Compliance by design
BailSoft is built to operate lawfully and sustainably in the U.S. bail bond market. We treat legal safety as an architectural requirement — engineered into the product, reflected in our agreements with agencies, and reviewed as laws change. This page explains the principles behind how BailSoft handles data, monitoring, communications and payments.
1. Our role
BailSoft is a software vendor. We are not a bail bondsman, a consumer reporting agency (CRA), a payment processor, a background-check provider, or a data broker selling personal information. We provide tools that licensed bail bond agencies use to run their own operations, and — through BailSoft Intelligence — a real-time feed of lawfully public county data.
Because different parts of the product carry different responsibilities, it helps to separate them:
- The agency application (BailSoft Pro, BondTrack, Guardian, Payments, and related modules) is self-hosted — each agency runs it on its own infrastructure, with its own database. Defendant, indemnitor, bond and payment records live there, under the agency's control. BailSoft does not receive or store that data.
- BailSoft Intelligence and the Data Network are hosted by us. This layer ingests, verifies, de-duplicates and distributes lawfully public county data (bookings, releases, court calendars). It does not include agency case files.
2. Public data only
The BailSoft Data Network is fed exclusively from lawful, publicly available sources, in order of preference:
- Official county and government APIs — the services counties publish themselves;
- Open-data portals and public transparency datasets;
- Public records — public arrest and court records;
- Public jail rosters and court calendars;
- Licensed third-party data providers under commercial agreements.
We do not access closed, restricted or credential-gated systems, we do not scrape sources that prohibit it, and we honor respectful request rates that do not burden county infrastructure. Records are validated and de-duplicated to improve quality, and coverage is configured to reflect what each jurisdiction makes lawfully available.
3. Not a consumer reporting agency (FCRA)
BailSoft data is intended for operational monitoring and awareness connected to bail bonds. It is not a consumer report, and BailSoft is not a consumer reporting agency under the federal Fair Credit Reporting Act (FCRA) or analogous state laws. Using BailSoft data for credit, employment, tenant/housing, insurance, or any other eligibility decision is prohibited.
Regulators have made clear that a disclaimer alone does not remove FCRA obligations. We therefore take a layered approach — we do not design, market or support BailSoft as a screening tool; we restrict permitted uses contractually; and we disclaim FCRA-regulated uses in plain language. See our FCRA notice for the full detail.
4. Permitted, operational use
BailSoft is built for legitimate, operational purposes connected to active or prospective bail bonds — for example, monitoring the status of a defendant an agency has bonded, tracking court dates, and staying aware of bookings and releases in the counties an agency works. It is not built for, and may not be used for, screening people for benefits, jobs, housing, credit or insurance.
5. Consent-based monitoring
Guardian, our GPS product, runs only on the defendant's explicit written consent, obtained as part of the bail agreement. The scope of monitoring and the data-retention period are defined transparently. We do not enable covert tracking, and monitoring is limited to what the agreement and applicable law allow. See Consent & data use.
6. Biometric data (selfies & facial features)
Where check-ins include a selfie, the photo is handled as an ordinary image by default. If an agency enables any feature that derives facial-geometry or other biometric identifiers from a photo (for example, face matching), that processing is regulated in states with dedicated biometric laws — Illinois (BIPA), Texas (CUBI) and Washington — which generally require prior written consent, a published retention-and-destruction schedule, a prohibition on sale, and (in Illinois) carry a private right of action with statutory damages.
BailSoft's posture: biometric processing is off by default, is opt-in and consent-gated where offered, follows a defined retention-and-destruction schedule, and is never sold. Because the agency is the party interacting with the defendant, the agency is responsible for obtaining and documenting the required biometric consent before enabling such features.
7. Communications & TCPA
SMS and email reminders are sent through the agency's own provider account (for example, the agency's own Twilio or Resend keys). This keeps the Telephone Consumer Protection Act (TCPA) consent burden — and the sending reputation — with the agency, where it belongs. BailSoft builds opt-in tracking into defendant records so agencies can capture and evidence consent (date, number, disclosure, method). Court-date reminders are informational messages; agencies remain responsible for honoring opt-outs (STOP) and applicable consent rules.
8. Mugshots & state law
BailSoft does not operate a commercial mugshot website, and it does not scrape or display booking photographs from external commercial sources. There is no single federal mugshot law; publication and use are governed by a patchwork of state rules (for example, removal-on-request statutes in Florida and California, and restrictions in Texas). Where booking imagery is available at all, its visibility in BailSoft is configured per state law and automatically disabled where restricted, and it is presented only for operational awareness — never for publication, shaming or resale.
9. Payments
BailSoft does not process card payments itself and includes no card-processing features beyond ledger record-keeping. Payment Plans is a ledger only — it records what is owed and paid. Where card collection is supported, it runs through licensed payment processors that serve the bail bond industry, which carry their own PCI-DSS and regulatory obligations. This keeps BailSoft out of the regulated flow of funds while still giving agencies full visibility.
10. Your data stays yours
The agency application is self-hosted, so your defendant and bond data never touches BailSoft infrastructure. You control where it lives, who can access it, and how long it is kept. From the product itself we collect only anonymous, aggregate usage counters (for example, which modules are enabled and version numbers) — never personal data. See our privacy policy.
11. Security & subprocessors
For the hosted parts of BailSoft (the marketing site and BailSoft Intelligence), we use reputable cloud infrastructure with encryption in transit and at rest, access controls, and monitoring, and we work only with subprocessors under appropriate contractual safeguards. For the self-hosted application, the agency controls its own environment; BailSoft provides role-based access controls, an audit log and secure defaults to support the agency's own security program.
12. Auditability
Surety audits and regulators expect a clean trail. BailSoft records every access and mutation, and BailSoft Audit provides an audit-ready activity log by default — so agencies can show exactly who did what and when.
13. Accountability
Compliance is not a one-time exercise. We review these practices as laws evolve, configure features to reflect jurisdictional differences, and expect agencies to use BailSoft lawfully within their own state's rules. This page describes our approach in good faith; it is not legal advice, and agencies should confirm their own obligations with qualified counsel.