Legal
Privacy Policy
Last updated: 27 July 2026
1. Who we are
AlertCore is a product of Digidrop Ltd, a company registered in England and Wales. When we refer to "we", "us", or "our" in this policy, we mean Digidrop Ltd.
We are committed to protecting and respecting your privacy. This policy explains how we collect, use, store, and safeguard personal data when you use the AlertCore website, platform, and our mobile applications (including ShopAssist, HomeAlert, MobilePatrol, and related AlertCore apps).
2. Data we collect
We may collect and process the following data about you:
- Identity data: your name, username or similar identifiers.
- Contact data: your email address, telephone number, and address.
- Location data: approximate and/or precise GPS location from your mobile device when you use our mobile apps, as described in section 3.
- Device and notification data: device identifiers and push notification tokens used to deliver alerts and messages to your iOS or Android device, as described in section 4.
- Technical data: IP address, browser type and version, device identifiers, time zone, and operating system.
- Usage data: information about how you use our platform and apps, including pages or screens visited, features used, and time spent.
- Communications data: messages you send us via contact forms or email.
3. Location data in our mobile apps
Our mobile applications access, collect, and use location data from your device. This includes approximate location and, where you grant permission, precise location (GPS).
How we access location:
- The apps request location permission through your device operating system (for example Android or iOS).
- Depending on the app and how it is configured for your organisation, location may be accessed while the app is in use and, where required for safety features to work reliably, while the app is running in the background.
- You can grant, deny, or later change location permission in your device settings. If you deny or disable location, some safety features (including panic alerting with position) may not work fully.
How we collect and store location:
- When a panic or emergency alert is raised (for example in ShopAssist or HomeAlert), we collect your device location at that time and transmit it to AlertCore systems so your security provider or control room can see where help is needed.
- In officer or field apps (for example MobilePatrol), we may collect location in connection with check-ins, patrol activity, and live duty status so authorised operators can see officer positions.
- Location data associated with alerts, check-ins, and operational activity is stored on our secure servers (and those of our hosting processors) as part of the AlertCore service for your organisation.
How we use location:
- To deliver personal safety and security features—so responders know who raised an alert and where they are.
- To support control-room operations, including dispatch, coverage, and verification of patrol or check-in activity.
- To maintain operational records and audit trails for your organisation's security service.
- We do not use location data for advertising, marketing profiling, or sale to third parties.
Location data is shared only with authorised users within your organisation's AlertCore deployment (for example control-room operators and security providers who manage your service), and with service providers who host or process data on our behalf under data processing agreements. It is not made publicly available.
4. Notifications and critical alerts (iOS and Android)
Our mobile applications on iOS and Android use push notifications—and, where supported and authorised for the app, critical alerts (iOS) or equivalent high-priority / full-screen / bypass-Do-Not-Disturb notifications (Android)—so that safety and operational messages can reach you even when the device is locked, muted, or in Focus / Do Not Disturb mode.
How we access notifications:
- The apps request notification permission through your device operating system.
- On iOS, where Apple has granted the relevant entitlement for the app, we may also use Critical Alerts so urgent safety messages can be delivered with sound even when the device is silenced or Focus is on.
- On Android, we may use high-priority notification channels and, where permitted by the system and your settings, alerts that can interrupt Do Not Disturb for time-sensitive safety messages.
- You can grant, deny, or later change notification (and critical / priority alert) permissions in your device settings. If you disable them, you may miss urgent updates from your security operation.
How we collect and store related data:
- When you allow notifications, we collect and store a push notification token (and related device identifiers) so we can send messages to that device via Apple Push Notification service (APNs), Firebase Cloud Messaging (FCM), or equivalent providers.
- Notification content and delivery metadata needed to operate the service may be processed and stored as part of AlertCore operational records for your organisation.
How we use notifications and critical alerts:
- To notify you of panic or emergency-related events, stand-down / safe confirmations, and other time-critical security messages from your organisation or control room.
- To deliver operational updates required for the AlertCore service (for example dispatch, duty, or account-related alerts).
- We do not use critical alerts or high-priority notifications for advertising or marketing.
Push delivery is handled through Apple, Google, and our infrastructure processors under their terms and our data processing arrangements. Notification permissions are controlled by you in iOS or Android settings.
5. How we use your data
We use your personal data to:
- Provide and manage your AlertCore account, website, and mobile app services.
- Provide safety alerting, location-based response, and related security operations features.
- Send push notifications and, where enabled, critical or high-priority alerts on iOS and Android.
- Process transactions and send relevant account or service messages.
- Respond to enquiries and provide customer support.
- Improve our platform and develop new features.
- Send marketing communications where you have given consent or where we have a legitimate interest.
- Comply with legal obligations.
6. Legal basis for processing
We process your personal data on the following legal bases under UK GDPR:
- Contract: processing is necessary to perform the contract we have with you or your organisation (including providing safety and operational features that rely on location and notifications).
- Legitimate interests: processing is in our legitimate interests, and these are not overridden by your rights.
- Legal obligation: we are required to process data to comply with applicable law.
- Consent: where we have obtained your explicit consent, such as for marketing emails, and where device-level permissions (location, notifications, or critical alerts) are required by your operating system before the app can use those features.
7. Data sharing
We do not sell your personal data. We may share your data with:
- Your organisation and its authorised operators (for example security control rooms and administrators) so they can deliver the AlertCore service, including receiving panic alerts and location.
- Push notification providers (such as Apple and Google) solely to deliver notifications to your device.
- Service providers who process data on our behalf (e.g. cloud hosting, email delivery), under strict data processing agreements.
- Law enforcement or regulatory bodies when required to do so by law.
- Professional advisers such as lawyers and accountants where necessary.
AlertCore Intel data—intelligence submitted by your organisation—is never shared with third parties or made publicly accessible. It is stored securely and visible only to authorised members of your organisation.
8. Data retention
We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy, or as required by law. Account data is retained for the duration of your subscription and for a period of 7 years thereafter for legal and accounting purposes.
Location data linked to alerts, check-ins, and operational activity is retained for as long as needed to provide the security service to your organisation, for operational reporting and audit, and as required by applicable law or your organisation's contract with us. Push notification tokens are retained while your account or device remains registered to receive alerts, and are removed or updated when you sign out, uninstall the app, or the token is invalidated. When data is no longer required, it is deleted or anonymised in line with our retention practices.
9. Your rights
Under UK GDPR, you have the right to:
- Request access to your personal data.
- Request correction of inaccurate data.
- Request erasure of your data (the "right to be forgotten").
- Object to processing or request restriction of processing.
- Request portability of your data.
- Withdraw consent at any time where consent is the legal basis (including withdrawing location, notification, or critical alert permissions in your phone settings).
To exercise any of these rights, please contact us at [email protected].
10. Cookies
We use cookies and similar tracking technologies on our website. For full details, please refer to our Cookie Policy.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. All data is encrypted in transit and at rest, including location data stored as part of the AlertCore service.
12. Changes to this policy
We may update this privacy policy from time to time. We will notify you of significant changes by email or via a notice on our platform. The date at the top of this page indicates when the policy was last revised.
13. Contact us
If you have questions about this policy or how we handle your data, please contact:
Digidrop Ltd
The Well House, 4 Stable Court
Herriard Park, Herriard
Basingstoke RG25 2PL
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.