CheckpointGuard
Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains how CheckpointGuard collects, uses, stores, shares, and protects personal and operational data through our website, web dashboard, Android Admin App, Android Guard App, NFC tag order pages, and related services.
CheckpointGuard is a security operations platform for security companies, hotels, resorts, patrol teams, and multi-location guard operations. It helps authorized users monitor guard activity, prove patrols with NFC checkpoints and geofences, respond to SOS alerts, review operational logs, manage schedules, and prepare operational reports.
1. Who we are
CheckpointGuard is operated by Ioannis Chorafas. CheckpointGuard is the product/trading name used for the service.
Operator / legal name: Ioannis Chorafas
Address: Agios Nikolaos, Crete, 72100, Greece
Country: Greece
Privacy contact email: [email protected]
For privacy questions, data requests, or account deletion requests, contact us at:
2. Services covered by this Privacy Policy
This Privacy Policy covers:
- CheckpointGuard website
- CheckpointGuard web admin dashboard
- CheckpointGuard Android Admin App
- CheckpointGuard Android Guard App
- Firebase login and authentication services
- NFC tag purchases and order pages
- Aegis AI features
- related APIs, notifications, and support services
3. Users of CheckpointGuard
CheckpointGuard is intended for business and operational use by authorized users, including:
CheckpointGuard is not intended for children.
- security company owners and administrators
- hotel or site supervisors
- patrol supervisors
- security guards
- approved company staff
4. Data we collect
Depending on the user role, app permissions, customer package, customer configuration, and enabled features, we may collect or process account and identity data, numerical face-verification templates, admin app and web dashboard data, guard app location data, NFC checkpoint data, geofence data, SOS alert data, messages and uploaded content, scheduling and payroll-ready review data, device and technical data, website analytics data, marketing/demo request data, and NFC tag order, Stripe payment, billing, and shipping data.
Some features are available only on certain packages. For example, live GPS and trail playback may be enabled only for Gold and Platinum customers, and Aegis AI may be enabled only for Platinum customers. If a feature is not enabled for a customer, the related data may not be collected or processed for that customer, except for security, account, audit, billing, or operational records required for the service.
Account and identity data may include name, email address, user ID, authentication identifiers, role, assigned company, hotel, or site, profile image if uploaded, account status, and access permissions.
Admin app and web dashboard data may include admin login information, admin actions and activity logs, selected hotels or sites, viewed guard operational data, viewed guard location data, SOS alert handling, NFC checkpoint management, geofence management, messages and operational notes, report and scheduling activity where enabled, and push notification tokens where notifications are enabled.
The Android Admin App may use the admin device location while the app is open and the admin is using map edit tools, such as placing NFC checkpoints or geofences. This location is used to suggest a checkpoint or geofence position on the map, and the admin can adjust the marker manually. The Admin App does not use this for continuous admin tracking or background admin location tracking.
The Android Guard App may collect device location data during active patrol or active shift workflows, including latitude and longitude, device GPS timestamp, server received timestamp, GPS accuracy meters, speed or provider/source where available, recent movement history, live guard location, guard trail/history for selected dates and time ranges, geofence visit signals, and site arrival or exit context.
The Android Guard App may continue collecting location during an active patrol or active shift while the screen is off, the app is in the background, or the app is not visibly open, depending on app/device settings, customer configuration, package, and app workflow. This may occur through an active foreground tracking service/notification. Location may be used for active patrol/shift tracking, live monitoring, SOS context, geofence visits, patrol history, and operational proof. Tracking should stop when patrol or shift tracking is stopped, the shift ends, the user signs out, or tracking is disabled according to the app/customer workflow. Authorized admins can view guard location only according to their role, site, hotel, operation-sector, and package permissions. Location is not used for unrelated advertising.
NFC scans are used to verify patrol visits and create operational records. Geofence data is used for site coverage monitoring and patrol review. SOS alerts are intended to notify authorized supervisors and create an operational record. CheckpointGuard does not replace emergency services.
Payments are processed by Stripe or another payment processor. We do not intentionally store full payment card numbers on our own servers. Stripe may process payment information according to its own terms and privacy policy.
