Legal
Privacy Policy.
Last updated: July 25, 2026
Information we receive
The public contact form sends the details you provide to SIMO's secure application, where they are stored for follow-up. This may include your name, email, phone number, requested service, and message. We temporarily retain source IP and browser information to prevent abuse and investigate security events; that technical metadata is removed after 180 days. Authorized portal accounts include name, email, Firebase UID, role, status, company, access history, and service records appropriate to the account.
Authentication and sessions
Firebase Authentication verifies identity. SIMO stores roles and permissions in its own database. The portal uses secure, HTTP-only session cookies and stores only cryptographic hashes of its application tokens. Google Sign-In may involve Google and Firebase processing account and device information under their own terms.
Operational information
Depending on role and service, the portal may process protected sites, assignments, reports, messages, documents, invoice metadata, attendance, and certification records. Access is limited by company, role, and record scope.
How information is used
We use information to respond to inquiries, authenticate and authorize users, deliver security services, communicate with authorized clients and personnel, maintain records, secure sessions, and meet legal or contractual obligations.
Sharing and retention
We do not sell personal information. Information may be shared with service providers needed to operate authentication, hosting, communications, or contracted services, and when required by law. Retention depends on operational, contractual, security, and legal requirements.
Your choices
You may request correction of account information or ask questions about retention and access by emailing support@simosecuritygroup.com. Some records may need to be retained for legitimate security, legal, or contractual reasons.
Security
We use access controls, encrypted transport, secure cookies, session revocation, and audit records. No system can guarantee absolute security, so users should protect their credentials and promptly report suspected unauthorized access.
Contact
Questions about this policy may be sent to support@simosecuritygroup.com.