Privacy Policy
This Privacy Policy describes how Atlas Glinn, LLC ("Atlas Glinn," "we," "us," or "our"), including its training division MAST Solutions, collects, uses, shares and protects personal information when you visit atlasglinn.com or mastsolutions.com, register for a MAST Solutions course, request a capability statement, subscribe to our newsletter, or use the Atlas EP iOS application.
It is written in plain language on purpose. Part A covers the websites and MAST course registration. Part B covers the Atlas EP app. Part C covers your rights and how to reach us. If anything here is unclear, write to atlasglinn.hq@atlasglinn.com.
Contents
- Who we are
- Website visitors
- MAST course registration
- Eligibility attestations
- Range agreement and waiver
- Payments
- Email: receipts, reminders, newsletter
- Who we share information with
- How long we keep it
- Artificial Intelligence
- Security
- Atlas EP app
- Your rights: Texas, California, everyone
- Age requirements
- Changes and contact
Part A — Websites and MAST Solutions
1. Who We Are
Atlas Glinn, LLC is a Houston, Texas security and training company. MAST Solutions is its tactical training division, operating since 2005. Atlas EP is its executive protection software platform. One company, one privacy team, one policy.
Contact: atlasglinn.hq@atlasglinn.com | 2450 Fondren Rd, Suite 255, Houston, TX 77063 | (281) 654-8100
2. Website Visitors
When you browse our sites we collect very little, and none of it identifies you unless you choose to identify yourself. Like every website, ours records standard technical information such as IP address, browser type and pages requested, for security and reliability, and we use aggregate visit statistics to understand how the sites are used. We honour the Global Privacy Control browser signal.
- Embedded media. Videos are hosted on YouTube and load only when you press play. Instagram posts load only when that section is on screen. When you activate them, Google or Meta may set their own cookies under their own policies. Nothing loads from them until you act.
- Forms. The capability statement and contact forms send us your name, email, organization and message by email. We use them to reply to you.
We do not use advertising cookies, we do not run third-party ad networks on our sites, and we do not sell website visitor data.
3. MAST Course Registration
To reserve a seat in a MAST Solutions course you provide, in this order:
- Course and training weekend selected
- Name, email address and phone number
- Eligibility attestations (see Section 4)
- Signed Class Participation and Use of Property Agreement (see Section 5)
- Acceptance of the refund and cancellation policy, recorded with the policy version, time and IP address
- Payment (see Section 6)
- An optional newsletter opt-in, unticked by default
Today you register as a guest and complete the agreement and attestations for each booking. When we offer profiles, a profile will let you reuse your signed agreement and your eligibility attestations for 12 months so you do not repeat them for every course. Both paths collect the same information; the difference is how long we keep it (Section 9).
We use registration information to run the course: confirming your seat, sending the receipt, gear list, directions and reminders, keeping the roster, and contacting you if a date changes.
The range address is not public. It is sent to you by email after your booking is confirmed, together with driving directions. Please do not repost it.
4. Eligibility Attestations
Before payment, every participant answers two yes-or-no questions: whether you are a United States citizen, and whether you have a felony conviction that prevents you from possessing or handling a firearm. You attest that your answers are true.
We do not run background checks.
Why we ask. These are live-fire courses. The attestation puts each participant on record, protects the other students and instructors, and gives our staff a basis to follow up or decline a booking. Answering "yes" to certain questions does not automatically decline you; it prompts a conversation.
This is sensitive personal data under the Texas Data Privacy and Security Act (criminal history, citizenship status). We therefore handle it differently from everything else:
- Answers are readable only by designated MAST Solutions staff.
- Answers are never emailed, never included in any notification, and never sent to any marketing or analytics system.
- We do not sell sensitive personal data, and we do not process it for any purpose other than course safety and eligibility.
- Raw answers are deleted on a schedule (Section 9). Only the outcome, cleared or flagged, is kept, so that a person who was declined cannot simply register again under the same identity.
5. Range Agreement and Waiver
Every participant signs the MAST Solutions Class Participation and Use of Property Agreement before payment. You complete it on our site by typing your name and the required fields; we record a typed attestation together with the date, time and IP address of signature, and generate the completed PDF.
