Public legal notice
Privacy Policy
How TRAKID handles information across its connected visitor-experience products.
Explorer Quest · Compass Quest · Adventure Quest · CheQRboard
This Privacy Policy explains how TRAKID, LLC ("TRAKID," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when people use Explorer Quest—including Compass Quest and Adventure Quest—CheQRboard, our customer-management systems and administrative dashboards, our websites at trakid.com, xplorerquest.com, cheqrboard.com, and cheqrboard.co.uk, and related support services (collectively, the "Services"). It also covers business contacts, job applicants, and workforce members to the extent described below.
It also explains the distinct roles played by TRAKID and the zoo, museum, aquarium, garden, park, school, event operator, or other organization that offers an experience through the Services (a "Venue Customer"). A Venue Customer may provide an additional privacy notice. When a Venue Customer asks its own questions or decides what visitor information to collect, that Venue Customer’s notice and choices also apply.
1. Scope and product overview
Explorer Quest. Explorer Quest is the U.S.-only product family that includes Compass Quest and Adventure Quest. Compass Quest combines the Explorer Quest iOS or Android application with a rechargeable compass wearable that pairs to the phone by Bluetooth, can use GNSS/satellite location, displays illuminated directional arrows, and may play prerecorded audio or vibrate at quest points. The wearable is ordinarily worn on a wrist or arm using an approved band but may use an approved clip or breakaway lanyard configuration. Adventure Quest uses pre-programmed paper, silicone, elastic-fabric, or other approved wearable bands that interact with venue-installed activation devices, sometimes called bump boxes, without a consumer mobile application. Those devices may trigger venue effects such as lights, sound, projection, fog, or animatronics. Explorer Quest is offered and supported only for authorized venue deployment in the United States.
CheQRboard. CheQRboard is the product TRAKID offers internationally. It lets Venue Customers create, download, organize, and manage dynamic QR codes whose destinations can be changed without replacing printed signage. Customers can build calls to action, images and galleries, multiple choice and open responses, polls, direct links, upcoming-event pages, link trees, business cards, video, PDF, audio, surveys, games, and other visitor-facing experiences; connect payment or donation experiences; translate content; and review engagement analytics. A visitor ordinarily may scan and view content without creating a TRAKID account or providing direct identifiers. A Venue Customer may, however, configure a survey or content template to request contact information, free-form responses, files, images, or other information.
Websites and support. This Policy also covers visits to our public websites, demo requests, business communications, and support interactions.
2. When TRAKID is a business/controller and when it is a service provider/processor
| Context | Primary decision-maker | TRAKID’s typical role |
|---|---|---|
| TRAKID websites, sales, security, support, billing, and workforce/customer administrator accounts | TRAKID | Business/controller |
| Compass Quest adult sign-in, app operation, device permissions, diagnostics, and account security | TRAKID, sometimes jointly with the Venue Customer depending on configuration | Business/controller for TRAKID purposes; processor where handled solely on documented Venue Customer instructions |
| Venue-authored content, surveys, questions, requested fields, visitor submissions, and venue analytics | Venue Customer | Service provider/processor, unless TRAKID independently determines a purpose |
| Adventure Quest configuration and venue effects | Venue Customer for the visitor experience; TRAKID for device/service security | Processor/service provider for customer-directed data; controller for security and operations |
The legal role depends on the facts, not the label. If TRAKID uses information for an independent purpose, it is responsible for that processing as a business/controller. Venue Customers are responsible for their own notices, lawful bases, permissions, consent language, and collection choices. TRAKID and the Venue Customer must enter into additional processing terms where a binding data-processing agreement is required by applicable law or contract.
3. Information we collect
3.1 Customer administrators and authorized users
- Account and organization data, including business email address, password or authentication credential, organization, role, permissions, folders, products enabled, and account status. Additional business contact details may be collected through contracting, billing, sales, or support interactions.
- Organization configuration, including global logos and footers, preset colors, coordinates, designated zones, location-specific app settings, FAQs, tutorials and onboarding content, badge images, badge names and descriptions, completion levels, languages, subscription tier, and feature settings.
