Scoring Systems

Scoring systems used by Orions Guard for evaluations of privacy and security

Here we will post the scoring systems we utilize for full transparency and to give companies a clear goal to achieve optimal success.


Privacy Policy Scoring

How we evaluate privacy policies

Each category is scored from 1 to 5, where 1 is "Poor" and 5 is "Excellent."

  1. Readability (Plain English): How easy is the policy for a non-expert to understand?
    • 1 - Opaque: Heavily laden with legal jargon, making it nearly impossible for a layperson to comprehend.
    • 3 - Complex: A mix of formal legal language and some simpler explanations, requiring effort to decipher.
    • 5 - Transparent: Written in clear, concise language with user-friendly summaries and an intuitive structure.
  2. Data Retention Policy: How specifically does the company state how long they will keep your data?
    • 1 - Vague: Provides no specific retention periods, using generic terms like "as long as necessary."
    • 3 - Inconsistent: Some data retention periods are mentioned, but policies are vague for other types of data.
    • 5 - Precise: Clearly outlines specific retention periods for all data types, with a rationale for each.
  3. Opt-Out as Defaults: Are data collection and sharing settings configured to protect privacy by default?
    • 1 - Default Opt-Out: The user must manually opt-out of extensive data collection and targeted advertising.
    • 3 - Mixed Defaults: Some features are opt-in, while others require the user to opt-out.
    • 5 - Default Opt-In: All non-essential data collection and sharing is disabled by default, requiring user consent to activate.
  4. User Control & Access: How much control do users have over their data, and how easy is it to manage?
    • 1 - None: Users have no clear way to access, correct, or manage their data.
    • 3 - Limited: The ability to manage data exists but is buried, difficult to use, or incomplete.
    • 5 - Empowering: Provides robust, easy-to-use tools (like a dedicated portal or dashboard) for users to access and manage their data.
  5. Third-Party Data Sharing: How transparent is the policy about selling or sharing data with other companies?
    • 1 - Selling Data: Explicitly states that personal data is sold to third parties without specific user consent.
    • 3 - Sharing for Business: Shares data with business partners and for targeted advertising, but with some user opt-out options.
    • 5 - No Sharing: Guarantees that data is not sold and is shared only when absolutely necessary for core services.
  6. Data Deletion & Records: Is it easy to request that your data be deleted and to receive a copy of your records?
    • 1 - Difficult: The process is complex, requests are frequently denied, and no clear portal exists.
    • 3 - Convoluted: A process exists but is slow, requires contacting customer service, or is not clearly explained.
    • 5 - Seamless: A clear, responsive, and easy-to-use portal exists for both data deletion and record requests.

Overall Tiers

Based on the total score (out of 30), a policy is assigned one of the following tiers:

  • Privacy Pitfall (6-14 points): A policy with major weaknesses that puts user data at significant risk.
  • Privacy Purgatory (15-22 points): An average policy with a mix of good and bad practices, leaving room for improvement.
  • Privacy Protector (23-27 points): A strong policy that demonstrates a genuine commitment to user privacy, with only minor issues.
  • Privacy Paragon (28-30 points): A model policy that sets the gold standard for user data protection and transparency.