TRICORN PRIVACY POLICY
Effective Date: September 11, 2026 Last Updated: September 20, 2026
Tricorn (“Tricorn,” “we,” “us,” “our”) provides a software platform for documenting security and crime-prevention-through-environmental-design (CPTED) assessments, including web and mobile applications, a Client Portal, report-generation tools, and related services (the “Services”). This Privacy Policy explains what personal information we collect, how we use and share it, how long we keep it, how we protect it, and the choices and rights you have.
This Policy applies to personal information we process as a controller: information about people who register for and use the Services (Administrators, Assessors, Client Portal Users, and Training Account holders), people who visit our websites, and people who communicate with us. It also explains, in Section 2, how we handle Customer Data, the assessment content our customers create, for which we act as a processor on our customers’ behalf.
The Services are provided by Tricorn LLC, 18426 Livingston Ave, Suite 2, Lutz, Florida 33559, United States. Our privacy contact is privacy@gotricorn.com.
PRIVACY AT A GLANCE
| Question | Short answer |
|---|---|
| What do you collect about me as a user? | Account and profile details (name, work email, organization, role, professional credentials), device and app information, usage data, support communications, and, only when you turn it on, precise location for geotagging assessments. |
| What about the assessment content, photos, property details, incident notes? | That is Customer Data. The customer organization that created it controls it; we process it only to provide the Services and as the customer instructs. If you appear in a customer’s report, your request goes to that customer, and we will help route it. |
| Do you sell personal information? | No. We do not sell it, and we do not share it for targeted advertising. |
| Do you use AI? | Some features use AI to draft, summarize, or organize assessment content. Our AI providers are contractually barred from training their models on your data. We may improve our own models using de-identified or aggregated data only. |
| Where is my data stored? | In the United States by default, with safeguards for international transfers (Section 10). |
| How long do you keep it? | Account data for the life of the account plus a limited period; Customer Data per the customer’s contract; details in Section 11. |
| What are my rights? | Access, correction, deletion, portability, objection, and complaint rights depending on where you live, Section 13 explains how to exercise them. |
| Can I delete my account? | Yes, in the app or web settings, or by contacting us (Section 13.8). |
| Is the app for children? | No. The Services are for business users aged 18 and over. |
1. WHO WE ARE AND HOW TO REACH US
Controller: Tricorn LLC, 18426 Livingston Ave, Suite 2, Lutz, Florida 33559, United States. Privacy contact / person in charge of personal information: Rini de Graaf, Director of Operations, privacy@gotricorn.com.
2. OUR ROLES: CONTROLLER AND PROCESSOR
The Services are used by organizations (“Customers”), security consultants, security companies, law-enforcement agencies, property owners and managers, and training organizations, and by the individuals those organizations authorize.
2.1 Where Tricorn is the controller. We decide how and why to process the following, and this Policy governs it:
- account, profile, and credential information of Administrators, Assessors, Client Portal Users, and Training Account holders;
- billing and payment contact information;
- device, technical, and usage information generated by your use of the Services;
- support, feedback, and other communications with us;
- website visitor and marketing information;
- Practitioner Directory profiles (Section 18).
2.2 Where Tricorn is the processor. Customer Data, assessment content, photographs, video and audio captured during assessments, property and site information, floor plans, personnel information, incident information, client contact details, notes, and generated Reports, belongs to the Customer that created it. The Customer is the controller (or, for public bodies, the responsible authority). We process Customer Data only to provide, secure, and support the Services, to generate the outputs the Customer requests, and as otherwise instructed by the Customer under our Terms of Service and, where applicable, our Data Processing Addendum (“DPA”). We do not use Customer Data for advertising.
2.3 If you appear in a Customer’s report. Assessors may photograph or describe properties where people are present, or record incident information that names individuals. The Customer that commissioned or produced the assessment is responsible for having a lawful basis to collect that information and for responding to your requests about it. If you contact us about content in a Customer’s report, we will identify the responsible Customer where we can and forward your request, and we will assist the Customer as our DPA requires. We will not alter Customer Data on our own initiative.
