1. At a glance
The detail matters and is set out below, but this is the short version. Nothing in this summary overrides the full sections that follow.
2. Who is responsible for your data
Sentinel360 is published by Vistaar Intuitive Solution, having its registered office at 614 Nakshtra-VIII, S V Road, Rajkot, Gujarat, India ("Vistaar", "we", "us").
Sentinel360 is licensed to organisations — factories, plants, warehouses, campuses and the security agencies that staff them. That organisation decides which sites to run, which people to enrol, what to record at its gates and how long to keep it. In the language of the Digital Personal Data Protection Act, 2023 ("DPDP Act"):
| Data | Data Fiduciary (decides why & how) | Our role |
|---|---|---|
| Operational records created in the app — visitors, vehicles, employee gate movements, patrols, incidents, shifts | The client organisation that operates the site | Data Processor. We store and process these on the client's documented instructions and do not use them for our own purposes. |
| Your Sentinel360 login account — name, email, phone, employee code, role | The client organisation, which approves and activates every account | Data Processor, save for the limited security and service-integrity purposes in §7 where we act on our own account. |
| Service logs, crash and abuse-prevention records | Vistaar | Data Fiduciary, strictly for keeping the service running and secure. |
Your data was entered by the site you visited, not by us, and we cannot amend or erase it on our own initiative. Please contact that site's security office or its grievance contact first. If you cannot reach them, write to us at the address in §17 and we will route your request to the relevant client organisation and support them in answering it.
3. Who this policy covers
This policy applies to three groups of people, and different parts will be relevant to each:
- App users — guards, gate staff and supervisors who hold a Sentinel360 login.
- Recorded individuals — visitors, drivers, contractors and employees whose details an app user enters at a gate or in a report. These people do not use the app but appear in it.
- Client administrators — staff who manage users and records through the Sentinel360 web console.
This policy describes the Sentinel360 Android mobile application. The Sentinel360 web console is governed by the agreement between Vistaar and the client organisation.
4. What the app collects
Everything below is entered or captured deliberately, by a signed-in user, in the course of a specific task. The app does not collect anything in the background and does not run when closed.
4.1 Your account
| Field | Detail | Source |
|---|---|---|
| Full name | Required at registration | You |
| Email address | Your sign-in identifier | You |
| Phone number | Required at registration; editable in Profile | You |
| Employee code | Required at registration; editable in Profile | You |
| Password | Held by Google Firebase Authentication in hashed form. Vistaar never sees or stores your password. | You |
| Role, account status, assigned site | Set by your organisation's administrator, not by you. New accounts start as pending and cannot use the app until an administrator activates them. | Your employer |
| Account identifier | An internal random ID that links the records you create to you | Generated |
4.2 Records you create about other people
This is the substantial part of what the app holds, and much of it concerns people other than you. Your organisation is responsible for having a lawful basis to collect it and for telling those people it is being collected.
| Feature | Personal data recorded |
|---|---|
| Visitor management | Visitor name, company, email, mobile number, postal address, person being visited, purpose of visit, number of accompanying persons, arrival and departure times, a facial photograph captured at the gate, and serial numbers of any laptops or mobile devices carried in. |
| Vehicle register | Vehicle registration number, vehicle type, transporter and party name, material carried, gate pass number, driver name and driving licence number, entry and exit times and gates, and up to three photographs of the vehicle (front, side, rear). |
| Employee gate movement | Employee identifier, gate, IN/OUT status, timestamps and free-text remarks. |
| Patrols | Guard name, checkpoint scan results and times, checkpoints missed, and free-text anomaly reports. |
| Incident, sleeping, indiscipline and unauthorised-entry reports | The name, employee code or agency of the person concerned, the shift in-charge, the date, time and site, and a description of what occurred. These may amount to disciplinary records about an identified individual and should be treated accordingly by the client organisation. |
| Compliance drills & footfall census | Activity type, site and location, who conducted it, timings, headcounts and findings. |
| Parking | Vehicle number, driver name, vehicle type, zone, time in and time out. |
| Shifts & shift swaps | Your rostered shifts, swap requests you raise or are named in, the free-text reason you give, and the approving administrator. |
4.3 Photographs
Visitor and vehicle photographs are stored inside the record they belong to, in the client organisation's database, and are visible to authorised users of that organisation. Visitor photographs are facial images and are treated as sensitive.
We do not generate facial-recognition templates, we do not match faces against any database, and we do not use any photograph to identify a person across records or sites. A photograph is stored as an image against one visit and nothing more.
4.4 Audit trail
Every record carries who created it, who last modified it and when. This is a security control: it is how a client organisation establishes what happened at its gate and who logged it. You cannot switch it off, and it means your actions in the app are attributable to you.
4.5 Service and diagnostic logs
Unlike everything above, this is not entered by anyone — it is recorded automatically by our servers whenever the app contacts them, which is what any hosted service must do to stay running and secure. These are the "service logs" referred to in §2 and §11.
- The IP address the request came from.
- Device and operating-system version, and the app version in use.
