Virtual Select Privacy & Security Policy
Effective Date March 23, 2026
PocketWatch is an AI-native manufacturing software platform designed to support manufacturing visibility, quality, workflow execution, process control, and related operational use cases. PocketWatch services may include applications or modules such as PocketWatch SPC, PocketWatch Traveler, and other current or future PocketWatch products released by Virtual Select.
This Privacy Policy applies to PocketWatch services, mobile applications, websites, account setup workflows, support processes, and related communications, including SMS messages used for user invitations, account setup, and verification codes.
PocketWatch is owned and operated by Virtual Select LLC (“Virtual Select,” “we,” “our,” or “us”). This Privacy Policy explains how we collect, use, protect, retain, disclose, return, and delete information when companies, administrators, and authorized users use PocketWatch and related Virtual Select services.
1. Information We Collect
Account and User Information
We may collect information such as name, work email address, mobile phone number, employer or company name, plant or facility information, user role, account status, and administrator-assigned permissions.
Manufacturing, Quality, and Operational Data
PocketWatch may collect or process manufacturing, quality, workflow, and operational information entered by users or provided by an authorized company administrator. This may include plant, department, line, model, station, characteristic, specification, measurement, shift, sample, work order, traveler, job, part, inspection, process, and related operational data, depending on the PocketWatch application or module being used.
Device and Usage Information
We may collect technical information such as device type, operating system, app version, login activity, access mode, timestamps, and usage activity necessary to operate, secure, support, and improve PocketWatch.
SMS Information
When PocketWatch uses SMS, we may collect and process mobile phone numbers, message delivery information, opt-in status, opt-out status, and related consent records. SMS is used for user invitations, account setup, and verification codes. PocketWatch does not use SMS for marketing or promotional texting.
2. How We Use Information
We use information to:
• Create and manage PocketWatch accounts.
• Invite authorized users to access their employer’s PocketWatch account.
• Send verification codes and account setup messages.
• Operate PocketWatch applications, modules, workflows, and related platform features.
• Support manufacturing quality, visibility, workflow execution, process control, analytics, and related operational use cases.
• Provide customer support.
• Maintain security, authentication, access control, and auditability.
• Improve PocketWatch products and services using authorized, appropriate information and methods.
• Comply with legal, contractual, carrier, security, and regulatory requirements.
3. SMS Communications
PocketWatch SMS messages are limited to account-related communications, including user invitations, account setup, app download or setup links, verification codes, administrator contact information, and required STOP/HELP language.
PocketWatch does not send SMS marketing messages, promotional texts, or sales campaigns. Operational manufacturing alerts in the PocketWatch MVP are handled inside the application, not by SMS.
Message frequency may vary depending on account setup activity and verification needs. Message and data rates may apply. Users may reply STOP to opt out of SMS messages and HELP for help.
4. Mobile Information and SMS Consent
PocketWatch may use SMS text messages for limited account-related purposes, including user invitations, account setup, login setup, verification codes, and account access instructions.
PocketWatch SMS messages are sent only to users who are added or invited to a PocketWatch customer account by an authorized company administrator. As part of the employer-sponsored account setup process, the authorized administrator may enter a user’s mobile phone number so that PocketWatch can send an invitation, setup link, verification code, or other account access message.
PocketWatch does not use SMS messages for marketing, promotions, sales outreach, advertising, or operational SPC alerts. Operational alerts and application messages are handled inside the PocketWatch application unless a separate SMS feature is expressly enabled in the future.
SMS message frequency varies based on account setup and verification activity. Message and data rates may apply. Users may opt out of PocketWatch SMS messages at any time by replying STOP. Users may request help by replying HELP.
PocketWatch does not sell, rent, or share mobile phone numbers, SMS opt-in data, or SMS consent information with third parties or affiliates for marketing or promotional purposes. Mobile phone numbers and SMS-related information may be used only as necessary to provide account invitations, verification messages, account access support, security, compliance, and service operations.
5. How We Share Information
With the Customer Organization
PocketWatch is used by companies and their authorized administrators. Information associated with a company account may be visible to authorized administrators or users within that company based on role and permission settings.
With Service Providers
We may use service providers to support hosting, database services, SMS delivery, authentication, analytics, security, customer support, and related operations. These service providers may process information only as necessary to provide services to Virtual Select and are subject to applicable contractual, confidentiality, security, and data-handling requirements.
