Back to Home

Privacy Policy

Rescue Agency Manager

Last Updated: September 14, 2026

Introduction


Rescue Agency Manager ("we," "our," or "us") is committed to protecting the privacy and security of our users' personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our emergency response asset management platform.

By using Rescue Agency Manager, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

1. Information We Collect


Personal Information

  • Name, email address, and contact information
  • Agency affiliation and role within your organization
  • Professional certifications and qualifications
  • User account credentials and authentication data

Operational Data

  • Asset tracking and inventory information
  • Mission and incident reports
  • Training records and certification status
  • K9 and animal records (if applicable)
  • Location data when using GPS tracking features (with consent)

Technical Information

  • Device information, browser type, and operating system
  • IP address and general location data
  • Usage analytics and feature interaction data
  • Error logs and performance metrics

Cookies and Website Analytics

Our public websites (including rescueagencymanager.com, learn.rescueagencymanager.com, and docs.rescueagencymanager.com) use cookies and similar technologies, along with third-party analytics services, to understand how visitors use our sites so we can improve them.

  • Google Analytics 4

    Collects aggregated usage data such as pages viewed, referring site, device and browser type, and approximate (city-level) location. Google Analytics sets first-party cookies (e.g. _ga). We enable IP anonymization.

  • Microsoft Clarity (when enabled)

    Provides aggregated usage insights and may record anonymized interaction data, such as clicks and scrolling, on our public marketing and educational pages.

We do not use these analytics tools to track activity inside the authenticated application, and we do not send personal or operational data (such as member, agency, animal, or record details) to them. You can control or block cookies through your browser settings, and you can opt out of Google Analytics using Google's opt-out browser add-on.

2. How We Use Your Information


We use the information we collect for the following purposes:

  • Platform Operations

    Provide, maintain, and improve our emergency response asset management platform

  • Resource Coordination

    Enable asset tracking, personnel management, and mission coordination

  • Communication

    Send notifications, alerts, and important updates related to your agency's operations

  • Analytics and Improvement

    Analyze usage patterns to improve platform effectiveness and develop new features

  • Compliance and Safety

    Maintain certification records, training compliance, and operational safety standards

  • Customer Support

    Respond to your requests, questions, and provide technical support

3. Information Sharing and Disclosure


We do not sell your personal information. We may share your information only in the following circumstances:

Within Your Agency

Information is shared with authorized members of your agency according to the access permissions and roles configured by your agency administrators.

Mutual Aid Partners

When your agency has established mutual aid agreements with other emergency response organizations, we may share relevant operational data (such as asset availability, personnel qualifications, and incident coordination information) with those authorized partner agencies. Incident documents produced by the Service and shared by your agency may additionally contain information about the person an incident concerns, including medical information gathered during the response — see “Incident Documents” below.

Incident Documents

Emergency response is coordinated through standard incident command documents — for example an Incident Briefing (ICS-201), a Medical Plan (ICS-206), or a Check-In List (ICS-211). The Service produces these documents from the information your agency records.

These documents routinely contain personal information. Depending on the form and the incident, that can include the name, physical description, and last known position of the person the incident concerns; medical information gathered during the response; and the names, qualifications, and assignments of responding personnel.

Sharing these documents with the leadership of other agencies responding to the same incident is a normal and expected part of incident command, and is often required so that each responding agency can document its own response.

We produce these documents. We do not send them to other agencies. Which documents are produced, who receives them, and how they are sent are decisions made by your agency under its own policies and legal obligations. Once a document leaves the Service it is no longer in our systems — it is held and handled by the agency that received it, and deleting a record here does not retrieve or delete copies that have already been shared.

Service Providers

We share information with trusted third-party service providers who assist us in operating our platform. These providers include:

  • Stripe, Inc.

    Payment processing - receives billing information and payment card data

  • Amazon Web Services (AWS)

    Cloud hosting and data storage

  • Google LLC

    Mapping services (Google Maps) for location-based features

  • Google Analytics (Google LLC)

    Website usage analytics on our public sites; receives aggregated, non-identifying usage data only

  • Microsoft Clarity (Microsoft Corporation)

    Aggregated website usage insights on our public sites (enabled periodically)

These providers are contractually obligated to protect your information and use it only for the services they provide to us. Each provider maintains their own privacy policy governing their use of your data.

Legal Requirements

We may disclose information when required by law, court order, or government regulation, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud or respond to a government request.

Emergency Situations

In active emergency or life-threatening situations, we may share critical information with authorized emergency management agencies, first responders, and other relevant authorities to protect life and property.

4. Data Security


We implement industry-standard security measures to protect your information from unauthorized access, disclosure, alteration, and destruction. Our security practices include:

  • Encryption

    Data is encrypted in transit using TLS/SSL and at rest using industry-standard encryption

  • Access Controls

    Role-based permissions that limit each user to the actions their role allows, and automatic account lockout after repeated failed sign-in attempts

  • Secure Infrastructure

    Hosted on AWS with enterprise-grade security, monitoring, and backup systems

  • Regular Audits

    Periodic security assessments and vulnerability testing

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to using commercially reasonable means to protect your data.

