Introduction
Rescue Agency Manager ("we," "our," or "us") is committed to protecting the privacy and security of our users' personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our emergency response asset management platform.
By using Rescue Agency Manager, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
1. Information We Collect
Personal Information
- Name, email address, and contact information
- Agency affiliation and role within your organization
- Professional certifications and qualifications
- User account credentials and authentication data
Operational Data
- Asset tracking and inventory information
- Mission and incident reports
- Training records and certification status
- K9 and animal records (if applicable)
- Location data when using GPS tracking features (with consent)
Technical Information
- Device information, browser type, and operating system
- IP address and general location data
- Usage analytics and feature interaction data
- Error logs and performance metrics
Cookies and Website Analytics
Our public websites (including rescueagencymanager.com, learn.rescueagencymanager.com, and docs.rescueagencymanager.com) use cookies and similar technologies, along with third-party analytics services, to understand how visitors use our sites so we can improve them.
- Google Analytics 4
Collects aggregated usage data such as pages viewed, referring site, device and browser type, and approximate (city-level) location. Google Analytics sets first-party cookies (e.g. _ga). We enable IP anonymization.
- Microsoft Clarity (when enabled)
Provides aggregated usage insights and may record anonymized interaction data, such as clicks and scrolling, on our public marketing and educational pages.
We do not use these analytics tools to track activity inside the authenticated application, and we do not send personal or operational data (such as member, agency, animal, or record details) to them. You can control or block cookies through your browser settings, and you can opt out of Google Analytics using Google's opt-out browser add-on.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Platform Operations
Provide, maintain, and improve our emergency response asset management platform
- Resource Coordination
Enable asset tracking, personnel management, and mission coordination
- Communication
Send notifications, alerts, and important updates related to your agency's operations
- Analytics and Improvement
Analyze usage patterns to improve platform effectiveness and develop new features
- Compliance and Safety
Maintain certification records, training compliance, and operational safety standards
- Customer Support
Respond to your requests, questions, and provide technical support
3. Information Sharing and Disclosure
We do not sell your personal information. We may share your information only in the following circumstances:
Within Your Agency
Information is shared with authorized members of your agency according to the access permissions and roles configured by your agency administrators.
Mutual Aid Partners
When your agency has established mutual aid agreements with other emergency response organizations, we may share relevant operational data (such as asset availability, personnel qualifications, and incident coordination information) with those authorized partner agencies. Incident documents produced by the Service and shared by your agency may additionally contain information about the person an incident concerns, including medical information gathered during the response — see “Incident Documents” below.
Incident Documents
Emergency response is coordinated through standard incident command documents — for example an Incident Briefing (ICS-201), a Medical Plan (ICS-206), or a Check-In List (ICS-211). The Service produces these documents from the information your agency records.
These documents routinely contain personal information. Depending on the form and the incident, that can include the name, physical description, and last known position of the person the incident concerns; medical information gathered during the response; and the names, qualifications, and assignments of responding personnel.
Sharing these documents with the leadership of other agencies responding to the same incident is a normal and expected part of incident command, and is often required so that each responding agency can document its own response.
We produce these documents. We do not send them to other agencies. Which documents are produced, who receives them, and how they are sent are decisions made by your agency under its own policies and legal obligations. Once a document leaves the Service it is no longer in our systems — it is held and handled by the agency that received it, and deleting a record here does not retrieve or delete copies that have already been shared.
Service Providers
We share information with trusted third-party service providers who assist us in operating our platform. These providers include:
- Stripe, Inc.
Payment processing - receives billing information and payment card data
- Amazon Web Services (AWS)
Cloud hosting and data storage
- Google LLC
Mapping services (Google Maps) for location-based features
- Google Analytics (Google LLC)
Website usage analytics on our public sites; receives aggregated, non-identifying usage data only
- Microsoft Clarity (Microsoft Corporation)
Aggregated website usage insights on our public sites (enabled periodically)
These providers are contractually obligated to protect your information and use it only for the services they provide to us. Each provider maintains their own privacy policy governing their use of your data.
Legal Requirements
We may disclose information when required by law, court order, or government regulation, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud or respond to a government request.
Emergency Situations
In active emergency or life-threatening situations, we may share critical information with authorized emergency management agencies, first responders, and other relevant authorities to protect life and property.
4. Data Security
We implement industry-standard security measures to protect your information from unauthorized access, disclosure, alteration, and destruction. Our security practices include:
- Encryption
Data is encrypted in transit using TLS/SSL and at rest using industry-standard encryption
- Access Controls
Role-based permissions that limit each user to the actions their role allows, and automatic account lockout after repeated failed sign-in attempts
- Secure Infrastructure
Hosted on AWS with enterprise-grade security, monitoring, and backup systems
- Regular Audits
Periodic security assessments and vulnerability testing
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to using commercially reasonable means to protect your data.
