Privacy Statement

How POPS Notebook collects, uses, and protects your data

Last updated: 28 July 2026

1. Data Controller and Data Processor

POPS Notebook, Inc. ("POPS Notebook", "we", "us") acts as a Data Processor in respect of any personal data processed through the Application. Your police force is the Data Controller for operational data created and used by its officers.

POPS Notebook processes limited account data as a Data Controller for the purposes of authentication, billing, and service delivery. This statement explains what we collect, why, and how we protect it.

2. Information We Collect

We collect and process the minimum data necessary to provide the Application. We operate a Zero-Knowledge architecture: the server cannot decrypt your operational data, officer profiles, or force broadcasts.

  • Username: a self-chosen identifier (e.g., collar number) used for display and audit. Your email is never shown to Force Admins.
  • Personal email address: used solely for authentication and OTP delivery. Stored as an irreversibly hashed identifier for linkage; the plaintext is retained by the authentication provider only.
  • Work email hash: a SHA-256 hash of your force-issued email, salted with a per-force cryptographic salt. The plaintext work email is never persisted — it is extracted in memory, hashed, and immediately discarded.
  • Home force hash: a SHA-256 hash of your force's email domain, salted with the same per-force salt. Used to partition data by force.
  • Encrypted officer profile: an AES-GCM ciphertext containing your name, mobile, collar number, rank, and specialisms. The server cannot decrypt this — only same-force officers holding the derived key can.
  • Role and qualification data: your ForceRole, Rank, PublicOrderLevel, and training status, stored on your user record for access control.
  • Payment identifiers: Stripe customer ID and subscription status. We do not store card numbers — payment is handled entirely by Stripe.

3. How We Store Your Data

The Application employs a layered encryption model designed so that a server breach exposes no decryptable operational data:

  • SHA-256 with per-force salt: Work email hashes and force domain hashes are salted with a cryptographically random per-force salt before hashing, preventing rainbow table attacks across forces.
  • AES-GCM encryption: Officer profiles and force broadcasts are encrypted on-device using the Web Crypto API. The encryption key is derived from force-scoped parameters and is never transmitted to the server.
  • Session-based key management: Encryption keys are held in sessionStorage and are destroyed when the browser session ends, ensuring key ephemerality.
  • Local-only operational caches: All operational data (rosters, plans, sketches, logs) is stored in ephemeral browser cache with a 24-hour TTL. No operational data is written to a cloud database.
  • Row-Level Security: Database access is enforced at the platform level, ensuring officers can only read and write data scoped to their own force hash.

4. Why We Collect Your Data

We collect data only for the following lawful purposes:

  • Authentication and account management: to verify your identity and grant access to the Application.
  • Operational status verification: to confirm you are a serving member of a legitimate UK police force by validating your force-issued email domain against a whitelist of approved forces.
  • Force isolation: to partition data so that only officers from the same force can access each other's encrypted profiles and broadcasts.
  • Audit and accountability: to record administrative actions (role changes, license grants, exports) using your Username, never your email, for PII compliance.
  • Billing and licensing: to manage individual subscriptions and force enterprise licenses via Stripe.
  • Communication: to send you OTP codes, force broadcasts, and critical service notifications via SendGrid.

5. Data Retention

Operational data (rosters, plans, sketches, NDM logs, use-of-force logs, broadcast messages) is retained in ephemeral local cache for a maximum of 24 hours and is never persisted to the cloud.

Account data (username, email hash, force hash, role, qualifications) is retained for the lifetime of your account. You may request deletion of your account at any time, which will permanently remove all associated data from the database.

Audit logs are retained for 12 months to support Information Assurance compliance reviews, as is standard for UK policing audit requirements.

Force license records are retained for the duration of the force's enterprise subscription and for 6 years thereafter for financial audit compliance.

6. Third-Party Processors

We use the following third-party processors, each acting under their own GDPR-compliant terms:

  • Stripe: processes subscription payments and force enterprise billing. Card details are never stored by POPS Notebook. See stripe.com/privacy for their privacy policy.
  • SendGrid: delivers OTP verification emails and force broadcast notifications. Only the recipient email address and message content are transmitted. See sendgrid.com/privacy.
  • Google OAuth: provides optional single sign-on for account registration. We receive your email address and a Google-issued token; no Google account data is stored. See policies.google.com/privacy.
  • Base44: provides the application hosting platform, database, and serverless compute infrastructure. See base44.com/privacy.

Sub-processor changes: We commit to providing a minimum of 7 days' written notice to your Force Data Protection Officer prior to engaging any new sub-processor or materially changing the terms of an existing sub-processor arrangement. Forces may raise objections during this notification period. A register of current sub-processors is available on request from info@popsnotebook.co.uk.

7. Your Rights Under UK GDPR

As a data subject, you have the following rights:

  • Right of access: you may request a copy of the personal data we hold about you.
  • Right to rectification: you may request correction of inaccurate data.
  • Right to erasure: you may request deletion of your account and all associated data.
  • Right to data portability: you may request your data in a machine-readable format.
  • Right to object: you may object to processing based on legitimate interests.
  • Right to restrict processing: you may request that we limit how we use your data.

To exercise any of these rights, contact your Force Data Protection Officer or submit a request through the Application's Settings page. We will respond within 30 days, as required by UK GDPR.

Data portability and off-boarding: Forces retain the right to bulk-export their ForceAdminAudit logs as a CSV report at any time via the Force Admin dashboard. Upon contract termination, forces are provided with a full export of all administrative audit trails and license records. All operational data is ephemeral and device-local — no operational data is held on the server to extract, and all local caches expire automatically within the configured TTL.

8. Cookies and Local Storage

The Application does not use tracking cookies or advertising cookies. It uses browser localStorage and sessionStorage for the following purposes:

  • Authentication token storage (sessionStorage): destroyed on logout or session end.
  • Ephemeral operational data caches (localStorage): auto-expire after 24 hours.
  • User preferences (localStorage): theme, night mode, and navigation state.
  • Encryption keys (sessionStorage): destroyed on session end to ensure key ephemerality.

9. Data Residency and International Data Transfers

The Application's hosting platform, database, and serverless compute infrastructure are hosted in United Kingdom data centres. Account data (email hash, force hash, encrypted profile ciphertext) is stored exclusively within the UK and is not transferred to or processed in any third country.

Operational data does not leave the officer's device and is therefore not subject to any transfer. Only account data (hashed identifiers and encrypted ciphertext) is stored on the UK-hosted platform.

Our Zero-Knowledge architecture provides an additional layer of data sovereignty assurance: the server stores zero plain-text PII or operational data. All operational payloads and officer profiles are AES-GCM encrypted on-device before transmission. The server functions as a zero-knowledge relay — it stores only opaque ciphertext blobs and irreversibly hashed identifiers. A database breach, regardless of the geographic location of the servers, exposes no decryptable personal data or operational intelligence.

Our sub-processors (Stripe and SendGrid) operate their own infrastructure which may be located outside the UK. Where any sub-processor transfers personal data internationally, we rely on Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum to ensure a level of data protection equivalent to UK GDPR. Sub-processor data processing is limited to payment processing (Stripe) and transactional email delivery (SendGrid); no operational data or officer profiles are shared with sub-processors.

10. Contact

If you have any questions about this Privacy Statement or how your data is handled, please contact your Force Data Protection Officer or reach out to POPS Notebook support through the Application's Settings page.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data in accordance with UK GDPR.

POPS Notebook, Inc. — Data Processor  |  Police Force — Data Controller  |  UK GDPR Compliant