OffDuty HQ legal
Privacy Policy
Effective September 9, 2026
This policy explains how OffDuty HQ collects, uses, shares, protects, and retains information when people use our website, installed web app, and related services. It applies to Officer, company, and platform-administration accounts.
1. Information we collect
Account and profile data. We may collect legal name, email address, phone number, law-enforcement department, account role, authentication identifiers, and company membership or approval status. If you use Google sign-in, we receive basic account information made available through that sign-in flow; we do not receive your Google password.
Officers may also provide optional application details: preferred name, employing agency city, state and ZIP code, rank or title, employment type, years of service, education level, languages, preferred work counties, training areas, and assignment interests. These are self-reported details. The application does not request a home street address, birth date, government ID number, medical information, or banking information.
Company and operational data. Companies may provide client, site, venue, event, post-order, availability, schedule, shift, pay-setting, role-permission, notice, and officer-approval information. Company account records may also include company contact email, business address, security-company license number, and a versioned responsibility acknowledgement with the accepting Administrator, date, request ID, and profile snapshots.
Time and location data. Check-in and checkout records include their date and time. Precise device location is requested and captured only when a user performs a check-in or checkout action, when the device and browser permit it. Companies may add or correct time records, and the service preserves an audit history of corrections.
Incident reports. A report may include scheduled-assignment facts, incident date and time, specific location, incident type, persons involved, narrative, responding agencies, case numbers, injury or property-damage details, and uploaded photos or documents.
Technical and billing data. We may collect device, browser, IP address, security, diagnostic, notification-delivery, and service-usage records. Payment providers process payment-card information; OffDuty HQ may receive transaction, subscription, invoice, and billing-status information rather than a complete card number.
2. How we use information
We use information to authenticate users; operate company-isolated workspaces; manage approvals and permissions; present availability, schedules, open shifts, post orders, time records, and reports; send requested email and push notices; support billing; troubleshoot the service; prevent abuse; preserve audit history; and comply with applicable obligations.
OffDuty HQ does not independently verify an Officer's identity, sworn status, department employment, or authorization for secondary employment. Companies remain responsible for their own onboarding and verification decisions.
3. Company separation and visibility
Company workspaces are separated by access controls. A company's users may access only that company's operational information, subject to the permissions assigned by its administrator. An Officer may see detailed calendars, rosters, locations, and company information only for companies that have approved that Officer.
Before approval, discovery information is limited to general opening details such as security-company name, assignment type, general area, compensation, tax classification, and available time. Detailed site addresses, rosters, and private company calendars are not disclosed through discovery. Platform administrators may access data when reasonably necessary for support, security, billing, or repair.
4. When information is shared
We share operational information with the company to which it belongs and with users that company has authorized. Shift-linked incident reports are routed only to the company responsible for the scheduled assignment. An Officer's interest in an unapproved company's opening may send the Officer's contact information to that company so the company can decide whether to begin onboarding.
Expanded Officer application details are available to the Officer and OffDuty HQ’s Master Administrator. They are shared with company approvers only when the Officer enables application sharing and has a pending request or an active approval with that company. Officers can update these details or turn sharing off in My application. Turning sharing off prevents subsequent company access through OffDuty HQ; it cannot remove information a company already viewed or retained. Expanded details are not included in general rosters or exports.
We may use service providers for identity, hosting, storage, email, push notifications, payments, monitoring, and customer support. They may process information only to provide those services under their applicable terms. We may also disclose information when required by law, to protect safety or rights, or as part of a merger, financing, reorganization, or sale. We do not sell personal information or use it for third-party behavioral advertising.
5. Retention and deletion
Incident reports and their attachments are retained in OffDuty HQ for 60 days after submission and are then scheduled for deletion. Companies are responsible for downloading records they need before that period ends. Deletion from active systems may not immediately remove a copy already downloaded by a company or a short-lived copy in a secured backup or system log.
Other account, scheduling, time, billing, audit, and security records are kept while reasonably needed to operate the service, maintain the account or company relationship, resolve disputes, protect the platform, and meet applicable obligations. We delete or de-identify information when it is no longer reasonably needed.
6. User and company responsibilities
Incident reports and attachments can contain sensitive information. Users must upload only information they are authorized to share and should avoid unnecessary personal, medical, criminal-justice, or confidential information. OffDuty HQ is an operational scheduling and reporting tool, not an evidence-management system or a replacement for an agency or company records-retention system.
Company administrators control their users, roles, Officer approvals, and access. Companies should promptly revoke access that is no longer appropriate and should export records they are independently required to retain.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including managed authentication, server-side authorization checks, tenant separation, and audit records. No online service is risk-free, so users must protect their credentials and promptly report suspected unauthorized access.
8. Choices, access, and communications
Users may update certain profile and availability information in the service. Device and browser settings can control push notifications and location access, although disabling them may prevent related features from working. Operational messages about assignments, calloffs, security, or account administration may still be necessary to provide the service.
To request access to, correction of, or deletion of information, email admin@offdutyhq.com. Some information may need to be handled by the company that controls the applicable workspace, and some records may be retained when reasonably necessary or required.
Company agreement execution records
When an authorized representative accepts a company agreement, we retain the company legal name, business address and notice email; representative name, title and verified account email; authenticated account reference; exact reviewed terms, version and integrity hashes; affirmative acknowledgments; server-recorded acceptance time and timezone; and a separate execution receipt. Applicable accepted resource orders are retained separately. Agreement acceptance does not request GPS, government identification or a drawn signature.
We use these records to document the transaction, deliver its confirmation, provide protected copies, resolve disputes and meet applicable obligations. Authorized company administrators may retrieve their company’s records; ordinary Officer accounts do not automatically receive access. Provider administrative retrieval is restricted and audited. Agreement evidence is separate from incident reports and is not erased by the 60-day incident cleanup or ordinary company closure. Separate retention and preservation review applies; contact Support for authenticated recovery when ordinary account access has ended.
9. Age, changes, and contact
OffDuty HQ is for adults and is not directed to children under 18. We may update this policy as the service changes. The effective date at the top identifies the current version, and material changes may also be communicated through the service or by email.
Questions about this policy may be sent to admin@offdutyhq.com.
