Privacy Policy
Last Updated: July 26, 2026
Shield Spire Ops ("Shield Spire Ops," "we," "us," or "our") is a multi-tenant security operations platform designed to help security companies, corporate security teams, and related organizations manage workforce operations, compliance, field activity, client visibility, and business workflows in a centralized environment.
This Privacy Policy explains how information is collected, used, disclosed, stored, and protected when individuals and organizations interact with the Shield Spire Ops website, platform, mobile-enabled workflows, portals, and related services. It is intended to reflect the operational reality of the Shield Spire Ops platform, including its multi-tenant structure, role-based access model, compliance workflows, operational reporting features, mobile field tools, and audit-ready architecture.
By accessing or using Shield Spire Ops, you acknowledge that you have read and understood this Privacy Policy.
1.Scope and Application
This Privacy Policy applies to information collected through:
- the public Shield Spire Ops website
- demo request and contact forms
- tenant administrator accounts
- employee and officer accounts
- supervisor and management accounts
- client portal accounts
- applicant portal accounts
- platform owner administrative tools
- mobile and field workflows supported through the platform
- operational submissions, reporting, messaging, and compliance tools made available through Shield Spire Ops
This Privacy Policy applies to several categories of users, including but not limited to:
- website visitors
- tenant administrators and managers
- supervisors and team leads
- employees, officers, patrol staff, dispatchers, and other operational personnel
- client users
- job applicants
- platform owner users
- authorized representatives of organizations using the platform
This Privacy Policy does not override any contractual agreement between Shield Spire Ops and a tenant organization. Where a tenant organization controls operational or employment data submitted into the platform, that tenant may also have its own internal privacy, HR, and compliance obligations.
2.Platform Role and Data Relationship
Shield Spire Ops operates as a multi-tenant software platform. Different organizations use the platform within isolated tenant environments. Because of that structure, the platform may process information in different roles depending on context.
In many cases, Shield Spire Ops acts as a technology provider that enables a tenant organization to manage its own workforce, clients, compliance records, scheduling, reporting, and related workflows. In that context, the tenant organization may determine what information is entered into the platform and how it is operationally used.
In other cases, Shield Spire Ops may collect information directly through public website forms, access requests, demo requests, contact forms, or platform-level administrative workflows.
Nothing in this Privacy Policy should be interpreted to mean that a tenant organization is relieved of its own legal, employment, operational, or regulatory responsibilities. Shield Spire Ops provides the infrastructure, controls, and workflows that support those processes, but each tenant remains responsible for how it uses the platform in its own business operations.
3.Information We Collect
The categories of information collected depend on how the platform is used, which role is involved, and which modules are enabled. Shield Spire Ops may collect the following categories of information.
3.1Account and Identity Information
We may collect account and identity information such as:
- full name
- email address
- phone number
- username or login identifier
- company or organization name
- user role and role code
- department, title, or position
- tenant affiliation
- profile image or avatar
- invitation acceptance status
- password setup and authentication metadata
- multi-factor authentication enrollment status
3.2Employment and Workforce Information
For employee, officer, supervisor, manager, recruiter, and similar users, the platform may process workforce-related information such as:
- employee profile details
- employment status
- position and department
- operational role designation
- license level or security qualification level
- certifications and training status
- onboarding progress
- emergency contact details
- disciplinary records
- time off requests
- assigned sites and shifts
- document acknowledgment records
- employee document uploads
- performance or attendance history
- internal operational notes where permitted by role
3.3Scheduling and Attendance Information
Shield Spire Ops may process scheduling and time-related information such as:
- weekly schedules
- recurring shift assignments
- open shift eligibility and pickup activity
- shift start and end times
- scheduled versus actual attendance
- tardiness and early departure records
- overtime monitoring
- shift reminders
- clock-in and clock-out timestamps
- break and attendance history
- timesheet export records
- administrative time verification actions
3.4Location, Presence, and Verification Information
Because Shield Spire Ops supports real-world field operations, the platform may process location and verification data including:
- GPS coordinates collected during clock-in and clock-out
- geofence validation results
- site location data
- checkpoint scan data
- patrol verification records
- gate scanner access logs
- entry and exit timestamps
- on-site duration tracking
- emergency muster status
- location-linked DAR entries
- location-linked incident submissions
3.5Media and Uploaded Content
