Privacy Policy
The short version: we collect what we need to run the services you use, we do not sell it, we do not send newsletters, and if you use SentinelVision your camera footage never leaves your own hardware. The long version is below.
Table of Contents
1. Who We Are
SentinelGrid is a software company and managed IT provider operated by Mason Collier, a sole proprietor based in the State of Florida. We build and run the services listed below at sentinelgrid.us and its subdomains. For information collected through our own Services we are the data controller. For data inside a Managed IT client's environment (their mailboxes, files, servers and devices) the client is the controller and we act on their instructions as a processor.
Privacy questions: support@sentinelgrid.us. We aim to respond within 5 business days.
2. What This Policy Covers
This policy applies to:
- sentinelgrid.us: this website, the blog, and the public contact and waitlist forms.
- Client Portal (portal.sentinelgrid.us): one sign-in for clients, contractors and staff: an app directory, a directory of people and companies we work with, and a window onto the support queue.
- Helpdesk (support.sentinelgrid.us): ticketing for Managed IT clients: a customer portal for raising and tracking tickets, a support console for our agents, and an email-to-ticket pipeline.
- Monitor & status pages (status.sentinelgrid.us): uptime checks, heartbeat dead-man's switches, incident tracking, a public status page for our own services and private per-client status pages.
- Fleet & remote support: device inventory and remote access for managed endpoints, built on self-hosted MeshCentral and reached over a private Tailscale network.
- Diagnostics drop box (dbg.sentinelgrid.us): a last-resort channel for a managed machine with no other way in: diagnostics up, fix scripts down.
- SentinelVision: on-premises computer-vision software that runs on hardware you own, detecting weapons, people and vehicles on camera feeds. It is deliberately built without facial recognition.
- Managed IT. The service itself: monitoring, patching, identity and access, network, and a helpdesk staffed by a human. Backups and single sign-on are on the roadmap and not part of the service yet. Currently in open beta. See the Managed IT Service Terms.
- Internal tooling: a shared HR mailbox, a CRM and admin console, a self-hosted asset CDN, and a daily operations checklist. These are ours; you will only touch them indirectly (for example, when you email us).
It does not cover third-party websites we link to, or a client's own internal systems except to the extent we process data in them on the client's behalf.
3. Information We Collect
We collect only what is reasonably necessary and proportionate to run the service you are using, which is the standard the strictest current U.S. state privacy laws (such as Maryland's) set, and nothing below is collected for advertising or resale.
3.1 Information you give us
- Contact and waitlist forms: name, email, company, team size, and what you tell us about your IT problems. Submissions go to our CRM, trigger a notification to us, and send you an automatic acknowledgement.
- Email you send to any @sentinelgrid.us address: the message, headers, attachments and your address. Mail is stored in our systems (Cloudflare Workers KV) and may be forwarded to verified staff addresses. Mail to support addresses becomes a Helpdesk ticket automatically. Mail to HR addresses is read in the HR mailbox by the people responsible for hiring.
- Helpdesk and Client Portal: your email address and name, the organisation you belong to, tickets, replies, attachments, and notes our agents write. Sign-in links are single-use tokens stored only as hashes.
- Job and contractor applications. Whatever you include: CV, portfolio links, correspondence.
- Managed IT onboarding: an inventory of your organisation's machines, accounts, servers, subscriptions and documentation, gathered during the audit and kept as your service documentation.
- Billing details: the billing contact name and email address for your organisation, your business address where you give one, your plan and quantities, and the invoices raised against you. Card numbers are entered on pages hosted by our payment processor and never reach a SentinelGrid system; we can see only the card brand and last four digits as the processor reports them. See Billing & Payment Terms.
3.2 Information collected automatically
- Website analytics. Google Analytics 4 on sentinelgrid.us and the legal and blog pages: pages viewed, approximate location, device and browser, referrer, and a pseudonymous client identifier set by a cookie.
- Server and edge logs: IP address, user agent, request path and timing for every request to any of our services, held by Cloudflare and in our own application logs for security and debugging.
- Monitoring data: for HTTP monitors, response codes and timings of URLs a client asked us to watch; for heartbeat monitors, the time of each ping plus any status and message the client's system chooses to send. Incident history is kept on the status page.
