Ring Integration Privacy Notice

Ring Integration Privacy Notice

Ring Integration Privacy Notice

This notice explains exactly what Evercam receives from your Ring account, why, where it is stored, how long it is kept, and how you stop it. It supplements our general Privacy notice, our Data Retention and Destruction policy and our Technical and Organizational Measures. Where this notice differs from the general notice, this notice governs Ring data.

Evercam is a construction documentation platform. The Ring integration exists for one purpose: to let you see your Ring cameras, and their recent photo history, alongside your other Evercam cameras.

1. What we receive from Ring, and how

We receive data only after you link your Ring account yourself, from the Ring app, and only through Ring's official partner API. We never ask for your Ring password and never have it.

What we receive

How we get it

Why we need it

Device id

Ring device API

Identifies the camera and prevents the same device being imported twice

Device name

Ring device API

Becomes the camera's name in Evercam, so you recognise it

Device type

Ring device API

Tells us what kind of device it is

Online status

Ring device API

Drives the online/offline indicator on the camera

Ring account id

Ring account API

Links incoming Ring notifications back to the right Evercam account

Ring account email

Ring account API

Matched against Evercam accounts to determine who owns the imported cameras

Authorisation tokens

Ring OAuth

Lets us call Ring on your behalf. Stored encrypted, never shown to you or anyone else

Motion and button-press notifications

Ring webhooks

Each one triggers the capture of a single still image

Still JPEG images

Ring media API

Your camera's browsable photo history in Evercam

Live video

Ring live-view (WebRTC)

Relayed to your browser on demand while you watch it

Still images are captured at most once per camera every ten minutes, plus one per motion or button-press event. Ring's image endpoint returns only media that already exists, so Evercam never causes your device to start recording.

Live video is never recorded. It is relayed from Ring to your browser while you are watching and is not written to disk, not buffered for later, and not retained in any form. The only video-related information we keep is the capture timestamp and owning camera of each still image, which is what makes the timeline work.

2. What we do not do with Ring data

We state these explicitly because they are the questions people actually have:

  • No video download or storage. We do not call Ring's recording-download or event-history endpoints at all.

  • No AI, machine learning or automated analysis of any kind is applied to Ring data. Evercam does offer AI features (PPE detection, gate and vehicle analytics, object detection) on its own installed cameras. These are enabled per camera and are not enabled for cameras imported from Ring.

  • No facial recognition, no biometrics, no licence plate recognition.

  • No location data. We do not collect or derive the location of your Ring devices.

  • No model training. Ring data is never used to train or fine-tune any model.

  • No profiling, no building of databases for sale, and no compiling of information about people seen on camera from any outside source.

  • No marketing, advertising or data mining. Ring data is used only to provide the features described above. It is never sold, and never shared for advertising.

  • No use beyond the core service. Data collected for the purposes in the table above is not repurposed for anything else without asking you first.

3. Where it is stored, and who else can see it

Your camera imagery is held in a segregated storage system. Each customer's data is stored in a separate directory, hashed and stored as a binary large object, and is not identifiable outside Evercam's own configuration. Image timestamps are stored in Evercam's databases. Authorisation tokens are held in a secure vault.

Ring-derived data is processed only by service providers acting on Evercam's instructions, under contract, and only to run the service. Today those are our infrastructure providers: Hetzner (hosting and image storage, Germany and Finland) and Amazon Web Services (image storage, Ireland). We use only ISO 27001 and SOC 2 certified providers, and we review their audit reports and certifications to confirm they continue to meet those standards.

Incidentally, if a request involving your Ring integration produces an error, a Ring account id or device id can appear in our error-monitoring and logging systems as part of the diagnostic record. These are operational logs, not a copy of your imagery, and they are covered by the same retention and access controls.

We do not sell Ring data, and we do not share it with anyone for their own purposes.

Law enforcement. Evercam does not give any law enforcement agency standing or direct access to your cameras or images. We respond only to valid, legally binding requests, and only to the extent the law requires.