For Legal or Safety Reasons
We may disclose information when required by law, regulation, legal process, or government request, or when necessary to protect the rights, safety, or security of Virtual Select, our customers, users, or others.
Business Transfers
If Virtual Select is involved in a merger, acquisition, financing, asset sale, or similar transaction, information may be transferred as part of that transaction, subject to appropriate confidentiality and data protection obligations.
6. Data Security and Access Control
We use reasonable administrative, technical, and organizational measures to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No system can be guaranteed to be completely secure, but we work to protect PocketWatch and customer data using security practices appropriate for the nature of the information we process.
Access to customer information is limited to authorized personnel, contractors, and approved service providers with a legitimate business need to know. Virtual Select may require customer-specific access rules, stronger isolation, private deployment, restricted support access, or other controls where required by contract, data classification, or regulation.
Credentials, secrets, and privileged access are controlled separately from ordinary customer information. Third-party, contractor, or offshore access to restricted customer information is not permitted unless the applicable customer, contractual, security, and regulatory requirements have been evaluated and the access path is authorized.
7. Security Incident Response and Customer Information Protection
Virtual Select maintains an incident-response process for suspected or confirmed unauthorized access, use, disclosure, loss, alteration, transfer, or exposure of customer information, proprietary information, credentials, systems, or regulated data.
Any employee, contractor, service provider, or other authorized person who becomes aware of a suspected security incident involving Virtual Select or customer information must report the matter promptly to Virtual Select management. Virtual Select will assess the event, preserve appropriate records and evidence, contain or terminate unauthorized access, identify affected information and systems, investigate the cause and scope, and implement appropriate remediation and corrective actions.
When customer or third-party proprietary information may have been disclosed to an unauthorized recipient, Virtual Select will take reasonable steps to prevent further use or disclosure, including requesting that the recipient cease use, return or destroy the information, and provide confirmation of destruction when appropriate.
Virtual Select will notify affected customers or other required parties in accordance with applicable contractual, legal, regulatory, and customer-specific reporting requirements. Where an agreement specifies a reporting period, that requirement governs. Where an applicable defense contract or flow-down requires cyber incident reporting or evidence preservation, Virtual Select will follow the requirements applicable to the authorized environment and information within its responsibility.
Virtual Select maintains sufficient incident records to document material findings, containment, notifications, remediation, access changes, and corrective actions.
8. Personal Information Protection, Retention, Return, and Deletion
Virtual Select collects, uses, processes, and retains personal information only when reasonably necessary to provide, administer, secure, support, improve, or fulfill authorized Virtual Select services and customer relationships.
Personal information may include a person’s name, business contact information, telephone number, email address, employer, job function, account information, authentication information, device or access information, and other information provided or authorized by the individual or customer.
Virtual Select applies data minimization principles and may redact, anonymize, aggregate, or use synthetic data when full customer or personal detail is unnecessary for the authorized purpose.
We retain information for as long as needed to operate PocketWatch, support customer accounts, comply with legal or contractual obligations, resolve disputes, maintain audit records, protect security, and enforce agreements. Customer organizations may request deletion, return, or export of certain data subject to contractual, legal, technical, security, and retention requirements.
Upon termination of an authorized purpose, expiration of an applicable retention period, or receipt of a valid customer deletion request, Virtual Select will delete, return, or render inaccessible covered information within the period required by the applicable agreement or law.
Deletion will include reasonably accessible production systems, working files, exports, temporary files, and other controlled copies within Virtual Select’s custody. Information contained solely in protected disaster-recovery or system backups may remain until overwritten or expired through the normal backup-retention cycle, provided it remains protected and is not restored for ordinary business use.
Where preservation is required by law, regulation, litigation hold, security investigation, contract, audit requirement, or another legitimate obligation, Virtual Select may retain only the information necessary to satisfy that requirement and will continue to protect it.
9. Customer Information Destruction and Certificate of Destruction
Where required by contract or reasonably requested by an authorized customer, Virtual Select will provide written confirmation that identified customer or third-party information under Virtual Select’s control has been returned, deleted, destroyed, or rendered inaccessible in accordance with the applicable requirement.