Face verification and biometric data
Where a customer enables face verification for an authorised work, shift, or attendance workflow, the Android Guard App captures a face image and processes it locally on the Guard device. The app converts the image into a 48-value numerical verification template using the identified on-device template model. The raw image is deleted after local processing, is not uploaded to CheckpointGuard, and is not stored by the CheckpointGuard backend.
The numerical template is personal data linked to the relevant guard or employee record; it is not anonymous. The app transmits the template over HTTPS with its model version and the minimum verification context required for the operation. That context may include the authenticated user reference, employee and site context verified by the server, enrolment or verification time, device identifier, and location or accuracy metadata where the workflow supplies it. The backend derives the authenticated user and permitted organisation/site scope from Firebase authentication and server-side assignments rather than accepting client-selected ownership.
The template is stored as numerical data in the CheckpointGuard payroll PostgreSQL database and is used only to compare a later on-device template for authorised identity verification. Access is restricted by Firebase authentication, server-side role and site checks, and database access controls. Organisation administrators receive enrolment status, verification results, and authorised audit information; the application does not provide them with the underlying numerical template.
A template is retained until it is replaced by re-enrolment, cleared by an authorised administrator, the linked employee record is deleted, or an eligible verified deletion request is completed. Verification audit records may be retained separately where required for legal, security, fraud-prevention, contractual, accounting, audit, dispute-resolution, or legitimate operational reasons; those audit records do not contain the template or raw face image.
CheckpointGuard does not use the face image or numerical template for advertising, marketing, emotion analysis, race or ethnicity analysis, gender analysis, unrelated employee surveillance, or general AI-model training. The template is not sent to Aegis or another AI system. Infrastructure providers that host or secure the CheckpointGuard backend or database may process the encrypted-in-transit data only as service providers acting on CheckpointGuard's instructions; it is not sold or supplied to advertising providers.
5. Aegis AI
CheckpointGuard may include an AI assistant called Aegis. Aegis is designed to help authorized admins understand operational data, such as guard status, SOS alerts, NFC scans, geofence visits, messages, patrol activity, schedules, and report context.
Where Aegis AI features are enabled, CheckpointGuard may process admin prompts, AI responses, selected operational context, context JSON, findings, severity, recommendations, audit logs, conversation messages, and metadata. Aegis only uses data the authorized admin is permitted to access and is decision-support only. Aegis does not override role, hotel, site, operation-sector, package, or feature permissions.
Where enabled, Aegis prompts, responses, interactions, feedback, reports, response reports, redacted response previews, request identifiers, and related safety logs may be stored for security, debugging, quality improvement, abuse prevention, operational review, and Super Admin review.
Aegis responses may be reported or flagged from inside the Android Admin App where available. Aegis response reports may include reporting admin ID/email, timestamp, reason, optional note, hotel/site scope, app/platform, redacted response preview or response/request ID, and demo/test marker where applicable.
Aegis may summarize, explain, warn, or suggest actions based on data the admin is already allowed to access. Aegis can make mistakes and should not be treated as a replacement for supervisor judgment, emergency services, legal advice, payroll decisions, safety procedures, or safety-critical decision-making. Important operational, payroll, safety, or emergency decisions must be verified and confirmed manually by an authorized human user.
Where enabled, Aegis may proactively notify admins about operational issues, such as SOS alerts, stale guard activity, overdue patrol activity, or other configured findings. Aegis does not have permission to access data outside the permissions of the authenticated admin account.
6. How we use data
We use data to provide the CheckpointGuard platform, authenticate users, manage roles and permissions, perform authorised face enrolment and identity verification, show live guard activity to authorized admins, record patrol activity, verify NFC checkpoint scans, detect geofence visits, send SOS alerts and notifications, support operational messages, generate logs and operational reports, support scheduling and payroll-ready review where enabled, process NFC tag orders, ship physical products, provide support, maintain security and prevent misuse, troubleshoot bugs and improve reliability, and comply with legal, accounting, tax, and contractual obligations.
We do not sell personal or sensitive user data.
7. Legal basis for processing
Where GDPR applies, we process personal data based on performance of a contract, legitimate interests in providing and securing security operations software, consent where required, compliance with legal obligations, and protection of vital or operational interests in urgent situations where applicable.
Customer organizations using CheckpointGuard are responsible for informing their staff and guards about their internal use of the platform, including location tracking, patrol monitoring, and operational reporting.
