Firehouse 360

Privacy Policy

Last updated August 3, 2026 · Version 2026-08-04 · version history

This Privacy Policy explains how Firehouse 360 ("Firehouse 360," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with our cloud-based software for fire departments and emergency-service organizations (the "Service"). Firehouse 360 is a business-to-business tool used by fire departments and similar organizations ("Departments"). For most member information, a Department is the party that decides what to collect and why, and we process that information on the Department's behalf.

Voluntary use. Use of Firehouse 360 is voluntary. You and your Department decide what information to enter, and you do so at your own discretion. Information that you or your Department submit is stored and retained on our systems and on our service providers' infrastructure (including cloud hosting and backups) so that we can provide the Service, and it may remain on those servers and in backups as described in Section 4 (Retention). You are responsible for having the right to provide the information you enter and for using the Service in accordance with your organization's policies and applicable law. By using the Service, you acknowledge and accept how information is collected, stored, shared, and retained as described in this Policy.

1. Information we collect

Depending on how your Department uses the Service, we collect:

2. How we use information

We use personal information to provide, maintain, secure, and improve the Service; to authenticate users and prevent fraud and abuse; to process payments and donations; to send transactional messages (such as receipts, confirmations, and account and call notifications) and, where permitted, other communications you have not opted out of; to provide support; and to meet our legal obligations. We do not sell your personal information for money. We may, however, share it with third parties in order to operate the Service, as described in Section 3.

3. How we share information

We share information with third parties strictly to run, secure, and improve the Service and our business — for example, to provide the features you use, process payments and donations, deliver email and text messages, and host and protect our systems. We do not share your information just to share it, and we do not sell it. The providers we currently use are named individually on our Subprocessors page, which we keep current. We share only what is reasonably necessary for the purpose, and we require these recipients to act as our service providers under contracts that limit their use of your information to providing services to us. We share with these categories of third parties:

Necessary sharing; no sale. Much of the sharing described above — such as hosting, payment processing, email delivery, and security — is necessary to provide the Service, and it cannot be turned off while you continue to use the Service. We do not sell your personal information, and we do not share it for anyone else's independent marketing or for cross-context behavioral advertising. We do not knowingly sell or share the personal information of anyone we know to be under 16. Depending on where you live, you may have rights regarding your personal information (including, in some states, a right to opt out of certain sharing); to exercise a right that applies to you, contact us and we will respond as required by law.

We may also use de-identified or aggregated information (which does not identify any individual) to operate, secure, and improve the Service. We do not sell de-identified data for commercial use.

4. Data retention

We retain each category of personal information for as long as reasonably necessary for the purposes described in this Policy, and no longer than is reasonably necessary for those purposes. Retention periods vary by category. Where we cannot state an exact period in advance, we determine how long to keep information using these criteria: (a) the life of your Department's relationship with us — we keep account, member, and operational information for as long as the account is active; (b) legal, tax, audit, and regulatory record-keeping obligations; (c) the need to establish, exercise, or defend legal claims and enforce our agreements; and (d) the nature and sensitivity of the information.

Membership, training, and certification records. Certain records — including firefighter and member personnel records and training, qualification, and certification records — are subject to legal, regulatory, insurance, and industry record-keeping obligations (which may include applicable state fire-service, OSHA, and NFPA/ISO standards). We retain these records for the duration required by those obligations, which may extend for a member's period of service and for an extended period afterward, and in some cases for the life of the record where an ongoing legal or record-keeping requirement applies. We retain these records under this criteria-based standard rather than for an indefinite or unlimited period, and we delete, de-identify, or securely archive them once the applicable obligation no longer applies. When information is no longer needed for any permitted purpose, we delete, de-identify, or aggregate it, or securely archive it where immediate deletion is not feasible until deletion is possible.

Apparatus records are cleared when an apparatus is retired. Inspection, check, and maintenance records tied to a specific apparatus are removed once your Department marks that apparatus retired in the Service. Standards such as NFPA 1911 §4.7.3 require your Department to keep those records for the life of the vehicle and to hand them over when the vehicle is sold or transferred — a period that can run for decades and that we do not commit to. You must export or print and keep your own copies. See your record-keeping obligations in our Terms.

