Consent & data use
This page explains how Guardian and BailSoft's monitoring features obtain consent and handle location, communication and biometric data — and the responsibilities that sit with the agency. It is written to reflect consent-based monitoring, the TCPA, and state biometric laws (Illinois BIPA, Texas CUBI and Washington).
1. The consent model
Guardian operates only where a defendant has given explicit, written consent as part of the bail agreement. That consent describes what is monitored, why, and for how long, and it is recorded in an audit-ready manner. Monitoring is limited to what the agreement and applicable law allow; BailSoft does not enable covert or unlimited tracking.
2. Scope of monitoring
Depending on what the agency enables and the defendant consents to, monitoring may include:
- GPS location sharing and scheduled check-ins;
- Geofence (allowed-zone) definitions and breach alerts;
- Court-date reminders and recorded agency–defendant messaging;
- Device signals such as low-battery warnings;
- Optional check-in photos (see biometric data below).
Agencies configure scope within lawful bounds and only for the duration of the supervision relationship.
3. GPS & location data
Location data is collected only under consent, for supervision connected to the bond, and is retained only for the period the consent and applicable law define. It is not used for advertising, profiling, or any purpose unrelated to the bail relationship, and it is not sold.
4. Communications consent (TCPA)
SMS and email are sent through the agency's own provider, and the agency is responsible for obtaining the consent the TCPA and applicable law require and for honoring opt-outs. Court-date reminders are informational; promotional messages require stronger consent. BailSoft builds opt-in tracking into defendant records — capturing the date, number, disclosure language and method — so agencies can evidence consent, and it supports honoring STOP/opt-out requests.
5. Biometric data (selfies & facial features)
Check-in photos are treated as ordinary images by default. If an agency enables a feature that derives facial-geometry or other biometric identifiers from a photo (for example, face matching), that processing is regulated in Illinois (BIPA), Texas (CUBI) and Washington, which generally require: prior written consent; a published retention-and-destruction schedule; a prohibition on sale; and, in Illinois, carry a private right of action with statutory damages. BailSoft keeps biometric processing off by default and opt-in where offered, applies a defined retention-and-destruction schedule, and never sells biometric data. The agency — as the party interacting with the defendant — must obtain and document the required biometric consent before enabling such features.
6. Data minimization
BailSoft collects only the data needed for supervision connected to the bond. It is not used for advertising, resale, or any purpose unrelated to the bail relationship.
7. Retention & deletion
Location, communication and any biometric data are retained only for the period defined in the consent and applicable law. When a bond is exonerated or the supervision relationship ends, data is deleted or anonymized according to the agency's configured retention policy and any statutory destruction requirement.
8. Withdrawal of consent
Consent terms — including the effect of withdrawal — are set out in the bail agreement. Where consent is withdrawn or the relationship ends, monitoring stops in line with those terms and applicable law, and data is handled per the retention policy above.
9. Where data lives
The BailSoft application is self-hosted by each agency; Guardian and monitoring data are held within the agency's own deployment. BailSoft does not store agency, defendant or monitoring data on its own infrastructure.
10. Security
Agencies are responsible for securing their deployment, including access controls, encryption and backups. BailSoft provides role-based access, an audit log and secure defaults to support the agency's own security program.
11. Agency responsibilities
As the party that interacts with defendants and indemnitors, the agency is responsible for obtaining valid consent, honoring its scope and duration, complying with state and federal law (including TCPA and biometric consent), configuring features lawfully for its jurisdiction, and handling individual requests appropriately.
12. Defendant & consumer rights
Individuals may have rights over the data an agency holds about them under applicable state law. Because that data lives in the agency's deployment, requests should be directed to the agency, which acts as the controller. BailSoft will help route or support a request where it can.
13. Mugshots & state law
BailSoft does not operate a commercial mugshot site or scrape booking photos from commercial sources. Where booking imagery is available, its visibility is configured per state law and automatically disabled where restricted, and it is presented for operational awareness only — never for publication or resale. See Compliance by design.