Legal
Privacy policy
Effective 25 September 2026. Briare Brothers LLC, 30 N Gould St Ste N, Sheridan, WY 82801.
Two kinds of data, two different roles
Badgewright is ID card software. An organization signs up, puts its people into it, and prints badges. That makes two very different kinds of personal data, and this policy treats them separately because the law does.
- Customer Data, where we are the processor
- The records your organization holds about its staff, students or visitors, and the photographs on their cards. Your organization decides what to collect and why; we only do what it asks. In data protection terms your organization is the controller (the business, under US state laws) and we are the processor (the service provider). If you are a pupil, a parent or an employee asking what is held about you, your school or your employer is the right place to ask, and we will help them answer. The data processing addendum is the contract that governs this.
- Account Data, where we are the controller
- The people who sign in to run the software, and people who write to us. Here we decide the purposes, so the rest of this policy is mostly about this.
Data your organization puts in
We hold, on your organization's behalf and under its instructions:
- Records. Whatever fields your organization defines. Typically a name, an ID number, a title or grade, and issue and expiry dates. The fields are yours to choose, so the contents are too.
- Photographs. Uploaded, or taken with a webcam attached to the computer running the browser.
- Card designs and printer profiles. Which include any fixed text and artwork you place on a card.
- Print history. Which card was printed, for which record, by which user, when, which copy it was, and the reason given for a reprint. A snapshot of the design and the record values as printed is kept with the job, because a print history that cannot show what was on the card is not one.
- The audit log. Who changed, imported, exported, printed or deleted what, and when.
We do not decide what goes in any of this, we do not use it for our own purposes, and we do not look at it except as section 9 of the terms describes.
Data about the people who sign in
For each person with a Badgewright sign-in we hold:
- Identity. Name and email address. A job title, if the organization sets one.
- Credentials. A password hash, never the password, using argon2id. Where a Google or Microsoft sign-in is offered and you use it instead, the provider's issuer and subject identifiers and the email address they return.
- Second factors. An encrypted authenticator secret, passkey public keys and their metadata, and hashes of your single-use recovery codes. A passkey's private key never leaves your device, and a recovery code cannot be read back out of what we store.
- Sessions and devices. For each sign-in: the time, how you signed in, the IP address, and the browser's user agent string. The same for a device you have chosen to have remembered.
- Security events. Sign-ins, sign-out, failures, lockouts, password changes and second-factor changes, each with the time, the outcome, the IP address and the user agent.
- Correspondence. What you write to us, and what we write back.
IP addresses and user agents are held for one reason: telling you, and us, whether a sign-in was yours. They are not used to locate you, to profile you, or for anything else.
This website
badgewright.com runs one measurement tool, Google Analytics, and nothing else. It is static pages, served by Google Firebase Hosting, with fonts served from here, no advertising tags and no social media pixels. The one third-party script is the Google tag, configured for measurement only; 4.1 describes it.
The hosting provider records ordinary server logs, including IP addresses, as any web server does. We do not combine those with anything else and we do not use them to identify visitors.
4.1 Analytics on this website
Google Analytics records which pages you view, the site that sent you, any campaign code on the link you followed, how far you scroll, links you click that leave the site, your browser and device type, and your approximate location, which Google derives from your IP address and does not store. It does not receive your name or email address. We have switched off Google signals, advertising personalisation and every link to an advertising product, so nothing here is used to follow you to other sites or to show you adverts. Google processes this data for us as our processor under the Google Ads Data Processing Terms and keeps it for fourteen months. How Google uses it is described at How Google uses information from sites or apps that use our services, and you can stop it in any browser with a content blocker or Google's opt-out add-on; the site works identically without it. If your browser sends the Global Privacy Control signal we do not load Google Analytics at all. If you are in the EEA, the UK or Switzerland no cookie is set and no identifier is stored, though a cookieless request still reaches Google's servers when a page loads.