2.4 Government and law-enforcement Customers. Where a Customer is a public body, its handling of Customer Data may also be governed by public-records, freedom-of-information, and records-retention laws that apply to that body, not to us.
3. INFORMATION WE COLLECT AS A CONTROLLER
3.1 Information you provide to us
- Account and profile: name, work email address, phone number, employer or organization, job title, user role, profile photograph, and signature image (used to sign Reports where the Customer enables it).
- Professional credentials (Assessors and Practitioners): license, registration, certification, and designation details, issuing body, credential numbers, expiration dates, and any supporting documents you provide. We may confirm credentials with the issuing organization or its public register.
- Authentication: password (stored in hashed form only), recovery information, and, where multi-factor authentication is offered, the details needed to operate it.
- Billing: billing contact name, address, tax or VAT identification number, and payment method details. Card and bank details are collected directly by our payment processor; we receive a token, card brand, and last four digits, not the full number.
- Training Account information: the Training Partner program through which your account was provisioned and your enrollment or completion status where the Training Partner provides it.
- Practitioner Directory profile (optional): the service areas, specialties, credentials, biography, photograph, and contact details you choose to publish.
- Communications: support requests, feedback, survey responses, event registrations, and other correspondence.
3.2 Information collected automatically
- Device and technical: device type and model, operating system and version, app version, unique device or installation identifiers, push-notification token, language and time-zone settings, IP address, and network information.
- Usage: features used, pages and screens viewed, actions taken, timestamps, referring pages, and session information.
- Diagnostics: crash reports, performance data, and error logs from the web application, collected through our crash-reporting provider (Section 4).
- Location: approximate location inferred from your IP address; and precise device location only when you grant the mobile app or your browser location permission (Section 4).
- Cookies and similar technologies on our websites and web application (Section 9).
3.3 Information from other sources
- Your Customer organization: the Administrator who creates or manages your account provides your name, work email, role, and permissions.
- Training Partners: confirmation of your enrollment, completion, or graduation for Training Account provisioning.
- Credential issuers and public registers: confirmation of professional designations and license status.
- Service providers: fraud-prevention and security signals, email delivery status, and analytics.
- Business contacts and referrals: if someone refers you or provides your business contact details for a demo or invitation.
3.4 Information we do not collect. We do not use facial-recognition or other biometric-identification technology on photographs or video. We do not collect payment card numbers, government identification numbers, or health information about users, and our Terms of Service prohibit Customers from uploading those and other restricted categories. We do not knowingly collect information from anyone under 18.
4. MOBILE APP PERMISSIONS AND FEATURES
The Tricorn mobile app requests device permissions only for assessment functionality. You control each permission in your device settings; disabling a permission may limit related features.
- Camera and photo library: to capture and attach photographs to assessments. Media you capture is Customer Data.
- Precise location: to geotag assessment records and associate them with the correct property. While an assessment is open in the mobile app or the web application, and only after you grant location permission, your position is recorded periodically and stored with the assessment as Customer Data. We do not collect location in the background, and we do not use precise location for advertising.
- Notifications: to send assessment, portal, security, and account alerts. You can turn notifications off at any time.
- Storage / files: to attach photographs and documents from your device.
- Network access: to synchronize data and deliver the Services.
Crash and performance reporting: the web application and the mobile app send error and crash reports to Sentry so we can fix defects. These reports contain device, browser or operating-system, and app information and the screen or page you were on; they are configured not to capture screen contents, screenshots, session recordings, or Customer Data.
Cross-app tracking: we do not track you across other companies’ apps or websites for advertising, and we do not use advertising identifiers. If Apple’s App Tracking Transparency prompt ever appears in our app, it will be because a feature has changed and we will update this Policy first.
App store providers: Apple and Google collect information about your download and use of the app under their own privacy policies, which we do not control.
