Privacy Notice
Last updated: July 29, 2026
This Privacy Notice is maintained by BMEC Products ("we", "us") to explain how we collect, use, share, and retain personal data when you use the Halo safety companion app ("Halo" or the "Service"). BMEC Products is the data controller for the personal data processed through Halo.
1. Data we collect
- Account data: name, email address, login credentials, language preference.
- Safety data: emergency contacts you add, location data when you actively enable location sharing, watch-button events.
- Content: messages you send in ghost chat, community reports you submit, prompts to the AI night-crime insights feature.
- Usage & device data: device identifiers, IP address, log data, and diagnostics used to keep the Service running and secure.
- Billing data: collected and processed by our reseller Paddle (see "Data sharing" below).
2. Purposes and legal basis
- Providing the Service (contract performance).
- Account creation, authentication, and customer support (contract performance).
- Security, fraud prevention, and abuse mitigation (legitimate interests / legal obligation).
- Product improvement and analytics on aggregated data (legitimate interests).
- Sending service and trial-related emails (contract performance / legitimate interests).
- Marketing communications only where you have consented (consent).
3. Data sharing
We share personal data only with:
- Service providers / subprocessors that host our infrastructure, provide authentication, run our database, and power AI features.
- Paddle.com Market Ltd. — our Merchant of Record for all sales. Paddle handles checkout, payments, taxes, invoicing, subscription billing, and refund processing. Paddle acts as an independent controller for payment data. See Paddle's Buyer Terms and Privacy Notice at paddle.com.
- Professional advisers (legal, accounting) where reasonably needed.
- Authorities where required by law, court order, or to protect the safety of users or the public.
We do not sell personal data.
4. International transfers
Personal data may be transferred to and processed in countries outside your own. Where required by law (including UK/EEA transfers), we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
5. Retention
We retain personal data only as long as necessary to provide the Service and to meet legal, tax, and accounting obligations. Account data is deleted (or anonymised) shortly after you delete your account from the Account screen. Location data shared with your Circle is retained only while a live-share session is active. Support and billing records may be retained longer where required by law.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, to object to processing, or to withdraw consent. UK/EEA users have these rights under the GDPR and may complain to their supervisory authority. We aim to respond to requests within one month. To exercise your rights, contact us using the details below or use the "Delete account" control in the Account screen.
7. Security
We use appropriate technical and organisational measures, including encryption in transit, access controls, and audit logging, to protect personal data. No system is perfectly secure; please use a strong, unique password and keep your device secure.
8. Cookies
Halo uses essential cookies and local storage required to keep you signed in and remember your language. We do not use third-party advertising cookies. Any future analytics or marketing cookies will be disclosed here and, where required, only set with your consent.
9. Contact
Questions or privacy requests? Contact BMEC Products through the support option in the Halo Account screen. Billing-specific questions are handled by Paddle at paddle.net.
This page is maintained by BMEC Products to answer common privacy questions about Halo. It is not a certification and does not replace legal advice.