FireRadarCanada wildfire map
FireRadar

Privacy Policy

How FireRadar handles information when you browse, search, save places, configure monitoring, receive notifications, subscribe to Plus, or contact us, and how to exercise your privacy choices.
Last updated: September 4, 2026

1. Scope and optional accounts

This policy applies to FireRadar.ca, its public map, highway pages, address and place search, “Fires near me,” media and embed products, feedback, accounts, passive Saved bookmarks, Wildfire Watch dashboard locations, Fire and condition Alerts, Route alerts, notifications, FireRadar Plus billing, and related services.

You can use the current FireRadar map and public media products without an account. FireRadar does not require signup to view current wildfire, smoke, AQHI, perimeter, hotspot, evacuation, search, sharing, Presenter View, embed, or newsroom-graphic information.

Third-party wildfire agencies, map providers, hosting providers, identity providers, billing providers, messaging providers, embedding websites, and linked websites have their own privacy practices.

2. Information we may collect

Public search and map information: addresses, place names, map coordinates, shared-map parameters, and related requests needed to resolve a location or return nearby wildfire context.

Browser location: when you deliberately choose a location feature and grant browser permission, your device provides coordinates needed to centre the map and calculate nearby results.

Account identity: the Supabase Auth user identifier, email address, available display-name or avatar metadata supplied by Google or email sign-in, sign-in provider, account creation time, and session information managed by Supabase Auth.

Saved workspace: fires, provinces, AQHI stations, searched locations, map coordinates, custom labels, groups, ordering, archive state, default-landing selection, and synchronization metadata for items you save to an account.

Focused Alerts: FireRadar stores the focused target and compatible conditions needed for the Alert you explicitly create. Depending on the Alert type, this may include an official wildfire source and incident identifier, highway or corridor, AQHI station, selected threshold, radius, modeled-smoke or Fire Danger condition, fire-restriction condition, recovery setting, delivery choice, pause state, and processing checkpoints. An implementation-only link to a Saved target does not mean you explicitly created a passive bookmark.

Wildfire Watch: FireRadar stores the selected dashboard-location label, province or territory, map point, notification settings, assessment state, and recent activity needed to build the location situation dashboard, check for meaningful changes, and prevent duplicate notifications. An exact home address is not required. If you choose a street address, FireRadar saves the resolved label and map point but not your original search text.

Route alerts: FireRadar stores the highway or corridor you select; supported closure, reopening, restriction, severe-weather, nearby-wildfire, and delivery settings; pause state; latest official road status; source/check times; and recent activity needed to detect changes and prevent duplicates.

Personalized My FireRadar dashboard: FireRadar may store which supported situation modules you choose to show. The preference identifies dashboard module types, not private-message contents or unrelated browsing activity.

Notifications: email-delivery preference, optional FireRadar Plus browser push endpoint and encryption keys, generated alert content, delivery status, retry count, and limited diagnostic information needed to prevent duplicates, remove expired push endpoints, and investigate failures. FireRadar does not offer user-selected quiet hours or delivery windows; enabled alerts are queued when the selected condition is detected.

FireRadar Plus SMS: if you deliberately enroll in eligible Canadian SMS delivery, FireRadar stores one verified mobile number in international E.164 format, the last four digits used for masked account display, verification and consent timestamps, an SMS consent-version identifier, enabled or opt-out state, and delivery records such as provider message identifier, segment count, retry status, and carrier delivery status. Eligible texts can be generated by meaningful Wildfire Watch events or enabled focused Alerts, including Route alerts. Verification-abuse controls store a keyed fingerprint rather than an additional raw copy. FireRadar does not place your mobile number into analytics events.

Billing: Stripe customer, subscription and price identifiers; billing interval; subscription state; billing-period dates; cancellation state; and provider event identifiers. FireRadar does not store full payment-card numbers.

Messages you send: your email address, name, message, attachments, and any other information you voluntarily include in feedback, privacy, media, or support correspondence.

Technical information: IP address, browser and device type, request timing, error information, and basic performance or security logs generated by hosting and infrastructure providers as part of normal service operation.

3. How we use information

FireRadar uses information to provide searches and map results; authenticate accounts; synchronize passive Saved items; enforce independent dashboard-location and Alert limits; apply a selected default landing; operate Wildfire Watch dashboards and focused Fire, Route, smoke, AQHI, Fire Danger, and fire-restriction Alerts; deliver email and eligible Plus browser or SMS notifications; process FireRadar Plus billing; resume an unfinished Save, dashboard-location, Alert, or delivery action after authentication or verified upgrade; operate and secure the service; diagnose failures; improve usability and data quality; respond to messages; prevent abuse; and meet legal or accounting obligations.

