Privacy Policy
Effective date: 8/20/2026
Contact: hello@homebasehaven.com
This policy covers two separate things. Part one is this website, where you can order products and services. Part two is Home Base Auth, the multi-factor authentication app for phones. They handle information very differently, so they are described separately.
Part 1 — This website (homebasehaven.com)
This part applies to homebasehaven.com: browsing the site, submitting the order or contact form, creating an account, and paying for an order.
What we collect
When you submit the order or contact form, we store the details you enter: your first and last name, email address, and — if you provide them — phone number, city, state, preferred contact method, preferred date, the services you selected, and any message you write. We also record the IP address the submission came from, as a basic protection against abuse of the form.
If you create an account, we store your username and email address along with your sign-in credentials.
When you place an order, payment is handled by Stripe. Your card details are entered on Stripe's own payment page and never reach our servers. We receive back a record of the order: the items, the amount, your email address, your phone number, and the shipping address you gave Stripe, so we can fulfil and schedule the work.
Your shopping cart is kept in your own browser's local storage. It is not sent to us until you check out.
What we do not do
This website carries no analytics, no advertising, and no third-party tracking of any kind. We do not profile you, and we do not sell, rent, or share your information with anyone for marketing. The only cookies set are the ones needed to keep you signed in to your account.
Who else is involved
- Stripe, as our payment processor. Stripe handles your card details and calculates tax, under its own privacy policy.
- Our email provider, used only to deliver order and enquiry notifications to us and receipts to you.
We may disclose information if legally required to do so, or where necessary to protect the safety of users or the integrity of the service.
Your choices
You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it, by writing to hello@homebasehaven.com. We keep order records for as long as we need them to provide support, honour warranties, and meet our tax and accounting obligations.
Part 2 — Home Base Auth (mobile app)
This part applies only to the Home Base Auth app on your phone. It does not describe this website — see Part 1 above for that.
Who we are
Home Base Auth is published by Guardian Systems, LLC on behalf of Home Base, which operates the multi-factor authentication service the app connects to at mfa.ourhouseoforder.com.
In practice: the app on your phone is built and distributed by Guardian Systems, while the account you enroll — and the record of it — lives on the service Home Base operates.
The app will only ever connect to mfa.ourhouseoforder.com. That address is built into the app. It cannot be redirected by a QR code, by a link, or by anyone who gains access to your phone.
What the app collects
Only what is required to deliver a sign-in request to your device and verify your answer to it.
| Data | What it is | Why it is needed |
|---|---|---|
| Push notification token | An identifier issued to this app by Google (on Android) or Apple (on iOS) | The only way to wake your device when a sign-in needs approving |
| Device identifier | A random identifier assigned when you enroll | Distinguishes this device from your other enrolled devices |
| Device nickname | A short label you type during enrollment, such as "Work phone" | Lets you tell your devices apart |
| Device public key | The public half of a key pair generated on your device | Lets the service verify an approval genuinely came from this device |
The app does not collect your name, email address, phone number, date of birth, contacts, photos, payment details, location, or any advertising identifier. It contains no analytics, no crash reporting, no advertising, and no third-party tracking of any kind. It does not record which screens you open or how long you spend in the app.
The camera is used solely to read an enrollment QR code. No image is stored or transmitted.
The device nickname is free text. Please do not type anything into it you would not want stored with your enrollment.
What stays on your device and is never sent anywhere
Three secrets are created or received during enrollment and held in the platform's protected storage — the Android Keystore and the iOS Keychain:
- The private key used to sign your approvals
- The access token identifying this device to the service
- The one-time-code seed, where your organization uses one
These never leave the device. Backups are disabled for this app, so they are not copied into iCloud, Google Drive, or a backup of your phone, and cannot be restored onto a different device.
What is not in your notifications
A notification tells you only that a sign-in request is pending. It never contains the account, the requesting application, a location, or any detail of the request. The app fetches those details over an encrypted connection, and only after you open it.
Who else is involved
- Home Base, as the operator of the service. Your enrollment, device identifier, nickname and approval history are held there, subject to Home Base's privacy practices and to any agreement between Home Base and the organization that asked you to enroll.
- Google and Apple, as message carriers only. To wake your device, a notification is handed to Google's Firebase Cloud Messaging on Android or Apple's Push Notification service on iOS. They receive your push token and delivery metadata. Because the notification carries no detail of the request, they do not receive the content of anything you approve or deny.
Your data is not sold, not rented, and not shared with anyone else. It is not used for advertising or for profiling.
We may disclose information if legally required to do so, or where necessary to protect the safety of users or the integrity of the service.
How it is protected
- All communication uses HTTPS, verified against the operating system's trusted certificate authorities. The app refuses unencrypted connections outright.
- Secrets are stored in the operating system's protected keystore, not in ordinary app storage.
- Approvals are cryptographically signed on your device, so an approval cannot be forged or replayed by anyone who intercepts it.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify affected users.
Deleting your data
Open the account in the app and choose Remove. This:
- 1.Tells the service to revoke the enrollment, which invalidates the device's access token immediately and cancels any pending request, and
- 2.Erases the private key, access token and one-time-code seed from your device.
If the service cannot be reached, the erasure on your device still happens and the app tells you plainly that the enrollment may still be active, so you can follow up. It will never report a deletion it did not complete.
A record that the device existed, and when it was removed, is retained by the service. Keeping that history is a security requirement — an organization investigating an incident has to be able to establish when an authenticator was added or removed. Everything that made the device usable or reachable is destroyed.
To request deletion of records held by the service, contact us at the address below.
Children
Home Base Auth is an account-security tool for people who have been asked to enroll a device by an organization. It is not directed to children and does not knowingly collect information from them.
Changes
If this policy changes we will update the effective date above. Material changes to what is collected or how it is used will be described here rather than silently replaced.
Contact
Questions about this policy, about the app, or about records held by the service: hello@homebasehaven.com