- Managed device data. For enrolled endpoints: hostname, hardware and OS details, installed software, patch state, encryption state, logged-in user, network addresses, and remote-session logs (who connected, when, for how long). We do not run keyloggers or continuous screen recording.
- Diagnostics drop box: diagnostic bundles uploaded from a managed machine, which can contain logs, configuration files and system information. These may incidentally include personal data present on that machine.
- Audit logs: sign-ins, administrative actions, account changes and integration events across the Portal, Helpdesk and Monitor, kept so we can investigate problems and abuse.
3.3 Information from other sources
A client administrator may enrol you by adding your email address or domain, or via a self-registration QR code. Our own apps push events and records about people and companies into the Client Portal so that it holds a complete picture of each relationship.
4. How We Use Information
- To provide, secure and support the Services, including signing you in, routing tickets, alerting on outages, and connecting to managed devices.
- To respond to enquiries, waitlist requests, applications and support tickets.
- To deliver Managed IT: monitoring, patching, account management, documentation and reporting to your organisation.
- To send transactional email: sign-in links, ticket updates, form acknowledgements, outage alerts and service notices. We do not send marketing newsletters and we do not sell or rent your details.
- To understand how the website is used and improve it (analytics).
- To detect, investigate and prevent abuse, fraud and security incidents, and to enforce our Acceptable Use Policy.
- To comply with legal obligations and protect our rights.
Use of AI
How we use AI. We use AI development tools, currently Anthropic's Claude, to help write, review and document our software, our websites, our blog and drafts of documents like this one. A named person reviews, tests and deploys everything before it ships and remains accountable for it under our agreements. Two narrow automated tasks also use Cloudflare Workers AI: writing a daily planning summary for our own operations checklist, and pre-reviewing requests for new HR mailbox addresses.
Where we do not use it. We do not put client data (tickets, credentials, documents, device inventories, monitoring output, email) into any AI tool unless the client has agreed to it in writing for a specific piece of work; our contractor agreements name which tools, if any, are approved for confidential information on each engagement. AI does not answer your support tickets or write to you pretending to be a person. We do not use AI or any automated system to make decisions that have legal or similarly significant effects on a person: hiring, pricing, access to services, or anything else covered by automated-decision-making rules such as the California CPPA regulations, Colorado's revised AI law (SB 25-189, in force January 1, 2027) or the EU AI Act. SentinelVision is a detection aid that draws boxes around objects; it does not identify, categorise or score people (see 8.5).
Training. We do not train AI models on your data, and we use our AI tools under terms that do not train on what we put into them. The tools and their data terms are listed on the Subprocessors & Security Billing & Payments page. If we expand AI use into anything client-facing we will update this policy first.
5. Legal Bases
Where a law such as the GDPR or UK GDPR applies, we rely on: contract (delivering Managed IT, the Helpdesk and Portal to people we have a relationship with); legitimate interests (securing our systems, responding to enquiries, basic analytics, preventing abuse); consent (where required for analytics cookies, and for applications you send us); and legal obligation (retaining records we must keep).
6. Sharing & Disclosure
We share personal data only with:
- Service providers who host and run the Services for us, listed with what they handle on the Subprocessors & Security page. The principal ones are Cloudflare (hosting, storage, email routing), Brevo (transactional email), Google (analytics and fonts), Tailscale (private networking), Pushover (on-call alerts to our staff) and GitHub (source code hosting).
- Your organisation: if you use the Helpdesk or Portal through a client organisation, that organisation's administrators can see your tickets, account status and activity. If your organisation has chosen to work its own support queue, their IT staff see your tickets instead of ours.
- Independent contractors working for SentinelGrid under confidentiality obligations, with access limited to the engagement.
- Authorities where required by law, subpoena or court order, or to protect the safety of any person. We will tell you before disclosing unless legally prohibited.
- A successor if SentinelGrid is sold, merged or wound down, subject to this policy.
We do not sell personal data, and we do not share it with advertisers or data brokers.
7. Cookies & Tracking
- Strictly necessary: session cookies for the Portal, Helpdesk, Monitor admin and internal tools. These are HMAC-signed, HttpOnly, and cleared when you sign out or your account is disabled. The website itself sets no first-party cookies.