5. Your Rights and Choices
Depending on your location and applicable laws, you may have the following rights regarding your personal information:
- Access
Request access to the personal information we hold about you
- Correction
Request correction of inaccurate or incomplete information
- Deletion
Request deletion of your personal information, subject to legal and operational requirements
- Data Portability
Request a copy of your data in a structured, commonly used format
- Opt-Out
Opt out of certain data processing activities or marketing communications
To exercise these rights, please contact us at privacy@rescueagencymanager.com. Please note that some information may need to be retained for legal compliance, emergency response operations, or legitimate business purposes.
6. Data Retention
We keep your Agency's records for as long as your Agency's account is active. We do not keep them for a fixed number of years, and we do not commit to keeping them beyond the life of the account. Our retention practices are:
- Account Information
Retained while your account is active, then handled under the account schedule below
- Former Members' Personal Details
When an agency removes you from its roster, your personal details (home address, phone numbers, date of birth, emergency contacts, photo) are removed after a window the agency sets — 90 days by default — while the agency's operational record of your service is retained
- Incident, Mission, Training and Certification Records
These are your Agency's records. They are retained for as long as your Agency's account is active, subject to the retention settings your Agency configures and the records its administrators choose to delete
- Aggregated Analytics
De-identified and aggregated data may be retained indefinitely for research and improvement
Your Agency Controls Retention
Retention requirements for public-safety, training and personnel records differ by state, by agency type and by funding source. We do not know which of them apply to your Agency, and we do not decide on your behalf. Your Agency's administrators choose the retention windows in Agency Settings (for example, how long a former member's personal details are kept, and how long chat messages are kept), may archive or permanently delete records at any time, and may export your Agency's data at any time. Selecting retention settings that satisfy the laws and rules that apply to your Agency, and keeping any copies those rules require, is your Agency's responsibility.
When an Account Ends
When your Agency's account ends — because its subscription lapses, it closes the account, or it is terminated — the account follows the schedule in the Terms of Service: thirty days of export-only access, then up to ninety days archived and inaccessible, then permanent deletion of the Agency and all of its records. Nothing is retained after that, so export anything your Agency must keep before the export period ends.
If We Discontinue the Service
If we discontinue Rescue Agency Manager, we will give at least ninety days' notice to an administrator of each Agency, during which the Service remains available for exporting your Agency's data. After that period all Agency data is permanently deleted. See the Terms of Service for the full terms.
Beta Program
If your Agency participates in the Rescue Agency Manager Beta Program, its data is retained for the duration of the Program. When the Agency's participation ends without converting to a paid subscription, the Agency's data remains available for export for thirty days, is then archived and inaccessible for up to ninety days, and is then permanently deleted, as set out in the Beta Program Agreement. During the Program, pre-release software may be reset or migrated; keep your own copies of what you enter.
7. Google User Data and Third-Party Integrations
Rescue Agency Manager offers optional integrations with third-party services that an agency administrator can choose to connect. These integrations are never required to use the platform and can be disconnected at any time.
Google Calendar
When an agency administrator connects Google Calendar, RAM requests permission to view the list of calendars on their Google account and to create, edit, and delete calendar events. We use this access for a single purpose: to synchronize events scheduled in RAM onto a Google Calendar that the administrator selects. Synchronization is strictly one-directional, from RAM to Google Calendar. We do not read, collect, or store the existing contents of your Google Calendar, and we only modify events that RAM itself created.
For this feature we store only an encrypted authorization token (so the sync can continue) and the identifier of the calendar you selected as the sync target. We do not sell or share Google user data, and we do not use it for advertising or for any purpose other than providing the calendar-sync feature you enabled.
Rescue Agency Manager's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can revoke RAM's access to your Google Calendar at any time by disconnecting the integration in Agency Settings → Integrations, or directly from your Google Account permissions page. Disconnecting stops all future synchronization and deletes the stored authorization token.
8. Children's Privacy
Accounts
The Service is not directed to individuals under the age of 18. We do not knowingly allow anyone under 18 to create an account, and we do not knowingly collect personal information directly from a child.
Children described in incident records
Incident records created by an agency may describe a child — for example, a missing or endangered minor, or a family member connected to an incident. That information is provided to us by the agency rather than by the child, and the agency is responsible for having a lawful basis to record it.
We treat this information as sensitive. Within the Service, access to incident records, and to any medical details they contain, is limited to agency personnel whose role permits it.
If you believe information about a child is held in the Service and you want to ask about it or request its removal, contact us at privacy@rescueagencymanager.com. Because the record belongs to the agency that created it, we will generally refer your request to that agency and support them in responding, and we will respond directly where the law requires us to.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:
- Sending an email to the address associated with your account
- Posting a notice on our platform
Your continued use of our services after such notification constitutes acceptance of the updated Privacy Policy.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: privacy@rescueagencymanager.com
Support: support@rescueagencymanager.com
Privacy Office: Rescue Agency Manager
This Privacy Policy is effective as of September 14, 2026.
© 2026 Rescue Agency Manager. All rights reserved.