The platform may collect, store, and process media and uploaded files such as:
- selfie verification images
- incident photos or videos
- onboarding documents
- licenses and certifications
- resumes and applicant documents
- company compliance documents
- shared client documents
- employee acknowledgments
- training content and related assets
- operational attachments uploaded through forms or reports
3.6Operational Activity and Reporting Information
Because Shield Spire Ops is an operations platform, it may process operational data including:
- Daily Activity Reports (DARs)
- incident reports
- incident response actions
- commander assignments
- status changes
- patrol scans and route compliance records
- operational form submissions
- activity entries logged during shifts
- dispatch messages and thread participation
- support messages
- field observations
- compliance review actions
- shift monitoring events
- no-show and overtime alerts
3.7Client and Business Relationship Information
For client organizations and related users, the platform may process:
- client organization details
- service sites
- assigned personnel visibility data
- invoice records
- quote and contract information
- shared documents
- communication logs
- feedback submissions
- onboarding and activation records
3.8Applicant and Recruitment Information
For recruitment workflows, the platform may process:
- applicant profile information
- application status
- interview schedules
- uploaded applicant documents
- saved job positions
- communication and status update history
3.9Billing and Payment Information
Shield Spire Ops may process billing-related information such as:
- subscription status
- billing account metadata
- invoice records
- payment status
- quote and contract conversion records
- Stripe-related transaction metadata
- tenant payment settings
- API billing and usage reports
Shield Spire Ops does not represent in this Privacy Policy that it directly stores raw payment card numbers in application-facing workflows where third-party payment providers are used. Payment processing may be handled through external payment processors such as Stripe and Stripe Connect, subject to those providers' own terms and privacy practices.
3.10Device, Session, and Technical Information
We may collect technical information such as:
- browser type and version
- operating system
- device identifiers
- IP address
- approximate location inferred from network data where applicable
- login timestamps
- failed login attempts
- session metadata
- user agent strings
- mobile device tokens
- connectivity state
- mobile security check outcomes
- application logs and error events
- API request metadata
3.11API and Integration Information
Where API or integration features are used, the platform may process:
- API key metadata
- scope configuration
- allowed IP restrictions
- expiration dates
- request logs
- endpoint usage data
- response status data
- integration credentials metadata
- sync activity logs
- webhook activity
3.12Compliance and Audit Information
The platform may process compliance and audit-related records including:
- compliance document uploads
- review statuses
- rejection or approval notes
- expiration dates
- compliance score calculations
- training gating decisions
- audit logs
- SLA events
- platform owner context-switch logs
- administrative actions
- role changes
- review and verification actions
4.How Information Is Collected
Shield Spire Ops may collect information in several ways, including:
- directly from users when they create accounts, submit forms, upload documents, or use workflows
- from tenant administrators who enter or manage personnel and client records
- through automated platform processes such as attendance logging, shift monitoring, notifications, and audit logging
- from mobile-enabled workflows such as GPS, camera, and checkpoint scans
- through public website forms such as request demo or contact requests
- through integrations and authorized third-party connections where configured
- through system logs, session tracking, and technical platform monitoring
5.How We Use Information
Shield Spire Ops uses information to operate, secure, maintain, and improve the platform and related services. Depending on context, information may be used to:
- create and manage accounts
- authenticate users and secure access
- apply role-based dashboard routing and permissions
- support tenant-specific operations
- manage employees, supervisors, clients, and applicants
- schedule shifts and monitor coverage
- validate geofence-based attendance
- record and verify time entries
- generate and maintain DARs
- submit, route, and manage incidents
- operate dispatch and messaging workflows
- monitor patrol and checkpoint compliance
- manage badge and access workflows
- support emergency muster visibility
- manage assets, maintenance, and disaster recovery workflows
- create, assign, and monitor training programs
- enforce training gating rules
- manage client activation, documents, and billing
- create quotes, contracts, and invoices
- support compliance workflows and expiration monitoring
- generate reports, exports, and audit packs
- send alerts, reminders, announcements, and notifications
- provide API access and monitor API usage
- investigate abuse, fraud, security incidents, or policy violations
- maintain audit readiness and accountability
- improve the quality, security, performance, and reliability of the platform
- comply with legal, regulatory, contractual, or operational obligations
6.Multi-Tenant Isolation and Role-Based Visibility
Shield Spire Ops is designed as a true multi-tenant platform. Data visibility is intentionally limited based on tenant boundaries and user role.
