Harbinge.rs builds field intelligence products that reduce operational friction.

[email protected]

Privacy Policy

Last updated: June 2026

Harbingers LLC, doing business as Harbinge.rs ("Harbinge.rs," "we," "us," or "our") operates the Forager platform, including Forager Mobile (Android), Forager Cloud, and associated services. This policy explains what information we collect, how we use it, and the choices available to you.

Data controller and processor. For personal data collected through harbinge.rs (contact forms, website visits), Harbinge.rs acts as the data controller. For personal data submitted by Customers in connection with the Forager platform (asset records, user accounts, location data), Harbinge.rs acts as a data processor on behalf of the Customer, who is the controller.

1. Who this policy covers

This policy applies to:

  • Organizations that deploy Forager under a service agreement ("Customers").
  • Users — field technicians, administrators, and other personnel who access Forager on behalf of a Customer.
  • Visitors to harbinge.rs.

If you are a User acting on behalf of a Customer, that Customer's data processing agreement with Harbinge.rs governs how your organization's data is handled. This policy supplements, and does not replace, that agreement.

2. Information we collect

Account and organization data. When a Customer enrolls, we collect the organization name, administrator email address, billing contact, and subscription information.

Asset records. Customers define the asset types and fields they track (serial numbers, equipment descriptions, locations, and similar operational data). Harbinge.rs stores this data on behalf of the Customer; we do not define or own it.

RF signal data. Forager Mobile captures Wi-Fi and Bluetooth Low Energy (BLE) signal observations to locate assets. MAC addresses observed by the app are hashed using a one-way function before transmission and storage. Raw MAC addresses are never retained on our servers.

Usage and diagnostic data. We collect application logs, crash reports, and feature usage telemetry to operate and improve the service. This data is aggregated or pseudonymized and is not linked to individual users beyond what is necessary to diagnose specific incidents.

Website data. When you visit harbinge.rs, standard web server logs record your IP address, browser type, referring page, and pages visited. We do not use third-party advertising trackers.

Contact inquiries. If you submit a contact form or email us, we retain your name, email address, and message to respond and follow up.

3. Information we do not collect

  • Raw MAC addresses (hashed before leaving the device).
  • Cellular identifiers (IMEI, IMSI, phone numbers).
  • Personal health information (PHI) about patients or individuals.
  • Financial account information.
  • Precise real-time location of individual people.

Forager is designed to track assets — equipment and devices — not individuals. The system is not intended for employee monitoring and should not be used for that purpose.

4. How we use information

  • Service delivery. To operate Forager Cloud, process asset location updates, and provide the features your organization subscribed to.
  • Security and integrity. To detect and prevent unauthorized access, abuse, or fraud.
  • Support and troubleshooting. To diagnose issues and respond to support requests.
  • Service improvement. To understand how Forager is used and prioritize product development. We use aggregated, non-identifiable data for this purpose.
  • Legal compliance. To meet applicable legal obligations, including audit requests and regulatory requirements.

We do not sell, rent, or share your data with third parties for advertising or marketing purposes.

5. Data isolation and access controls

Forager Cloud enforces Row-Level Security (RLS) at the database layer. This means each Customer's data is completely isolated — no query, user, or administrator can access records belonging to a different organization, even within a shared infrastructure. Access is governed by role and organization at the database level, not only the application layer.

Harbinge.rs employees access Customer data only when necessary to provide support or investigate a security incident, and only after authorization.

6. HIPAA and regulated environments

Forager was designed from the ground up for regulated industries. We are prepared to execute a Business Associate Agreement (BAA) with covered entities and business associates subject to HIPAA. Contact us at [email protected] to request a BAA or discuss compliance requirements specific to your organization.

Nothing in this policy constitutes legal advice. Organizations with HIPAA, GLBA, or other regulatory obligations should review Forager's data handling in consultation with their compliance and legal teams.

7. Data retention

Data category Retention period
Customer platform data (assets, scans, users)Duration of contract + 90 days post-termination
Contact form submissions and email inquiries2 years, or until deletion is requested
Billing and payment records7 years (US tax and financial record requirements)
Anonymized usage telemetryIndefinite (no personal data retained)
Server access logs (IP address, pages visited)90 days

Forager is provided to your organization under contract with your employer or organization (the "Customer"), who controls the data generated through your use of the app. Individual users should direct data deletion requests to their organization's administrator. At the Customer's written request, or upon termination of the Customer's contract with us, we will delete all of the Customer's data, including all individual user accounts and records, within 30 days unless retention is required by law.

8. Lawful basis for processing (EU/UK)

For individuals in the European Union or United Kingdom, we process personal data under the following lawful bases:

  • Contract performance — processing necessary to deliver the Forager platform to Customers and their users.
  • Legitimate interests — processing contact form submissions, operating website security, and diagnosing service issues. Our legitimate interests do not override your rights.
  • Legal obligation — retaining billing records and responding to lawful government requests.
  • Consent — sending marketing communications. You may withdraw consent at any time by unsubscribing.

We do not make automated decisions that produce legal or similarly significant effects on individuals.

9. Third-party services

Forager Cloud is hosted on infrastructure provided by Supabase, Inc. (database, authentication, and file storage) and cloud infrastructure providers. These vendors process data on our behalf under data processing agreements consistent with this policy.

We do not embed third-party advertising scripts, social tracking pixels, or analytics platforms that share data with advertisers.

International data transfers. Harbinge.rs is based in the United States. When we process personal data from EU or UK residents, we rely on Standard Contractual Clauses (SCCs, 2021 EU Commission version) as the lawful transfer mechanism. Enterprise Customers may request a signed DPA incorporating the SCCs by contacting [email protected].

10. Your rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Access. Request a copy of the personal data we hold about you.
  • Rectification. Request correction of inaccurate or incomplete data.
  • Erasure ("right to be forgotten"). Request deletion of your personal data where we have no lawful basis to continue processing it.
  • Restriction. Request that we limit processing of your data while a dispute is resolved.
  • Portability. Receive your personal data in a structured, machine-readable format.
  • Objection. Object to processing based on legitimate interests or for direct marketing purposes.
  • Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. EU and UK residents may also lodge a complaint with their local supervisory authority (e.g., their national Data Protection Authority).

If you are a User acting on behalf of a Customer, requests related to asset records or organizational data should be directed to your organization's Forager administrator, who is the data controller for that data.

Canadian residents (PIPEDA). You have similar rights to access and correct your personal data. Contact us at [email protected].

11. Cookies

harbinge.rs uses only essential cookies and browser local storage. We do not use advertising, analytics, or cross-site tracking cookies.

Name Storage Purpose Duration
harbingrs_consentlocalStorageStores dismissal of cookie noticePersistent until cleared
__cf_bmCookieCloudflare bot management (essential security)30 minutes
PHPSESSIDCookiePHP session for contact form handlingSession

All cookies listed are strictly necessary under GDPR Article 5(3) and do not require prior consent. You may clear cookies at any time through your browser settings.

12. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to Customers by email or in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

Questions about this policy or data handling practices:

Harbingers LLC (dba Harbinge.rs)
Upland, California
[email protected]