1. Scope
This Privacy Policy applies to websites, applications, integrations, and services operated by ScanOne Solutions, including SecureOne and ScanOne SecureAccess. A customer or venue may provide an additional notice for a particular deployment. That notice controls the customer's collection and use of information for that deployment.
Where an organization determines why and how information is processed, that organization acts as the data controller and ScanOne Solutions may act as its service provider or processor. ScanOne Solutions acts as a controller for its own account, website, security, and business records.
2. Information we collect
Information you provide
We may collect your name, verified email addresses and phone numbers, account identifiers, organization memberships, credentials, preferences, consent choices, support communications, and information you choose to add to a SecureOne profile.
Connected account and integration information
When you choose to connect a ticketing service, mailbox, membership system, wallet, or other provider, we receive the information necessary to establish the connection and provide the requested feature. Depending on the provider and your authorization, this may include provider account identifiers, access tokens, message metadata and content, ticket or order details, membership status, subscription information, and connection activity.
Device and service activity
We may collect device, browser, network, diagnostic, authentication, audit, and security-event information. ScanOne deployments may also record access decisions, reason codes, credential status, and the time and location of an access interaction.
Biometric information
Some deployments may offer optional facial verification or another biometric capability. Before collecting biometric information, the applicable experience must present a separate notice describing the information, purpose, and retention period and obtain the consent or release required by law. These general terms do not constitute biometric consent. A usable non-biometric path should remain available.
3. How we use information
We use information to:
- create, secure, and support accounts and verified contact methods;
- match authorized tickets, memberships, orders, and credentials to a person;
- provide consent-based enrollment and physical-access decisions;
- operate read-only integrations selected by the user or an authorized organization;
- detect fraud, misuse, replay, unauthorized access, and service failures;
- maintain audit, consent, revocation, and deletion records;
- improve reliability, accessibility, and performance; and
- meet legal, safety, contractual, and compliance obligations.
We do not use protected biometric information or linked mailbox content for behavioral advertising, and we do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
4. Mailbox connections
FORGE SecureOne Mail Broker is the production connector that lets a person link a verified Google or Microsoft mailbox to SecureOne. The person initiates the OAuth connection and chooses the discovery categories. Eligible tickets, travel records, purchases, subscriptions, memberships, account notices, and security notices can then be organized into the appropriate SecureOne category. The connection may be disconnected at any time.
We request read-only access where the provider supports it. We do not use that permission to send, move, alter, or delete messages. The connector examines message headers, metadata, and only the content needed to identify a user-authorized record. It retains normalized records and provenance needed to provide the feature rather than complete message bodies or attachments. It is not designed to collect or retain passwords, password-reset links, magic links, one-time authentication codes, ticket barcodes, pickup codes, or other login or redemption secrets.
OAuth credentials are protected and used only to maintain the connection the person requested. Disconnecting the mailbox stops ongoing access. A person may also revoke access through Google or Microsoft and may request deletion of retained Google-derived or Microsoft-derived records. We may preserve narrowly limited security, consent, audit, or legal records when required to protect the service or comply with law.
ScanOne Solutions' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. How we disclose information
We may disclose information:
- to the organization or site you intentionally connect to;
- to service providers that operate infrastructure, security, identity, communications, or support functions for us;
- to a provider when necessary to complete an action you request;
- to protect people, rights, systems, and property or investigate misuse; or
- when required by law, legal process, or a valid governmental request.
We do not disclose connected-account information to an organization merely because you belong to that organization. Access is limited by purpose, role, consent, and the applicable connection.
6. Retention and deletion
We retain information only for the period reasonably necessary for the stated purpose, security, contractual obligations, dispute resolution, and applicable law. Retention may vary by customer deployment and data category. Raw biometric captures should be deleted after template creation or verification unless a separate notice, consent, and legally approved purpose requires otherwise.
Protected biometric templates are subject to a purpose-specific retention and destruction schedule. When the purpose is satisfied, consent is withdrawn, or the applicable retention limit is reached, the template is scheduled for deletion subject to lawful exceptions. Backups and audit evidence may age out on separate protected schedules.
7. Security
We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including encryption, tenant separation, role-based access, signed and scoped assertions, audit controls, and edge processing where appropriate. No method of storage or transmission can be guaranteed completely secure.
8. Your choices and rights
Depending on your location and relationship with ScanOne Solutions, you may have the right to access, correct, delete, obtain, or restrict certain information and to withdraw consent. SecureOne is designed to let users review verified contact methods, connected services, enrollment state, and consent choices.
You may disconnect a mailbox or provider in SecureOne and may also revoke access directly through that provider. To request privacy assistance or deletion, contact us at info@scanonesolutions.com. We may need to verify your identity before completing a request.
9. Children
ScanOne Solutions services are not directed to children under 13. The initial SecureOne biometric enrollment model excludes minors unless a separately reviewed deployment establishes appropriate authority, notices, safeguards, and legally valid consent.
10. Changes and contact
We may update this policy as our services or legal obligations change. We will publish the revised policy with a new effective date and provide additional notice when required. Questions and requests may be sent to info@scanonesolutions.com.