Privacy Policy
Last updated 1 October 2026
This policy explains what ShieldGuard collects, why, and what you can do about it. It covers our website and the application, including the data our customers keep in their workspaces.
1. Who is responsible
Xu Jack, Hong Kong, is the controller for the website and for account data. For the employee records our customers keep in their workspaces, we are a processor: the customer — your employer, or the company that invited you — decides what is collected and why, and we handle it only on their instructions. Our Data Processing Agreement describes that relationship.
2. What we collect
- Account data. Name, work email, company name, role, and password credentials for people who sign in. Payment details go directly to Stripe; we never see card numbers.
- Employee records. For the people a customer tracks: name, work email, department, role, optional phone number, and their training history — assignments, completion dates, expiry dates, and review decisions.
- Certificates. Files that customers or their employees upload as proof of training, and the text and dates read out of them to help a reviewer.
- Usage and support. Audit entries for actions taken in a workspace, and the contents of support conversations you have with us (including live chat).
- Website analytics. Pages visited and basic device information, when analytics is enabled (see section 4).
3. How we use it, and why
- To provide the service: run reminders, calculate compliance figures, and show the right records to the right roles.
- To keep accounts secure: authenticate sign-ins, enforce roles, and detect misuse.
- To bill subscriptions: process payments and send invoices through Stripe.
- To send service email: invitations, password resets, and the reminders a workspace enables.
- To support you: answer questions and investigate problems.
- To improve the product: understand which features are used, in aggregate.
Where the GDPR applies, our legal bases are: performance of a contract (running the service you signed up for), legitimate interests (security, product improvement), consent (optional analytics and chat cookies), and legal obligation (tax and accounting records).
6. International transfers
Some providers process data outside the EEA or the UK. Where that happens, we rely on appropriate safeguards — the European Commission’s Standard Contractual Clauses together with the UK Addendum, or an equivalent adequacy decision.
7. How long we keep it
Account and workspace data is kept while the workspace is active. If a subscription ends, the data stays readable for 30 days so the customer can export it, and is then deleted from production systems. Deleted data may persist briefly in encrypted backups before rotating out. We keep billing records for as long as tax law requires, and the notification log — which records what email was sent about what training, when — for the period needed to avoid duplicate reminders.
8. Security
Data is encrypted in transit and at rest, workspaces are isolated from each other at the database level, certificates live in private storage and are shared only through short-lived links, and access is limited to the roles a workspace admin defines. There is more detail on the security page.
9. Your rights
Where the GDPR or similar laws apply, you can ask to access, correct, export, restrict, or delete your personal data, and object to processing based on legitimate interests. Write to safetytracker@xack.dev and we will respond within the time the law allows. You also have the right to complain to your local supervisory authority.
10. If your employer keeps your data here
If your employer or another organisation invited you to a workspace, they decide what is stored about you, and they are the ones to contact first about access or deletion — we will help them respond. We will also pass on a request you send us directly if we can.
11. Children
The service is for workplaces and is not directed at children. We do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We will post any update here with a new “last updated” date, and tell workspace admins about material changes before they take effect.
13. Contact
Privacy questions and requests: safetytracker@xack.dev.