- Customer content, including dynamic QR destinations, quest stops, maps and coordinates, trivia, polls, open responses, calls to action, images, galleries, video, audio, PDFs, links, event pages, surveys, game designs, translations, and manual translation overrides.
- Administrative and audit data, including sign-in events, user and permission changes, content actions, timestamps, device/browser data, IP address, and security records.
- Commercial, billing, contracting, sales, support, and communications data.
3.2 Compass Quest adult app users
- Telephone number, one-time-code request and verification status, account identifier, and authentication metadata. Twilio receives the telephone number and verification-transaction metadata to transmit the code and protect the verification process. TRAKID does not send Compass Quest location to Twilio for this purpose.
- Precise or approximate mobile-device location, location permission state, and location events needed to identify a participating venue, determine whether the device is in a configured zone, guide the user toward quest points, and confirm arrival. During an active quest, phone-derived location may continue to reach TRAKID’s servers when the phone is locked or the app is minimized, if the user granted the required permission. Phone-derived location transmission stops immediately when the user finishes or exits the quest.
- Bluetooth permission and connection status; paired wearable identifier; battery level; firmware information; signal strength; connectivity events; wearable-derived GNSS/satellite location; and related diagnostics. The wearable sends its location to the paired phone, and the app transmits that location to TRAKID’s servers. During an active quest, wearable-derived location may continue to reach TRAKID’s servers when the phone is locked or the app is minimized. Transmission stops immediately when the user finishes or exits the quest.
- Quest activity, including venue and quest selected, stops reached, timestamps, progress, answers, polls, open responses, calls to action, earned completion levels or badges, help events, skips, and engagement measures. These records may be stored within player or game-session records that are deleted through the account-deletion cascade, even when an individual answer is not used as a stand-alone identity profile.
- Chosen language and app-operational information, including crash records, battery level, Bluetooth status, firmware version, signal strength, and connectivity events. Network and security infrastructure may also process an IP address and standard request information needed to deliver and protect the Service.
3.3 Adventure Quest participants
- Wearable or chip identifier and programmed experience configuration.
- Server-side activation records containing the wearable or device identifier, activation timestamp, and the activated bump-box, checkpoint, or associated venue zone.
- Aggregated or device-level completion and engagement information, if configured.
Adventure Quest does not require a consumer app or visitor account and is not designed to require a participant’s name, telephone number, email address, precise mobile-device location, or other direct identifier. A device identifier may be reused across different guests, dates, events, or venues. Venue Customers receive aggregated Adventure Quest statistics rather than device-level activation histories. TRAKID does not connect an Adventure device identifier to a ticket, reservation, name, school group, payment, or other guest record. A Venue Customer may conduct a separate linkage outside TRAKID’s Services; that activity is controlled by the Venue Customer and governed by its notice.
3.4 CheQRboard visitors
- QR and content interactions, including the applicable organization, QR code or content identifier, chosen language, aggregate scans, clicks and views, requested content, engagement and completion rates, top-language totals, survey-response totals, and donation-engagement totals.
- Transient network and security data needed to deliver and protect the page, which may be processed by Cloudflare or hosting infrastructure. CheQRboard does not use IP-derived approximate location for ordinary engagement analytics and does not create a cookie, device identifier, unique visitor identifier, or temporary session identifier to link an anonymous visitor’s interactions across QR codes, browser sessions, visits, or content events.
- Content-specific engagement, such as multiple-choice response counts and percentages; poll votes and percentages; video views, total and average watch time, drop-off and completion; audio plays, total and average listening time, drop-off and completion; gallery and image views; direct-link and call-to-action clicks; image-upload counts; open-response completion; survey responses, answer breakdowns and completion points; and game or checkpoint progress.
- Survey data and visitor submissions selected by the Venue Customer. Depending on the fields configured, this may include text, email address, URL, telephone number, contact details, acceptance of terms, number, date, time, dropdown or choice selection, rating, opinion scale, grouped answers, uploaded file or image, and open response. A response may also include the applicable organization, survey, QR code, language, response identifier, and timestamp. Authorized Venue Customer users can review and export individual responses, including identifying fields and open text. Visitor-entered survey text, including open responses, may be sent to Microsoft Azure Translator when survey-response translation is used. If a submission contains identifying information, TRAKID keeps it separate from otherwise anonymous scan and engagement analytics and does not link it to those analytics.