This includes, where implemented:
- tenant-scoped data separation
- role-based access controls
- dashboard routing by application role
- granular module access by staff role code
- row-level security controls
- restricted visibility for sensitive data categories
- context-switch logging and safeguards for platform owner workflows
Examples of how visibility differs by role may include:
- employees seeing only their own data
- supervisors seeing team-scoped data
- tenant admins seeing organization-scoped operational and administrative data
- clients seeing only their own organization's permitted information
- platform owners seeing cross-tenant information only through authorized governance workflows
Shield Spire Ops is designed to prevent unauthorized cross-tenant exposure.
7.Sensitive and Operationally Important Data
Because the platform is used in security operations, some data handled through the system may be operationally sensitive, including:
- site assignments
- incident records
- access activity
- patrol verification
- client service records
- personnel license and training status
- disciplinary records
- attendance verification
- audit trails
- compliance submissions
We take the sensitivity of this information seriously and design the platform around controlled access, auditability, and accountability.
8.Legal and Operational Bases for Use
Shield Spire Ops may process information where necessary to:
- provide requested services
- perform contractual obligations
- operate tenant workflows
- authenticate and secure accounts
- prevent misuse, fraud, or unauthorized access
- maintain service reliability and auditability
- support compliance and regulated operational environments
- respond to lawful requests or legal obligations
- protect the platform, tenants, users, and the public where necessary
Where a tenant organization uses Shield Spire Ops to manage its workforce, clients, applicants, or compliance activity, that tenant remains responsible for ensuring that its own use of the platform aligns with its applicable employment, privacy, and regulatory obligations.
9.Sharing and Disclosure of Information
Shield Spire Ops does not sell personal information.
We may disclose information in the following circumstances:
9.1To the Relevant Tenant Organization
Where a tenant organization manages its workforce, clients, applicants, and operations through the platform, authorized tenant personnel may access information within the limits of their assigned permissions.
9.2To Service Providers and Infrastructure Providers
We may rely on third-party service providers to support platform operation, such as providers of:
- hosting and database infrastructure
- authentication
- notifications and messaging
- SMS and voice communications
- payment processing
- mapping and location services
- email delivery
- bot protection
- artificial intelligence infrastructure and model providers
- meeting scheduling on our marketing website
- integrations and support tooling
Examples referenced in platform architecture may include services such as Supabase, Stripe, Stripe Connect, Firebase Cloud Messaging, Mapbox, Resend, Twilio, hCaptcha, Calendly, and AI model providers used to deliver AI-assisted functionality, among others as configured. A current list is maintained on our Subprocessors page.
9.3For Legal, Safety, and Security Reasons
We may disclose information where reasonably necessary to:
- comply with applicable law
- respond to lawful process
- investigate suspected misuse or fraud
- protect users, tenants, or the platform
- enforce our policies or contractual rights
- respond to emergencies or security incidents
9.4In Business or Organizational Transactions
If the platform or related business operations undergo a merger, acquisition, restructuring, financing, or transfer, information may be disclosed as part of that process subject to appropriate safeguards.
10.Payments and Financial Workflows
Payment-related workflows may involve third-party processors such as Stripe and Stripe Connect.
Shield Spire Ops may process billing metadata, invoice states, subscription details, and payment-related records necessary to support subscription services, client invoicing, and related platform functions. Where Stripe Connect is used for tenant client payments, Shield Spire Ops may facilitate those workflows while maintaining a separation between platform subscription revenue and tenant client-payment revenue according to the platform's design.
Users should also review the privacy practices of any payment provider used in connection with the platform.
11.Cookies, Sessions, and Similar Technologies
Shield Spire Ops may use cookies, session tokens, local storage, and similar technologies to:
- keep users signed in
- maintain authenticated sessions
- remember user preferences
- support navigation and platform functionality
- improve reliability and security
- detect abuse or suspicious activity
Additional details may be provided in the separate Cookie Policy.
12.Data Retention
Shield Spire Ops retains information for as long as reasonably necessary for service delivery, platform security, compliance support, auditability, dispute resolution, and legitimate operational purposes.
Retention periods may vary depending on data category. For example:
- audit logs may be retained for extended periods
- API usage data may be retained for monitoring and billing support
- session or auth-related metadata may have shorter retention windows
- operational, compliance, and reporting records may be retained to support contract, legal, and audit obligations
Retention practices may also be influenced by tenant requirements, applicable law, or contractual commitments.