- The date and time of the request and which service it reached.
- Error and crash diagnostics when something fails — what broke and where, not what you were recording at the time.
We use these only to keep the service running, to investigate faults, and to detect abuse or unauthorised access (§7.2). They are held by Vistaar as Data Fiduciary, are never combined with gate records to profile anyone, and are not shared for advertising. Note that this is server-side logging: it is separate from, and should not be confused with, the third-party analytics SDKs that §6 confirms the app does not contain.
5. Device permissions
Android will ask before granting any of these. You can withdraw them at any time in Settings → Apps → Sentinel360 → Permissions; the features that rely on them will then stop working, but the rest of the app will continue to function.
| Permission | Used for | Required? |
|---|---|---|
| Camera | Capturing visitor and vehicle photographs, and reading patrol checkpoint QR codes. The camera preview is only ever live while you are on a capture screen. | Optional — the app remains usable without it, but photo capture and patrol scanning will not work. |
| Photos / media | Attaching an existing JPG or PNG to a vehicle record when the photograph was taken on another device. Only the file you pick is read. | Optional. |
| Internet & network access | Communicating with the Sentinel360 servers. The app has no offline mode. | Required. |
| Vibrate | Haptic feedback on a successful checkpoint scan. | Optional. |
The current Android build additionally declares RECORD_AUDIO,
SYSTEM_ALERT_WINDOW and WRITE_EXTERNAL_STORAGE, none of which correspond to
any feature described in this policy. Either remove them from the manifest before you build the
release, or add an accurate row for each above and declare them in the Play Console Data Safety form.
A declared microphone permission with no stated purpose is a common cause of Play review rejection.
6. What we do not collect
Stated plainly, because absence is as important as presence:
- No location data of any kind. The app requests no GPS, network-location or background-location permission. It cannot tell where you or your device are.
- No microphone recording. No feature in the app records audio.
- No contacts, call logs, SMS, calendar or files beyond a photo you explicitly pick.
- No advertising identifiers and no cross-app or cross-site tracking.
- No third-party analytics SDKs — there is no Google Analytics, Firebase Analytics, Facebook SDK or comparable telemetry package in the app.
- No biometric templates. Facial photographs are stored as images; no faceprint, embedding or other biometric identifier is derived from them.
- No health, financial, caste, religious or political data. Please do not enter such information into free-text fields.
7. Why we process this data
7.1 On behalf of the client organisation
The client organisation processes personal data through Sentinel360 for physical security and site safety: controlling who enters and leaves, keeping a verifiable gate register, running guard patrols, managing rosters, investigating incidents and meeting statutory safety and security obligations. It is responsible for identifying its lawful basis under the DPDP Act — typically consent for visitors, and legitimate employment purposes for staff — and for giving the required notice to those individuals.
7.2 On our own account
We process a narrow set of data for our own purposes, limited to:
- authenticating sign-in and keeping accounts secure;
- diagnosing faults, crashes and errors;
- detecting and preventing abuse, fraud and unauthorised access;
- meeting our own legal obligations and defending legal claims.
We do not use client data to train machine-learning models, and we do not use it to build any product.
8. Automated and AI-assisted processing
Sentinel360 includes an AI-assisted vehicle scan. When a guard photographs a vehicle at entry or exit, the images are transmitted to our processing service and then to Google's Gemini API, which reads the registration plate and describes visible physical attributes of the vehicle.
What this means concretely
- What is sent: the vehicle photographs you captured. Vehicle photographs may incidentally include a driver or bystander in frame.
- What is kept: only the short text description the model returns — the plate it read, whether the vehicle appears loaded or empty, and a physical description, a few hundred bytes in total. This is retained on the vehicle record so that an exit can be compared against the entry.
- Purpose: flagging a possible plate swap or vehicle substitution between entry and exit. Nothing else.
- Not determinative: the result is advisory. A flagged exit is not blocked by the app; it requires a human explanation from the guard. No decision about any person is taken automatically by the model.
Google's handling of data submitted to the Gemini API is governed by its own terms. Client organisations that do not want images leaving their environment should ask us to disable the vehicle scan feature for their deployment; the vehicle register works without it.
[Confirm which Gemini API tier your key uses and state here whether submitted content is excluded from model improvement — this differs between the free and paid tiers and materially changes the sentence above.]
10. Storage, location and security
Sentinel360's services and database are hosted on Google Cloud infrastructure in the Mumbai (asia-south1) region, India. Some sub-processor functions — including authentication and AI inference — may be performed outside India by Google. Where that happens, the transfer is made under Google's contractual data-protection commitments and is permitted under §16 of the DPDP Act.
Safeguards
- All traffic between the app and our services is encrypted in transit (TLS).
- Data is encrypted at rest by the underlying Google Cloud platform.
- Passwords are hashed by Firebase Authentication and are never visible to us.
- Server-side access rules enforce who may read what. A guard can read only the records they created, except in the shared gate registers listed in §9 where the operational handover requires visibility. Administrative access is restricted by role.