- Files and images a visitor uploads are stored in Supabase and can be accessed by TRAKID and authorized users of the applicable Venue Customer. Uploaded files are not currently subjected to automated malware scanning. Users must not upload executable, malicious, unlawful, or unauthorized material.
- Chosen language and translated-content interactions.
- Donation or payment engagement, such as donation-page clicks, referral and campaign data, transaction status, conversion, amount, currency, and revenue totals, if the Stripe functionality is enabled. Stripe generally receives payment-card or bank credentials directly; TRAKID is not intended to receive full payment-card numbers or security codes.
CheQRboard engagement analytics are anonymous or aggregated by default when a visitor does not submit identifying information. In that circumstance, TRAKID records language and collective scan or interaction counts and cannot link the visitor’s activity across QR codes, content events, browser sessions, or visits. If a survey response or other submission identifies the visitor, TRAKID keeps that submission separate from otherwise anonymous scan or engagement activity. Transient network and security data processed by Cloudflare, Supabase, or other infrastructure may nevertheless constitute personal information under applicable law even though TRAKID does not use it for visitor analytics or cross-session linkage.
3.5 Websites, demos, and support
- Contact, company, inquiry, demo, event, marketing preference, and support-request information.
- Website usage, cookie, device, IP, referral, and campaign-interaction information collected through technologies such as Google Analytics and HubSpot, subject to available consent and privacy choices.
- Information submitted in troubleshooting materials, attachments, recordings, or correspondence.
3.6 Job applicants and workforce members
When applicable, TRAKID may process identification and contact details; application, résumé, interview, work-history, education, reference, eligibility, onboarding, payroll, benefits, tax, expense, performance, training, leave, accommodation, safety, security, device, system-access, investigation, and separation records. TRAKID uses this information for recruiting, employment administration, compensation, benefits, security, legal compliance, and the establishment or defense of claims. Particular fields depend on the person’s relationship with TRAKID and applicable law.
3.7 Sensitive information
Depending on the jurisdiction and configuration, precise geolocation, information about a known child, account credentials, health information, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic or biometric identifiers, or contents of private communications may be treated as sensitive data. TRAKID needs precise device location to operate Compass Quest. TRAKID does not require Venue Customers to collect other sensitive data and prohibits them from using general survey tools to collect regulated health records, biometric identifiers, government-issued identifiers, financial credentials, or information from children unless expressly authorized in writing and supported by required notices, consent, and safeguards.
4. Sources of information
- Directly from users, customer administrators, visitors, parents or guardians, and people who contact us.
- Automatically from apps, browsers, QR interactions, connected wearables, bump boxes, servers, and device permissions.
- From the Venue Customer that configures the experience or provides content, account, ticket, group, or support information.
- From service providers such as identity, messaging, hosting, translation, analytics, security, app-store, and payment providers.
- From public and business sources for sales, due diligence, fraud prevention, and legal compliance.
5. Why we use information
| Purpose | Examples | Typical EEA/UK lawful basis |
|---|---|---|
| Provide and administer the Services | Authenticate users; pair wearables; navigate quests; display content; store responses; run QR links and dashboards | Contract; legitimate interests; consent where required |
| Location-enabled functions | Find participating venue; guide to stops; confirm arrival; diagnose location errors | Consent and/or contract, depending on law and context |
| Customer configuration and analytics | Operate CMS; translate content; calculate engagement, completion, and response statistics | Contract; legitimate interests; customer’s instructions |
| Security and integrity | Audit logs; access control; abuse, fraud, and incident detection; debugging | Legitimate interests; legal obligation |
| Support and communications | Respond to requests; send service notices; provide training; manage preferences | Contract; legitimate interests; consent for marketing where required |
| Improve and develop | Measure reliability; test features; use deidentified or aggregated trends | Legitimate interests; consent where required |
| Legal and corporate | Comply with law; establish or defend claims; transactions; accounting | Legal obligation; legitimate interests |
TRAKID does not use visitor survey responses, children’s information, or precise quest location to build advertising profiles or to train a general-purpose artificial-intelligence model. We do not make decisions producing legal or similarly significant effects solely by automated means.