Encryption in transit. Every leg of the Ring path is encrypted with HTTPS: our calls to Ring's API, Ring's notifications to us, the image download, and your browser's connection to Evercam. Live view uses WebRTC, which is encrypted by the protocol (DTLS-SRTP).

Encryption at rest. Data at rest is stored at ISO 27001 and SOC 2 certified cloud service providers offering encryption using the AES-256 algorithm and Key Management Services (KMS). Databases are hosted by these providers and use block-level storage encryption. All sensitive information, credentials and tokens are stored in a secure vault, encrypted using BCrypt, PBKDF2 and AES algorithms.

4. Who at Evercam can see your Ring images

Only authorised Evercam personnel, and only for technical support or troubleshooting within the scope of your contract, or where required by a valid binding legal request. Access follows the principle of least privilege, requires multi-factor authentication, is formally approved, is reviewed periodically, and is revoked automatically when someone leaves. Administrative actions on cameras are recorded in our audit log.

5. How long we keep it

Data

Retention

Live video

Not retained. Never written to storage

Still images

Kept while your Ring account is linked. After you unlink, retained for 90 days in line with our Data Retention and Destruction policy, and may be deleted at any point after that. Deleted sooner on request

Image timestamps

Same as the image they describe

Authorisation tokens

Deleted immediately when you unlink or disconnect

Device id, name, type, status

Retained while the camera exists in Evercam; the camera is decommissioned when you unlink

Error and diagnostic logs

Per our standard log retention

6. Your controls

To stop all processing: remove Evercam from your Ring account in the Ring app, or disconnect the Ring connector on Evercam's Connectors page. Either one:

  • deletes our authorisation tokens immediately, so we can make no further calls to Ring

  • stops all image capture, and cancels any capture already queued

  • decommissions the imported cameras and closes the Ring project

  • causes any further notifications Ring sends us to be ignored

Unlinking stops all collection immediately. Your already-stored images are then retained for 90 days in line with our Data Retention and Destruction policy, and may be deleted at any point after that. If you want them gone sooner, ask us and we will delete them.

To delete stored images on request: email support@evercam.io and ask for deletion of your Ring camera data. We verify the request with the nominated contact on the account, then delete the data from our servers and storage media. Deletion normally completes within two to three business days, depending on how much data there is, and that includes removal by our storage providers. We issue a Certificate of Deletion confirming it, and deletion requests are logged.

To exercise any other privacy right (access, correction, portability, objection, restriction), contact compliance@evercam.io. We acknowledge within 3 working days and respond fully within one month, extended only for genuinely complex requests, and we verify your identity first.

Our Data Protection Officer can be reached at compliance@evercam.io.

7. Cameras on workplaces and construction sites

Ring cameras imported into Evercam may overlook places where people work. If you are an employer, a main contractor or a site operator using Evercam to view imagery of a workplace, you are the controller of that imagery and you are responsible for meeting the employment and data protection law that applies to you. That normally includes telling workers that cameras are in use and what they are for, displaying appropriate signage, obtaining any consents your jurisdiction requires, and consulting employee representatives where required.

Evercam acts as your processor for this imagery and provides tools that help, including role-based access control so only the right people see a camera, and a blur tool for redacting imagery before it is shared. Evercam cannot give you your notices or consents, and cannot assume that responsibility for you.

8. Legal basis, and where data is held

Our legal basis for processing Ring data is performance of our contract with you, and your consent, given by linking your Ring account. You can withdraw that consent at any time by unlinking, as described above.

Evercam's infrastructure for this integration is located in the European Union (Germany, Finland and Ireland), so linking a Ring account results in your data being transferred to and stored in the EU, at ISO 27001 and SOC 2 certified providers, under the protections described in this notice and in our Technical and Organizational Measures.

9. Changes

We will update this notice when the integration changes, and the date at the top will change with it. Material changes affecting how Ring data is used will be communicated to affected users rather than only posted here.

10. Contact

Privacy and data protection: compliance@evercam.io Deletion requests and support: support@evercam.io Evercam US, Inc.

—————————————————————

Created by: Engineering, reviewed by Compliance (ISMS team)

Creation date: 29.09.2026

Last modification date: 29.09.2026

Document approver: Head of Compliance