Privacy Policy
Riskcast Solutions, Inc. provides the Riskcast Solutions platform, including associated applications such as the Attendance Kiosk, for use with active customer accounts. This policy describes how we collect, use, and disclose information through those services and our public marketing website. The website analytics described below are separate from customer-platform data. We use information to provide and improve our services as described in this policy. Visiting the website does not replace an explicit consent choice where one is required.
The terms used in this Privacy Policy have the same meanings as in our Terms of Service, unless otherwise defined in this Privacy Policy.
Information Collection and Use
For a better experience while using our platform, we may require you to provide us with certain personally identifiable information, including but not limited to your email address. The information we request will be retained and used as described in this Privacy Policy. The Riskcast platform does not use third-party services that collect personal information without disclosure but does operate in conjunction with other Riskcast modules that, per our customers' Terms & Conditions with Riskcast, will supplement and enhance this platform.
Log Data
We want to inform you that whenever you use our Service, in a case of an error in the app we collect data and information (through third-party products) on company iPad called Log Data. This Log Data may include information such as your device Internet Protocol ("IP") address, device name, operating system version, the configuration of the app when utilizing our Service, the time and date of your use of the Service, and other statistics.
Cookies
Our public website uses cookies and similar browser storage for necessary functions, consent choices, and optional analytics and marketing features. Optional analytics, marketing, and preference choices are off by default. Google Analytics and browser AI-referral submissions require analytics consent; HubSpot tracking, forms and chat, and Leadfeeder require marketing consent. You can reject optional features or change your choices in Cookie Settings. Some optional features, such as embedded marketing forms or chat, will not load without the relevant consent.
Consent choices are stored in your browser. Session storage can also hold a temporary landing-source record and a random identifier for AI-referral duplicate prevention. Preparing that local record does not itself submit an AI-referral event. The consent controls above do not disable necessary server operations or all first-party website reporting: separate website traffic reporting records session and landing-page information, which can include URL parameters.
AI Traffic Analytics on Our Public Website
When enabled, this feature helps us understand which public pages are requested by software identifying itself as an AI crawler and which website landing sessions appear to come from AI services. It measures crawler requests separately from referral landing sessions. It does not measure unique people, prove that an AI provider visited, or establish that our content was cited, recommended, used for training, or led to a sale. User-agent and referral-source signals can be incomplete or spoofed.
- Crawler observations: For eligible completed requests to known public pages, we retain the time, page pathname without query parameters, matched provider and bot label, response status, classification version, collection source, an unverified status, and a hashed duplicate-prevention identifier. Classification uses user-agent patterns; the AI-traffic record does not retain the full user-agent string.
- AI referrals: After analytics consent, the browser may submit the landing-page pathname, a normalized source label or referring hostname, and a random duplicate-prevention identifier to our own server. Recognized sources produce a record containing the time, page pathname, provider/product label, matching method, classification version, and a keyed hash of the identifier. The raw identifier is not retained in the AI-traffic database.
- Daily summaries: We combine these records into daily counts by public page, provider, metric type, and applicable response status. Reports are restricted to authenticated administrators.
These AI-traffic records exclude raw IP addresses, full referrer URLs, URL query strings, raw session identifiers, cookies, request bodies, and full user-agent strings. This limitation applies to the AI-traffic dataset, not to separate infrastructure logs, customer-platform records, or other website services described in this policy. Hashed identifiers are pseudonymous, not a guarantee of anonymity.
We process this analytics dataset within our website and database services; this feature does not send its records to AI model providers for classification or training. A provider label describes the matched source signal, not a data-sharing relationship.
AI Traffic Retention and Deletion
When this feature is enabled, its planned retention period is 90 days. Detailed crawler and referral records, including their hashed identifiers, receive an expiry time based on that period. Expired records are removed during cleanup, not necessarily at the exact expiry instant. Daily summaries use whole UTC days, so the cutoff day's summary can remain for up to one additional day, plus cleanup delay. A summary supporting an unexpired detail record is preserved until that detail can expire.
Cleanup verifies summary consistency before deleting data. A verification failure pauses deletion for investigation rather than silently discarding inconsistent records. Changing a retention setting does not automatically shorten expiry times already assigned to existing records. The 90-day period is therefore not a promise that every copy disappears at an exact timestamp.
Database backups and recovery copies have a separate lifecycle; this feature's cleanup does not erase them. Backup expiry and handling of deletion requests must be covered by the applicable backup and privacy procedures before collection begins. We do not represent the AI-traffic retention period as a verified backup-deletion deadline.
Your Choices and Privacy Requests
You can withdraw analytics consent in Cookie Settings to stop future browser AI-referral submissions. Withdrawal cancels pending browser work where possible, but does not automatically delete records already received. Server-side crawler observations are separate from browser analytics consent; a cookie choice is not authorization for that collection.
To ask about this processing or request access, correction, or deletion where applicable, contact support@riskcast.com. Requests are subject to applicable law, appropriate verification, and our ability to locate the relevant records. Because the AI dataset excludes direct identifiers and stores only keyed hashes of temporary identifiers, we may not be able to associate a particular record with you. Do not send passwords or other credentials with a request.
Service Providers
On our public marketing website, we use Leadfeeder (Dealfront) only after you allow marketing cookies. It processes IP addresses, cookie identifiers, and information about website visits to help identify visiting companies and understand their interest in Riskcast. You can refuse or withdraw this consent in Cookie Settings. Withdrawing consent after the tracker starts reloads the page to stop it. This website tracking is separate from our customer platform.
We may employ third-party companies and individuals due to the following reasons:
- To facilitate our Service;
- To provide the Service on our behalf;
- To perform Service-related services; or
- To assist us in analyzing how our Service is used.
We want to inform users of this Service that these third parties have access to their Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.
Security
We value your trust in providing us your Personal Information if required, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.
Links to Other Sites
This Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these websites. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Children's Privacy
These Services do not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13 years of age. In the case we discover that a child under 13 has provided us with personal information, we immediately delete this from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we will be able to do the necessary actions.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. Thus, you are advised to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page.
Contact Us
If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at support@riskcast.com.