5. HOW WE USE PERSONAL INFORMATION AND OUR LEGAL BASES
Where the GDPR, UK GDPR, or similar laws apply, we must have a legal basis for each use. The table below lists our purposes and the basis we rely on.
| Purpose | What we do | Legal basis |
|---|---|---|
| Provide the Services | Create and manage accounts; authenticate users; synchronize data; generate Reports; operate the Client Portal; enable Customer Administrators to manage users; process payments | Performance of a contract (with you or with the Customer that authorized you); legitimate interests in serving our Customers |
| Security and fraud prevention | Detect and block unauthorized access; enforce authentication controls; monitor for abuse; investigate incidents; keep audit logs | Legitimate interests (protecting the Services, our Customers, and the sensitive nature of assessment data); legal obligations |
| Support and communications | Respond to requests; send service, security, billing, and account notices; notify you of changes to the Services or our terms | Contract performance; legitimate interests; legal obligations |
| Credential verification | Confirm Assessor and Practitioner designations and license status with issuing bodies | Legitimate interests (integrity of Reports and the Practitioner Directory); contract performance |
| Training programs | Provision Training Accounts; report activation, status, and conversion to the sponsoring Training Partner | Contract performance; legitimate interests; your consent where required |
| Improve and develop the Services | Analyze usage and diagnostics; fix defects; test features; develop new features, methodologies, and models using de-identified or aggregated data | Legitimate interests (improving our products); consent for non-essential cookies where required |
| Marketing | Send information about features, events, and offers to business users; measure campaign performance | Legitimate interests (B2B marketing) or consent where required by law; you can opt out at any time |
| Legal compliance and protection | Comply with laws, respond to legal process, enforce our terms, defend claims, protect rights and safety | Legal obligations; legitimate interests |
| Business transactions | Evaluate and carry out a merger, financing, reorganization, or sale of assets | Legitimate interests |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights. You may object at any time (Section 13). Where we rely on consent, you may withdraw it at any time without affecting processing that already occurred.
Automated decision-making. We do not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. Scores and analytics in the Services (where offered) evaluate properties and security conditions, not people, and our Terms of Service prohibit Customers from using the Services or Reports to make decisions about any individual’s eligibility for housing, employment, credit, or insurance.
6. AI FEATURES
Some features of the Services use artificial intelligence, including large language models provided by third-party AI providers, to draft, summarize, classify, extract, or organize assessment content and to support future scoring and analytics.
- What is processed. Assessment content (Customer Data) that an Assessor chooses to run through an AI feature, together with the minimum account context needed to deliver the feature.
- Our AI providers. We use AI providers as subprocessors under written terms that prohibit them from using your data to train or improve their generally available models and require confidentiality and deletion. Our current subprocessors are listed at /legal/subprocessors, where you can also subscribe to change notifications.
- Our own models. We may develop, train, evaluate, and improve our own models, methodologies, and benchmarks using de-identified or aggregated data that does not identify a person, a Customer, or a specific property. We do not use identifiable Customer Data for that purpose.
- Human review. AI outputs are suggestions. The Assessor, not the AI feature, is responsible for reviewing and finalizing every Report.
- No automated decisions about people. See Section 5.
7. HOW WE SHARE PERSONAL INFORMATION
We share personal information only as described below. We do not sell personal information and do not share it for cross-context behavioral advertising.
- Your Customer organization. Administrators can see the accounts, roles, activity, and assessment work of users in their organization. If your account was provisioned by your employer or a Practitioner firm, that organization controls it.
- Client Portal Users and Report Recipients. Reports display the name, organization, credentials, and signature of the Assessor who produced them, and Customers share Reports with their clients, insurers, lenders, counsel, and authorities. Our Terms of Service govern how Reports may be shared.
- Service providers (subprocessors). Companies that host and operate the Services on our behalf: cloud hosting and storage, AI providers, analytics and crash reporting, email and notification delivery, payment processing, customer-support tools, mapping and geocoding, identity and authentication, and document generation. They may use personal information only to provide services to us and are bound by contractual confidentiality and security obligations. Current list: /legal/subprocessors.
- Training Partners. If your account was provisioned through a Training Partner, we share account status information, activation, active or inactive status, and conversion to a paid subscription, with that Training Partner to administer the program. We do not share your Customer Data or Reports with a Training Partner unless your organization directs us to.
- Credential issuers. We may share the minimum information needed to confirm a credential with the organization that issued it.