6. Cookies, pixels, local storage, and mobile permissions
The Services may use strictly necessary cookies, local storage, SDKs, pixels, logs, and similar technologies for authentication, routing, security, preferences, analytics, and service performance. The public website may also use optional analytics or marketing technologies if shown in the consent interface. In the EEA and UK, non-essential storage or access technologies are used only with consent or another applicable exception. In U.S. states that recognize browser-based opt-out signals, we process legally valid Global Privacy Control or similar signals for the browser or device sending the signal.
Mobile operating systems separately control location, Bluetooth/nearby devices, notifications, camera, and other permissions. Users can change those permissions in device settings, but doing so may disable a feature. "Do Not Track" signals are not yet interpreted consistently across the industry; we honor legally recognized opt-out preference signals as described above.
7. Translation
Venue Customer content may be translated into up to 134 supported languages using Microsoft Azure translation services. When survey-response translation is used, visitor-entered survey text, including open responses, is sent to Microsoft Azure Translator to generate the translated response. Other visitor-entered free text outside surveys is not currently sent to Azure Translator. If TRAKID later expands translation to additional categories of visitor-entered information, it will update this Policy and provide any notice or obtain any consent required by applicable law before that expanded processing begins.
TRAKID currently uses Microsoft’s standard Azure Translator text-translation service and does not use Custom Translator models or training workspaces. According to Microsoft’s current documentation for the standard service, text submitted for translation is not written to persistent storage and is not used to train Microsoft models. TRAKID may temporarily create separate source-text and translated-output copies, together with associated organization, survey, response, QR code, language, timestamp, or contact metadata, to complete and troubleshoot the translation. TRAKID’s adopted policy is to delete those separate copies after successful processing and within no more than 30 days when retained for failed-job troubleshooting, unless a valid legal hold or other mandatory preservation duty applies. Venue Customer administrators cannot directly delete those temporary copies but may request deletion through TRAKID staff. Venue Customers should not request personal or sensitive information in translated surveys unless the collection and translation are necessary, disclosed, lawfully authorized, and covered by appropriate processor arrangements.
Venue Customers may manually override a machine translation. Machine translation can be inaccurate, incomplete, or culturally inappropriate. Venue Customers must review legally significant instructions, safety notices, consent language, terms, and accessibility content with a qualified human translator before relying on them. TRAKID does not guarantee the accuracy of automatic or customer-supplied translations.
8. How we disclose information
- Venue Customers and their authorized users. Depending on product and configuration, we make customer-controlled content, individual survey submissions, telephone numbers, precise and live Compass Quest location, location trails, paired wearable identifiers, individual quest responses, operational information, and analytics available within the applicable organization, product, and folder permissions. Adventure Quest customers receive aggregated statistics rather than device-level histories.
- Service providers and processors. These include Supabase for hosted database and storage services; Cloudflare for network delivery and security; Twilio for telephone verification; Microsoft Azure Translator for translation; Stripe for payments and donations; Google Analytics and HubSpot for website analytics and business communications; Apple and Google for app distribution and mobile-platform functions; and other providers supporting security, diagnostics, communications, customer support, and professional services. They process information under their applicable terms and any legally required restrictions. We do not publish confidential credentials, security configurations, or vendor-contract terms in this Policy.
- Payment and donation parties. Stripe and the Venue Customer or designated recipient handle the payment or donation. Their privacy notices also apply.
- Legal and safety disclosures. We may disclose information when reasonably necessary to comply with law or legal process; protect rights, safety, and security; investigate fraud or abuse; or establish, exercise, or defend legal claims.
- Corporate transactions. Information may be disclosed in connection with financing, diligence, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and law.
- At direction or with consent. We may disclose information when the relevant person or Venue Customer directs us or provides valid consent.