- Analytics: Google Analytics (
_gaand related cookies) on sentinelgrid.us. You can block these with a browser setting, an ad/tracker blocker, or Google's opt-out add-on. Google's use of data is described in its privacy policy. - Fonts: pages load type from Google Fonts, which means your browser requests the font files from Google and Google sees your IP address.
- No advertising cookies. We do not run ads or use retargeting pixels.
- Global Privacy Control: if your browser sends the GPC signal, the website does not start Google Analytics at all; we treat it as a universal opt-out, as the California, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland and other state laws require. Our application services set no tracking cookies, so there is nothing further for the signal to switch off. We do not respond differently to Do Not Track, which has no legal or technical standard.
8. Service-Specific Practices
8.1 Helpdesk & Client Portal
Closed systems with no public sign-up. Sign-in is by a single-use emailed link valid for about 15 minutes; tokens are stored as SHA-256 hashes so a database copy cannot be replayed as a login. Unknown addresses get no email, and the sign-in page shows the same message either way so the form cannot be used to discover who our clients are. Disabling a person or a whole client revokes their sessions immediately. Customer-facing replies are emailed; internal notes are never sent to customers.
8.2 Monitor & status pages
Our public status page shows the state of our own services and contains no personal data. Client status pages are private, token-protected URLs; we do not index them and we advise clients to treat the link as confidential. Heartbeat pings are received from client systems and carry only the token, a timestamp, and an optional status and message; we recommend clients do not put personal data in that message.
8.3 Fleet & remote support
We install remote-management agents only on devices a client has enrolled. The agent reports inventory and health and lets our staff open a remote session to support the device. Sessions are initiated by us for support purposes, logged with who connected and when, and where the platform supports it the signed-in user is shown that a session is active. The management server is self-hosted and reachable only over our private Tailscale network, not from the public internet. Clients are responsible for telling their staff that devices are managed.
8.4 Diagnostics drop box
Uploads are kept only as long as needed to diagnose and fix the problem and are then deleted. Because a diagnostic bundle can contain anything present on the machine, we treat every upload as confidential client data.
8.5 SentinelVision
SentinelVision runs entirely on hardware the customer owns, typically a Raspberry Pi capturing camera feeds and a local inference host. Video frames, detections, the event log, annotated snapshots and short clips around weapon detections are stored on that hardware and stay on the customer's premises. The dashboard is reachable only over the customer's Tailscale network. SentinelGrid does not receive, view or store camera footage unless a customer deliberately sends us an excerpt for support, in which case we delete it once the issue is resolved.
By design the system detects object classes (firearms, knives, people, vehicles) and draws a box. It does not perform facial recognition, gait analysis, emotion recognition, licence-plate reading or any other biometric identification or categorisation, and we will not add those capabilities. That is deliberate: it keeps SentinelVision outside biometric-privacy laws such as Illinois BIPA and Texas CUBI, and outside the practices the EU AI Act prohibits outright (Article 5, in force since February 2, 2025): real-time remote biometric identification, biometric categorisation and emotion recognition. The EU's 2026 Digital Omnibus deferred the Act's high-risk obligations to December 2027, but the prohibitions were never deferred and we design against them regardless of where a customer is. Alert notifications are sent using services the customer configures. The customer is the controller of everything SentinelVision records and is responsible for notice, signage, retention and lawful use.
8.6 Email to @sentinelgrid.us
Inbound mail is received by a Cloudflare Email Worker, stored in Workers KV organised by recipient address, and forwarded to verified staff addresses. Several of our tools read that store: the Helpdesk (to create tickets), the HR mailbox, and the admin console's conversation view. Conversations are grouped by the pair of addresses involved, so earlier messages between you and us may be shown alongside new ones.
8.7 Website forms
Forms post to our CRM API. Each submission is stored, a notification goes to us, and an automatic reply goes to you. Forms include a hidden honeypot field to catch bots; a real visitor never sees or fills it. As the form says: no newsletter, no reselling your details.
8.8 Billing portal
The billing portal at billing.sentinelgrid.us shows your plan, next billing date and invoice history. Those figures are read from Stripe when you load the page and are not copied into our database. Our own store holds a mapping from your organisation to its Stripe customer record, your sign-in session, and a log of billing events for support and audit.
