Privacy Policy
1. Scope and optional accounts
This policy applies to FireRadar.ca, its public map, highway pages, address and place search, “Fires near me,” media and embed products, feedback, accounts, Saved features, monitored locations, Wildfire Watch, Highway Watch, exact-fire Watch, alerts, FireRadar Plus billing, and related services.
You can use the current FireRadar map and public media products without an account. FireRadar does not require signup to view current wildfire, smoke, AQHI, perimeter, hotspot, evacuation, search, sharing, Presenter View, embed, or newsroom-graphic information.
Third-party wildfire agencies, map providers, hosting providers, identity providers, billing providers, messaging providers, embedding websites, and linked websites have their own privacy practices.
2. Information we may collect
Public search and map information: addresses, place names, map coordinates, shared-map parameters, and related requests needed to resolve a location or return nearby wildfire context.
Browser location: when you deliberately choose a location feature and grant browser permission, your device provides coordinates needed to centre the map and calculate nearby results.
Account identity: the Supabase Auth user identifier, email address, available display-name or avatar metadata supplied by Google or email sign-in, sign-in provider, account creation time, and session information managed by Supabase Auth.
Saved workspace: fires, provinces, AQHI stations, searched locations, map coordinates, custom labels, groups, ordering, archive state, default-landing selection, and synchronization metadata for items you save to an account.
Monitored Saved items and exact-fire Watch: coordinates, label, radius, selected AQHI station or nearest-station configuration, AQHI threshold, modeled-smoke threshold, selected wildfire conditions, recovery-alert setting, pause state, processing checkpoints, and, when you choose Watch this wildfire, the official fire source and stable incident identifier already associated with the Saved wildfire. Monitored locations may correspond to a home, workplace, cabin, family location, or another place important to you and are treated as private account data.
Wildfire Watch: FireRadar stores the resolved location label, province or territory, monitoring point, Watch state, and retained Watch activity needed to evaluate meaningful changes and prevent duplicate alerts. An exact home address is not required. If you choose a street address, FireRadar stores its resolved address label and monitoring point as the Watch location; the raw search query itself is not saved as the Watch record.
Highway Watch: FireRadar stores the highway or corridor you select; selected closure, reopening, restriction, severe-weather, wildfire-distance and SMS settings; pause state; the last explicit official road state; environmental assessment and processing checkpoints; source and retrieval timestamps; and retained Watch activity needed to detect meaningful changes and prevent duplicate alerts.
Personalized My FireRadar dashboard: FireRadar Plus may store which supported briefing modules you choose to show. The preference identifies dashboard module types, not the contents of private messages or unrelated browsing activity.
Notifications: email-delivery preference, optional FireRadar Plus browser push endpoint and encryption keys, generated alert content, delivery status, retry count, and limited diagnostic information needed to prevent duplicates, remove expired push endpoints, and investigate failures. FireRadar does not offer user-selected quiet hours or delivery windows; enabled alerts are queued when the selected condition is detected.
FireRadar Plus SMS: if you deliberately enroll in FireRadar Plus SMS alerts, FireRadar stores one verified mobile number in international E.164 format, the last four digits used for masked account display, verification and consent timestamps, an SMS consent-version identifier, enabled or opt-out state, and delivery records such as provider message identifier, segment count, retry status, and carrier delivery status. Eligible texts can be generated by your standard monitors, meaningful Wildfire Watch events, or enabled Highway Watch events. Verification-abuse controls store a keyed fingerprint of the number rather than an additional raw copy. FireRadar does not place your mobile number into alert payloads or analytics events.
Billing: Stripe customer, subscription and price identifiers; billing interval; subscription state; billing-period dates; cancellation state; and provider event identifiers. FireRadar does not store full payment-card numbers.
Messages you send: your email address, name, message, attachments, and any other information you voluntarily include in feedback, privacy, media, or support correspondence.
Technical information: IP address, browser and device type, request timing, error information, and basic performance or security logs generated by hosting and infrastructure providers as part of normal service operation.
