Twilio, Resend) and may process data in any of their regional facilities. Each sub-processor has its own certified cross-border transfer mechanism (e.g. Standard Contractual Clauses for EU data).

10. Children's Data

Uniguard Pro is a business-to-business security platform and is not directed at individuals under 13 (or 16 in jurisdictions where that is the applicable threshold). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact [email protected].

Note: cameras at customer-monitored sites may capture images of children present at those premises. Those images are processed under the same retention and security policies described above. The account holder (the site owner) is responsible for any local-jurisdiction obligations around surveillance disclosure or signage.

11. Changes to This Policy

We may update this policy as the service evolves or as applicable law changes. The effective date at the top of this page reflects the most recent revision. Material changes — new sub-processor, expanded data collection, changes to your rights — will be communicated to active customers via email at least 30 days before they take effect.

Continued use of the service after the effective date of an updated policy constitutes acceptance of the updated terms.

12. Contact Us

Privacy Policy — Uniguard Pro — Uniguard Pro