We do not sell personal information for money. We do not sell or share Compass Quest location, visitor survey responses, or known children’s information for cross-context behavioral advertising. If optional marketing technology on a TRAKID public website constitutes a "sale" or "sharing" under a state law, users may opt out through the site’s privacy choices control or a recognized preference signal. We will keep this disclosure aligned with the technologies actually deployed.
9. Customer permissions and tenant separation
TRAKID personnel may access customer organizations to provide, secure, support, configure, and administer the Services. Venue Customer users are provisioned to their own organization and authorized folders and products. Organization administrators may add, suspend, and manage users, permissions, branding, folders, and enabled features only within their organization. No access-control system is infallible; customers must use unique credentials, promptly remove departed users, apply least privilege, and notify TRAKID of suspected unauthorized access.
10. Payments and donations
CheQRboard uses Stripe Connect for live payment and donation functionality. Payment-card and bank credentials are submitted directly to Stripe and are not independently stored by TRAKID. The Venue Customer is the merchant, fundraiser, charity, or designated recipient. Authorized TRAKID personnel can view information available through the connected Stripe dashboard, which may include a payer or donor’s name and email, amount, currency, campaign, transaction identifier, status, refunds, chargebacks, and conversion information. TRAKID does not maintain a separate copy of this transaction data and Stripe retains it under Stripe’s applicable terms and legal obligations. The Venue Customer is responsible for identifying the recipient, refund policy, charitable status, tax-deductibility disclosures, and fundraising or payment obligations.
11. Children and family use
Adult account. Before telephone-number, location, or wearable data collection, Compass Quest requires the account creator to affirm that the person is at least 18 or otherwise legally authorized to accept the Terms for the participating group. A self-identified minor cannot create the account. This adult confirmation is not represented as verifiable parental consent under every child-privacy law. A child may wear a compass or Adventure Quest band only with appropriate adult and venue supervision. The wearable itself does not require a child’s name, email address, telephone number, or account.
QR access. CheQRboard content is publicly reachable by QR code or link and may be scanned by a minor even when a Venue Customer intended a form only for teachers, parents, or other adults. The Services do not require personal information merely to view ordinary QR content. An adults-only form must clearly say so and should use an adult confirmation before collecting information. Venue Customers must not configure child-directed experiences to request a child’s email, telephone number, contact information, precise geolocation, photograph, file, persistent identifier used beyond internal operations, or open response likely to reveal personal information unless TRAKID has approved a lawful notice, authorization, minimization, retention, and security process.
Parental submissions. A parent or legal guardian who chooses to submit information about a child represents that the person has authority to do so. This representation does not eliminate any consent, notice, minimization, deletion, or security duty imposed by law.
Schools and groups. A school may be able to authorize limited collection for a school-directed educational purpose in circumstances permitted by COPPA, but not for TRAKID’s or a Venue Customer’s unrelated commercial use. School deployments may also implicate FERPA, PPRA, state student-privacy laws, procurement rules, and contractual security requirements.
TRAKID applies high-privacy defaults when it knows an experience is being used by minors and does not sell, share for behavioral advertising, profile for advertising, or otherwise monetize known minors’ information. If we learn that personal information was collected from a child in a manner requiring authorization that was not obtained, we may immediately suspend the collection, preserve only what law requires, delete or deidentify the information, restrict the account or experience, and contact the Venue Customer or parent as appropriate. A parent or guardian may request access to or deletion of a child’s information by emailing [email protected] with the subject "Child Privacy Request." We will take reasonable steps to verify identity and authority.