3. How we use information
FireRadar uses information to provide searches and location-based map results; authenticate accounts; synchronize Saved items; enforce plan limits; apply a selected default map landing; operate Wildfire Watch, Highway Watch and exact-fire Watch; create official-fire, perimeter-revision, fire-status, road-status, modeled-smoke, and AQHI alerts; personalize the My FireRadar dashboard; deliver optional browser notifications and, for enrolled FireRadar Plus subscribers, SMS alerts for eligible standard-monitor, Wildfire Watch and Highway Watch events; process FireRadar Plus billing; resume an unfinished Saved, Watch, or monitoring action after authentication or a deliberate upgrade; operate and secure the service; diagnose failures and performance problems; improve usability and data quality; respond to messages; prevent abuse; and meet legal or accounting obligations.
Monitored coordinates, Wildfire Watch locations and Highway Watch selections are used only to provide the monitoring and alert features you configure. FireRadar does not sell user data, publish monitored coordinates or mobile numbers, or intentionally use precise location to build advertising profiles.
4. Location permission and choices
FireRadar requests browser location only after you choose a location feature. Your browser controls the permission and may allow you to deny, revoke, or limit it. Address and place search remain available without browser-location permission.
FireRadar does not intentionally save ordinary public address searches or “Fires near me” coordinates to its application database. A location is stored with an account only when you explicitly save or monitor it. Wildfire Watch does not require a street address, but when you deliberately choose one for a Watch, its resolved label and monitoring point are stored with that Watch.
Location and search requests may still appear temporarily in operational logs or service-provider systems as part of normal request processing, security, abuse prevention, and troubleshooting.
5. Analytics, performance diagnostics, local storage, and advertising
FireRadar uses Vercel Web Analytics for aggregate page and visitor reporting. Before an automatic page-view event is sent, FireRadar removes URL query strings and fragments so shared-map parameters and other URL state are not included in the page-view URL.
FireRadar deliberately limits custom Vercel Analytics to explicit product actions needed to understand account, Watch, subscription, and media workflows. Watch analytics use one compact event family with two bounded properties describing the action context; passive Watch CTA exposure is sampled rather than emitted for every eligible fire card.
FireRadar does not send exact fire identifiers, community names, street addresses, precise map coordinates, full URLs, account identifiers, email addresses, mobile numbers, Stripe customer identifiers, or similar sensitive values in Watch analytics. Custom emitters respect browser Do Not Track and Global Privacy Control signals.
Outside the sampled Watch exposure needed to estimate Watch uptake, custom events are not used to duplicate broad traffic or ordinary map interaction. FireRadar does not use custom analytics for map movement, slider movement, passive media viewing, or autoplay state. Account and Watch custom event properties are intentionally bounded rather than carrying user-entered content.
Growth continuity: after you explicitly configure a paid FireRadar action, FireRadar may store a random intent identifier, coarse product/source category, an allow-listed FireRadar recovery path, and milestone timestamps such as account continuation, checkout start, Plus activation, Watch activation, first assessment, SMS verification, or first delivered alert. This private ledger does not store the configured address or location label, coordinates, search text, wildfire IDs, email address, phone number, or arbitrary URLs.
FireRadar may use Vercel Speed Insights for aggregate application-performance diagnostics. Speed Insights is used to identify performance regressions rather than to operate a broad account, navigation, or marketing event funnel.
Some browser storage is necessary for product behavior. FireRadar may temporarily preserve a general account-action trigger and item type so a save, monitoring setup, history action, or FireRadar Plus continuation can resume after authentication or checkout. Pending actions expire automatically.
When you choose Watch this wildfire while signed out, FireRadar may temporarily preserve the official wildfire Saved-item payload, a same-site return path, an idempotency key, and an expiry time in browser local storage so the selected Watch can be completed after authentication without making you find and configure the incident again. The pending Watch expires automatically and is not attached to analytics.
Watch analytics may store a coarse browser-local sampling choice and session-level deduplication markers. These markers contain no fire identifier, community name, coordinates, account ID, email address, or mobile number and exist to keep passive measurement bounded.
When you reach a FireRadar Plus limit or locked capability and choose to upgrade, browser local storage may temporarily preserve the unfinished action so FireRadar can resume it after Plus is activated. That continuation can include a local Saved-item target key, monitoring draft, configured Wildfire Watch location and sensitivity, or configured Highway Watch route and selected rules. It expires automatically and is not attached to analytics.
Browser local storage may also preserve device-local Saved items, non-sensitive display preferences, dismissed-help state, default-landing loop protection, and the latest account Saved synchronization status. A browser push subscription is managed by the browser and its push service after a FireRadar Plus subscriber explicitly grants notification permission. Clearing browser site data or revoking permission may remove or disable that browser subscription.
