Effective October 1, 2026
This Privacy Policy explains how EntryOne Systems, Inc. ("EntryOne," "we," "us") collects, uses, and shares personal information when you visit entryone.com (the "Site") or use the EntryOne Access Control Platform, including our cloud-connected readers, door controllers, visitor kiosks, intercoms, license-plate recognition cameras, mobile apps, and web portals (together, the "Service").
1. Two roles: our customers and the people who use their facilities
EntryOne provides access-control products and services to organizations ("Customers"): corporations, government and institutional facilities, property owners and managers, residential communities, and the security integrators who deploy on their behalf. When a Customer uses the Service to control access for its employees, residents, tenants, contractors, and visitors ("End Users"), the Customer decides what information is collected, how it is used, and how long it is kept; EntryOne processes that information on the Customer's behalf and under its instructions, as a service provider. If you are an End User, the organization that operates your facility is the primary contact for questions about your information, and we will refer any request you send us to it.
2. Information we collect
Information Customers provide about End Users: name, organization or unit, phone number, email address, credential identifiers (card, fob, PIN, mobile credential, QR code), vehicle license-plate number, and, where a Customer enables face credentials, a facial template derived from an enrollment photo.
Information generated by the Service: access events (which credential was used at which device and when, with a grant or deny result), images captured by readers and gate devices when a credential is presented, a code is entered, or a vehicle arrives at a gate, license-plate reads, intercom call records, and device status and diagnostic data.
Information you provide directly: account details when you register for the portal or app; the contents of support requests; and information you submit through forms on the Site.
Information collected automatically on the Site: IP address, browser type, pages visited, and similar analytics data collected through cookies and similar technologies.
3. How we use information
- To provide, operate, secure, and support the Service, including granting and logging access at Customer facilities
- To communicate with Customers and End Users about the Service, including service and security notices
- To detect, investigate, and prevent security incidents, fraud, and misuse
- To improve the Service, including analyzing aggregated usage
- To comply with law and enforce our agreements
We do not sell personal information, we do not use End User information for advertising, and we do not use End User information to train models or build profiles for any purpose other than delivering the Service to that Customer.
4. How we share information
- With the Customer that operates the facility where the information was collected
- With service providers that host and support the Service — principally Amazon Web Services (cloud hosting, United States), Twilio (telephony), and Microsoft (email and identity) — bound by contract to use the information only to provide services to us
- For legal reasons, when required by law, subpoena, or to protect the rights, safety, or property of EntryOne, our Customers, or others
- In a business transfer, such as a merger or acquisition, subject to this Policy
5. License-plate, face, and image data: usage and privacy policy
Because EntryOne products can read license plates, recognize enrolled faces, and capture images at doors and gates, this section sets out how that data is used and protected. It is EntryOne's published usage and privacy policy for automated license-plate recognition under California Civil Code §1798.90.51, and our written retention and destruction policy for biometric identifiers under applicable biometric-privacy statutes. Customers that operate EntryOne systems may adopt it as their own.
Effective dates. The commitments in this section on purpose, sharing, law enforcement, watchlists, and aggregation are in effect now, and face credentials are not currently offered at sites in Illinois. The following take effect on November 1, 2026: the retention limits in Section 6 with automatic deletion; the non-storage of plate numbers for vehicles that are not enrolled; the export limits; access records; and, at any site where face verification mode is not yet in place, the requirement that the Customer confirm each enrolled person's consent. Face verification mode and consent capture at enrollment are being deployed by software and firmware update, and this policy will be updated as they are completed.
Purpose. Plate reads, face matches, and the images captured with them are used for one purpose: to decide whether to grant access at the specific door or gate where they were captured, and to document that decision for the Customer's audit trail. Vehicle attributes visible in an image (for example color, make, or body type) may be compared with the enrolled vehicle as an additional authentication factor for the same access decision. We do not use this data for any other purpose.
License plates work like keys. A plate is read only to decide whether the vehicle at the gate is enrolled. When it is, the gate opens and the event is recorded against that vehicle's credential, as with any key or card. When the vehicle is not enrolled, its plate number is not stored: the read is used for the comparison and then discarded. An image of a vehicle that is not enrolled may be kept for security review for 7 days; it is not linked to a plate number and cannot be searched by plate. Matching is performed on the device first; if the device cannot resolve a read, the image is sent to EntryOne's cloud for matching, the decision is returned to the device, and the same rules apply.
Face credentials: verification, not search. In verification mode, a person first presents another credential — a code, card, or mobile credential — and the reader then compares the face in front of it with that one person's enrolled template. Faces are not searched against a database of people, and no face template is created for anyone who has not enrolled. Templates are stored encrypted and cannot be converted back into an image.
Images at doors and gates. Readers and gate devices capture an image when someone interacts with them — a credential presented, a code entered, a vehicle arriving at a gate. These images document the access decision and are retained as set out in Section 6.
What we do not do. We do not operate or participate in a network of cameras across customers or sites. We do not pool, aggregate, or correlate plate, face, or image data across Customers, locations, or time to track the movements of any person or vehicle. We do not maintain, subscribe to, or match plates or faces against law-enforcement or third-party watchlists or hotlists, and the Service does not generate alerts about vehicles or people who are not enrolled. We do not sell this data, license it, share it with data brokers, or use it for advertising. We do not use it to infer characteristics of individuals (such as demographics, emotion, or health), and we do not use Customer images to train or improve models without the Customer's explicit written consent.
