OpenTech Services
Last updated: April, 2026
Overview
OpenTech Services (“OpenTech,” “we,” “us,” or “our”) operates PeopleTrack, a cloud-based visitor management and attendance tracking platform. This Privacy Policy describes how we collect, use, disclose, retain, and protect information when you use:
- The PeopleTrack website and web application (app.peopletrack.us)
- PeopleTrack mobile applications (including Android)
- Self Check-In / kiosk-style station modes
- Related support, billing, and account services
(collectively, the “Services”)
Please read this policy carefully. If you do not agree with it, do not use the Services.
Who This Policy Applies To
PeopleTrack serves different types of users. Your relationship to us depends on how you interact with the platform:
| Audience | Description |
|---|---|
| Organization customers | Schools, businesses, nonprofits, government agencies, and other entities that subscribe to PeopleTrack (“Customers”) |
| Authorized users | Employees, administrators, and staff who sign in to operate PeopleTrack on behalf of a Customer (“Account Users”) |
| Individuals tracked in the system | Members, visitors, guests, and others whose information a Customer enters or collects through PeopleTrack (“Profile Subjects”) |
In most cases, Customers decide what information to collect and how it is used. OpenTech processes that information on behalf of Customers as a service provider / data processor. Profile Subjects should contact the Customer organization that collected their information for questions about access, correction, or deletion.
Account Users and website visitors who interact directly with OpenTech (for example, when creating an account or contacting support) are covered by this policy as described below.
1. Information We Collect
The information collected depends on how a Customer configures PeopleTrack and which features are enabled.
1.1 Account and authentication information (Account Users)
When you create or manage a PeopleTrack account, we may collect:
- Name and display name
- Email address
- Phone number (optional; used for SMS two-factor authentication when enabled)
- Password (stored as a salted cryptographic hash — not in plain text)
- Google account identifier (if you use Google Sign-In)
- Email verification and password-reset activity
- Login timestamps, session identifiers, IP address, and browser/device user agent (for security and audit purposes)
1.2 Profile and operational information (Profile Subjects)
Customers may store the following types of information in PeopleTrack. Not all fields are required, and availability varies by Customer configuration:
Identity and contact
- Full name
- Email address and phone numbers
- Mailing address
- Date of birth
- Organization, employer, or affiliation
- Emergency contact information
Identification and credentials
- Member or badge ID numbers
- Driver’s license or government ID numbers
- Other government-issued identification fields configured by the Customer
Biometric and image data (when enabled by the Customer)
- Profile photographs
- Visitor badge photos
- Signatures
- Identification document images
Operational and attendance records
- Check-in and check-out times
- Visit history and duration
- Visit reason, notes, and station/operator identifiers
- Event registrations, passes, schedules, and performance/incident records
- Custom fields defined by the Customer
Vehicle information (when collected)
- Make, model, year, color, and license plate
1.3 Billing information (Account Users / Customers)
Subscription billing is processed through Stripe. We receive and store:
- Stripe customer and subscription identifiers
- Plan type, billing period, and payment status
- Limited payment method metadata (for example, card brand and last four digits — not full card numbers)
Full payment card data is handled directly by Stripe in accordance with Stripe’s privacy policy.
1.4 Device, technical, and usage information
We automatically collect certain technical information when you use the Services, including:
- Device type, operating system, and browser type
- IP address and general connection information
- Application version and session activity
- Server logs, error reports, and diagnostic data
- Health-check and performance-related system logs
We use this information to operate, secure, troubleshoot, and improve the Services.
1.5 Information from device permissions (mobile and browser)
The PeopleTrack mobile app and web application may request access to:
| Permission | Purpose |
|---|---|
| Camera | Scanning QR codes, barcodes, IDs, and capturing profile or visitor photos |
| Storage / file access | Temporary image handling, imports, and document uploads |
| Notifications | Alerts, system messages, and operational notifications |
You may disable permissions through your device or browser settings, though some features may not function without them.
1.6 Information we do not intentionally collect
PeopleTrack is a record-keeping and visitor management tool, not a certified compliance platform. Unless explicitly configured and entered by a Customer, we do not:
- Perform background checks
- Operate physical access control or door systems
- Use facial recognition
- Sell personal information
2. How We Use Information
We use collected information to:
- Provide, maintain, and improve the Services
- Authenticate Account Users and manage access permissions
- Enable check-in, check-out, visitor management, and attendance tracking
- Generate reports, exports, badges, and notifications configured by Customers
- Process subscriptions and manage billing through Stripe
- Send account, security, and service-related communications
- Detect, investigate, and prevent fraud, abuse, and unauthorized access
- Comply with legal obligations and enforce our terms
- Provide customer support
We do not sell personal information. We do not use Profile Subject data for our own advertising or marketing purposes.
3. Roles: Customer, OpenTech, and Service Providers
3.1 Customer-controlled data
For information that Customers enter about Profile Subjects:
- The Customer is generally the controller of that data
- OpenTech acts as a processor/service provider, handling data according to the Customer’s instructions and this policy
- Requests from Profile Subjects regarding their records should be directed to the Customer organization that collected the information
3.2 OpenTech-controlled data
For account registration, billing, security logs, and direct communications with OpenTech, OpenTech acts as the controller of that information.
4. How We Share Information
We share information only as described below.
