Data Deletion Policy

Effective Date: July 18, 2025
Version: 1.0
# Data Deletion Policy **Last updated:** January 2026 This policy explains how you can request deletion of your personal data from QRPatrol and what happens when you do. ## 1. Right to Data Deletion Under data protection laws including GDPR and CCPA, you have the right to request deletion of your personal information. ## 2. What Data Can Be Deleted When you request data deletion, we will remove: - Your account information (name, email, phone) - Guard profiles and employee data - Patrol history and GPS breadcrumbs - Checkpoint scan records - Incident reports and photos - User preferences and settings - Device information ## 3. What Data Cannot Be Deleted Some data must be retained for legal and business purposes: - Transaction records (required for accounting and tax purposes) - Audit logs (required for security and compliance) - Aggregated, anonymized analytics data - Data subject to legal holds or disputes ## 4. How to Request Data Deletion ### 4.1 For Company Administrators To delete your entire company account: 1. Log in to the web dashboard 2. Navigate to **Settings > Account** 3. Click **Delete Account** 4. Confirm deletion and provide a reason (optional) 5. Your account will be scheduled for deletion **OR** Send an email to **privacy@qrpatrol.app** with: - Your company name - Company admin email address - Confirmation of deletion request ### 4.2 For Guards Guards cannot delete company data themselves. To request deletion of your personal data: 1. Contact your company administrator 2. OR submit a request through the help form in the mobile app 3. OR email **privacy@qrpatrol.app** with your name and email ## 5. Deletion Timeline ### 5.1 Immediate Actions Upon receiving a valid deletion request: - Your account will be immediately suspended - Login access will be revoked - Mobile app access will be disabled ### 5.2 Grace Period - **30-day grace period:** During this time, deletion can be canceled - You can contact support to restore your account - After 30 days, deletion becomes irreversible ### 5.3 Complete Deletion - **Within 60 days:** All personal data will be permanently deleted from our systems - **Within 90 days:** Data will be removed from all backups - **Confirmation:** You will receive an email confirming deletion ## 6. What Happens After Deletion ### 6.1 Access - All user accounts will be deactivated - Mobile app login will fail - Web dashboard access will be revoked ### 6.2 Subscriptions - Active subscriptions will be canceled - No further charges will be made - No refunds for partial billing periods ### 6.3 Data Recovery - After the grace period, data cannot be recovered - We recommend exporting important data before deletion ## 7. Data Export Before Deletion Before requesting deletion, you can export your data: 1. Log in to the web dashboard 2. Navigate to **Settings > Data Export** 3. Request an export of: - Patrol history (CSV) - Incident reports (PDF) - Checkpoint data (CSV) - User information (JSON) 4. Download the exported files 5. Then proceed with deletion request ## 8. Partial Deletion Requests If you want to delete specific data without closing your account: ### 8.1 Individual Records - Delete specific patrol sessions - Remove individual incident reports - Delete old checkpoint scans - Update or remove photos Go to the relevant section in the dashboard and use the delete option. ### 8.2 User Removal Company admins can remove individual users: - Navigate to **Users** - Select the user to remove - Click **Delete User** - User data will be permanently deleted ## 9. Third-Party Services We will also request deletion of your data from our service providers: - **Stripe:** Payment data (subject to legal retention requirements) - **Firebase:** Push notification tokens and device info - **AWS:** Stored files and backups Some third parties may retain data according to their own policies and legal requirements. ## 10. Verification To prevent unauthorized deletion, we may require verification: - Confirmation from registered email address - Security questions - Admin credentials - Identity verification documents (if suspicious activity detected) ## 11. Special Circumstances ### 11.1 Legal Holds Data deletion may be delayed if: - Subject to active litigation - Required by law enforcement - Part of a regulatory investigation - Necessary to comply with legal obligations ### 11.2 Shared Data If your data is part of shared records (e.g., patrol data involving multiple guards), we will: - Remove your personal identifiers - Anonymize your contributions - Retain operational records as necessary ## 12. Children's Data If we discover we have collected data from a child under 18: - We will delete it immediately upon discovery - No grace period will apply - Parents/guardians can request immediate deletion ## 13. Complaints and Appeals If you are unsatisfied with our data deletion process: ### 13.1 Contact Our Privacy Team - Email: **privacy@qrpatrol.app** - Subject: "Data Deletion Complaint" ### 13.2 Regulatory Authorities You have the right to lodge a complaint with: - **GDPR (EU):** Your local Data Protection Authority - **CCPA (California):** California Attorney General - **Other Regions:** Relevant data protection authority ## 14. Updates to This Policy We may update this policy to reflect: - Changes in data protection laws - Updates to our deletion procedures - Improvements to the deletion process You will be notified of significant changes via email. ## 15. Contact Information For data deletion requests or questions: - **Email:** privacy@qrpatrol.app - **Help Form:** Available in the application - **Subject Line:** "Data Deletion Request" **Required Information for Deletion Requests:** - Your full name - Email address associated with your account - Company name (if applicable) - Reason for deletion (optional but helpful) --- **Response Time:** We respond to deletion requests within 30 days. **Last Updated:** January 8, 2026 **Version:** 1.0

Last updated: January 18, 2026