Hosting and infrastructure providers may retain aggregate, historical, or operational records according to their own retention systems.
FireRadar is ad-free for both Free and FireRadar Plus users and does not operate behavioural advertising on the public map.
6. Service providers and data location
FireRadar relies on service providers including Supabase for authentication and database services, Vercel for application hosting, scheduled execution, Web Analytics, and aggregate performance diagnostics, Stripe for FireRadar Plus billing, Resend for account alert email delivery, browser push services for optional FireRadar Plus notifications, Twilio for optional FireRadar Plus mobile-number verification and SMS delivery, and providers for map tiles, geocoding, security, and infrastructure.
When you enroll in SMS, FireRadar sends the mobile number and verification or message-delivery information needed to provide that service to Twilio. Twilio and mobile carriers may process message metadata and delivery information according to their own terms and legal obligations.
These providers process information on FireRadar's behalf or under their own terms. Information may be processed or stored outside your province or outside Canada, where it may be subject to the laws and lawful-access rules of that jurisdiction.
7. When information may be disclosed
Information may be disclosed to service providers that help operate FireRadar; when reasonably necessary to investigate abuse, security incidents, billing problems, or technical failures; to comply with law, court orders, or lawful requests; to protect users, the public, FireRadar, or its rights; or as part of a business reorganization with appropriate safeguards.
FireRadar does not sell personal information for money.
8. Retention and deletion
FireRadar retains information only as long as reasonably necessary to provide the selected features, resolve correspondence, maintain security and billing records, enforce terms, and meet legal or accounting requirements.
Alert history, Wildfire Watch and Highway Watch state and activity, Saved archive state, monitoring configuration, dashboard preferences, browser push subscriptions, optional SMS destination and consent state, SMS delivery records, default-landing preference, and billing idempotency records are retained while an account is active or as reasonably necessary to operate and audit the selected feature. Expired or rejected push endpoints may be removed automatically. Removing a FireRadar SMS number removes the active destination from the account; provider or operational records may remain for a limited time where needed for opt-out enforcement, delivery diagnostics, abuse prevention, accounting, backups, or legal obligations.
You can delete your FireRadar account from Account & security. FireRadar first attempts to cancel an attached FireRadar Plus subscription, then deletes the Supabase Auth user and FireRadar-owned account, Saved, monitoring, Wildfire Watch, Highway Watch, notification, SMS, preference, default-landing, and alert records through database cascades. If cancellation or deletion fails, FireRadar reports the failure rather than claiming deletion succeeded. Stripe and messaging providers may retain invoices, message metadata, opt-out records, or other records required for billing, fraud prevention, compliance, security, or legal obligations.
9. Safeguards
FireRadar uses administrative, technical, and organizational measures appropriate to the information, including authenticated access, Row Level Security, narrowly scoped database functions, server-only service credentials, transport encryption where supported, push-payload encryption, billing-signature verification, messaging-webhook signature verification, rate limiting, idempotency controls, masked mobile-number display, and limited collection.
No internet or carrier-delivered messaging service can guarantee absolute security or delivery. Do not send highly sensitive personal, medical, financial, or emergency information through ordinary email, SMS replies, or feedback channels.
10. Access, correction, notification choices, and deletion requests
You may review account information and notification preferences from the account page. Email alert delivery can be disabled without deleting monitoring configuration. FireRadar Plus browser and supported mobile notifications can also be disabled separately, and notification permission can be revoked in browser or operating-system settings.
If you enroll in FireRadar Plus SMS, you may disable SMS in FireRadar, remove the verified number, or use supported carrier opt-out commands such as STOP. An SMS opt-out does not disable your FireRadar email alerts. FireRadar does not automatically reverse an SMS opt-out because a subscription renews or an account remains active.
You may ask whether FireRadar holds personal information about you and request access, correction, or deletion where applicable.
Privacy requests may be sent to privacy@fireradar.ca. FireRadar may need to verify identity and may retain information where permitted or required.
11. Children, changes, and contact
FireRadar is a general public information service and is not directed specifically to children. FireRadar does not knowingly seek personal information from children. A parent or guardian who believes a child submitted personal information may contact FireRadar.
This policy may be updated as FireRadar changes. The “Last updated” date will be revised when material changes are published.
Questions or complaints may be sent to privacy@fireradar.ca.