12. Retention
| Category | Retention criteria |
|---|---|
| Compass Quest account and telephone number | Retained while the account is active. TRAKID’s adopted dormant-account rule permits deletion after 24 months of inactivity, with advance notice where practical. Selecting Remove Account triggers cascading deletion of the account and associated telephone number, players, band pairings, game sessions, waypoint navigation records, completions, skips, help events, location trail, and account-linked technical-log entries containing the telephone number or precise location. No backup copies of this deleted account data remain unless a valid legal hold or other mandatory preservation duty applies. |
| Precise quest location and device events | Stored for the life of the Compass Quest account, which may extend until the account is deleted or becomes subject to the 24-month dormant-account rule. This extended retention supports account continuity, troubleshooting, product analysis, and evaluation of location-enabled functionality. TRAKID will not use historical precise location for a materially different purpose without any additional notice or consent required by law. The location trail, waypoint-navigation records, and account-linked telephone-number or precise-location logs are included in the account-deletion cascade. |
| Adventure Quest activation records | Device identifiers, activation timestamps, and bump-box, checkpoint, or venue-zone records are retained at device level for up to 24 months and then deleted or aggregated or deidentified. Venue Customer administrators receive aggregated statistics and cannot directly delete device-level records; they may request deletion through TRAKID staff. A valid legal hold or other mandatory preservation duty may require longer retention. |
| Twilio Verify records | Twilio's public Verify documentation identifies the verified telephone-number field as subject to a 30-day minimum time to live; this is a minimum retention period, not a promise of automatic deletion on day 30. Twilio's Verification Attempts API covers attempts from the preceding 30 days. Other transaction, security, fraud-prevention, billing, legal, or fields Twilio designates as non-PII may be retained under Twilio's applicable terms, product configuration, and legal obligations. |
| Customer content, survey responses, files, and analytics | Venue Customer administrators can review and export individual survey responses but currently must ask TRAKID staff to delete an individual response. Main responses, associated uploads, and analytics follow the customer contract, the disclosed purpose, applicable law, and customer instructions. Uploaded files follow the associated response’s period unless the Venue Customer disclosed and lawfully established a different period. Customer content is returned or deleted within 90 days after contract termination unless the contract, law, or a valid hold requires otherwise. |
| Temporary translation copies | Separate source-text and translated-output copies, including associated metadata, are deleted after successful processing and within no more than 30 days when retained for failed-job troubleshooting. Venue Customer administrators may request deletion through TRAKID staff. A valid legal hold or other mandatory preservation duty may require longer retention. |
| Security, audit, and diagnostic logs | Compass Quest technical logs containing a telephone number or precise location are retained while the associated account exists and are deleted with it. Other administrator, security, and diagnostic logs are generally retained for up to 12 months, with longer retention for an incident, contract, or legal obligation. |
| Business, workforce, billing, and legal records | Ordinary business records are retained for the relationship and a reasonable period afterward. Necessary tax, accounting, payment, employment, contract, and legal records may be retained for at least two years and generally up to seven years, or longer when law or a valid legal hold requires. |
| Other backup copies | Backups outside the specifically confirmed Compass account, Adventure activation, and temporary translation-copy deletion paths follow TRAKID’s protected backup practices. Those practices currently do not establish a fixed maximum deletion date. Backup data is isolated from ordinary use and, if restored, applicable active-system deletions are reapplied where reasonably feasible. |
| Deidentified or aggregated data | May be retained for longer where it cannot reasonably be linked to an individual and we maintain measures against reidentification. |
Compass Quest account deletion is complete when the Remove Account cascade finishes: the listed account data and account-linked telephone-number or precise-location logs are deleted and no backup copies remain. Manual deletion of Adventure activation records and temporary translation copies likewise removes the covered records from primary storage, replicas, technical logs, and applicable backups. These commitments are subject to a narrow exception for information covered by a valid legal hold, court order, subpoena, regulatory demand, or other mandatory preservation duty. The CTO or a written designee may issue or release a hold, after consulting counsel where practical. TRAKID preserves only the reasonably necessary scope, restricts ordinary use and access, and resumes deletion when the duty ends unless another lawful ground applies.
13. Security
We use administrative, technical, and physical measures designed for the nature and volume of information, including role-based access, organization and folder permissions, authentication controls, logging, encryption in transit and where appropriate at rest, vendor management, backups, secure development practices, and incident response. No transmission, software, connected device, or storage system can be guaranteed completely secure. Users and Venue Customers must protect credentials, devices, QR administration access, and physical wearables and report suspected compromise promptly.
14. Your choices
- Do not submit optional survey fields or files you do not want the Venue Customer and TRAKID to process.
- Change mobile location, Bluetooth, notification, camera, or other permissions in device settings. Core Compass Quest functions may stop working.