Dashboard-location coordinates and focused Alert targets are used only to provide features you configure. FireRadar does not sell user data, publish monitored coordinates or mobile numbers, or intentionally use precise location to build advertising profiles.

4. Location permission and choices

FireRadar requests browser location only after you choose a location feature. Your browser controls the permission and may allow you to deny, revoke, or limit it. Address and place search remain available without browser-location permission.

FireRadar does not intentionally save ordinary public address searches or “Fires near me” coordinates to its application database. A geographic dashboard location is stored when you explicitly create a Wildfire Watch. Supported resources are stored when you explicitly Save them or create a focused Alert. Legacy Saved locations remain preserved without becoming monitoring. Wildfire Watch does not require a street address, but a resolved label and coordinates are stored when you deliberately choose one.

Location and search requests may still appear temporarily in operational logs or service-provider systems as part of normal request processing, security, abuse prevention, and troubleshooting.

A saved address label and coordinates can identify a home or another private place even when the original search text is not retained. Review the locations and labels you choose to save or share.

5. Analytics, performance diagnostics, local storage, and advertising

FireRadar uses Vercel Web Analytics for aggregate page and visitor reporting. Before an automatic page-view event is sent, FireRadar removes URL query strings and fragments so shared-map parameters and other URL state are not included in the page-view URL.

Custom product-interaction events are currently disabled in FireRadar's Web Analytics filter. Account, subscription, assessment and notification outcomes may still be measured from aggregate service records needed to operate those features.

Safeguards for the currently disabled custom product-decision events remain in place. The configured decision event uses two coarse, allow-listed properties. Custom emitters respect browser Do Not Track and Global Privacy Control signals. In these custom events, FireRadar does not send fire, route, Saved-item, Watch, Alert, account, billing, or contact identifiers; community or place names; addresses; coordinates; full URLs; arbitrary errors; or user-entered values.

FireRadar does not record map movement, slider movement, component mounts, focus changes, passive media viewing, autoplay state, or form input in custom product analytics. These safeguards describe custom events whose delivery is currently disabled; they do not describe the separate performance and error diagnostics below.

Resuming setup: after you configure a FireRadar action, FireRadar may store a random intent identifier, a bounded product/source category, an approved same-site return path, and milestone times needed to resume it after authentication or verified Plus activation. FireRadar's custom Web Analytics events are disabled, so these setup fields are not sent through those events.

FireRadar configures Vercel Speed Insights for application performance diagnostics separately from Web Analytics. Its SDK supports page route and URL information. FireRadar's Web Analytics query-string and fragment removal is not configured for Speed Insights. This configuration and SDK capability do not establish actual production payload contents or provider retention.

Sampled browser error reports help diagnose runtime, map and smoke-display failures. They may include the page path, error message and diagnostic details. FireRadar limits and redacts these reports before writing them to operational logs, including removing URL query strings and fragments and patterns for email addresses, credentials and labelled coordinates. These safeguards do not guarantee that every sensitive value can be recognized.

Some browser storage is necessary for product behavior. FireRadar may temporarily preserve a general account-action trigger and item type so a save, monitoring setup, history action, or FireRadar Plus continuation can resume after authentication or checkout. Pending actions expire automatically.

When you choose “Get updates about this fire” while signed out, FireRadar may temporarily preserve the official fire target, approved return path, idempotency key, selected supported condition/delivery, and expiry so the Fire alert can complete after authentication. It expires automatically and is not attached to analytics.

FireRadar may store a session marker made only from bounded event categories to avoid counting the same explicit decision twice. It contains no target or person identifier.

When you reach a Plus limit or locked capability and choose to upgrade, browser storage may temporarily preserve the unfinished action so FireRadar can resume it only after Plus is verified. This can include a dashboard-location draft, focused Alert draft, Route alert rules, or SMS setup. It expires automatically and is not attached to analytics.

Browser local storage may also preserve device-local Saved items, non-sensitive display preferences, dismissed-help state, default-landing loop protection, and the latest account Saved synchronization status. A browser push subscription is managed by the browser and its push service after a FireRadar Plus subscriber explicitly grants notification permission. Clearing browser site data or revoking permission may remove or disable that browser subscription.

