Legal

Privacy Policy

Effective September 4, 2026 · Last updated September 4, 2026

The short version

1. Who we are and what this covers

Beacon (“Beacon,” “we,” “us”) provides a help desk, asset management, and knowledge base platform at beaconhelpdesk.com, app.beaconhelpdesk.com, api.beaconhelpdesk.com, and in the Beacon mobile apps (together, the “Service”). This policy explains what personal information we collect, why, who we share it with, how long we keep it, and the choices you have.

Two roles matter throughout this policy:

If you are a User and have questions about how your organization uses Beacon, contact your organization’s administrator; they control your account and data.

2. Information we collect

2.1 Information you or your organization provide

2.2 Information collected automatically

2.3 Information we do not collect

We do not use third‑party advertising or analytics trackers on the Service. We do not collect payment card numbers; if paid billing is added, card details will be entered directly with a PCI‑DSS compliant payment processor and never stored by Beacon.

3. Cookies and local storage

The web app stores your sign‑in tokens in your browser’s local storage so you stay signed in, and a short‑lived, HttpOnly, secure cookie during single sign‑on to protect the login from tampering. The marketing website sets no cookies. We do not use cookies for advertising or cross‑site tracking. You can clear local storage in your browser at any time; doing so signs you out.

4. How we use information

We do not sell personal information, do not share it for cross‑context behavioral advertising, and do not use Customer data to train artificial intelligence models.

5. Artificial intelligence features

Beacon includes AI features that read ticket content to help technicians: automatic triage (suggested category, priority, team, and related articles), suggested replies, ticket summaries, draft knowledge articles, and natural‑language reporting.

6. Who we share information with

We share personal information only with the service providers below (our subprocessors), with your organization’s administrators, and when the law requires it. Each provider is bound by contract to use the data only to provide its service to us.

ProviderPurposeLocationWhat it can see
Fly.io, Inc.Hosting for the API and the databaseUnited States (Virginia)All Service data at rest and in transit, encrypted
Vercel, Inc.Hosting for the web app and this websiteUnited StatesRequest logs (IP address, pages requested); the web app itself stores no Customer data on Vercel
Cloudflare, Inc.Domain registration and DNSUnited StatesDNS queries only
Resend, Inc. (on Amazon SES)Sending email notificationsUnited StatesRecipient address, subject, and message text of emails we send
Anthropic, PBCAI features (Section 5)United StatesTicket text and organization category and article names when an AI feature runs
Apple Inc. and Google LLCMobile app distribution and push notificationsUnited StatesPush tokens and notification text; app store account information stays with the store
Expo (650 Industries, Inc.)Mobile app builds, updates, and push deliveryUnited StatesPush tokens and app diagnostic data

We will update this list before adding a new subprocessor and, for District and Enterprise customers, give 30 days’ notice by email with the right to object. We do not share data with data brokers. If we are ever involved in a merger or acquisition, Customer data would transfer only under this policy and the Customer’s agreement.

We may disclose information when required by a valid legal process. If the law allows, we will notify the affected Customer first so it can seek protection.

7. Security

We designed Beacon to keep each organization’s data separate and protected. Measures include:

No system is perfectly secure. If we learn of a breach affecting personal information, we will notify affected Customers without undue delay and within 72 hours of confirming it, with the information they need to meet their own notification obligations.

8. Students and schools

Schools and districts use Beacon to support staff and, at their option, students. When a school directs Beacon to process student information:

We will sign a student data privacy agreement, including state model agreements such as the National Data Privacy Agreement, on request.

9. How long we keep information

DataRetention
Tickets, comments, assets, articles, usersUntil your organization deletes them or closes its account
AttachmentsDeleted from storage when the ticket or comment they belong to is deleted, or with the organization
Closed or cancelled organizationsMarked for deletion immediately; permanently erased, including backups rolling off, within 30 days. Export is available for 90 days before cancellation takes effect on paid plans
Technical and security logs30 days
Audit logsKept with the organization’s data so administrators can review activity
BackupsRolling, encrypted, up to 30 days
AI provider copiesDeleted by the provider within its retention window, currently up to 30 days

10. Your choices and rights

Residents of California, Colorado, Connecticut, Virginia, and other states with privacy laws may have additional rights to know, delete, correct, and opt out. Because we process most personal information on behalf of a Customer, we will direct requests to that Customer where the law requires, and otherwise respond within 45 days. We do not discriminate against anyone for exercising their rights.

11. International users

Beacon is operated from the United States and stores data there. If you use the Service from outside the United States, your information is transferred to and processed in the United States. For Customers in the European Economic Area, United Kingdom, or Switzerland we offer a data processing addendum with standard contractual clauses on request.

12. Changes to this policy

We will post any changes here and update the dates at the top. For material changes we will email organization administrators at least 30 days before they take effect. Continued use of the Service after that date means you accept the updated policy.

13. Contact us

Questions, requests, and complaints: privacy@beaconhelpdesk.com. Security reports: security@beaconhelpdesk.com. We respond to every message within five business days.