- Use the app’s Remove Account feature or contact us to request account deletion. Remove Account triggers cascading deletion of the account and associated telephone number, players, band pairings, game sessions, waypoint navigation records, completions, skips, help events, location trail, and account-linked technical-log entries containing the telephone number or precise location. No backup copies of this deleted account data remain unless a valid legal hold or other mandatory preservation duty applies.
- Use the website privacy choices control, where available, to reject optional cookies or opt out of legally regulated sale, sharing, or targeted advertising.
- Unsubscribe from marketing email using its link; service and security communications may still be sent.
- Contact the Venue Customer for a survey, donation, school-group, or venue record it controls; TRAKID will assist as required.
15. Privacy rights
Depending on where you live and the law that applies, you may have rights to confirm processing; access and obtain a copy; correct; delete; restrict or object; withdraw consent; obtain portability; opt out of sale, sharing, targeted advertising, or qualifying profiling; limit certain uses of sensitive information; appeal a refusal; and receive non-discriminatory treatment. Authorized agents may act where permitted. EEA and UK individuals may also complain to a supervisory authority and object to processing based on legitimate interests.
Submit a request to [email protected] with the subject "Privacy Request" and identify the product, Venue Customer, and right requested. Do not email sensitive proof unless asked through a secure process. We will verify requests proportionately and respond within the legally required period. If a Venue Customer controls the information, we may forward the request to that customer and assist it. We may deny or limit a request where permitted by law and will explain appeal options. To appeal, reply with "Privacy Appeal" and the reasons for review.
California consumers may also use an authorized agent. We may ask for proof of authorization and identity. We will honor a legally valid Global Privacy Control signal for the browser or device from which it is sent. We do not discriminate because a person exercises a privacy right.
16. U.S. state privacy disclosures
This section supplements the rest of the Policy for residents of U.S. states with applicable comprehensive privacy laws. As of the effective date, comprehensive laws are in force in California, Colorado, Connecticut, Delaware, Florida (narrow applicability), Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Vermont, and Virginia. Additional state privacy laws and amendments may take effect after this date. Coverage thresholds and exemptions differ, and TRAKID will apply a right only when the law covers the relevant entity, person, and data; TRAKID may voluntarily honor a request more broadly.
16.1 California notice at collection
| California category | Examples collected | Business/commercial purposes | Recipient categories |
|---|---|---|---|
| Identifiers | Telephone number; account ID; IP address; device, QR, cookie, or wearable ID; business contact | Operate, authenticate, secure, support, analyze | Venue Customer; hosting, identity, messaging, security and support providers |
| Customer-record information | Name, contact details, business role; optional survey contact information | Account/customer management; venue-directed survey | Venue Customer; contracted providers |
| Commercial information | Subscription, donation/payment metadata, campaign interaction | Billing; donation analytics; customer administration | Venue Customer; Stripe; business providers |
| Internet/electronic activity | Scans, clicks, views, responses, media duration, app/site logs | Deliver content; analytics; security; improvement | Venue Customer; hosting, analytics and security providers |
| Geolocation | Compass Quest phone and wearable location; venue and bump-box zone | Quest navigation, arrival, support, product analysis, security | Venue Customer where configured; hosting infrastructure |
| Audio/visual information | Customer media; optional image/file upload; support recording | Display content; venue submission; support | Venue Customer; hosting/support providers |
| Professional or employment information | Administrator organization and permissions; application, work-history, performance, payroll, benefits, and workforce records | B2B administration; recruiting; employment administration; security; legal compliance | Organization; workforce, payroll, benefits, professional and business providers |
| Protected classifications and education | Age or other legally protected information, accommodations, and education where supplied for recruiting or employment | Employment administration; accommodations; legal compliance | Workforce and professional providers; government authorities where required |
| Inferences | Engagement or completion measures, content popularity | Analytics and product improvement | Venue Customer; contracted analytics infrastructure |
| Sensitive personal information | Precise Compass Quest location; account credentials; known-child data if supplied | Provide requested features, security, legal compliance | Limited service providers and Venue Customer as necessary |
Sources are described in Section 4; retention criteria are in Section 12. In the preceding 12 months, TRAKID may have disclosed the categories above for the stated business purposes. TRAKID does not use or disclose sensitive personal information to infer characteristics. TRAKID does not knowingly sell or share personal information of consumers under 16. If public-site advertising technology is deemed a sale or sharing, the site must present a "Your Privacy Choices" mechanism and honor preference signals.