Nothing crosses from this website into the app. The analytics here stops at the link you click; the app is measured not at all, and no identifier from this website is carried into it or kept against anything.
4.2 Cookies on this website
| Cookie | What it does | How long |
|---|---|---|
_ga | Google Analytics. A random number that tells one browser from another. | 2 years; badgewright.com only, never sent to the app |
_ga_<id> | Google Analytics. Keeps the current visit together. | 2 years; same rule |
4.3 Cookies in the application
| Cookie | What it does | How long |
|---|---|---|
| Session | Keeps you signed in. Marked HttpOnly, Secure and SameSite=Lax. | Up to 30 days, ending sooner when the session idles out |
| Trusted device | Set only if you tick "remember this device", so you are not asked for a second factor every time on that browser. | Until it expires or you revoke the device |
| Sign-in handle | Carries one sign-in attempt through a passkey prompt, or through a redirect to Google or Microsoft where that sign-in is offered, and back. | 5 minutes |
The three application cookies are strictly necessary to provide a service you asked for, which is why you are not asked to consent to them. The two analytics cookies in 4.2 are not, and they are the only ones that are not: they are used for measurement only, they are never sent to the app, and they are not set if your browser sends Global Privacy Control. There are no others.
Why we process it, and on what basis
| Purpose | Data | Basis |
|---|---|---|
| Providing the service | Account Data, Customer Data | Performance of our contract with your organization |
| Signing you in and keeping the account secure | Credentials, sessions, security events | Contract, and our legitimate interest in preventing unauthorised access |
| Support you ask for | Correspondence, and whatever the question concerns | Contract |
| Service notices, trial reminders, security alerts | Name, email | Contract, and legal obligation for tax records |
| Detecting and investigating abuse | Security events, IP addresses | Legitimate interest in a service that is not abused |
| Understanding how the website and the sign-up flow are used | Pseudonymous usage events (section 4) | Legitimate interest in knowing which pages and campaigns lead to sign-ups, and where trials stall |
| Complying with the law | Whatever is compelled | Legal obligation |
There is no marketing basis in that table because we do not send marketing email to people whose organization signed up. If we ever want to, we will ask.
Photographs, faces and biometrics
This section is deliberately specific, because the general version of it is where most software is vague.
When you take or upload a photograph, the cropping happens in your browser, before anything is sent to us. If your browser offers face detection, Badgewright uses it for exactly one thing: to put the crop rectangle in a sensible place, so the face is not off-centre. The detector returns a box with a position and a size. That box is used to compute a rectangle and is then discarded. It never leaves your computer.
What we receive is a cropped photograph. What we do not do, at any point:
- We do not extract facial geometry, generate a faceprint, template, embedding or descriptor, or derive any other mathematical representation of a face.
- We do not compare one face to another, match a face against a gallery, or identify or verify anyone from a photograph.
- We do not store anything derived from a face. The crop rectangle is not saved either: the image we hold is already cropped.
- We do not send photographs to any third party for analysis, and no facial recognition service of any kind is used by this product.
So Badgewright does not collect, capture, store, use, disclose or profit from a biometric identifier or biometric information as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington My Health My Data Act or comparable state statutes define those terms. A photograph of a person is not a biometric identifier under those statutes, and we do nothing to it that would turn it into one.
A photograph is still personal data, and where it is of a student it is very likely an education record under FERPA. It is treated as such throughout: see the student data addendum.
Where it is kept
In the United States, in Google Cloud's us-central1 region, in Iowa. The application, the
database, the file storage and the backups are all there. Nothing is replicated to another country.
The analytics events in section 4 are the one exception: Google may process them in any country where it or its subprocessors have facilities. They contain no Customer Data and nothing that names you.
Badgewright is sold to organizations in the United States. We are not certified under the EU-US Data Privacy Framework and we have no standard contractual clauses in place. If you are subject to the GDPR or the UK GDPR, talk to us before you put personal data into the Service, because you need a transfer mechanism and we do not currently offer one. We would rather say that than let you assume otherwise.