4.1 Service providers
We use trusted third parties to help operate the Services. These providers may process information on our behalf and are contractually required to protect it. Current categories include:
| Provider type | Examples / purpose |
|---|---|
| Cloud infrastructure | Microsoft Azure (application hosting, database, file storage) |
| Payment processing | Stripe (subscriptions and billing) |
| Authentication | Google (optional OAuth sign-in) |
| Email and SMS delivery | Notification automation providers (for example, Make.com webhooks configured for transactional messages) |
| Support and operations | Tools used for customer support, monitoring, and service reliability |
A list of subprocessors may be updated as our vendors change. Customers requiring a formal subprocessor list may contact us at support@peopletrack.us.
4.2 Customer-directed sharing
Customers may export data, send virtual ID badges, or otherwise share information through features they enable. OpenTech is not responsible for how Customers use exported or shared data outside the platform.
4.3 Legal and safety disclosures
We may disclose information if we believe it is reasonably necessary to:
- Comply with applicable law, regulation, legal process, or governmental request
- Enforce our agreements or protect the rights, property, or safety of OpenTech, our Customers, or others
- Detect or prevent fraud, security incidents, or technical issues
4.4 Business transfers
If OpenTech is involved in a merger, acquisition, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to continued protection consistent with this policy.
5. Cookies and Session Technologies
PeopleTrack uses cookies and similar technologies to:
- Maintain authenticated sessions
- Remember preferences and station settings
- Protect against unauthorized access
Our primary authentication cookie is HttpOnly and expires after a period of inactivity (currently up to 12 hours with sliding renewal during active use). You can control cookies through your browser settings, but disabling them may prevent sign-in.
We do not use cookies to sell personal information or for third-party behavioral advertising.
6. Data Retention
We retain information for as long as necessary to:
- Provide the Services to Customers
- Fulfill contractual and billing obligations
- Meet legal, tax, and regulatory requirements
- Resolve disputes and enforce agreements
- Maintain security and audit records
Customer-controlled retention: Customers may delete individual profiles, bulk-delete visit history, or remove expired records through authorized administrative functions. Customers are responsible for establishing retention schedules that meet their legal and policy requirements.
When information is no longer needed, we take reasonable steps to delete or de-identify it, subject to backup retention and legal hold requirements.
7. Data Security
We implement administrative, technical, and organizational safeguards designed to protect personal information, including:
- Encrypted connections to databases and cloud services
- Separate databases per Customer tenant (multi-tenant isolation)
- Hashed password storage (PBKDF2-SHA256 with per-user salt)
- Role-based access controls within the application
- Session management and authentication event logging
- Secure handling of billing events through Stripe
No method of transmission or storage is completely secure. While we work to protect information, we cannot guarantee absolute security.
8. International Data Transfers
PeopleTrack is primarily hosted in the United States through Microsoft Azure. If you access the Services from outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries where we or our service providers operate.
Where required by law, we rely on appropriate safeguards for international transfers. By using the Services, you acknowledge such transfers as permitted by applicable law.
9. Children’s Privacy
PeopleTrack may be used by schools, youth programs, and other organizations serving minors. In those cases:
- The Customer organization — not OpenTech — determines whether and what information about minors is collected
- Collection and use of minor information is conducted under the Customer’s authority and policies
- OpenTech does not knowingly market directly to children
Parents and guardians seeking access to, correction of, or deletion of a child’s information should contact the organization using PeopleTrack that collected the information.
10. Your Privacy Rights
Depending on your location, you may have rights regarding personal information, including the right to:
- Access information we hold about you
- Correct inaccurate information
- Delete information, subject to legal exceptions
- Restrict or object to certain processing
- Receive a portable copy of certain information
- Withdraw consent where processing is consent-based
- Non-discrimination for exercising privacy rights (where applicable)
10.1 Profile Subjects
If your information was collected by a Customer through PeopleTrack, submit requests to that Customer organization first. We will assist Customers in responding as required by our agreements and applicable law.
10.2 Account Users
Account Users may contact us directly at support@peopletrack.us for requests related to their PeopleTrack account, authentication data, or billing records.
We may need to verify your identity before fulfilling a request. We will respond within timeframes required by applicable law.
11. Compliance Notice
PeopleTrack provides tools to help organizations maintain digital visit and attendance records. PeopleTrack is not certified as HIPAA, FERPA, SOC 2, or PCI compliant as an application. Payment card processing is handled by Stripe. Customers are responsible for evaluating whether their use of PeopleTrack meets their industry, jurisdictional, and organizational compliance obligations.
12. Third-Party Links and Services
The Services may contain links to third-party websites or services (for example, public registry lookup tools opened in an external browser). We are not responsible for the privacy practices of those third parties. Review their policies before providing information.
Use of integrated third-party services (such as Google Sign-In or Stripe) is also subject to those providers’ privacy policies.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes may also be communicated through the Services or by email where appropriate.
Continued use of the Services after changes take effect constitutes acceptance of the updated policy, unless applicable law requires otherwise.
14. Contact Us
For questions about this Privacy Policy or OpenTech’s privacy practices:
OpenTech Services — PeopleTrack Support
Email: support@peopletrack.us
Website: https://peopletrack.us
For questions about information collected by a specific organization using PeopleTrack, please contact that organization directly.