16.2 State-specific points
- California: rights include know/access, correction, deletion, portability, opt out of sale or sharing, limit qualifying sensitive-information use, and non-discrimination. California’s Shine the Light law may provide additional rights concerning direct-marketing disclosures. California users may complain to the California Privacy Protection Agency or Attorney General.
- Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Jersey, Oregon, and other states impose enhanced requirements for sensitive data, minors, opt-out signals, or data-protection assessments. Maryland applies especially strict data-minimization rules. Oregon and Minnesota may require information about specific third parties or categories of recipients in defined circumstances.
- Nevada provides a statutory opt-out for certain covered sales even though it does not use the same comprehensive-law model. Washington and Nevada have consumer-health-data laws; TRAKID does not offer the Services as a health-record system and forbids regulated consumer-health-data collection without a separately approved workflow and notice.
- Illinois, Texas, Washington, and other states regulate biometric identifiers. TRAKID does not design the Services to collect face geometry, fingerprints, voiceprints used for identification, or other regulated biometric identifiers. Ordinary audio playback, video views, or visitor-uploaded images are not used by TRAKID to identify a person biometrically.
- Every U.S. state has a security-breach notification law, and numerous states require reasonable security or special protection for government identifiers, student data, health data, and children’s data. Those laws may apply even when a comprehensive consumer law does not.
17. EEA, UK, and international users
CheQRboard is TRAKID’s internationally offered product and may be marketed or made available in the EEA, United Kingdom, Middle East, Far East, and other markets. TRAKID’s current Venue Customers are located in the United States and United Kingdom. Explorer Quest, including Compass Quest and Adventure Quest, is offered and supported only for authorized venue deployment in the United States; TRAKID does not market, sell, rent, ship, or support Explorer Quest hardware for deployment outside the United States. For EEA or UK personal data processed through CheQRboard, TRAKID identifies its lawful bases in Section 5, uses information only for compatible purposes, and applies data minimization, transparency, security, retention, and data-subject rights. Where TRAKID is a processor, the Venue Customer is generally responsible for selecting the lawful basis and giving the visitor a notice; TRAKID processes the data under documented instructions and legally required processing terms.
TRAKID is based in the United States and has no establishment in the EEA or United Kingdom. Information may be transferred to the United States, stored through Supabase cloud services, and accessed by authorized personnel from other countries using appropriate credentials. Where required, TRAKID uses Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, and documented transfer-risk measures. Individuals may request information about the relevant safeguard.
TRAKID has designated EEA and UK representatives where required. Requests for the applicable representative’s contact details may be sent to [email protected]. A person in the EEA may complain to the supervisory authority in the country of residence, work, or alleged infringement. A UK person may complain to the Information Commissioner’s Office.
For UK data-protection complaints submitted to TRAKID, we provide a clear complaint channel, acknowledge a complaint within 30 days, investigate it without undue delay, keep the complainant informed, and communicate the outcome, subject to applicable law.
18. Third-party services and links
Venue content may link to external websites, ticketing systems, donation pages, social platforms, maps, files, or media players. TRAKID does not control their privacy or security practices. A QR code can be changed dynamically by an authorized Venue Customer. Visitors should review the destination and its notice before providing information. App stores, operating-system providers, Twilio, Stripe, Microsoft, Supabase, and other providers also publish their own notices for processing they control.
19. Changes to this Policy
We may update this Policy as products, vendors, laws, or practices change. We will post the revised version, update the effective date, and provide additional notice or obtain consent if required. Material changes do not retroactively authorize materially different processing where law requires consent.
20. Contact and complaints
TRAKID, LLC
132 Citation Ln.
Smithfield, North Carolina 27577, United States
Email: [email protected]
TRAKID’s leadership team monitors this address for privacy, child-privacy, legal, and support requests. Use the subject line described above. Nothing in this Policy limits a person’s right to contact a regulator or exercise a nonwaivable legal right.