1. Who we are
SecTrak is a field service management platform for security companies, developed and operated by Montalex Limited, a company registered in England and Wales.
Montalex Limited
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Email: info@montalex.co.uk
Phone: +44 (0) 207 870 6230
2. What this policy covers
This privacy policy explains how Montalex Limited collects, uses, stores and protects personal data in connection with the SecTrak platform — including the web dashboard used by security company administrators and the SecTrak Android mobile application used by field engineers.
SecTrak is a business-to-business (B2B) platform. The security companies that subscribe to SecTrak (referred to as "tenants") are responsible for their own data protection obligations in relation to their clients and employees. Montalex Limited acts as a data processor on behalf of tenants in relation to the personal data they manage through SecTrak.
3. Data we collect
Account and user data
When a security company registers for SecTrak, we collect:
- Company name and contact details
- Administrator name and email address
- Engineer names, email addresses and phone numbers
- Encrypted passwords
- Login timestamps and session data
Job and operational data
As part of normal platform use, we store:
- Client company names, addresses and contact details
- Site addresses and access notes
- Job details, descriptions and status history
- Engineer job reports including work completed, parts used and recommendations
- Client signatures collected at the point of job completion
- Scheduled dates and times
Photos and images
The SecTrak Android app requests access to your device camera. Engineers may use this to photograph:
- Completed work for job documentation purposes
- Outstanding faults or defects identified on-site
- Any other relevant site conditions
Photos are uploaded securely and stored in Cloudflare R2 object storage in Western Europe. They are used exclusively for generating job reports and maintenance certificates delivered to the security company's clients. Photos are never used for advertising or shared with third parties.
Device and technical data
- Device push notification tokens (used to send job assignment alerts to engineers)
- IP addresses (used for security monitoring and rate limiting)
- API request logs (retained for security purposes)
Billing data
Payment and subscription data is handled entirely by Stripe. Montalex Limited does not store card numbers or payment credentials. We retain Stripe customer IDs and subscription status only.
4. How we use your data
- To provide and operate the SecTrak platform
- To send push notifications to engineers when jobs are assigned
- To generate branded job reports and maintenance certificates
- To process subscription payments via Stripe
- To monitor platform security and prevent abuse
- To provide customer support
- To send transactional emails (job notifications, billing updates) via Resend
We do not use your data for advertising. We do not sell your data to any third party.
5. Legal basis for processing
We process personal data under the following legal bases:
- Contract performance — to deliver the SecTrak service to subscribing companies
- Legitimate interests — for platform security monitoring and fraud prevention
- Legal obligation — to comply with applicable UK law
- Consent — for push notifications, which can be withdrawn at any time via device settings
6. Camera permission
The SecTrak Android app requests access to your device camera solely to allow field engineers to photograph job sites, completed work and outstanding faults. Photos are used only for generating client-facing job reports. Camera access is never used for any other purpose. You can revoke camera permission at any time in your device settings.
7. Data storage and security
- All data is stored within the European Union or European Economic Area
- Database: Supabase (PostgreSQL) — EU region
- File storage: Cloudflare R2 — Western Europe
- All data is encrypted in transit using TLS
- Passwords are hashed using bcrypt and never stored in plain text
- Each tenant's data is logically isolated — no cross-tenant data access is possible
- Security logging and IP-based rate limiting protect against unauthorised access
8. Data retention
We retain your data for as long as your SecTrak subscription is active. If a subscription is cancelled, account data is retained for 30 days before permanent deletion, unless an earlier deletion is requested.
Security logs are retained for 90 days. Billing records are retained for 7 years as required by UK financial regulations.
9. Third-party services
SecTrak uses the following third-party services to operate the platform:
- Supabase — database hosting (EU)
- Cloudflare R2 — file and photo storage (Western Europe)
- Stripe — payment processing
- Resend — transactional email delivery
- Expo / Firebase FCM — Android push notifications
- Railway — API hosting
- Vercel — web dashboard hosting
Each of these providers operates under their own privacy policies and data processing agreements.
10. Your rights under UK GDPR
You have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your personal data
- Restriction — request that we limit how we use your data
- Portability — receive your data in a portable format
- Object — object to processing based on legitimate interests
To exercise any of these rights, please contact us at info@montalex.co.uk. We will respond within 30 days.
11. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
12. Changes to this policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated date. Continued use of SecTrak after changes are posted constitutes acceptance of the updated policy.
13. Contact us
For any privacy-related queries or requests:
Montalex Limited
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Email: info@montalex.co.uk
Phone: +44 (0) 207 870 6230