5. Your Rights and Choices


Depending on your location and applicable laws, you may have the following rights regarding your personal information:

  • Access

    Request access to the personal information we hold about you

  • Correction

    Request correction of inaccurate or incomplete information

  • Deletion

    Request deletion of your personal information, subject to legal and operational requirements

  • Data Portability

    Request a copy of your data in a structured, commonly used format

  • Opt-Out

    Opt out of certain data processing activities or marketing communications

To exercise these rights, please contact us at privacy@rescueagencymanager.com. Please note that some information may need to be retained for legal compliance, emergency response operations, or legitimate business purposes.

6. Data Retention


We keep your Agency's records for as long as your Agency's account is active. We do not keep them for a fixed number of years, and we do not commit to keeping them beyond the life of the account. Our retention practices are:

  • Account Information

    Retained while your account is active, then handled under the account schedule below

  • Former Members' Personal Details

    When an agency removes you from its roster, your personal details (home address, phone numbers, date of birth, emergency contacts, photo) are removed after a window the agency sets — 90 days by default — while the agency's operational record of your service is retained

  • Incident, Mission, Training and Certification Records

    These are your Agency's records. They are retained for as long as your Agency's account is active, subject to the retention settings your Agency configures and the records its administrators choose to delete

  • Aggregated Analytics

    De-identified and aggregated data may be retained indefinitely for research and improvement

Your Agency Controls Retention

Retention requirements for public-safety, training and personnel records differ by state, by agency type and by funding source. We do not know which of them apply to your Agency, and we do not decide on your behalf. Your Agency's administrators choose the retention windows in Agency Settings (for example, how long a former member's personal details are kept, and how long chat messages are kept), may archive or permanently delete records at any time, and may export your Agency's data at any time. Selecting retention settings that satisfy the laws and rules that apply to your Agency, and keeping any copies those rules require, is your Agency's responsibility.

When an Account Ends

When your Agency's account ends — because its subscription lapses, it closes the account, or it is terminated — the account follows the schedule in the Terms of Service: thirty days of export-only access, then up to ninety days archived and inaccessible, then permanent deletion of the Agency and all of its records. Nothing is retained after that, so export anything your Agency must keep before the export period ends.

If We Discontinue the Service

If we discontinue Rescue Agency Manager, we will give at least ninety days' notice to an administrator of each Agency, during which the Service remains available for exporting your Agency's data. After that period all Agency data is permanently deleted. See the Terms of Service for the full terms.

Beta Program

If your Agency participates in the Rescue Agency Manager Beta Program, its data is retained for the duration of the Program. When the Agency's participation ends without converting to a paid subscription, the Agency's data remains available for export for thirty days, is then archived and inaccessible for up to ninety days, and is then permanently deleted, as set out in the Beta Program Agreement. During the Program, pre-release software may be reset or migrated; keep your own copies of what you enter.

7. Google User Data and Third-Party Integrations


Rescue Agency Manager offers optional integrations with third-party services that an agency administrator can choose to connect. These integrations are never required to use the platform and can be disconnected at any time.

Google Calendar

When an agency administrator connects Google Calendar, RAM requests permission to view the list of calendars on their Google account and to create, edit, and delete calendar events. We use this access for a single purpose: to synchronize events scheduled in RAM onto a Google Calendar that the administrator selects. Synchronization is strictly one-directional, from RAM to Google Calendar. We do not read, collect, or store the existing contents of your Google Calendar, and we only modify events that RAM itself created.

For this feature we store only an encrypted authorization token (so the sync can continue) and the identifier of the calendar you selected as the sync target. We do not sell or share Google user data, and we do not use it for advertising or for any purpose other than providing the calendar-sync feature you enabled.

Rescue Agency Manager's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

You can revoke RAM's access to your Google Calendar at any time by disconnecting the integration in Agency Settings → Integrations, or directly from your Google Account permissions page. Disconnecting stops all future synchronization and deletes the stored authorization token.

8. Children's Privacy


Accounts

The Service is not directed to individuals under the age of 18. We do not knowingly allow anyone under 18 to create an account, and we do not knowingly collect personal information directly from a child.

Children described in incident records

Incident records created by an agency may describe a child — for example, a missing or endangered minor, or a family member connected to an incident. That information is provided to us by the agency rather than by the child, and the agency is responsible for having a lawful basis to record it.

We treat this information as sensitive. Within the Service, access to incident records, and to any medical details they contain, is limited to agency personnel whose role permits it.

If you believe information about a child is held in the Service and you want to ask about it or request its removal, contact us at privacy@rescueagencymanager.com. Because the record belongs to the agency that created it, we will generally refer your request to that agency and support them in responding, and we will respond directly where the law requires us to.

9. Changes to This Privacy Policy


We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:

  • Sending an email to the address associated with your account
  • Posting a notice on our platform

Your continued use of our services after such notification constitutes acceptance of the updated Privacy Policy.

10. Contact Us


If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@rescueagencymanager.com

Support: support@rescueagencymanager.com

Privacy Office: Rescue Agency Manager

This Privacy Policy is effective as of September 14, 2026.

© 2026 Rescue Agency Manager. All rights reserved.