How it is protected
- In transit: TLS everywhere, with HTTP Strict Transport Security.
- At rest: the database, the file storage and the backups are encrypted by Google Cloud.
- Passwords: argon2id, a memory-hard algorithm designed to be expensive to attack in bulk. A minimum of 12 characters, and the breached-password check in section 7.1.
- Second factors: available to everyone on every plan, by authenticator app, passkey or emailed code, and an organization can require them of everyone. Authenticator secrets are encrypted before storage.
- Sessions: expire 30 days after sign-in at the latest, and after 8 hours idle by default, which an organization can set to any of eight values from 15 minutes to 24 hours. Sensitive actions ask you to authenticate again.
- Tenant isolation: each organization's rows are separated in the database by row-level security, so the separation is enforced by the database itself rather than by application code remembering to filter. A test suite exists whose only job is to try to read across that boundary and fail.
- Photographs: in a private bucket with public access prevention enforced and no public path of any kind. A browser never talks to the storage bucket. The application reads the bytes itself, checks that you are allowed to see that image, and sends it on.
- Backups: a daily database backup kept seven days, with point-in-time recovery over a seven-day window of transaction logs. Deleted or overwritten files are recoverable from storage for seven days. Restores are made to a clone, never onto production; the first rehearsal is scheduled before there is customer data to lose.
- Administrative access: limited to what running the service requires, logged, and, for anything that could affect your data, delayed and announced to your organization's owners before it happens.
No system is perfectly secure, and we will not pretend otherwise. If something goes wrong we will tell you: the 72-hour notification commitment in section 8 of the terms is a contractual obligation, not an aspiration.
How long it is kept
| What | Kept | Why |
|---|---|---|
| Customer Data | While your subscription lasts, then 90 days | So you can come back or export it. Shorter if you ask, and shorter by default under the student data addendum |
| Sign-in accounts | While the person belongs to an organization | An account that can sign in nowhere is deleted with the last organization it belonged to |
| Security events | While the account exists, then pseudonymised | Investigating account compromise. On deletion the account identifier and IP address are cleared: the row still records that a sign-in failed, and no longer records whose |
| Sessions and trusted devices | Until they expire or are revoked | They are the sign-in itself |
| Audit log | With the organization | It is your record, not ours, and it goes when your data goes |
| Invoices and billing records | 7 years | Tax law. Most of this is held by Stripe rather than by us |
| Correspondence with us | 3 years from the last message | So we can pick up a thread, and so a dispute has a record |
| Backups | 7 days | Section 11 explains how deletion and backups interact |
| Server request logs | 30 days | The IP address and the address requested, recorded by Google Cloud Run outside our own code and kept by Google Cloud Logging for its default 30 days, to diagnose faults and abuse. A request carrying a one-time link is dropped from this log entirely. Our own log lines record the route pattern rather than the address you asked for. Not tied to your account by us, and not pseudonymised on deletion, because they expire on their own |
| Analytics events | 14 months, at Google | The longest a standard Google Analytics property allows. Aggregated counts persist in reports after that; the per-event data does not |
Deletion, and what deletion means here
An owner of your organization can ask us at support@badgewright.com and we will delete the organization and everything in it. Today the request is made by email and carried out by us; asking from within the application is planned. The process is deliberately not instant:
- An export first. Before an organization is deleted we offer a complete export, on request, so nobody deletes data they have no copy of.
- A pause. Deletion is scheduled rather than immediate, normally 30 days out, and every owner of the organization is emailed with what was asked for, when it will happen, and a link to cancel it. This is what stops a compromised account from quietly erasing a district.
- Erasure. A real delete, in one transaction: records, datasets, templates and their versions, printer profiles, print jobs and their items, users, invitations, the audit log and the organization row. And the photographs, removed from the storage bucket. Sign-in accounts left belonging to no organization go with it.
