Legal
Privacy Policy
The short version
- We collect user data. Names, work emails, the tickets and files people submit, device records, and technical logs. Section 2 lists everything.
- Your organization owns its data. We process it only to run Beacon for you. We never sell it, never use it for advertising, and never use it to train AI models.
- Beacon uses AI. Ticket triage, suggested replies, summaries, and reports are generated by a third‑party AI provider under a no‑training agreement. Section 5 explains exactly what is sent and how you can turn it off.
- Third parties help us run the service. Section 6 names every one of them and what they see.
- Deletion is real. Delete a ticket and its attachments are removed from storage. Delete your organization and everything, including uploads, is permanently erased within 30 days.
- Student data has extra protection. For schools we act as a “school official” under FERPA and follow COPPA and SOPIPA. Section 8.
1. Who we are and what this covers
Beacon (“Beacon,” “we,” “us”) provides a help desk, asset management, and knowledge base platform at beaconhelpdesk.com, app.beaconhelpdesk.com, api.beaconhelpdesk.com, and in the Beacon mobile apps (together, the “Service”). This policy explains what personal information we collect, why, who we share it with, how long we keep it, and the choices you have.
Two roles matter throughout this policy:
- Customers are the organizations (school districts, schools, colleges, governments, and companies) that create a Beacon organization. For the data they put into Beacon, the Customer is the data controller and Beacon is the processor acting on its instructions.
- Users are the people a Customer allows to use Beacon: technicians, administrators, staff, and, where a Customer chooses, students or parents submitting requests.
If you are a User and have questions about how your organization uses Beacon, contact your organization’s administrator; they control your account and data.
2. Information we collect
2.1 Information you or your organization provide
- Account information: name, work email address, password (stored only as a salted argon2id hash), role, job title, phone number, and the site or building you belong to.
- Organization information: organization name, type, approximate size (for example student enrollment), time zone, branding, and settings.
- Ticket content: the subject, description, replies, internal notes, tags, and any custom fields submitted through the portal, the agent workspace, the mobile apps, email, or the API.
- Attachments: files and photos uploaded to tickets and comments.
- Asset records: device tags, serial numbers, models, locations, purchase and warranty information, and which User a device is assigned to.
- Knowledge base content: articles and feedback on them.
- Directory data synced from Google Workspace, Microsoft Entra ID, Clever, or ClassLink if your organization enables single sign‑on or rostering: name, email, role, school, and an external identifier.
- Support communications: messages you send us by email.
2.2 Information collected automatically
- Technical logs: IP address, browser or app version, device type, operating system, the pages and API endpoints requested, timestamps, and error reports.
- Usage and audit records: who created, viewed, changed, or deleted records inside the Service, kept so administrators can audit activity.
- Sign‑up details: the IP address, browser, plan chosen, and the time you accepted our Terms.
- Mobile app permissions: the camera (only while you scan a barcode or take a photo you attach) and, if you enable them, push notifications. We do not collect precise location.
2.3 Information we do not collect
We do not use third‑party advertising or analytics trackers on the Service. We do not collect payment card numbers; if paid billing is added, card details will be entered directly with a PCI‑DSS compliant payment processor and never stored by Beacon.
3. Cookies and local storage
The web app stores your sign‑in tokens in your browser’s local storage so you stay signed in, and a short‑lived, HttpOnly, secure cookie during single sign‑on to protect the login from tampering. The marketing website sets no cookies. We do not use cookies for advertising or cross‑site tracking. You can clear local storage in your browser at any time; doing so signs you out.
4. How we use information
- To provide, operate, secure, and support the Service, including routing tickets, tracking devices, sending notifications, and enforcing access rules.
- To send transactional messages: invitations, ticket updates, password and security notices, renewal reminders, and important changes to the Service.
- To detect abuse, prevent fraud, and keep the Service reliable, for example rate limiting and bot protection on sign‑up and login.
- To understand aggregate usage so we can improve the product. We use aggregated or de‑identified statistics for this; we do not profile individual Users.
- To comply with law and enforce our Terms.
We do not sell personal information, do not share it for cross‑context behavioral advertising, and do not use Customer data to train artificial intelligence models.
5. Artificial intelligence features
Beacon includes AI features that read ticket content to help technicians: automatic triage (suggested category, priority, team, and related articles), suggested replies, ticket summaries, draft knowledge articles, and natural‑language reporting.
- What is sent: the text of the ticket or question being processed, plus your organization’s category names, team names, and knowledge article titles so suggestions use your real setup. We do not send attachments, passwords, or your directory.
- Who processes it: Anthropic, PBC (the maker of Claude) under commercial API terms. Anthropic does not use data submitted through its API to train its models. It may retain API inputs and outputs for a limited period, currently up to 30 days, for trust‑and‑safety purposes, after which they are deleted.
- What we keep: the AI’s suggestions are stored with the ticket so your team can see and audit them, along with token counts for usage metering. We do not store a separate copy of the prompt.
- Human control: AI suggestions are suggestions. A technician can accept, edit, or ignore them, and automatic categorization can be disabled. Administrators can turn each AI feature off for their organization in Settings.
- Safety: if ticket content indicates that someone may be at risk of self‑harm, harm to others, abuse, or a medical emergency, Beacon flags the ticket as urgent, notifies your organization’s administrators, and shows the person who submitted it crisis resources such as the 988 Suicide & Crisis Lifeline in the United States. Beacon is not a crisis service or a substitute for one. If someone is in immediate danger, call your local emergency number.
