ATTORNEY-REVIEW DRAFTThis text is not approved for commercial launch. Counsel must confirm the legal entity, address, jurisdiction, risk allocation, retention terms, and privacy obligations.

DATA PRACTICES

Privacy Policy

This Policy explains how SafeGuard handles personal information when providing Fire Command and operating its business.

Effective date
September 22, 2026
Provider
SafeGuard Command
Contact
admin@safeguardcommand.com

1. Scope and roles

This Privacy Policy applies to SafeGuard Fire Command websites, hosted services, mobile applications, support, and business communications. For department operational records, the customer department generally decides why and how the data is used and acts as the responsible organization or controller; SafeGuard Command processes that data to provide the service. For account administration, billing, security, and our own business operations, we determine the purposes described below.

This Policy does not replace a customer department’s own notices, public-records duties, records schedules, collective-bargaining obligations, or other legal responsibilities.

2. Information we collect

  • Account and contact data: name, email, phone, role, department, station, membership, authentication and MFA status, and communications.
  • Department operational data: personnel and emergency-contact records, qualifications, availability, training, certifications, apparatus, equipment, inspections, deficiencies, incidents, exposure records, policies, preplans, building diagrams, photos, water supplies, addresses, response districts, tasks, and audit history.
  • Location and sensor data: precise GPS coordinates and accuracy when a user chooses field mapping, hydrant, preplan, address, or tactical-location functions; device camera or photo metadata when submitted.
  • Security and device data: IP address, browser/user-agent, device name, session and login events, timestamps, audit events, error and diagnostic data, push token, and synchronization status.
  • Billing data: subscription, plan, payment state, customer and subscription identifiers. Stripe processes payment-card and bank details; we do not intentionally store full card or bank-account numbers.
  • Support and sales data: messages, requested demonstrations, contract and organization details, and troubleshooting material voluntarily supplied.

3. Sources

We receive information from users and customer administrators; authorized devices; department records and imports; public or government sources such as Arkansas GIS address services; service providers such as Stripe; and automatically from use of the service. We do not treat map or government data as guaranteed accurate.

4. How we use information

  • Provide accounts, tenant separation, preplans, field workflows, offline synchronization, reports, billing, support, and requested features.
  • Authenticate users, enforce permissions and plan limits, detect abuse, scan uploads, investigate incidents, keep audit records, back up data, and protect people and systems.
  • Send activation, invitation, password reset, security, operational, support, and billing communications.
  • Comply with law, valid legal process, contractual duties, records holds, and lawful customer instructions.
  • Measure reliability and improve the service using aggregated or de-identified information where reasonably possible.

We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use Customer Data to train a public generative-AI model.

5. When information is disclosed

We disclose information to authorized users within the applicable customer department; to vetted service providers that host, store, scan, email, monitor, support, map, synchronize, or process payments; at the customer’s direction; during a merger, financing, reorganization, or sale subject to appropriate protection; and when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or defend claims.

Current categories of providers may include infrastructure and S3-compatible storage, transactional email, malware scanning, monitoring, Stripe, Expo/mobile distribution, and street or satellite map services. Public map services receive ordinary web request information and the requested tile area; do not place confidential information in a map-provider URL. We require providers to use information for contracted purposes and apply appropriate safeguards.

6. Precise location, camera, and mobile permissions

Location and camera access are optional device permissions used only when a user invokes a related field feature. A department may store submitted coordinates and photos as operational records visible to users with permission. Revoking a device permission stops new collection by that device but does not delete records already submitted. Background location is not collected unless a separately disclosed feature and device permission expressly enable it.

7. Cookies and authentication storage

The web application uses strictly necessary session and security mechanisms, including an HttpOnly refresh cookie and short-lived access information kept for the browser tab. We may use similar local storage for interface state. We do not use third-party advertising cookies. Customer administrators should require managed, encrypted devices and sign out of shared computers.

8. Retention and deletion

We retain Customer Data during the subscription and for the post-termination export period stated in the agreement, then delete or de-identify it according to our retention schedule unless the customer instructs otherwise or law, a legal hold, security investigation, backup cycle, or signed order requires longer. Security, billing, contract, and audit records may be retained as reasonably necessary to prove transactions, enforce agreements, detect abuse, and meet legal obligations. Encrypted backups expire on a controlled rotation and are not used for ordinary access.

Customer administrators control most operational-record correction, export, archival, and retention decisions. Deletion from the active service may not immediately remove an item from immutable logs or encrypted backups.

9. Security

We use measures designed for the sensitivity of the service, including encryption in transit, tenant-scoped authorization, MFA support, private object storage, upload scanning, audit trails, rate controls, least-privilege deployment, vulnerability checks, encrypted off-server backups, and restore testing. No system is completely secure. Customers must protect credentials and devices and promptly report suspected compromise to admin@safeguardcommand.com.

10. Security incidents

We maintain an incident-response process. If we confirm unauthorized access to Customer Data, we will notify affected customers without unreasonable delay as required by contract and applicable law, provide available information needed for their response, and take reasonable containment and remediation steps. Customer remains responsible for notices it must provide as the record owner, except where law assigns that duty to us.

11. Choices and rights

Users may update many account and operational fields in the service. Requests to access, correct, export, restrict, or delete department records should normally go first to the customer department, which controls those records. Requests about SafeGuard-controlled account or business data may be sent to admin@safeguardcommand.com. We will verify identity and authority, respond as applicable law requires, and may retain information that law or legitimate security needs require.

Email recipients may opt out of promotional mail, but not essential service, security, billing, or operational notices while an account remains active.

12. Children and household use

The service is offered to organizations and authorized personnel, not children or consumers for personal or household use. We do not knowingly collect personal information directly from children under 13. A customer that records junior-member information is responsible for legal authority, notices, permissions, minimization, and access controls.

13. U.S. processing and public records

The service is currently intended for United States customers and may process information in the United States. Fire departments and public entities may be subject to freedom-of-information, open-records, archival, discovery, or evidence requirements. Customer—not SafeGuard—decides how those requirements apply to its records and should configure retention and disclosures with counsel.

14. Changes and contact

We may update this Policy to reflect service, provider, or legal changes. We will post the effective date and provide additional notice of material changes where appropriate. Questions, rights requests, and security reports may be sent to admin@safeguardcommand.com or mailed to SafeGuard Command, Business mailing address pending counsel review.