Sign-in is through your SentinelGrid portal account; the billing portal has no password of its own. Which people at your organisation can see billing is controlled by you, and an ordinary member account with no billing grant is refused. Payment and payment-method data is held by Stripe under its own privacy policy; Stripe is listed on our Subprocessors page.
9. Data Retention
- Form submissions and enquiries: kept while we are in contact and for up to 24 months after the last exchange, then deleted unless the relationship became a client engagement.
- Inbound email: retained in our mail store while the mailbox is active; we review and prune old mail periodically. Mail that became a ticket follows ticket retention.
- Helpdesk tickets and Portal records: for the life of the client relationship plus 12 months, so there is a service history on exit; then deleted or handed over at the client's request.
- Monitoring and incident history: check results are rolled up over time; incident records are kept for the life of the monitor.
- Device inventory and remote-session logs: for the life of the device enrolment plus 12 months.
- Diagnostics uploads: until the issue is resolved, then deleted.
- Job and contractor applications: 12 months unless you ask us to delete them sooner, or you join us.
- Audit and security logs: 12 months.
- Backups: where we take backups of our own systems, retained data may persist in them for a further 30 days.
10. Security
We are a small shop and we try to make that a strength rather than an excuse. What we actually do:
- Passwordless sign-in for client-facing services; tokens stored hashed; sessions signed with a secret held only in the Worker environment.
- No public sign-up anywhere; enrolment is by an administrator or a client-specific link.
- Internal admin surfaces, the fleet server and SentinelVision dashboards are not exposed to the public internet; they sit behind a private Tailscale network or an authenticated Cloudflare Tunnel.
- Secrets live in Cloudflare's secret store, never in source control. Every service is in version control and deployed from it, so a fix cannot be silently lost.
- TLS everywhere, security headers on the website, and Cloudflare in front of all public endpoints.
- Contractor access is scoped to the engagement and removed when it ends.
No system is perfectly secure. If we learn of a breach affecting your data we will notify you without undue delay, and our target is within 72 hours of confirming it, which is also the GDPR deadline for notifying a supervisory authority. Under the Florida Information Protection Act (§ 501.171, Fla. Stat.) we must notify affected Florida residents no later than 30 days after determining a breach of covered data, and the Florida Department of Legal Affairs if 500 or more Florida residents are affected; we treat those as outer limits, not targets. For Managed IT clients we notify your primary contact so you can meet your own obligations under FIPA, HIPAA, PCI DSS or any other regime that applies to you. If you find a vulnerability, please tell us at support@sentinelgrid.us. We will not take action against good-faith research that respects our Acceptable Use Policy. More detail is on the Subprocessors & Security page.
11. Your Rights
Depending on where you live you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate data.
- Have your data deleted, subject to retention we are legally required or contractually obliged to keep.
- Restrict or object to processing based on legitimate interests.
- Receive your data in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority.
To exercise any of these, email support@sentinelgrid.us from the address concerned, or raise a ticket if you are a Helpdesk user. We will verify your identity, respond within 30 days (extendable once by 45 days for complex requests, and we will tell you if so), and never charge for a reasonable request. An authorised agent may act for you with your written permission.
Appeals. If we decline a request, reply within 60 days saying you are appealing. Someone other than the original reviewer will look at it and answer within 45 days with reasons, and with details of how to complain to your state attorney general or, in the EU/UK, your supervisory authority.
11.1 U.S. state privacy laws
As of 2026, twenty U.S. states have comprehensive consumer privacy laws in force: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island among them, and more have been enacted. Almost all of them apply only to businesses above a size threshold that SentinelGrid does not meet, and several exempt data we process as a processor for a client. We extend the rights above to everyone anyway, wherever they live. We do not sell personal data, do not process it for targeted advertising or profiling, and do not collect sensitive data as those laws define it except where a Managed IT client has placed it in an environment we manage, in which case we act only on the client's instructions.
