Privacy Policy
Version française à venir. Ce document est offert en anglais seulement pour le moment; une version française révisée sera publiée prochainement. Pour toute question, écrivez-nous à support@shadowplus.ca.
Shadow+ ("we", "us", "our") operates the Shadow+ mobile
applications for iOS and Android, the Shadow+ web dashboard, and the services behind them at
api.shadowplus.ca (together, the "Service"). This policy explains what personal
information we collect, why, who we share it with, how long we keep it, and the choices and rights you have.
It should be read together with our End User License Agreement. Where the two conflict about personal information, this policy controls.
Shadow+ is operated by Shadow Plus LLC, a Wyoming limited liability company, at 1309 Coffeen Avenue, Sheridan, WY 82801, United States.
1. What the Service does, in one paragraph
Shadow+ lets you keep track of, and protect, things you own — a car, a boat, a trailer, a bag. You attach hardware to an asset (a ShadowTag that is located through a crowd-sourced network, a GT06 cellular tracker with its own GPS, or a KillSwitch engine-immobiliser that the app talks to over Bluetooth), and the app shows you where that asset is, tells you when it moves or crosses a boundary you drew, and lets you arm or disarm it. Dealerships can additionally use the app to manage their vehicle inventory, test drives and customer enquiries.
Almost everything in this policy follows from that: to show you where your asset is, we have to know where your asset is.
2. Information we collect
2.1 Information you give us
| What | When | Why |
|---|---|---|
| Email address and password | creating an account | to identify you and secure your account. Passwords are stored hashed; we never see the plain text |
| Phone number (optional) | creating an account | account recovery and, if you are dealership staff, so colleagues can reach you |
| Preferred language (English / French) | Settings | so notifications and emails reach you in the language you chose |
| Asset details — name, type, an optional photo | adding an asset | to identify your asset in the app. The photo is intended for insurance purposes and is stored with the asset |
| Geofence zones — the boundaries you draw, their names and messages | creating a zone | to alert you when the asset enters or leaves |
| Hardware identifiers — a ShadowTag serial and claim code, a tracker's IMEI, a KillSwitch device ID | attaching hardware | to link the hardware to your account and your asset |
| A transfer code | accepting an asset from another user | to move that asset into your account |
2.2 Information the hardware you own generates
This is the core of the Service and the largest category of data we hold about you.
| What | From | Detail |
|---|---|---|
| Location of your assets | ShadowTag, GT06 tracker | the last known position, its address, when it was recorded, and a history of previous positions so you can play back where the asset has been |
| Movement and geofence events | server-side detection | that the asset moved after being armed; that it entered or left a zone you drew; when |
| Tracker telemetry | GT06 tracker | ignition on/off, whether it is charging, battery / vehicle-battery voltage, cellular signal strength, speed, whether the immobiliser is engaged, and alarms (SOS, power cut, collision, tamper, tow, overspeed, harsh driving, door) |
| ShadowTag battery level, over time | ShadowTag | so you know when to charge it |
| KillSwitch state | KillSwitch, via your phone | whether it is armed or disarmed, and when the app changed that |
How ShadowTag location works. A ShadowTag has no GPS of its own. It is located when a nearby phone in a crowd-sourced network — which may be a stranger's — hears its Bluetooth signal and reports the position to the network operator, who passes it to us. This is why ShadowTag positions can be delayed, approximate, or absent. Our EULA §6 describes the accuracy limits.
2.3 Information your phone provides
| What | Detail |
|---|---|
| Device fingerprint — manufacturer, model, Android/iOS version, app version, language setting | recorded each time you sign in or bring the app to the foreground, so you can see the devices signed into your account and their "last seen" time, and so we can investigate a problem you report |
| Push notification token | issued by Apple or Google's notification service; lets us send you alerts. Stored with your account and removed when you sign out |
| Bluetooth diagnostics (KillSwitch only) | when the app talks to a KillSwitch, it may upload a technical log of that exchange — the device ID, which step was attempted, whether it succeeded, the error code if not, and the raw bytes that went over Bluetooth. The bytes are encrypted between the phone and the KillSwitch and are meaningful only to our engineers; they contain no message content you could read. This exists so an administrator can see why a KillSwitch failed to arm |
| Camera | used to scan a QR code, VIN barcode or IMEI barcode when you attach hardware, and to take an asset or vehicle photo. Frames from barcode scanning are processed on your phone and never leave it |
2.4 What we do not collect
We want to be explicit about this, because it is the first question people ask about a tracking app.
- We do not track your phone's location. The app never reads your device's GPS. The Android app does not request location permission on Android 12 or later; on older Android versions it declares a location permission solely because Android required it for Bluetooth scanning, and the app never uses it for location. Every position you see in the app comes from hardware attached to your assets, not from your phone.