5. Children's and minors' data

Firehouse 360 is a general-audience, business-to-business tool and is not directed to children or intended to be used directly by children. We do not knowingly collect personal information directly from children under 13 online.

Some Departments operate junior-firefighter or cadet programs that may include minors. In those cases, information about a minor is entered into the Service by the Department (for example, by an officer or program administrator); the minor does not create an account with us or submit information to us directly. Each Department is solely responsible for obtaining any parental or legal-guardian consent required by the Children's Online Privacy Protection Act (COPPA) and applicable state laws before entering a minor's information, and for providing any required notice. We do not sell or share minors' personal information and do not use it for targeted advertising or profiling, and we treat information we know pertains to individuals under 16 as sensitive. A parent or guardian who wishes to review, correct, or delete a minor's information should contact the Department that manages those records, or contact us and we will work with the responsible Department.

6. How we protect information — and what we cannot promise

We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption of sensitive data at rest, role-based access controls, audit logging, and isolation of each Department's data, and we review and update these measures over time. See our Security page for more.

However, no method of transmission over the Internet and no method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot and do not guarantee its absolute security, and we do not promise that information will never be accessed, disclosed, altered, lost, or destroyed by a breach of our safeguards. Even organizations with vast security resources experience breaches; security is a shared responsibility, and you provide information at your own risk and are responsible for keeping account credentials confidential. If we become aware of a security incident affecting your personal information, we will notify affected parties and any applicable regulator as required by law.

7. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to opt out of any sale/sharing or targeted advertising, and to limit the use of sensitive information, along with a right to appeal a decision on your request. Because much of the information in the Service is controlled by your Department, we may direct certain requests to the Department or ask you to make them through it. To exercise a right or ask a question, contact us. We will not discriminate against you for exercising your rights. You can also unsubscribe from marketing email at any time using the link in any such message.

8. Cookies and tracking

We use a small number of essential cookies and privacy-respecting measurement. See our Cookie Notice for details and how to manage them.

9. AI-assisted features

Some features use artificial-intelligence services to help draft text, interpret files you upload, or summarise information. Where a feature does this, we send the AI provider only the content needed for that task.

What we send. Support-reply drafting sends the contact name, department name, and the message text of the inquiry being answered. AI-assisted data import sends the contents of the file you choose to import. We do not send AI providers your members' Social Security numbers, background-check results, or medical or incident data unless that data is contained in a file you yourself submit to an AI-assisted feature.

Our contractual terms with AI providers. We engage AI providers as service providers under written terms that prohibit using your information to train their models and that limit their use of it to performing the task for us. We list them at Subprocessors.

Human review. AI output is a draft. A person reviews and is responsible for anything sent or saved. We do not use AI to make decisions that produce legal or similarly significant effects about an individual.

Your choice. AI-assisted features are optional and are controlled by your Department's administrator.

Our own development tools. We also use AI-assisted tools internally for software development, code review, security review, and debugging. Where those tools are used against production data or a copy of it, the provider is listed at Subprocessors and is bound by the same terms.

10. Meetings, recordings, and live streams

We hold demonstrations, onboarding sessions, and support calls by video. Those sessions are hosted by Proton Meet, and the meeting audio, video, and anything shown on screen passes through that provider.

Sometimes we record a session, or broadcast it live — for example, a product demonstration published to a public channel such as Facebook or YouTube. We tell you before a session is recorded or streamed, and you may decline. If you do not wish to appear, you may keep your camera and microphone off, leave the session, or ask us not to record; we will not condition support on your agreement to be recorded.

We do not use live customer data in a recorded or streamed session. Demonstrations use sample data. Nothing in a public broadcast should contain your members' personal information.

Where a session is published to a third-party platform, that platform receives the recording and applies its own terms and privacy policy to it. Once material is published we cannot guarantee its removal from copies others have made. The providers involved are listed at Subprocessors.

11. Changes to this Policy

This Privacy Policy is a living document and is always subject to future revision and update. We reserve the right to change, add to, or remove any part of it at any time, in our sole discretion. We will post the updated Policy with a new "last updated" date and version, and for material changes we will provide reasonable notice. Your continued use of the Service after an update takes effect means you accept the updated Policy, so please review it periodically.

12. Contact us

Questions or privacy requests? Contact us, or write to us at:

Firehouse 360
PO Box 105
Prospect, PA 16052

← Back home