Florida. The Florida Digital Bill of Rights (§ 501.701 et seq., Fla. Stat.) applies its controller duties to businesses with more than US$1 billion in revenue; we are not one, but we honour its consumer rights: confirmation, access, correction, deletion, portability and opt-out of sale, targeted advertising and profiling. We never sell sensitive data, which Florida forbids without consent regardless of a business's size. We do not knowingly process the personal data of anyone under 18 for advertising or profiling.
California. We have not sold or shared personal information in the preceding 12 months and do not discriminate against anyone who exercises their rights. The categories we collect, their sources and purposes, and the parties we disclose them to are set out in sections 3, 4 and 6.
If you use a Service through a client organisation, that organisation is the controller for much of your data; we will pass your request to them within 10 business days and help them respond.
12. Children's Privacy
Most of our Services are for adults and businesses, and we do not knowingly collect personal data from children under 13 through them. If you believe a child has given us data through one of those Services, contact support@sentinelgrid.us and we will delete it promptly.
One product is different, and follows the Children's Online Privacy Protection Act (as amended by the FTC's 2025 rule, fully effective April 22, 2026): Rally, our classroom quiz game, is used by students under a teacher's direction. Students have no accounts and give no name, email or other personal information; Rally relies on the school's authorisation for classroom use and deletes game data 12 months after a game at the latest. See Rally: Children, COPPA and FERPA.
VerifyBlox is for people 13 and older only, because it works through Discord and Discord does not allow accounts for anyone under 13. It asks every user their age, and deletes at once everything it held about anyone who says they are under 13. See VerifyBlox for parents.
Sixteen- and seventeen-year-olds may use our other Services only under adult supervision as described in the Terms; we do not sell the data of, or target advertising to, anyone we know to be under 18. Managed IT clients that are schools or otherwise handle children's data are the controller of that data; we process it only under the FERPA Student Data Addendum or the client's written instructions, and never for our own purposes.
13. International Transfers
We are based in the United States and our providers operate globally; Cloudflare in particular runs at the network edge nearest the visitor. If you are outside the U.S., your data will be transferred to and processed in the U.S. and wherever our providers operate. For transfers from the EEA, Switzerland and the UK we rely on the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions) where a provider is certified, and otherwise on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum as incorporated in our providers' data-processing terms. Where a client asks us to keep data in a particular region, we will say in the statement of work whether we can.
14. Third-Party Services
A complete, maintained list of the providers that handle data for us, covering what each one does, what it sees and where it is based, is kept on the Subprocessors & Security page so that this policy does not go out of date every time infrastructure changes.
Payments are processed by Stripe, Inc. under the Stripe Privacy Policy. See Billing & Payment Terms.
15. Changes to This Policy
We update this policy when our services or the law change. The version and date at the top will change, and material changes will be announced on the blog and by email to clients at least 14 days before they take effect. Previous versions are available on request.
Version 2.1 (August 23, 2026): added the U.S. state privacy law notice, appeal process and Global Privacy Control commitment; updated the children's, AI, international-transfer and breach-notification sections for the amended COPPA Rule, Colorado SB 25-189, the EU AI Act and Digital Omnibus, the Data Privacy Framework and Florida's FIPA; corrected section numbering. Version 2.2 (August 24, 2026): rewrote the Use of AI section to say plainly that AI development tools help build our software and documents, and where they are never used.
Version 2.3 (September 4, 2026): added the billing portal to the service-specific practices, named Stripe as the payment processor, and described the billing information we hold. See the Billing & Payment Terms.
Version 2.4 (September 13, 2026): removed backups from the description of Managed IT, because the backup service is on the roadmap and not delivered yet, and described SentinelGrid as a software company.
Version 2.5 (September 19, 2026): corrected the children's section, which said none of our Services is directed at children. Rally is used in classrooms and VerifyBlox accepts children under 13 with a parent's verified consent; both follow COPPA, and the section now says how.
Version 2.6 (September 19, 2026): VerifyBlox no longer accepts children under 13 with a parent's consent, because Discord does not allow accounts for anyone under 13; it now deletes the data of anyone who says they are under 13.
16. Contact Us
SentinelGrid, operated by Mason Collier, sole proprietor, Florida
Privacy and data requests: support@sentinelgrid.us
Managed IT clients: support@sentinelgrid.us or support.sentinelgrid.us