Glassboard

Privacy Policy

This Privacy Policy is effective as of January 14, 2014. Your continued use of Second Gear’s websites (http://www.secondgearsoftware.com, http://www.glassboard.com) and applications or services after such time shall signify your express acceptance of this Privacy Policy. This Privacy Policy is intended to inform you of our policies and practices regarding the collection, use and disclosure of information that we collect from you or that you may submit to us through our website, applications, or services. This Privacy Policy is hereby incorporated in the Second Gear Terms of Service, and by registering for our services, or otherwise using our services, you signify that you have read, understood, and agree to be bound by the terms of this Privacy Policy. This policy does not apply to the practices of companies that Second Gear does not own or control, or to people that Second Gear does not employ or manage.

By submitting information through Second Gear websites or services, you agree to the terms of this Privacy Policy and you expressly consent to the processing of your information according to this Privacy Policy.

Overview

Privacy is the foundation of our business. Our service provides users with the ability to connect and share in a private environment, and we’ve implemented both our user experience and security model to support this fundamental requirement. This policy will outline how our platform, our APIs our external clients and third party service providers store and transmit the content created within the system.

This policy includes all Glassboard client applications released by Second Gear (Android, iOS, Windows Phone 7, Silverlight) as well as the Glassboard Platform.

Further inquiries can be sent to support@secondgearsoftware.com.

Glassboard Platform

The Glassboard Platform is deployed in Microsoft Windows Azure. Data is stored encrypted in table storage and blob storage. Supplemental data such as analytical data is stored in a SQL Azure database. All analytical data is de-personalized and obfuscated prior to being recorded.

Data Stored

- Protection of Personal Information

Second Gear takes numerous precautions, including administrative, technical, and physical measures, to safeguard your personal information against loss, theft, and misuse, as well as against unauthorized access, disclosure, alteration, and destruction.

- Personally-Identifiable Data

Glassboard collects email addresses for all users. Our platform will accept an email address as a username for authentication as well as a user’s system-generated unique ID. The platform has the ability to correlate multiple email addresses with a single Glassboard unique user ID. We may also store multiple phone numbers per user if the user has supplied them.

This data is never shared with any outside entities, except when necessary to supply services as specified. For example, email addresses are shared with our email service provider so that we can send email.

Data Created

All statuses, comments, user locations, board names, and phone numbers in the Glassboard Platform are encrypted using well-recognized practices before being written to storage. Glassboard Platform-generated metadata such as unique identifiers and messages counts are not encrypted. Uploaded files such as photos and videos are also not encrypted.

Encrypted Glassboard data is decrypted only on our production servers. No other machines, including those of the developers, have the ability to decrypt production data. All certificates are uniquely password-protected. Certificates are stored in source control for backup but are stored as an encrypted and password-protected archive.

Any Second Gear employee with access to all of these certificates and passwords is strictly prohibited from using that access except in the case of catastrophic system failure or in compliance with any law enforcement agency with legal right to the information requested.

- Location

When requested by the user (via a switch on the message interface) Glassboard will request your location only when you would like to use it. End users have the ability to choose whether to include their location with each message. Glassboard for Windows Phone 7 uses Microsoft’s Location Service APIs.

Data Theft Assessment

All connections to the Glassboard Platform are made via SSL. The Glassboard Platform does not support non-SSL HTTP requests. All data transmitted between client applications and the Platform is secured in accordance with current standard practices.

Data sent in push notifications and/or email alerts is not encrypted. If you disable those features, the messages will not be sent.

Decrypted data is accessible on the Glassboard Platform servers as requests are processed, as well as on client applications making web service requests to the platform.

Second Gear strives to maintain the strictest privacy and security practices recommended by each platform and service provider.

Microsoft Windows Azure hosts the servers and data storage for the Glassboard Platform. Microsoft outlines its physical and data security measures in this document (PDF). Glassboard adds further data protection by encrypting sensitive user data prior to writing to storage.

Disclosure to Third Parties and Links to Other Sites

We DO NOT sell, rent, or otherwise share personal information to Third Party companies for marketing purposes. We may share your personal information with other companies who work on our behalf or to improve our products and services. In some cases, your purchase of Second Gear products or services may be handled by a third-party store or service, over whose privacy policies we do not have control.

We may include or offer third party products or services on our website. These third party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our website and services and welcome any feedback about these third party sites.

Changes to Privacy Policy

Second Gear may update this policy. Second Gear reserves the right, at its sole discretion, to change, modify, or otherwise alter the provisions of this Privacy Policy from time to time by updating its website or any linked information. Unless otherwise provided in such change, modification, or alteration, the updated Privacy Policy provisions, or any part thereof, will take effect when they are posted to the Second Gear website. Such change, modification, or alteration to the Privacy Policy provisions may be made without notice to you. You agree that your continued use of the Second Gear website or services obligates you to review the Privacy Policy provisions from time to time for any changes, modifications, or alterations which may occur.

For more information send inquiries to support@secondgearsoftware.com