- Practitioner Directory. If you publish a Practitioner Directory profile, the information you choose to include is visible to prospective clients and the public (Section 18).
- Professional advisors. Lawyers, accountants, auditors, insurers, and consultants under confidentiality obligations.
- Legal and safety. Courts, regulators, law enforcement, and other parties when required by law or legal process, to enforce our terms, to defend legal claims, or to protect the rights, property, or safety of Tricorn, our Customers, users, or the public. Where legally permitted and practicable, we notify the affected Customer of legal process relating to Customer Data.
- Business transfers. A buyer, successor, or financing party in connection with a merger, acquisition, reorganization, financing, or sale of all or part of our business, under confidentiality obligations. This Policy will continue to apply, and we will notify you of any material change in how your information is handled.
- With your direction or consent. For example, integrations you enable or information you ask us to share.
Aggregated and de-identified data. We create and use aggregated or de-identified data, statistics, benchmarks, and trend analyses that do not identify a person, a Customer, or a specific property, for any lawful purpose, including product development, research, and industry analytics, and may share it with third parties. We commit not to attempt to re-identify de-identified data and require the same of recipients.
8. CUSTOMER DATA: WHAT WE DO AND DO NOT DO
As a processor of Customer Data, we:
- process it only to provide, secure, and support the Services and as the Customer instructs;
- do not use it for advertising, and do not use identifiable Customer Data to train our own models;
- restrict access to personnel and subprocessors who need it, under confidentiality obligations;
- encrypt it in transit and at rest;
- keep it for the periods set by the Customer’s contract (Section 11), then delete or de-identify it;
- notify the Customer of a confirmed Security Incident affecting its Customer Data without undue delay and no later than 72 hours after we determine one has occurred;
- assist the Customer with data-subject requests, impact assessments, and regulator inquiries as our DPA requires;
- make Customer Data available for export by the Customer.
Customers are responsible for the content they upload, for having any consents or notices required for photographs, recordings, and personal information they collect, and for how they share Reports.
9. COOKIES, ANALYTICS, AND SIMILAR TECHNOLOGIES
Our websites and web application use cookies, local storage, software development kits, and similar technologies for:
- Essential operation: sign-in sessions, security, load balancing, and remembering your settings. These cannot be turned off.
- Analytics: we do not currently use a third-party analytics service in the web application or the mobile app. If we add one, we will update this Policy and, where required by law, ask for your consent first.
- Marketing (websites only): measuring the performance of our marketing and, where you consent, showing you relevant information about Tricorn. We do not use advertising cookies inside the logged-in application.
Your choices. Because we use only the cookies the Services need to work, there is nothing here to consent to and we do not show a consent banner. If we ever add a non-essential cookie we will update this Policy and, where the law requires it, ask you first. You can block cookies in your browser at any time, though sign-in will stop working. What we use is listed at /legal/cookies. We honor Global Privacy Control signals on our websites as an opt-out of any sale or sharing of personal information. Because there is no common industry standard for “Do Not Track” browser signals, we do not respond to them separately.
10. INTERNATIONAL TRANSFERS
We are based in the United States, and we host and process personal information in the United States by default. Our subprocessors may process information in other countries where they operate. When we transfer personal information from the European Economic Area, the United Kingdom, Switzerland, Canada, Australia, Brazil, or other jurisdictions with transfer restrictions, we rely on:
- Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum and Swiss adaptations, included in our DPA;
- other mechanisms permitted by applicable law, including your consent where appropriate; and
- supplementary safeguards, including encryption, access controls, and our policy of challenging government requests that we believe are unlawful or overbroad.
You may request a copy of the transfer mechanism we rely on by contacting us. Where a Customer requires regional hosting, it may be available under the Customer’s contract.