Hosting and infrastructure providers may retain aggregate, historical, or operational records according to their own retention systems.

FireRadar is ad-free for both Free and FireRadar Plus users and does not operate behavioural advertising on the public map.

6. Service providers and data location

FireRadar relies on service providers including Supabase for authentication and database services, Vercel for application hosting, scheduled execution, Web Analytics, and aggregate performance diagnostics, Stripe for FireRadar Plus billing, Resend for account alert email delivery, browser push services for optional FireRadar Plus notifications, Twilio for optional FireRadar Plus mobile-number verification and SMS delivery, and providers for map tiles, geocoding, security, and infrastructure.

When you enroll in SMS, FireRadar sends the mobile number and verification or message-delivery information needed to provide that service to Twilio. Twilio and mobile carriers may process message metadata and delivery information according to their own terms and legal obligations.

These providers process information on FireRadar's behalf or under their own terms. Information may be processed or stored outside your province or outside Canada, where it may be subject to the laws and lawful-access rules of that jurisdiction.

7. When information may be disclosed

Information may be disclosed to service providers that help operate FireRadar; when reasonably necessary to investigate abuse, security incidents, billing problems, or technical failures; to comply with law, court orders, or lawful requests; to protect users, the public, FireRadar, or its rights; or as part of a business reorganization with appropriate safeguards.

FireRadar does not sell personal information for money.

8. Retention and deletion

FireRadar retains information only as long as reasonably necessary to provide the selected features, resolve correspondence, maintain security and billing records, enforce terms, and meet legal or accounting requirements.

Alert history, Wildfire Watch assessment/activity, Route alert state, Saved archive state, focused Alert configuration, dashboard preferences, browser push subscriptions, optional SMS destination/consent, delivery records, default-landing preference, and billing idempotency records are retained while an account is active or as reasonably necessary to operate and audit the feature. Losing Plus preserves records but stops paid-only evaluation or delivery while entitlement is absent. Expired or rejected endpoints may be removed automatically.

You can delete your FireRadar account from Account & security. FireRadar first attempts to cancel an attached Plus subscription, then removes the account and its associated Saved, Alert, Wildfire Watch, Route alert, notification, SMS, preference, and activity records. If cancellation or deletion fails, FireRadar reports the failure rather than claiming deletion succeeded. Providers may retain records required for billing, opt-out enforcement, fraud prevention, compliance, security, or law.

9. Safeguards

FireRadar uses administrative, technical, and organizational measures appropriate to the information, including authenticated access, Row Level Security, narrowly scoped database functions, server-only service credentials, transport encryption where supported, push-payload encryption, billing-signature verification, messaging-webhook signature verification, rate limiting, idempotency controls, masked mobile-number display, and limited collection.

No internet or carrier-delivered messaging service can guarantee absolute security or delivery. Do not send highly sensitive personal, medical, financial, or emergency information through ordinary email, SMS replies, or feedback channels.

10. Access, correction, notification choices, and deletion requests

You may review account information and notification preferences from the account page. Email alert delivery can be disabled without deleting monitoring configuration. FireRadar Plus browser and supported mobile notifications can also be disabled separately, and notification permission can be revoked in browser or operating-system settings.

The account page provides a versioned JSON export covering current identity and account data, Saved items, Wildfire Watch locations, Alerts, preferences, recent activity, delivery records and billing identifiers. The export fails rather than presenting a partial file as complete. Push endpoints, encryption keys, provider credentials, verification challenges and internal abuse controls are excluded because exposing them would weaken account or delivery security.

If you enroll in FireRadar Plus SMS, you may disable SMS in FireRadar, remove the verified number, or use supported carrier opt-out commands such as STOP. An SMS opt-out does not disable your FireRadar email alerts. FireRadar does not automatically reverse an SMS opt-out because a subscription renews or an account remains active.

You may ask whether FireRadar holds personal information about you and request access, correction, or deletion where applicable.

Privacy requests may be sent to privacy@fireradar.ca. FireRadar may need to verify identity and may retain information where permitted or required.

11. Children, changes, and contact

FireRadar is a general public information service and is not directed specifically to children. FireRadar does not knowingly seek personal information from children. A parent or guardian who believes a child submitted personal information may contact FireRadar.

This policy may be updated as FireRadar changes. The “Last updated” date will be revised when material changes are published.

Questions or complaints may be sent to privacy@fireradar.ca.