- We do not read your contacts, messages, call log, or calendar. When you tap a phone number in the dealership screens, the app opens your phone's dialler; it does not access your contacts.
- We do not collect payment card details. Subscriptions and purchases are handled by Stripe in a secure browser page; the card number never passes through the app or our servers. We receive confirmation that a payment succeeded and what it was for.
- We do not run advertising or analytics SDKs. There is no ad network, no behavioural analytics, and no crash-reporting service in the apps. The only third-party SDKs are Google Maps (to draw the map) and Firebase Cloud Messaging (to deliver notifications).
- We do not sell personal information. To anyone, for anything.
3. How we use information
- To provide the Service — show your assets and where they are, deliver alerts, arm and disarm hardware, run geofences, and keep your account working across your devices.
- To keep your account secure — sign-in, session tokens, device registry, password reset, email verification.
- To bill you — for a Pro subscription, a tracker data plan, or hardware you buy through the app.
- To support you — when you report a problem, the device fingerprint and (for a KillSwitch) the Bluetooth diagnostics are what let us find out what went wrong.
- To run a dealership — for staff of a dealership using Shadow+, to manage inventory, test drives, enquiries, reconditioning, and the dealership's own protective hardware. See §5.
- To meet legal obligations — including the retention and disclosure duties described in §7.
We rely on your consent (given when you create an account and accept the EULA) for the collection described in §2, on the performance of our contract with you to provide the Service, and on our legitimate interest in keeping the Service secure and working. You can withdraw consent at any time — see §8 — but the Service cannot locate an asset without its location.
4. Alerts and notifications
You can turn each category of alert on or off, per asset and per channel (push, email), in the app. Alert wording is prepared on our servers in the language you chose, which is why that language preference is stored with your account rather than only on your phone.
5. Dealerships — information about people who are not Shadow+ users
Dealerships use Shadow+ to manage their business, and in doing so their staff enter information about their customers — people who may never have installed the app.
| What a dealership may record | About whom |
|---|---|
| Name, phone number, email address, and the message left | a person who enquired about a vehicle (a "lead") |
| Name and phone number, the vehicle taken, and when it is due back | a person on a test drive |
| Name and contact details | a person booked for a hardware installation |
For that information, the dealership is the organisation responsible under privacy law, and Shadow+ processes it on the dealership's behalf. If you are such a customer and want to know what a dealership holds about you, or want it corrected or deleted, please contact the dealership; we will assist them in responding. Dealerships agree, in using the Service, to have a lawful basis for entering their customers' information and to honour their customers' rights.
Dealership staff should also know: the app shows each colleague only what their assigned role permits; every action on a vehicle (arming, marking sold, moving it through reconditioning, starting a test drive) is logged with who did it and when, and that activity is visible to the dealership's managers.
Hardware on sold vehicles. Tracking hardware left on a vehicle after it is sold continues to report that vehicle's location. Shadow+ surfaces those vehicles to the dealership and expects the hardware to be recovered, transferred to the new owner, or a reason recorded — because continuing to track a car that now belongs to someone else, without their knowledge, would be a privacy violation under Quebec's Law 25 and Canada's PIPEDA. This is a deliberate feature, not an accident.
6. Who we share information with
We share personal information only with the providers we need to run the Service, and only what each one needs:
| Provider | What they receive | Why |
|---|---|---|
| Our ShadowTag network provider | tag identifiers; they provide us the tag's position | to locate ShadowTags |
| Cellular network / tracker vendor | tracker IMEI; the tracker's own reports | GT06 trackers report over the mobile network |
| Google Maps | map tile requests, which include the map area being viewed and standard device information | to draw the map. Governed by Google's privacy policy |
| Firebase Cloud Messaging (Google) and Apple Push Notification service | your device's push token and the notification content | to deliver alerts |
| Stripe | your email, and what you are buying | payment processing. Stripe's privacy policy governs card handling |
| Apple and Google | standard app-store data | distribution of the apps |
| none. | An earlier version of the app could open a WhatsApp chat to our monitoring line; the current line is a toll-free telephone number reached through your phone's dialler | |
| Our hosting provider | everything, encrypted at rest | to run the servers |
We may also disclose information when the law requires it, to protect someone's safety, or to enforce our terms. We will tell you if we can lawfully do so.
We do not share your data with data brokers, advertisers, or anyone who would use it for their own purposes.