13.Security Measures
Shield Spire Ops implements layered security measures designed for operational and regulatory environments. Depending on the workflow, these may include:
- role-based access controls
- tenant-scoped data access restrictions
- row-level security policies
- multi-factor authentication
- secure session management
- access and audit logging
- restricted visibility for sensitive data
- mobile security controls
- secure storage mechanisms
- certificate validation and platform hardening
- review and approval workflows for compliance-sensitive records
No method of transmission or storage is guaranteed to be absolutely secure, but we take reasonable and platform-appropriate steps to reduce risk and improve accountability.
14.Mobile, Location, Camera, and Field Data
Certain platform features rely on mobile and field data to function properly. Depending on user permissions and enabled workflows, Shield Spire Ops may collect and process:
- GPS coordinates
- geofence validation results
- selfie verification images
- incident photos and videos
- checkpoint scan events
- mobile device notification tokens
- network connectivity status
- mobile security check outcomes
This information is used to support legitimate operational functions such as time verification, patrol validation, incident documentation, dispatch awareness, and accountability workflows.
If a tenant chooses to enable such workflows, those capabilities form part of the platform's intended use. Location data is collected in connection with specific operational actions, such as clock-in and clock-out, geofence validation, checkpoint scanning, and dispatch awareness. Mobile workflows generally require an active connection. Offline field capabilities remain under development and are not generally available.
15.AI-Assisted Processing
Where AI-assisted features are enabled by the platform owner and the tenant, operational content may be processed by artificial intelligence infrastructure to generate suggestions, drafts, summaries, or assistance.
Depending on the enabled capability, this may involve:
- incident and report drafting assistance
- scheduling suggestions
- compliance review assistance
- conversational assistance within the platform
- form intelligence and structured data extraction
- operational summaries and analytics assistance
In connection with AI-assisted processing, we may record:
- AI usage and request records for auditing
- which capability was invoked and by which role
- usage volume against configured limits and spending caps
AI output is advisory and requires human review before operational reliance. AI features may be disabled at the platform or tenant level, and additional opt-in and redaction controls may apply to sensitive form workflows. AI-assisted processing does not make employment, disciplinary, compensation, dispatch, or emergency decisions.
16.Payroll Preparation Data
Where payroll preparation functionality is used, Shield Spire Ops processes information necessary to consolidate timesheets and prepare payroll-ready output, which may include:
- worked hours, breaks, and attendance records
- pay rates, overtime, and differential configuration
- gross-pay calculations and payroll period summaries
- exported payroll files provided to the tenant's external payroll system
Shield Spire Ops does not act as a payroll provider or employer of record, does not calculate, withhold, file, or remit taxes, and does not disburse wages. Tax identifiers and banking details for wage disbursement are handled by the tenant's own payroll provider, not by the platform. The tenant remains responsible for verifying payroll data before use.
17.International and Jurisdictional Considerations
Shield Spire Ops may be used by organizations operating in different jurisdictions. Compliance workflows may vary by jurisdiction, and some data may be processed in infrastructure environments or by service providers operating across geographic regions.
Tenants remain responsible for ensuring that their own use of the platform aligns with their applicable laws, employment obligations, privacy obligations, contractual requirements, and regulated-environment needs.
18.User Requests and Data Rights
Depending on the user's relationship to the platform and applicable law, individuals may request:
- access to certain personal information
- correction of inaccurate information
- deletion of certain data where deletion is legally and operationally permitted
- clarification regarding how information is used
Because Shield Spire Ops is often used by tenant organizations to manage workforce and operational data, many requests may need to be directed first to the relevant tenant organization.
Where Shield Spire Ops directly controls the relevant information, requests may be submitted using the contact details provided below.
We may need to verify identity and authority before responding.
19.Children's Data
Shield Spire Ops is not designed for use by children and is intended for organizational, professional, and operational use. We do not knowingly design the service for minors or intentionally collect personal information from children through the platform in the ordinary course of business.
20.Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect platform changes, legal developments, operational changes, security improvements, or new workflows.
If we update this Privacy Policy, we may revise the "Last Updated" date above. Continued use of the platform after updates become effective may constitute acceptance of the updated policy where permitted by law and contract.
21.Contact Information
For privacy-related questions, requests, or concerns regarding Shield Spire Ops, please contact:
If your issue relates to a tenant-specific account, workforce record, client record, or employment workflow, you may also need to contact the organization that invited you to or manages your access to the platform.
Shield Spire Ops operates as part of the GEEC AI Platform ecosystem.