6. Who we share information with
We share personal information only with the service providers below (our subprocessors), with your organization’s administrators, and when the law requires it. Each provider is bound by contract to use the data only to provide its service to us.
| Provider | Purpose | Location | What it can see |
|---|---|---|---|
| Fly.io, Inc. | Hosting for the API and the database | United States (Virginia) | All Service data at rest and in transit, encrypted |
| Vercel, Inc. | Hosting for the web app and this website | United States | Request logs (IP address, pages requested); the web app itself stores no Customer data on Vercel |
| Cloudflare, Inc. | Domain registration and DNS | United States | DNS queries only |
| Resend, Inc. (on Amazon SES) | Sending email notifications | United States | Recipient address, subject, and message text of emails we send |
| Anthropic, PBC | AI features (Section 5) | United States | Ticket text and organization category and article names when an AI feature runs |
| Apple Inc. and Google LLC | Mobile app distribution and push notifications | United States | Push tokens and notification text; app store account information stays with the store |
| Expo (650 Industries, Inc.) | Mobile app builds, updates, and push delivery | United States | Push tokens and app diagnostic data |
We will update this list before adding a new subprocessor and, for District and Enterprise customers, give 30 days’ notice by email with the right to object. We do not share data with data brokers. If we are ever involved in a merger or acquisition, Customer data would transfer only under this policy and the Customer’s agreement.
We may disclose information when required by a valid legal process. If the law allows, we will notify the affected Customer first so it can seek protection.
7. Security
We designed Beacon to keep each organization’s data separate and protected. Measures include:
- Tenant isolation enforced by the database itself through PostgreSQL row‑level security, so one organization’s query cannot return another organization’s rows.
- Encryption in transit (TLS 1.2 or higher, HTTPS enforced) and at rest, including database volumes and backups. Passwords are hashed with argon2id; session and API tokens are stored only as hashes; single sign‑on secrets are encrypted at rest.
- Attachments are stored privately under randomized keys, are never publicly accessible, and are served only to authorized users through short‑lived signed links with restricted file types.
- Role‑based access, server‑side authorization on every request, rate limiting, bot protection, input validation, and security headers.
- Audit logs of administrative actions, available to your administrators.
- Daily backups and tested restores; dependency vulnerability scanning; secrets held in a managed secret store and never in source code.
No system is perfectly secure. If we learn of a breach affecting personal information, we will notify affected Customers without undue delay and within 72 hours of confirming it, with the information they need to meet their own notification obligations.
8. Students and schools
Schools and districts use Beacon to support staff and, at their option, students. When a school directs Beacon to process student information:
- FERPA: we act as a “school official” with a legitimate educational interest under the school’s direct control, use education records only for the purposes the school authorizes, and do not re‑disclose them except as the school directs or the law requires.
- COPPA: we do not knowingly collect personal information from children under 13 except through a school that has authorized the collection on the parent’s behalf for educational purposes. We collect only what is needed to provide the Service and never use it for marketing.
- SOPIPA and similar state laws: we do not sell student information, use it for targeted advertising, or build profiles of students for any purpose other than the school’s. We do not disclose it except as permitted by the school and by law.
- Deletion: a school can delete any record at any time, and we permanently delete all of a school’s data within 30 days of the school’s request or the end of its agreement, and confirm in writing on request.
- Parents and eligible students may review and request correction of student records through their school, which can fulfil the request directly in Beacon.
We will sign a student data privacy agreement, including state model agreements such as the National Data Privacy Agreement, on request.
9. How long we keep information
| Data | Retention |
|---|---|
| Tickets, comments, assets, articles, users | Until your organization deletes them or closes its account |
| Attachments | Deleted from storage when the ticket or comment they belong to is deleted, or with the organization |
| Closed or cancelled organizations | Marked for deletion immediately; permanently erased, including backups rolling off, within 30 days. Export is available for 90 days before cancellation takes effect on paid plans |
| Technical and security logs | 30 days |
| Audit logs | Kept with the organization’s data so administrators can review activity |
| Backups | Rolling, encrypted, up to 30 days |
| AI provider copies | Deleted by the provider within its retention window, currently up to 30 days |
10. Your choices and rights
- Access and export: administrators can export all organization data at any time from Settings or through the API, in open formats (CSV and JSON).
- Correction: Users can update their profile; administrators can correct any record.
- Deletion: administrators can delete individual records or the entire organization from Settings, and Users can ask their administrator to delete their account. We honor deletion within 30 days.
- Notifications: you can turn off non‑essential email notifications in your profile. Security and account notices cannot be turned off while you have an account.
- AI features: administrators can disable them for their organization.
- Do Not Track and Global Privacy Control: we do not track Users across sites, so these signals require no change in our behavior.
Residents of California, Colorado, Connecticut, Virginia, and other states with privacy laws may have additional rights to know, delete, correct, and opt out. Because we process most personal information on behalf of a Customer, we will direct requests to that Customer where the law requires, and otherwise respond within 45 days. We do not discriminate against anyone for exercising their rights.
11. International users
Beacon is operated from the United States and stores data there. If you use the Service from outside the United States, your information is transferred to and processed in the United States. For Customers in the European Economic Area, United Kingdom, or Switzerland we offer a data processing addendum with standard contractual clauses on request.
12. Changes to this policy
We will post any changes here and update the dates at the top. For material changes we will email organization administrators at least 30 days before they take effect. Continued use of the Service after that date means you accept the updated policy.
13. Contact us
Questions, requests, and complaints: privacy@beaconhelpdesk.com. Security reports: security@beaconhelpdesk.com. We respond to every message within five business days.