The signed agreement is emailed to you and to the people who need it to run the course: MAST Solutions staff and the host of the range facility. The range host receives the signed agreement and nothing else about you. With a profile, your signed agreement is valid for 12 months and is not re-collected for later courses in that window.
6. Payments
Payments are processed by Stripe, Inc. You enter your card on Stripe's secure checkout page; we never see or store full card numbers. Stripe sends us confirmation of payment, the amount, your billing name and address, and your phone number if you provide it, which we keep with your booking. Stripe's privacy policy is at stripe.com/privacy.
7. Email: Receipts, Reminders, Newsletter
We send two kinds of email and keep them separate.
- Transactional (sent through Resend): your receipt, signed agreement, gear list, range directions and, as we add them, a reminder about a week before class, a reminder the day before, and a follow-up after. These are part of the service you bought and cannot be unsubscribed from while you hold a booking.
- Marketing (sent through Mailchimp): the newsletter, course announcements and offers. You receive these only if you opted in. Every marketing email has an unsubscribe link, and unsubscribing never affects your booking emails.
If you opt in, your name, email, the courses you have taken and your opt-in date are synced to Mailchimp so we can send relevant course news. Your eligibility answers, agreement and payment details are never synced to Mailchimp.
8. Who We Share Information With
We share personal information only with providers who help us run the service, and only the part each one needs.
| Provider | What they receive | Why |
|---|---|---|
| Stripe | Name, email, billing details, amount | Payment processing |
| Resend | Name, email, booking details, agreement PDF | Transactional email |
| Mailchimp | Name, email, course history, opt-in date (opt-in only) | Newsletter |
| Hosting and infrastructure providers | Booking records and standard technical data | Operating the sites and the booking system |
| Range facility host | Your signed range agreement only | Access to the range on your course date |
Each provider is bound by its own privacy terms and our agreements with it, and may not use your information for its own purposes. We also disclose information when required by law, court order or governmental authority, or when necessary to protect the safety of people at our courses or facilities. In a merger, acquisition or sale of assets, information may transfer to the acquiring entity under these same protections.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
9. How Long We Keep It
| Information | Kept for |
|---|---|
| Booking and payment records | Seven years, for tax and accounting |
| Signed range agreement | Five years after your last course, for liability records |
| Eligibility answers, profile holder | 12 months, then deleted and re-asked |
| Eligibility answers, guest, cleared | Deleted within 7 days after the course |
| Eligibility answers, flagged or declined | Deleted 30 days after staff review |
| Eligibility outcome (cleared or flagged, date, question set) | Cleared: 12 months. Flagged or declined: kept, so the decision is not lost |
| Newsletter subscription | Until you unsubscribe |
| Analytics events | Up to 24 months, then aggregated or deleted |
| Profile | Until you ask us to delete it |
Deletion runs on a schedule, not on memory. When you ask us to delete your profile we do so within 30 days, except for records we are required to keep by law and the flagged-or-declined outcome described in Section 4.
10. Artificial Intelligence
We use AI tools and we say so.
- Building the sites. We use Anthropic's Claude to help draft and edit website content, documents and code. Drafts are reviewed by our people before publication. Where an article is drafted with AI assistance from our own course material, the instructor remains responsible for its accuracy.
- Atlas EP. The app uses Anthropic's Claude for threat analysis features, described in Part B.
- What is never sent to AI systems. Your course registration, eligibility attestations, signed agreements, payment details and email address are processed by the systems in Section 8 only. They are not sent to Claude or to any other AI service, and we do not use them to train models.
- No automated decisions about you. Whether a flagged eligibility attestation leads to a follow-up or a declined booking is decided by a person at MAST Solutions, not by software.
11. Security
We use administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold. Payment card data never touches our systems. No system is perfectly secure. If a breach affects your personal information we will notify you as required by Texas law and any other law that applies to you.
Part B — Atlas EP App
12. Atlas EP App
Atlas EP is our executive protection platform for professional security operators, protection agents and principals. By using Atlas EP you agree to the practices in this section as well as Parts A and C.
12.1 Information the app collects
- Account: full name, email, phone, job title and role (Agent, Operator, Command), optional profile photo, team affiliations.
