Last updated: June 2026
Harbingers LLC, doing business as Harbinge.rs ("Harbinge.rs," "we," "us," or "our") operates the Forager platform, including Forager Mobile (Android), Forager Cloud, and associated services. This policy explains what information we collect, how we use it, and the choices available to you.
Data controller and processor. For personal data collected through harbinge.rs (contact forms, website visits), Harbinge.rs acts as the data controller. For personal data submitted by Customers in connection with the Forager platform (asset records, user accounts, location data), Harbinge.rs acts as a data processor on behalf of the Customer, who is the controller.
This policy applies to:
If you are a User acting on behalf of a Customer, that Customer's data processing agreement with Harbinge.rs governs how your organization's data is handled. This policy supplements, and does not replace, that agreement.
Account and organization data. When a Customer enrolls, we collect the organization name, administrator email address, billing contact, and subscription information.
Asset records. Customers define the asset types and fields they track (serial numbers, equipment descriptions, locations, and similar operational data). Harbinge.rs stores this data on behalf of the Customer; we do not define or own it.
RF signal data. Forager Mobile captures Wi-Fi and Bluetooth Low Energy (BLE) signal observations to locate assets. MAC addresses observed by the app are hashed using a one-way function before transmission and storage. Raw MAC addresses are never retained on our servers.
Usage and diagnostic data. We collect application logs, crash reports, and feature usage telemetry to operate and improve the service. This data is aggregated or pseudonymized and is not linked to individual users beyond what is necessary to diagnose specific incidents.
Website data. When you visit harbinge.rs, standard web server logs record your IP address, browser type, referring page, and pages visited. We do not use third-party advertising trackers.
Contact inquiries. If you submit a contact form or email us, we retain your name, email address, and message to respond and follow up.
Forager is designed to track assets — equipment and devices — not individuals. The system is not intended for employee monitoring and should not be used for that purpose.
We do not sell, rent, or share your data with third parties for advertising or marketing purposes.
Forager Cloud enforces Row-Level Security (RLS) at the database layer. This means each Customer's data is completely isolated — no query, user, or administrator can access records belonging to a different organization, even within a shared infrastructure. Access is governed by role and organization at the database level, not only the application layer.
Harbinge.rs employees access Customer data only when necessary to provide support or investigate a security incident, and only after authorization.
Forager was designed from the ground up for regulated industries. We are prepared to execute a Business Associate Agreement (BAA) with covered entities and business associates subject to HIPAA. Contact us at [email protected] to request a BAA or discuss compliance requirements specific to your organization.
Nothing in this policy constitutes legal advice. Organizations with HIPAA, GLBA, or other regulatory obligations should review Forager's data handling in consultation with their compliance and legal teams.
| Data category | Retention period |
|---|---|
| Customer platform data (assets, scans, users) | Duration of contract + 90 days post-termination |
| Contact form submissions and email inquiries | 2 years, or until deletion is requested |
| Billing and payment records | 7 years (US tax and financial record requirements) |
| Anonymized usage telemetry | Indefinite (no personal data retained) |
| Server access logs (IP address, pages visited) | 90 days |
Forager is provided to your organization under contract with your employer or organization (the "Customer"), who controls the data generated through your use of the app. Individual users should direct data deletion requests to their organization's administrator. At the Customer's written request, or upon termination of the Customer's contract with us, we will delete all of the Customer's data, including all individual user accounts and records, within 30 days unless retention is required by law.
For individuals in the European Union or United Kingdom, we process personal data under the following lawful bases:
We do not make automated decisions that produce legal or similarly significant effects on individuals.
Forager Cloud is hosted on infrastructure provided by Supabase, Inc. (database, authentication, and file storage) and cloud infrastructure providers. These vendors process data on our behalf under data processing agreements consistent with this policy.
We do not embed third-party advertising scripts, social tracking pixels, or analytics platforms that share data with advertisers.
International data transfers. Harbinge.rs is based in the United States. When we process personal data from EU or UK residents, we rely on Standard Contractual Clauses (SCCs, 2021 EU Commission version) as the lawful transfer mechanism. Enterprise Customers may request a signed DPA incorporating the SCCs by contacting [email protected].
Depending on your jurisdiction, you have the following rights regarding your personal data:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. EU and UK residents may also lodge a complaint with their local supervisory authority (e.g., their national Data Protection Authority).
If you are a User acting on behalf of a Customer, requests related to asset records or organizational data should be directed to your organization's Forager administrator, who is the data controller for that data.
Canadian residents (PIPEDA). You have similar rights to access and correct your personal data. Contact us at [email protected].
harbinge.rs uses only essential cookies and browser local storage. We do not use advertising, analytics, or cross-site tracking cookies.
| Name | Storage | Purpose | Duration |
|---|---|---|---|
harbingrs_consent | localStorage | Stores dismissal of cookie notice | Persistent until cleared |
__cf_bm | Cookie | Cloudflare bot management (essential security) | 30 minutes |
PHPSESSID | Cookie | PHP session for contact form handling | Session |
All cookies listed are strictly necessary under GDPR Article 5(3) and do not require prior consent. You may clear cookies at any time through your browser settings.
We may update this policy from time to time. Material changes will be communicated to Customers by email or in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions about this policy or data handling practices:
Harbingers LLC (dba Harbinge.rs)
Upland, California
[email protected]