Effective July 26, 2026

Privacy Policy

Watchbill is a product of VST Inc. ("we", "us"). This policy explains what we collect, why, and who can see it — for both the companies that subscribe to Watchbill and the guards, supervisors, and clients who use it.

The short version

  • We collect what's needed to run a security-guard operation: accounts, schedules, time-clock events, reports, photos, and device location during clocked-in shifts only.
  • Your data belongs to your employer's Watchbill account and is visible to their managers (and, for approved reports, their clients). We don't sell it or use it for advertising.
  • Location tracking is always visible: a notification (Android) or system indicator (iOS) shows whenever it's on, and it stops at clock-out.

What we collect

Account information. Name, email, phone, role, and employer, provided when your company creates your account.

Operational records. Shifts, clock-in/out events, checkpoint scans, patrol stops, reports and their attachments (photos, videos, documents), pass-downs, tasks, and messages — created by you or about your work. In-app messages are company records: your employer's account owner can review conversations, and the app says so on the messaging screen.

Location. Collected in two ways, both tied to work: (1) a GPS stamp when you perform a work action (clocking in or out, scanning a checkpoint, making a patrol stop, submitting a report); and (2) if your company uses live tracking and you have agreed to it in the app, continuous location while you are clocked in, including when the app is in the background. On-shift tracking is always accompanied by a visible notification or system indicator, starts only at clock-in, stops at clock-out, and is never collected off shift. You can decline or revoke location permission in your device settings; work actions that require location verification may then be limited by your employer's policy, not by us.

Camera, photos & microphone. When you attach evidence to a report, checklist, or patrol, the app uses your device camera, photo library, and microphone to capture photos, videos, and audio. These are accessed only when you choose to attach media, and you can decline the permissions in your device settings.

Push notifications. With your permission we register a device push token (via Apple and Google's notification services) so we can deliver alerts such as new tasks, missed tours, and messages.

Device information. Device model, operating system version, app version, and notification/location permission state — so your company can troubleshoot ("why didn't the alert arrive?").

Diagnostics. If enabled, we collect crash and error diagnostics (via Sentry) to find and fix problems — technical details about the error, app, and device, not the contents of your reports.

Billing. Subscription payments are processed by Stripe; we never see or store full card numbers.

How it's used

To operate the service your employer subscribes to: proving patrols happened, scheduling and paying staff accurately, documenting incidents, and showing clients the service they pay for. We also use aggregate, de-identified data to keep the service reliable and secure. We do not sell personal data, and we do not use it for third-party advertising.

Who can see it

Your company's managers and supervisors see operational records and on-shift locations for the guards they manage. Your company's clients see only what your company shares with them (typically approved reports and patrol visits for their own sites). Watchbill staff access customer data only to provide support or as required by law. We use service providers to run the platform — hosting, Stripe (payments), Google and Apple (maps, push notifications), Sentry (error diagnostics), and email delivery — each bound to process data only on our instructions.

Retention & deletion

Operational records are retained for the life of your employer's account, since they are your employer's business records (incident reports in particular may have legal retention requirements). When an account closes, data is deleted or returned per the subscription agreement. To exercise access or deletion rights for your personal information, start with your employer (the data controller for workplace records) or contact us at hello@getwatchbill.com.

Security

Data is encrypted in transit, access is role-based and tenant-isolated, and media files are served through expiring, authenticated links. No system is perfectly secure, but we treat security as a product feature, not a checkbox.

Changes & contact

We'll post updates to this policy here with a new effective date, and notify subscribing companies of material changes. Questions: hello@getwatchbill.com · VST Inc.