8. How we share data
We may share data only where necessary to provide, secure, or support the service. Numerical face-verification templates are not shared with customer administrators, advertising providers, Aegis, or general AI systems. They may be processed by infrastructure providers that host or secure the CheckpointGuard backend or database, acting only as service providers under CheckpointGuard's instructions. Other data may be shared with the customer organization that manages the user account, authorized admins and supervisors within permitted company/site access, hosting and database providers, Firebase/Google authentication services, Google Maps or location service providers, push notification providers, email providers, analytics providers where enabled, Stripe or payment processors, shipping/delivery providers where needed for NFC tag orders, AI infrastructure or AI service providers where Aegis is enabled, and legal authorities where required by law.
We do not sell personal data.
9. Data security
We use technical and organizational measures designed to protect data, including HTTPS encryption in transit, Firebase authentication, role-based access controls, hotel/site-level access restrictions, server-side authorization checks, scoped operational broadcasts, rate limits on sensitive endpoints, logging and monitoring, restricted access to operational data, and secure handling of secrets and configuration.
No system can be guaranteed completely secure, but we work to protect personal and operational data from unauthorized access, misuse, alteration, or loss.
10. Data retention
We keep data only for as long as needed for the purposes described in this policy, unless a longer retention period is required for legal, accounting, tax, security, audit, contractual, or legitimate operational reasons.
Face-verification templates are kept until replacement, authorised clearance, deletion of the linked employee record, or completion of an eligible verified deletion request. Other retention periods may vary by data type, including account data, patrol and operational records, location history and guard trails, SOS alerts and logs, NFC scans and geofence visits, payment/order records, technical logs, and AI logs if stored in the future.
11. Account deletion and data deletion
Users may request deletion of their account or related personal data through https://checkpointguard.com/account-deletion/ or by contacting [email protected].
In the Android Admin App and web account page, authorized users may also initiate an account deletion or data deletion request.
After verification, CheckpointGuard will delete or anonymize the personal account information and associated personal data covered by a valid deletion request, including an eligible face-verification template, except for information that must be retained for legitimate legal, security, fraud-prevention, contractual, accounting, audit, dispute-resolution, or operational reasons.
An authorised administrator may clear a guard's face-verification template through the applicable shift-verification settings. Re-enrolment replaces and deletes the previous template, and deleting the linked employee record deletes its stored template. The underlying numerical template is not included in ordinary administrator views or exports.
Some data may be retained where required or justified for security, fraud prevention, legal obligations, accounting or tax obligations, contractual obligations, dispute resolution, audit logs, operational records required by the customer organization, and safety or SOS-related accountability.
Deleting an admin account does not automatically delete all company, hotel, guard, patrol, SOS, NFC, geofence, invoice, or operational records unless the requester is authorized and the deletion is legally and operationally appropriate.
Company or workspace deletion may require verification of authority and may be handled as a separate request.
12. User rights
Depending on applicable law, users may have rights to access personal data, correct inaccurate data, request deletion, restrict processing, object to certain processing, request data portability, withdraw consent where processing is based on consent, and lodge a complaint with a data protection authority.
To exercise these rights, contact: [email protected]
13. Customer organization responsibility
CheckpointGuard is used by businesses and organizations for security operations. Customer organizations are responsible for assigning authorized users, informing guards and staff about monitoring, ensuring they have a lawful basis for location and patrol tracking, configuring user permissions correctly, complying with employment, labor, privacy, and security obligations, deciding internal retention rules where configurable, and handling internal employee notices and approvals where required.
14. International data transfers
Some service providers may process data outside the user’s country. Where required, we use appropriate safeguards for international transfers, such as contractual protections or other lawful transfer mechanisms.
15. Cookies and website tracking
Our website may use cookies or similar technologies for website functionality, analytics, security, and performance measurement.
Users may control cookies through browser settings or cookie preference tools where available.
16. Children
CheckpointGuard is not intended for children and does not knowingly collect data from children.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date above.
If changes are significant, we may provide additional notice where appropriate.
18. Contact
For privacy questions, data requests, or complaints, contact:
Ioannis Chorafas
Agios Nikolaos, Crete, 72100, Greece
Email: [email protected]