Privacy Policy
Last updated: August 31, 2026
PatrolKit is patrol management software used by ski patrol organizations to run duty scheduling, time tracking, ski swaps, and patrol-wide communication. This policy explains what information PatrolKit collects, why, and who it is shared with.
Throughout this policy, "we" means PatrolKit, and "your organization" means the ski patrol organization whose PatrolKit account you belong to. Most of the information in PatrolKit is entered by you or by your organization's administrators, and your organization decides who inside it can see what.
Information we collect
Information you give us
- Identity. Your first and last name, your National Ski Patrol ID, and your patrol certification level.
- Contact details. Your email address and mobile phone number, and whether each has been verified.
- Mailing address. Street, city, state, and ZIP — used for ski swap payouts and organization correspondence.
- Payout preferences. If you sell items in a ski swap, how you would like to be paid (check, PayPal, Venmo, or donation) and the account handle you supply for that method.
- Ski swap listings. Item names, descriptions, prices, and any photos you upload.
Information generated as you use PatrolKit
- Time clock records. Clock-in and clock-out events, duty type and notes, and the resort and device involved. PatrolKit does not collect GPS or location data.
- Session records. When you sign in, we store the IP address and browser user agent associated with that session so you and your administrators can spot unfamiliar sign-ins.
- Audit logs. A record of significant actions taken in your organization — who did what, when, and from what IP address — so administrators can review changes.
- Device records. Shared organization devices (check-in stations, label printer bridges) are registered with a name, role, and last-seen time.
PatrolKit does not use advertising trackers, third-party analytics, or cross-site tracking cookies. Cookies are used only to keep you signed in.
How we use your information
- To sign you in and keep your session secure.
- To show you and your organization's administrators the schedules, hours, rosters, and swap records you need to do patrol work.
- To run ski swaps — printing item tags, processing sales, and paying sellers.
- To send you transactional messages, such as sign-in codes and notices about your account or your swap items.
- To keep the service secure, prevent abuse, and diagnose problems.
- To meet legal obligations.
We do not sell your personal information, and we do not use it for advertising.
Text messages (SMS)
We do not sell, rent, or share mobile phone numbers or SMS consent with anyone for their own marketing purposes, and we never share them with third parties or affiliates for marketing. Phone numbers are used only to deliver the messages described below.
PatrolKit sends SMS only in response to something you do. Providing your mobile number and requesting a code is how you opt in.
- What we send. One-time verification codes used to sign in or to confirm your phone number, and account notices related to your patrol organization. We do not send marketing or promotional texts.
- How often. Message frequency varies — messages are sent only when you request a sign-in code or when your organization sends you an account notice.
- Cost. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
- Opting out. Reply STOP to any message to stop receiving texts. Reply HELP for help. You can also remove your phone number from your PatrolKit profile, or ask your organization's administrator to remove it, and sign in by email instead.
How your information is shared
Within your organization
Your name, contact details, certification level, hours, and swap activity are visible to the administrators and officers of your patrol organization, according to the permissions they have configured. PatrolKit keeps each organization's data separate — members of one organization cannot see another organization's data.
With service providers
We use a small number of vendors to operate the service. They may process your information only to provide their service to us:
- Amazon Web Services — hosting, database storage, uploaded photos (S3), outbound email (SES), and text messages (SNS).
- Square — point-of-sale checkout and payment processing at ski swaps, where your organization has enabled it.
- PayPal — seller payouts to PayPal or Venmo, where you have chosen that payout method.
Business transfers
If PatrolKit is reorganized, or transferred to or merged with another entity, information held in the service may transfer as part of that transaction. The receiving entity will remain bound by this policy for information transferred to it, unless and until you are notified of a replacement policy.
For legal reasons
We may disclose information if required by law, or where we believe disclosure is necessary to protect the rights, safety, or property of PatrolKit, our users, or the public.
How long we keep it
We retain your information for as long as your membership in an organization is active, and afterward as needed to maintain accurate patrol, payroll, and swap records for your organization. Sign-in codes expire within minutes and one-time codes are stored only as a hash. Session tokens expire and are revoked when you sign out.
Security
PatrolKit is served over HTTPS. Passwords are not used — sign-in is by one-time code sent to a verified email address or phone number. One-time codes, session tokens, and device secrets are stored hashed, and third-party credentials such as Square access tokens are encrypted at rest. No system is perfectly secure, but we work to protect your information against unauthorized access, loss, and misuse.
Your choices
- Review and update. You can view and correct your name, contact details, mailing address, and payout preferences in your PatrolKit profile at any time.
- Stop text messages. Reply STOP to any message, or remove your phone number from your profile.
- Access or deletion. Contact your organization's administrator, or us at the address below, to request a copy of your information or ask that it be deleted. Some records may need to be retained where your organization or the law requires it.
Children
PatrolKit is intended for use by patrol organization members and is not directed to children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be communicated to organization administrators.
Contact us
Questions about this policy or about your information? Email privacy@patrolkit.io, or contact your patrol organization's administrator. Your use of PatrolKit is also governed by our Terms of Service.