A person who wants only their own sign-in deleted writes to privacy@badgewright.com; that is done by hand and does not need the pause, because the blast radius is one person. We will refuse if they are the sole owner of an organization that still exists, because that would leave your data with nobody able to reach it; transfer ownership first and we will then do it.
11.1 Backups, said honestly
Deleted data remains inside the backup window for up to seven days after erasure, because a backup cannot have one organization surgically removed from it without corrupting it. So the promise is this, in these words: live data is erased within the stated period, backups roll off within seven days after that, and if a backup is ever restored the erasure is re-applied to the restored copy before it serves traffic. The last clause is what makes the promise true rather than nearly true.
11.2 What survives, and why
- Invoices and billing records, for seven years, because tax law requires it and erasure law allows for it.
- Security event rows with the account identifier and IP address cleared, so the security history survives without the person in it.
- The fact that an organization was deleted, and when, kept indefinitely, because otherwise there is no evidence the obligation was met, and that evidence is exactly what an assessment asks for.
Nothing else. There is no archive table. The random analytics number kept against an organization is deleted with the organization, and Google Analytics keeps the events sent under it for fourteen months; if you want them purged from Google Analytics sooner, ask and we will do it.
Your rights, and how to use them
Depending on where you live, you may have rights to know what personal data is held about you, to get a copy, to correct it, to delete it, to limit how it is used, and not to be discriminated against for asking. We honour these for everyone who asks, wherever they live, rather than checking first whether we have to.
If the data is your organization's — a record about a student or an employee — ask the organization. They control it, they can change or delete it themselves, and if they need us we will help them. Sending the request to us first is fine; we will pass it on and tell you we have.
If the data is about your own sign-in, write to privacy@badgewright.com. We will answer within 45 days, and tell you if we need longer. We will not charge you, and we will not ask you to create an account to make a request.
We will need to be reasonably sure you are who you say you are, which usually means replying from the address on the account. An authorised agent may act for you with written permission.
12.1 The ones we can answer now
- Do you sell my personal information? No. We have never sold or shared personal information for cross-context behavioural advertising, and have no plans to. There is no "Do Not Sell" link because there is nothing behind it.
- Do you use it to train AI? No. Section 7 names the one AI tool we work with, and what it can see.
- Do you profile people or make automated decisions about them? No.
- Do you honour Global Privacy Control? Yes. If your browser sends the Global Privacy Control signal, badgewright.com does not load Google Analytics, and there is nothing else it could apply to. There is no selling anywhere.
If you think we have got something wrong, tell us and we will fix it. You may also complain to your state attorney general, and, in California, to the California Privacy Protection Agency.
Children
Badgewright is sold to organizations, not to individuals, and it is not directed at children. Nobody under 18 signs up for it.
Schools do hold records about children in it, including their photographs. That data is entered by the school and controlled by the school, never collected by us from a child. Where a school uses Badgewright for pupils under 13, the school provides consent on behalf of parents, as COPPA allows it to for a service used solely for school purposes; we use that data only to provide the service to the school and for nothing else. The student data addendum sets out the whole of it, and parents should direct questions to their school, which can answer them and can have the data deleted.
Changes to this policy
We will post any change here with a new effective date. For a change that materially affects how we handle personal data we will give at least 30 days' notice by email to organization owners before it takes effect. Previous versions are kept and we will send you any of them if you ask.
Contact
The controller for Account Data is Briare Brothers LLC, 30 N Gould St Ste N, Sheridan, WY 82801. For Customer Data the controller is your own organization, and we are its processor.
Privacy questions and requests: privacy@badgewright.com. Security: security@badgewright.com. Everything else: support@badgewright.com.
Questions about this document: legal@badgewright.com. Questions about your own data: privacy@badgewright.com. To report a security problem: security@badgewright.com.