- Location: precise GPS location for Blue Force Tracker, route monitoring and emergency coordination, in the foreground while the app is in use and, with explicit permission, in the background during active deployments. Background access can be disabled in iOS Settings; team tracking then stops.
- Communications: encrypted operational messages, voice and status updates between authorized team members, end-to-end encrypted with AES-256-GCM. We do not read or analyse their content.
- Device and technical: device model, iOS version, identifiers, app version, crash and diagnostic data, connectivity, push tokens.
- Health and biometric: with explicit permission, heart rate and motion data from Apple HealthKit and Apple Watch for operator wellness. Processed on device; not transmitted without your consent.
- Emergency and incident: when SOS features are activated, your location, device status and incident details are sent to the emergency contacts and team members configured in your account.
12.2 How the app uses it
- Team coordination, tracking, encrypted communications and threat monitoring
- Emergency response to your authorized team during SOS events
- Authentication, profile and team management
- Fraud prevention, abuse detection and enforcement of our Terms
- Anonymized crash reports and performance analytics
- Legal compliance
Your name, role, status and, when sharing is enabled, location are visible to other authorized members of your operational team. We do not use app data for advertising and do not sell it.
12.3 App service providers
- Apple (push notifications, HealthKit, in-app purchases)
- Stripe (subscription payments; we never store full card numbers)
- Twilio (SMS and voice)
- Anthropic (AI-powered threat analysis features)
- Infrastructure providers for authentication, data storage and network delivery
12.4 App retention and security
We keep app account data while your account is active. Operational logs and communications are retained 90 days by default; you may set a shorter period in account settings. On account deletion we delete personal data within 30 days except where law requires retention. Subscription payments are processed by Stripe; in-app purchases, if any, by Apple.
Atlas EP implements industry-leading security measures including:
- AES-256-GCM encryption for all data at rest and in transit
- WireGuard VPN for secure network communications
- Zero-trust architecture: data is verified at every access point
- Role-based access controls limiting data access to authorized personnel
- Regular security audits and penetration testing
You can manage the app's access to location, camera, microphone, health data and notifications in iOS Settings → Atlas EP.
Part C — Your Rights and Our Contact Details
13. Your Rights
Wherever you live, you can ask us to:
- Access a copy of the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your personal information, subject to the legal retention in Section 9
- Receive your information in a portable format
- Opt out of marketing email at any time
- Withdraw consent you previously gave
Email atlasglinn.hq@atlasglinn.com from the address on your booking or account, or write to the address below. We respond within 45 days, and we will tell you if we need longer. We will verify your identity before releasing or deleting anything. If we decline a request we will say why, and you may appeal by replying to our response.
Texas residents
Under the Texas Data Privacy and Security Act you have the rights above, plus the right to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. We do none of those three. Sensitive personal data, including the eligibility attestations in Section 4, is processed only with your consent, given when you complete the form, and is never sold. We honour the Global Privacy Control browser signal as an opt-out. If you believe we have not resolved a concern, you may contact the Texas Attorney General's Consumer Protection Division.
California residents
Under the California Consumer Privacy Act you have the right to know the categories of personal information we collect and why, to delete it, to correct it, and to opt out of sale or sharing. We do not sell personal information and do not share it for cross-context behavioural advertising. We do not discriminate against you for exercising these rights.
Outside the United States
Our services operate from the United States. If you use them from elsewhere your information is transferred to and processed in the United States and in the countries where our providers operate.
14. Age Requirements
MAST Solutions courses are for adults aged 18 and over; some courses carry additional age requirements under applicable law, stated on the course. Atlas EP is for professional use by adults. We do not knowingly collect personal information from anyone under 18. If you believe we have, tell us at atlasglinn.hq@atlasglinn.com and we will delete it.
15. Changes to This Policy and Contact
We update this policy when our practices change. The "Last Updated" date at the top moves, and for material changes affecting course registration or the app we notify you by email or in the app. Continued use after a change is posted means you accept the revised policy.
Atlas Glinn, LLC — Privacy Team
Email: atlasglinn.hq@atlasglinn.com
Phone: (281) 654-8100
Address: 2450 Fondren Rd, Suite 255, Houston, TX 77063
Websites: atlasglinn.com · mastsolutions.com