Legal
Acceptable use policy
Effective 25 September 2026. Briare Brothers LLC, 30 N Gould St Ste N, Sheridan, WY 82801.
Who this applies to
This policy applies to every use of Badgewright and forms part of the terms of service. It applies to you and to everyone you give access to. If you invite someone, you are responsible for what they do.
Badgewright is licensed for your own organization: your staff, your students, your contractors, your visitors. It is not licensed for you to run a badging bureau for unrelated organizations without a written agreement with us. If you want to do that, ask; the answer is often yes.
Data you may not put in
You may define whatever fields you need, and we do not inspect them. That makes the list of things not to put in worth stating plainly. Do not upload or store:
- personal data you have no lawful basis or authority to hold, including photographs taken without the notice or consent your jurisdiction requires;
- health or medical information. Badgewright is not built for protected health information, we will not sign a HIPAA business associate agreement, and it should not be treated as a HIPAA-eligible service. "Has an inhaler" does not belong in a badge database;
- social security numbers, driver's licence numbers, passport numbers or financial account numbers. A badge needs an internal identifier, and an internal identifier is what you should put on it;
- criminal history, immigration status, or information about a person's religion, sexual orientation, trade union membership, or the exercise of any legal right;
- biometric identifiers of any kind: no fingerprints, no iris scans, no facial templates or faceprints. A photograph for printing on a card is fine and is what the product is for;
- data belonging to a different organization, or anything you are contractually forbidden from moving;
- malware, or a file whose purpose is to attack whoever opens it.
If your organization genuinely needs a field we have told you not to create, write to us before you create it rather than after. There is usually a way to do what you need without holding the thing.
Uses we will not support
Badgewright produces identity cards. It is not an access control system, an attendance system or a tracking system, and we will not support its use as the data layer for one. Specifically, you may not use it, or the data in it:
- to build or feed a facial recognition system, or to supply photographs to one;
- to track the movements or location of individuals, or to infer their attendance or behaviour;
- to profile people by race, ethnicity, religion, national origin, immigration status, disability or any other protected characteristic;
- to supply personal data to a law enforcement or immigration authority other than in response to lawful process served on you, which is a decision for your organization and its counsel, not a feature of ours;
- to harass, stalk or endanger anyone;
- for any purpose that would be unlawful discrimination.
The print history exists so a school can answer "who printed this card, and when". It is a record of badge issuance, and it should not be repurposed as a record of people.
Technical limits
Do not:
- share a single sign-in between people, which defeats the audit log and is the one rule whose breach makes every other record less useful;
- circumvent record limits, plan limits or rate limits, or create multiple organizations to avoid them;
- automate access other than through an interface we publish for that purpose;
- attempt to reach another customer's data, or any part of the system you have not been granted;
- overload, disrupt or degrade the Service for anyone else;
- resell, sublicense or white-label the Service without a written agreement.
Security testing
You may test the security of your own organization's data, and we would rather you did than did not. Test only your own organization, do not degrade the Service for anyone else, do not access or keep another customer's data, and tell us what you find at security@badgewright.com before you tell anyone else.
Do that, and section 9.1 of the terms applies: we will not pursue or support a legal claim against you. Denial of service testing is the exception and needs written agreement first, because we cannot tell it apart from the real thing.
What happens if this is breached
We will tell you what the problem is and give you a reasonable chance to fix it. We will suspend first and explain afterwards only where somebody is being harmed now, where the law requires it, or where the Service itself is at risk.
Any suspension will be as narrow as the problem allows. We will not delete your data as a punishment, and if matters end with termination, the export window in section 13 of the terms still applies.
Reporting a problem
To report misuse of Badgewright, including by another customer, write to support@badgewright.com. To report a security vulnerability, write to security@badgewright.com. Tell us what you saw and when. You do not need to be a customer to report either, and we will not need your name.
Questions about this document: legal@badgewright.com. Questions about your own data: privacy@badgewright.com. To report a security problem: security@badgewright.com.