11. HOW LONG WE KEEP PERSONAL INFORMATION
We keep personal information only as long as necessary for the purposes in this Policy, unless a longer period is required by law, contract, or legal process.
| Category | Typical retention |
|---|---|
| Account and profile information | Life of the account, then deleted or de-identified within 90 days after account or subscription termination, except as needed for the items below |
| Assessor identity on Reports | Retained with the Report for the Report’s retention period, to establish, exercise and defend legal claims and because a Report’s value as a record depends on identifying who prepared it and under what qualification |
| Customer Data and Reports (as processor) | Per the Customer’s contract: exportable for 60 days after termination, deleted or de-identified within 90 days, purged from backups within 180 days; archival copies of Reports and audit logs retained up to 7 years (or the applicable limitations period) to verify authenticity and defend claims |
| Credential records | Life of the account plus 3 years |
| Security, access, and audit logs | 12 months, longer if needed for an investigation |
| Diagnostics and crash reports | 90 days |
| Billing and tax records | 7 years |
| Support communications | 3 years after the request is closed |
| Marketing preferences | Until you opt out, then a suppression record so we honor the opt-out |
| Website analytics | 14 months |
When information is no longer needed, we delete it, anonymize it, or securely destroy it. Where deletion from backups is not immediately possible, we isolate the data from further use until it is overwritten in the ordinary backup cycle.
12. HOW WE PROTECT PERSONAL INFORMATION
We maintain administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity, including encryption in transit and at rest, role-based access controls, multi-factor authentication where offered, logging and monitoring, secure software-development practices, vendor security review, and employee confidentiality obligations and training. We periodically test our security program.
No system is completely secure. You are responsible for keeping your credentials confidential, enabling multi-factor authentication where offered, securing the devices you use, and telling us promptly at security@gotricorn.com if you suspect unauthorized access. If we determine that a Security Incident has affected your personal information, we will notify you, your Customer organization, or regulators as applicable law requires.
13. YOUR RIGHTS AND CHOICES
Depending on where you live and which law applies, you may have some or all of the following rights. We honor them in accordance with applicable law regardless of where you are located, to the extent we reasonably can.
13.1 Rights available to most users
- Access, a copy of the personal information we hold about you and information about how we use it.
- Correction, updating inaccurate or incomplete information; you can edit most profile information in your account settings.
- Deletion, deletion of your personal information, subject to exceptions (for example, information we must keep for legal, security, or contractual reasons, and Assessor identity embedded in Reports controlled by a Customer).
- Portability, your information in a structured, commonly used, machine-readable format.
- Objection and restriction, objecting to processing based on legitimate interests, including direct marketing, and asking us to restrict processing in certain circumstances.
- Withdrawal of consent, where processing is based on consent.
- Marketing opt-out, using the unsubscribe link in any marketing email or contacting us. We will continue to send service and account messages.
- Complaint, to us first, we hope, and to a supervisory authority or regulator.
13.2 European Economic Area, United Kingdom, and Switzerland. You have the rights in 13.1 under the GDPR, UK GDPR, and Swiss FADP, and the right to lodge a complaint with your local data-protection authority (in the UK, the Information Commissioner’s Office; in Switzerland, the FDPIC). Providing account information is necessary to use the Services; without it, we cannot provide an account.
13.3 California and other U.S. states. To the extent the California Consumer Privacy Act (as amended by the CPRA) or a similar state law (including in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states) applies to you, you have the rights to know, access, correct, delete, and obtain a portable copy of your personal information; to opt out of sale, sharing, or targeted advertising (we do none); to limit the use of sensitive personal information (we use precise location only to provide the assessment features you enable); and to be free from discrimination for exercising your rights. You may appeal a denied request by replying to our response, and we will explain how to contact your state attorney general if you disagree with the outcome. In the last 12 months we have collected the categories of personal information listed in Section 3, from the sources listed there, for the purposes in Section 5, and disclosed them to the categories of recipients in Section 7 for business purposes only. We have not sold or shared personal information. Authorized agents may submit requests on your behalf with proof of authorization. Under California’s “Shine the Light” law, we do not disclose personal information to third parties for their own direct-marketing purposes.
13.4 Canada. We comply with PIPEDA and applicable provincial laws, including Quebec’s Law 25. You may request access to and correction of your personal information and may file a complaint with the Office of the Privacy Commissioner of Canada or your provincial commissioner. Personal information may be stored and processed outside Canada, including in the United States, where it is subject to the laws of those jurisdictions. Our person in charge of the protection of personal information is identified in Section 1.