A Certificate of Destruction may identify the customer or requesting organization; the categories of information covered; the applicable system, repository, environment, or project; the date destruction was completed; the destruction or deletion method at a reasonable level of description; any permitted backup, archival, legal-hold, or regulatory exception; confirmation that covered information is no longer available for ordinary operational use; and the authorized Virtual Select representative certifying completion.
Virtual Select will not falsely certify deletion from systems, backups, service providers, or environments it does not control. Any documented exception will be identified in the certification.
10. Customer-Controlled Data
PocketWatch is used by employer-sponsored accounts. If you are an employee, contractor, or authorized user of a company using PocketWatch, your employer or account administrator may control certain account information and manufacturing data associated with your use of PocketWatch.
Requests to access, correct, export, return, or delete company-controlled data may need to be directed to your employer or PocketWatch account administrator.
11. Proprietary, Regulated, Export-Controlled, and Defense-Related Information
Virtual Select does not assume that customer information is Controlled Unclassified Information (CUI), ITAR-controlled, EAR-controlled, classified, Covered Defense Information, or otherwise export-restricted merely because a customer participates in aerospace, defense, government, or regulated programs.
When a customer identifies information as restricted, controlled, export-controlled, CUI, classified, or subject to contractual cybersecurity requirements, Virtual Select will establish the applicable handling boundary before that information is imported, processed, transferred, disclosed, or made available to AI-enabled functionality.
Customer-specific controls may include approved users and roles; U.S.-person, citizenship, nationality, location, or residency restrictions where legally required; restrictions on foreign-person or offshore access; approved computing and storage environments; approved transfer methods; identity and authentication controls; logging, retention, and backup requirements; limitations on subcontractors and service providers; restrictions on external or generative AI; customer-controlled, private, on-premises, or isolated processing environments; and incident-reporting or evidence-preservation requirements.
For information subject to the U.S. Export Administration Regulations (EAR), International Traffic in Arms Regulations (ITAR), CUI requirements, DFARS clauses, NIST SP 800-171, CMMC-related contractual requirements, or similar obligations, Virtual Select will apply the controls required by the applicable contract, classification, markings, authorization, customer direction, and regulatory requirements. Virtual Select does not represent that every PocketWatch environment is certified or compliant with a particular defense or export-control framework unless that status has been formally established for the specific environment.
12. AI Processing and Customer Information
PocketWatch includes AI-enabled capabilities, including Virtual Coach, that may assist authorized users with explanation, analysis, manufacturing context, trends, alerts, SPC conditions, likely causes, recommended next steps, and other approved support functions.
Customer proprietary or restricted information will not intentionally be used by Virtual Select to train, fine-tune, or improve a shared AI model, nor will customer information be intentionally made available for another customer’s benefit.
Restricted customer information will not be exposed to an external AI system merely because Virtual Select software includes AI-enabled functionality. The authorized AI operating mode is determined from the customer’s information classification, contractual requirements, and approved deployment boundary.
Depending on the approved engagement, Virtual Select may use an approved enterprise-grade private AI service, an approved private or customer-controlled AI endpoint, a customer-controlled private language model, or a deterministic non-generative operating mode.
AI-assisted outputs are advisory. Final decisions involving product acceptance, nonconforming material, engineering disposition, product release, regulatory compliance, export classification, quality sign-off, process changes, or other controlled manufacturing actions remain with the customer’s qualified and authorized personnel.
13. Your Choices
Users may:
• Reply STOP to opt out of PocketWatch SMS messages.
• Reply HELP for SMS support information.
• Contact their PocketWatch administrator for account-related questions.
• Contact Virtual Select for privacy-related questions using the contact information below.
Please note that opting out of SMS may affect your ability to receive text-based invitations or verification codes. Other account setup or verification methods may be required if available.
14. Children’s Privacy
PocketWatch is intended for business and workplace use. It is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the effective date above. Continued use of PocketWatch after changes are posted means the updated Privacy Policy applies.
16. Contact Us
For questions about this Privacy Policy, PocketWatch data practices, security incidents, customer information return or deletion, or Certificates of Destruction, contact:
Virtual Select LLC
Website: pocketwatch.ai
Email: support@virtualselect.ai
Mailing Address: 755 W Big Beaver, Suite 2020, Troy, MI 48084