7. How long we keep information
| Category | Kept for |
|---|---|
| Account (email, phone, preferences) | while the account exists, and after you delete it only for as long as we still need it or the law requires |
| Asset location and history | while the asset is on your account and you need to be able to play its history back; deleted with the asset, and with your account |
| Events, alerts, activity logs | while the asset is on your account; deleted with the asset, and with your account |
| Device fingerprint / sign-in registry | until you sign that device out, or the account is deleted |
| Push token | until you sign out on that device |
| Bluetooth diagnostics | only as long as needed to investigate the problem they were recorded for |
| Billing records | as long as tax law requires (typically seven years in Canada) |
| Dealership customer records | for as long as the dealership keeps them — this is the dealership's decision |
When a retention period ends, information is deleted or irreversibly anonymised.
8. Your rights and choices
Under Canada's PIPEDA and, if you are in Quebec, the Act respecting the protection of personal information in the private sector (Law 25), you have the right to:
- Access the personal information we hold about you, and be told how it is used and shared;
- Correct it if it is inaccurate or incomplete;
- Withdraw consent to its collection or use — subject to legal or contractual restrictions, and understanding that the Service cannot locate an asset without collecting its location;
- Delete your account and the information associated with it;
- Data portability (Quebec) — receive the information you gave us in a structured, commonly used format;
- Complain — to us first, and then to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.
In the app, you can already: rename or delete assets; delete an asset's photo; detach hardware; adjust or switch off every alert category; see and sign out the devices on your account; change your language; and sign out. Signing out removes the push token and the local caches from that phone.
To delete your account entirely, see §9. To exercise any other right, write to us (§12). We will respond within 30 days, as the law requires, and we may ask you to verify your identity first.
Automated decisions. The Service does not make decisions about you by automated means that have legal or similarly significant effects. Alerts are triggered by rules you set.
9. Deleting your account
You can ask us to delete your Shadow+ account, and the data associated with it, at any time. You do not need to give a reason.
How to request deletion
- From the email address on your account, email support@shadowplus.ca with the subject Delete my Shadow Plus account.
- Reply to our confirmation message to verify it is you — we ask so that nobody else can delete your account.
If you cannot email us from your account address, write to us anyway and we will find another way to verify your identity.
We acknowledge every request within 2 business days and complete deletion within 30 days of verifying your identity.
What is deleted
- your account and sign-in credentials — email address, password, phone number if you gave one, and your language preference;
- your name;
- every asset on your account, with its name, type, notes and any photo you added;
- the location history of those assets, including last known positions and the addresses recorded with them;
- the geofence zones you drew, with their names and messages;
- movement and geofence events, alerts, your notification inbox and your activity log;
- the registry of devices signed into your account, and the push notification tokens for them;
- KillSwitch and tracker pairings — your hardware is detached from the account so that it can be claimed again, by you or by a new owner.
Deletion is permanent. We cannot restore an account, an asset or a location history afterwards, so export anything you want to keep before you write to us.
What is kept
Billing records outlive the account, because tax law requires us to keep them for the period set out in §7. They record what was purchased and when; they contain no location data. If you are the customer of a dealership that uses Shadow+ — you left an enquiry, or took a test drive — that record belongs to the dealership rather than to us and is kept for as long as the dealership keeps it; see §5.
Deleting some data without closing your account
You do not have to delete your account to remove data from it. §8 lists what you can already do in the app at any time — delete an asset and its history, delete a photo, detach hardware, remove a zone, switch off alerts, and sign a device out.
10. Security
- All traffic between the apps and our servers uses HTTPS.
- On your phone, sign-in tokens are stored in the operating system's encrypted storage (Android Keystore / iOS Keychain). The cryptographic key used to talk to a KillSwitch is generated on your phone and, on modern devices, never leaves its secure hardware.
- The Bluetooth link to a KillSwitch is encrypted end-to-end between your phone and the device using industry-standard cryptography (P-256 ECDH key agreement and AES-256-GCM).
- Server data is encrypted at rest.
- Access to production data is limited to staff who need it, and is logged.
No system is perfectly secure. If we become aware of a breach that creates a real risk of serious harm, we will notify you and the relevant privacy regulator as the law requires.
11. Children
The Service is for adults. Our EULA requires users to be at least 18. We do not knowingly collect personal information from anyone under 18, and if we learn we have, we will delete it.
12. Contact
For any question, request or complaint about privacy:
- Email: support@shadowplus.ca
- Post: Shadow Plus LLC, 1309 Coffeen Avenue, Sheridan, WY 82801, United States
13. Changes to this policy
We will post any change here and update the date at the top. For a change that materially affects how we use your personal information, we will also tell you in the app or by email before it takes effect, and where the law requires, ask for your consent again.
14. Governing law
This policy is governed by the laws of the Province of Ontario and the federal laws of Canada, consistent with our EULA. Nothing in it limits rights you have under the privacy law of the province where you live.
© 2026 Shadow+.