Sharing and law enforcement. Plate, face, and image data belongs to the Customer that operates the facility and is disclosed only (a) to that Customer through its portal, apps, and reports; (b) to our subprocessors solely to host and operate the Service; or (c) when EntryOne is legally compelled by a valid subpoena, warrant, or court order, in which case we disclose only the specific records demanded, and notify the Customer before disclosure unless prohibited by law. EntryOne does not provide standing, direct, or self-service access to any government agency. A Customer may itself choose to share its own records with law enforcement; that is the Customer's decision and responsibility.
Authorized access and training. Within EntryOne, access to Customer plate, face, and image data is limited to the Engineering Lead, engineers assigned to production support, and the Information Security Officer, solely to operate and support the Service; it requires multi-factor authentication and is logged. These personnel complete security and privacy training on hire and annually, including this policy. Within a Customer's organization, access is controlled by the roles the Customer assigns in the portal; the Customer is responsible for training and supervising its users, and EntryOne provides training material for that purpose.
Monitoring and access records. EntryOne monitors the Service for security and for compliance with this policy through access logging, continuous configuration monitoring, threat detection, and an annual independent SOC 2 examination. The Service records each access to plate and image data — the date and time, the plate number or other search terms used, the user and organization, and the purpose where the user supplies one — and makes those records available to the Customer for audit. Images can be exported only one event at a time, and each export is recorded; bulk export of images is not available.
Accuracy and correction. Plate reads are confirmed against the enrolled vehicle before access is granted; a read that does not match is treated as unmatched and never as evidence about a person. Customers and End Users may report a misread or an incorrect record to their facility operator or to privacy@entryone.com, and EntryOne corrects or deletes erroneous records on request.
Custodian. EntryOne's Data Protection Officer is the custodian responsible for this policy and for the Service's handling of plate, face, and image data. Each Customer designates an administrator as custodian of its own records.
Retention and destruction. EntryOne sets the retention limits in Section 6. Customers may shorten them but cannot extend them, except by placing a legal hold on specific events for an investigation or proceeding. Data is permanently deleted from production systems when its retention period ends, and from backups within 35 days thereafter.
Consent and notice. Face credentials are optional and are enabled only by the Customer's configuration and the End User's enrollment. Enrollment records the End User's informed consent — in Illinois, a signed written release — before any template is created. The Customer is responsible for any notice required at its facility and for its own consent obligations; EntryOne provides template notices and enrollment records to support this. Face credentials are not offered where local law prohibits them, including places of public accommodation in Portland, Oregon.
New uses. If EntryOne introduces any additional use of plate, face, or image data beyond producing and documenting the access decision, it will do so only with prior notice to Customers, an update to this policy, and the Customer's opt-in.
6. Data retention
The table below is EntryOne's retention schedule, effective November 1, 2026. These periods are maximums: EntryOne deletes data when they are reached, and Customers may choose shorter periods. Where local law requires a shorter period — for example, for smart-access systems in New York City multifamily buildings — the shorter period applies. A Customer may place a legal hold on specific events to preserve them for an investigation or proceeding, for up to 12 months or until the hold is released.
| Data | Retained for |
|---|---|
| Access events (credential or enrolled vehicle, device, date and time, result) | 365 days |
| Images and video captured with access events and intercom calls | 30 days |
| Images of vehicles that are not enrolled | 7 days, not linked to a plate number |
| Plate numbers of vehicles that are not enrolled | Not stored |
| Raw plate-read data (character reads and confidence scores) | 14 days, for accuracy review |
| Face templates | Life of the credential; deleted within 30 days of revocation or after 12 months without use |
| Records of access to plate and image data | 2 years |
| Device status and diagnostic data | 90 days |
| Site analytics (entryone.com) | 24 months |
Customer account and configuration data is retained for the life of the Customer relationship and deleted or returned within 90 days of termination, subject to legal obligations.
7. Security
The Service runs on a fully serverless architecture hosted by Amazon Web Services in the United States (dedicated regional environments are available to Customers with data-residency requirements). Data is encrypted in transit (TLS 1.2 or later) and at rest. Access to production systems requires multi-factor authentication and is limited to authorized personnel. EntryOne maintains a security program aligned with the SOC 2 Trust Services Criteria, including continuous configuration monitoring, threat detection, vulnerability scanning, and incident response procedures. No system is perfectly secure; if we learn of a breach affecting your information, we will notify affected Customers without undue delay and as required by law.
8. Your choices and rights
California residents (CCPA/CPRA): you have the right to know what personal information we collect and how we use and share it, to request deletion, to correct inaccurate information, and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise these rights, contact us at the address below; if we hold your information on behalf of a Customer, we will forward your request to that Customer. We will verify your identity before acting on a request.
Other jurisdictions: you may have similar rights under the law of your state or country. We honor rights requests as required by applicable law.
Cookies: you can control cookies through your browser settings; disabling cookies may limit some Site functionality.
Marketing email: you can unsubscribe at any time using the link in any marketing message.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children. Any credentials issued to minors are issued and managed by the Customer.
10. International
We are located in the United States and process information in the United States. If you access the Service from outside the United States, you consent to processing in the United States.
11. Changes to this Policy
We will post any changes on this page and update the effective date. Material changes will be communicated to Customers by email.
12. Contact us
EntryOne Systems, Inc., 4695 MacArthur Court, 11th Floor, Newport Beach, CA 92660 USA. Email: privacy@entryone.com. Phone: 877-661-0551