13.5 Australia and New Zealand. We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles and the New Zealand Privacy Act 2020. You may request access to and correction of your personal information. Personal information is likely to be disclosed to overseas recipients in the United States and in the countries where our subprocessors operate. Complaints may be made to us and, if unresolved, to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner.
13.6 Brazil. Under the LGPD, you may confirm the existence of processing, access, correct, anonymize, block, or delete unnecessary data, obtain portability, learn with whom we share data, and revoke consent, and you may complain to the ANPD.
13.7 Individuals in Customer Reports. If your request concerns content in a Customer’s assessment or Report, Section 2.3 applies: the Customer is responsible for responding, and we will route your request and assist as our DPA requires.
13.8 How to exercise your rights. Use your account settings for profile edits and account deletion (in the mobile app under Profile → Delete account, or in the web application under your account or profile settings), or contact us at privacy@gotricorn.com or Tricorn LLC, Attn: Privacy Lead, 18426 Livingston Ave, Suite 2, Lutz, Florida 33559, United States. We will verify your identity, usually by confirming control of your account email, and respond within 30 days (45 days where California law applies, extendable once where permitted, in which case we will tell you). Deleting your account removes your profile and login immediately: your sessions end and you cannot sign in again. For fourteen days afterwards the account can be reinstated, so that a deletion made in error is not final; ask an administrator at your organization, or contact us at privacy@gotricorn.com. After those fourteen days the deletion is permanent and cannot be reversed: your email address, phone number, photo and password are erased, and your professional credentials, any certificate files you uploaded, your location history and your notifications are deleted. Customer Data you created remains under your Customer organization’s control, and your name stays on Reports you signed. We retain that one item to establish, exercise and defend legal claims, and because a Report’s value as a record depends on identifying who prepared it and under what qualification; erasure rights do not extend to it for those reasons. We will not charge a fee for a reasonable request and will not treat you differently for making one.
14. CHILDREN
The Services are for business use by adults. We do not knowingly collect personal information from anyone under 18, and Customers may not authorize minors to use the Services. If you believe a minor has provided us personal information, contact us and we will delete it.
15. THIRD-PARTY SERVICES AND LINKS
The Services may contain links to, or integrate with, third-party websites and services, including map providers, app stores, payment processors, identity providers, and Training Partners. Their privacy practices are their own. We encourage you to read their policies before providing information to them.
16. GOVERNMENT AND LAW-ENFORCEMENT REQUESTS
We disclose personal information to government authorities only when we are legally required to, when necessary to protect life or safety, or with the relevant Customer’s or your consent. We review each request for legal validity, seek to narrow overbroad requests, and, where legally permitted and practicable, notify the affected Customer so it may seek protection. We do not provide any government with direct or unfettered access to personal information.
17. YOUR CUSTOMER ORGANIZATION’S ROLE
If your account was created by an employer, a Practitioner firm, or another organization, that organization is our Customer. It can add or remove your access, assign your role, view your activity in the Services, and direct us regarding Customer Data. Questions about how your organization uses the Services or the information it collects should go to your organization first.
18. PRACTITIONER DIRECTORY PROFILES
If we offer a Practitioner Directory and you choose to publish a profile, the information you include (name, organization, credentials, service areas, biography, photograph, and contact details) is visible to prospective clients and may be visible to the public and indexed by search engines. Credential information may display the date we last confirmed it. You can edit or unpublish your profile at any time in your account settings. A listing is not an endorsement by Tricorn.
19. CHANGES TO THIS POLICY
We may update this Policy as the Services, our practices, or the law change. We will post the updated Policy with a new “Last Updated” date and, for material changes, notify you through the Services or by email at least 30 days before the change takes effect, or sooner where required by law. Prior versions are available on request.
20. CONTACT US
Tricorn LLC Attn: Rini de Graaf, Director of Operations (Privacy Lead) 18426 Livingston Ave, Suite 2 Lutz, Florida 33559, United States Email: privacy@gotricorn.com Security concerns: security@gotricorn.com