- Every account is approved by an administrator before it can be used, and can be suspended immediately.
- Every record carries an immutable creation and modification trail.
No system is perfectly secure. If a personal data breach occurs, we will notify the affected client organisation and the Data Protection Board of India as required by the DPDP Act, and support the client in notifying affected individuals.
11. How long data is kept
Retention is set by the client organisation, since it owns the records and is subject to its own statutory obligations for security and safety registers. As a processor we retain data for as long as that organisation's agreement with us requires.
| Data | Retention |
|---|---|
| Operational records (visitors, vehicles, movements, patrols, incidents) | As instructed by the client organisation — default [e.g. 24 months] from creation. |
| Your account | For as long as your organisation keeps it active, plus [e.g. 30 days] after deactivation. On an approved deletion request the personal fields are purged at once, leaving only the anonymous identifier described in §13. |
| Visitor photographs | Deleted with the visit record they belong to. |
| Vehicle scan descriptions | Deleted with the vehicle record. |
| Security and service logs | [e.g. 90 days]. |
On termination of a client's contract we delete or return that client's data within [e.g. 60 days], except where law requires us to keep it longer.
12. Your rights
Under the DPDP Act you have the right to:
- Access — obtain a summary of your personal data being processed and who it has been shared with.
- Correction and erasure — have inaccurate or incomplete data corrected, and have data erased where it is no longer needed for the purpose it was collected for.
- Withdraw consent — where processing rests on your consent, withdraw it as easily as you gave it.
- Nominate — nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal — raise a complaint with us, and escalate to the Data Protection Board of India if unresolved.
How to exercise them
- App users: you can view and edit your name, phone and employee code directly on the Profile screen, and request erasure of the account itself from the same screen (Delete my account, see §13). For anything else, contact your organisation's administrator, or write to us at §17.
- Visitors, drivers and employees: contact the site whose gate recorded you — it holds the record and decides on it. We will assist that organisation but cannot act unilaterally on records we hold as a processor.
We respond to requests within 30 days. We may need to verify your identity first, and may decline requests that are manifestly unfounded, repetitive, or that would compromise a security investigation or another person's rights.
Some rights are limited in an employment and physical-security context: a gate register is a security record, and an organisation may be legally required to retain it even after an erasure request. We will explain the reason in any such case.
13. Deleting your account
Full instructions, including what is deleted and what your organisation retains, are on the Account & Data Deletion page. In summary:
- In the app, open Profile → Delete my account and confirm. This is also available on the web console's Profile page. You are signed out at once, and the request goes to your organisation's administrator for review.
- Or ask your administrator directly — they administer the account and can revoke access immediately.
- Or, if you can no longer sign in, email info@vistaarintuitivesolution.com from your registered email address with the subject "Account deletion request", including your registered email address and employee code.
- Deletion is confirmed within 30 days. A request raised in the app can be withdrawn from the same screen at any time before it is approved — nothing is deleted until then.
What is deleted
Your login credentials, name, email, phone number, employee code and site assignment. These are overwritten one-way and cannot be recovered. A single internal record survives, holding only the random account identifier, the role you held and a marker that the account was deleted — no name, email, phone or employee code. It exists so the records described below can render a plain "Former user" rather than a raw identifier.
What is retained, and why
The operational records you created — gate entries, visitor check-ins, patrol logs, incident reports — are not deleted with your account. They belong to the client organisation, form part of its statutory security register, and other people's data is recorded in them. Your name is removed from them in every case, including where it had been copied onto patrol records, and shown as "Former user". We may also retain data where law requires or to resolve a dispute.
Any app offering account creation must provide an in-app account-deletion path
and a publicly reachable web URL for the same request. Both exist: the in-app route is
Profile → Delete my account, and the web route is published at
https://sentinel.vistaarintuitivesolution.com/account-deletion.html — the URL entered
in the Play Console under App content → Data safety → Data deletion.
14. Children
Sentinel360 is a workplace tool for adults in employment and is not directed at children. We do not knowingly create accounts for anyone under 18. Under the DPDP Act, processing a child's personal data requires verifiable parental consent; if a visitor under 18 must be recorded at a gate, the client organisation is responsible for obtaining that consent.
If you believe a child's data has been recorded without proper consent, contact us at §17 and we will work with the client organisation to remove it.
15. Grievance Officer
In accordance with the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, our Grievance Officer can be reached at:
Grievance Officer
Vistaar Intuitive Solution
614 Nakshtra-VIII, S V Road, Rajkot, Gujarat, India
Email: info@vistaarintuitivesolution.com
Response time: within 30 days of receipt.
If your grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India.
16. Changes to this policy
We may update this policy as the app changes or the law does. The version number and "last updated" date at the top of this page will always reflect the current version. Where a change materially affects how personal data is handled, we will notify client organisations in advance and, where required, obtain fresh consent. Continued use of the app after a change takes effect indicates acceptance of the updated policy.
17. Contact us
Registered office
Vistaar Intuitive Solution
614 Nakshtra-VIII, S V Road, Rajkot, Gujarat
India