1. Introduction
EMSCommand is an EMS agency management platform operated by CrisisZone LLC ("we," "us," or "our"). EMSCommand helps emergency medical services agencies manage scheduling, vehicle tracking, inventory, incident reports, continuing medical education (CME) logs, narcotics accountability, and compliance checklists.
This Privacy Policy explains how we collect, use, store, and protect your information when you use the EMSCommand platform, visit our website, or interact with our services. We are committed to transparency and to safeguarding the data entrusted to us by EMS professionals and their agencies.
EMSCommand does not currently collect, store, or process Protected Health Information (PHI) as defined by HIPAA. The platform is designed for agency operations management and does not handle patient care records or individually identifiable health information.
2. Information We Collect
We collect the following categories of information in order to provide and improve our services:
Account Information
- Full name, email address, and phone number
- Role within your agency (e.g., Paramedic, Lieutenant, Chief)
- EMS certification level and related credentials
- Authentication credentials (email/password, managed by Supabase)
- Multi-factor authentication (MFA/TOTP) enrollment status
Agency and Operational Data
- Agency name, structure, and configuration
- Scheduling and shift assignment data
- Vehicle and fleet tracking information
- Inventory and supply records
- Incident reports and run documentation
- Continuing medical education (CME) logs and training records
- Narcotics accountability and controlled substance logs
- Compliance checklists and audit records
Usage and Device Data
- Browser type, operating system, and device information
- Error and crash reports collected via Sentry, which include your anonymized user UUID (no personally identifiable information such as name or email is sent to Sentry)
- General usage patterns to help us understand how the platform is used and where improvements are needed
Information You Provide Voluntarily
- Contact form submissions (name, email, organization, message content)
- Support requests and correspondence with our team
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service — To operate, maintain, and deliver the EMSCommand platform, including authentication, scheduling, compliance tracking, and all core agency management features.
- Improving the Platform — To analyze aggregated usage data and error reports in order to identify bugs, improve performance, and develop new features that serve EMS agencies more effectively.
- Communication — To respond to your inquiries, send service-related announcements (such as maintenance windows or security updates), and provide customer support.
- Security and Fraud Prevention — To protect the integrity of the platform, detect unauthorized access or abuse, and enforce our Terms of Service.
- Legal Compliance — To comply with applicable laws, regulations, or legal processes when required.
We do not sell, rent, or trade your personal information to third parties for marketing purposes. We do not use your data for advertising or behavioral profiling.
4. Data Storage and Security
We take the security of your data seriously and employ industry-standard measures to protect it:
- Infrastructure — EMSCommand is built on Supabase, which provides managed PostgreSQL databases hosted on secure cloud infrastructure. All data is stored in the United States.
- Encryption in Transit — All data transmitted between your browser and our servers is encrypted using TLS (HTTPS). API calls and authentication tokens are always transmitted over encrypted connections.
- Encryption at Rest — Data stored in our database is encrypted at rest using AES-256 encryption provided by the underlying infrastructure.
- Row-Level Security (RLS) — We enforce row-level security policies at the database level, ensuring that users can only access data associated with their own agency and their assigned role. This prevents cross-agency data leakage by design.
- Multi-Factor Authentication — EMSCommand supports MFA via time-based one-time passwords (TOTP). We encourage all users, especially those with administrative roles, to enable MFA for their accounts.
- Access Controls — Role-based access controls limit what data and actions are available to each user based on their assigned role within their agency.
While no system can guarantee absolute security, we are committed to promptly addressing any vulnerabilities and continuously improving our security posture.
5. Third-Party Services
EMSCommand integrates with a limited number of third-party services to deliver and maintain the platform. We carefully select our providers and only share the minimum data necessary for each service to function:
- Supabase — Provides our authentication system (email/password login, MFA/TOTP) and managed PostgreSQL database. Supabase processes account credentials and stores all application data on our behalf. For more information, see the Supabase Privacy Policy.
- Sentry — Provides error monitoring and crash reporting. When an error occurs in the application, Sentry receives diagnostic information including the error details, browser and OS type, and an anonymized user UUID. No personally identifiable information (such as name, email, or phone number) is sent to Sentry. For more information, see the Sentry Privacy Policy.
- Google Fonts — Our website loads typefaces from Google Fonts. When you visit our pages, your browser makes requests to Google's servers to retrieve font files. This may expose your IP address and browser information to Google. For more information, see the Google Privacy Policy.
We do not integrate with any advertising networks, analytics platforms that track individual users across websites, or data brokers.
6. Cookies and Local Storage
EMSCommand uses minimal browser storage, limited to what is necessary for the platform to function:
- Authentication Tokens — Supabase stores authentication session tokens in your browser's local storage to keep you signed in between visits. These tokens are required for the platform to function and are cleared when you sign out.
- Theme Preference — We store your selected theme (light or dark mode) in local storage so that your display preference persists across sessions.
- Service Worker and Offline Caching — EMSCommand uses a service worker to cache application assets for offline access and faster load times. The service worker caches static resources (HTML, CSS, JavaScript, icons) and does not store or cache user data or agency information.
We do not use tracking cookies, third-party cookies, or any form of cross-site tracking technology. We do not use cookies for advertising, analytics, or behavioral profiling.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide the services you have requested. Specifically:
- Account Data — Retained for the duration of your active account. If you or your agency administrator requests account deletion, we will remove your personal information within 30 days, except where retention is required by law.
- Agency Operational Data — Retained for as long as your agency maintains an active subscription. Agencies may request export or deletion of their data at any time.
- Error Logs (Sentry) — Error reports are retained according to Sentry's standard retention policies (typically 90 days) and contain no personally identifiable information.
- Contact Form Submissions — Retained for as long as necessary to respond to and resolve your inquiry, and no longer than 24 months.
When data is deleted, we take commercially reasonable steps to ensure it is removed from our active systems. Some data may persist in encrypted backups for a limited period before being automatically purged through our backup rotation cycle.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access — You may request a copy of the personal information we hold about you.
- Correction — You may request that we correct any inaccurate or incomplete personal information.
- Deletion — You may request that we delete your personal information, subject to any legal retention requirements.
- Data Portability — You may request a machine-readable export of your personal data so that you can transfer it to another service.
- Opt-Out of Communications — You may opt out of non-essential communications from us at any time. Service-critical notifications (such as security alerts) may still be sent as necessary.
- Restrict Processing — You may request that we limit the processing of your personal information under certain circumstances.
To exercise any of these rights, please contact us at hello@emscommand.com. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request to protect against unauthorized access.
If you are a member of an agency using EMSCommand, some data management actions (such as account deletion or data export) may need to be initiated by your agency administrator.
9. Children's Privacy
EMSCommand is a professional platform designed for use by EMS agencies and their credentialed personnel. Our services are not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13.
If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete that information as promptly as possible. If you believe a child under 13 has provided us with personal information, please contact us at hello@emscommand.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Provide notice through the EMSCommand platform or via email for significant changes
- Where required by law, obtain your consent before applying material changes
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
CrisisZone LLC
Email: hello@emscommand.com
Web: emscommand.com/contact
We take every inquiry seriously and aim to respond within 2 business days.