Arborlook Insights Risk & Response

Privacy Policy

How we collect, use, and protect information about your department and users.

Effective date: February 21, 2026  ·  Last updated: October 1, 2026  ·  Arborlook Insights, LLC

Short version: We collect what we need to run the Service. We don't sell your data. Incident data, whether it comes from NERIS or from history your department uploads, is used only to generate analytics for your department. Sharing identified data with a regional partner such as a state fire marshal is opt-in too, unless that partner sponsors your access, in which case it is part of the arrangement. You can request deletion of your data at any time.

1. Overview

Arborlook Insights, LLC, an Oregon limited liability company ("Arborlook," "we," "us," or "our"), operates Risk & Response, a community risk analytics platform for U.S. fire and EMS agencies. This Privacy Policy describes how we collect, use, store, and share information when you use our Service.

This policy applies to all users of the Service, including visitors to free department profile pages, registered account holders, and subscribers.

2. Information We Collect

Information You Provide

When you create an account or subscribe, we collect:

  • Name and email address
  • Organization name and NERIS ID
  • Role / title (optional)
  • Payment information (processed by Stripe; we do not store full card numbers)

Free-Page Email Signups

Free department profile pages offer an optional email signup ("Know when this profile updates"). If you sign up, we store your email address, the department whose page you signed up from, and the signup date. We use this list for two things: notices when that department's profile is updated with new public data, and occasional Arborlook announcements such as product launches, pilot invitations, and deadlines relevant to the fire service. Together these come to a few emails a year. Signups are confirmed by email before anything else is sent, and every email includes a one-click unsubscribe that removes you from both kinds of email at once.

Information We Receive from NERIS

For paid subscribers who have completed NERIS enrollment, we receive incident data from the NERIS API on your behalf. This includes incident timestamps, type codes, incident location (the address and coordinates NERIS provides, and the census tract we assign from them), unit response times, crew staffing, and other fields returned by the NERIS API. This data is used solely to generate analytics for your department.

Incident History Your Department Uploads

Departments on the CRA/SOC plan can upload incident history from before their NERIS enrollment, as exports from their computer-aided dispatch (CAD) system or as NFIRS records, so their reports can cover several years. Only a department administrator can upload. From each file we import only the columns the administrator maps: incident numbers, call and unit timestamps, incident type and dispatch codes, unit identifiers, types and staffing, response priority, and incident location. We never import free-text columns such as narratives, comments, caller names, or phone numbers, even when a file contains them, and we ask departments to remove columns they do not need before uploading. The uploaded file itself is kept only for a short time, as described in Section 9. Uploaded history is used solely to generate analytics for your department, in the same way as NERIS data.

Information We Collect Automatically

When you access the Service, we automatically collect standard web analytics information:

  • IP address (anonymized by Google Analytics)
  • Browser type and version
  • Pages visited and time spent
  • Referrer URL
  • Device type

We use Google Analytics (GA4) and HubSpot for this purpose. See Section 7 for details on cookies and analytics.

Information from Public Sources

Free tier department pages are built entirely from public government datasets (FEMA, U.S. Census Bureau, NERIS Public, OpenFEMA). This data is not personally identifiable and is publicly available from its original sources.

3. How We Use Information

Information How we use it
Account information (name, email, org) Deliver the Service, send transactional emails (signup, Weekly Intelligence Brief, trial notices), provide customer support
Payment information Process subscription payments via Stripe; detect fraud
NERIS incident data Generate response analytics shown on your dashboard; compute aggregate metrics for your department; nightly data refresh
Uploaded incident history Generate the same response analytics and CRA/SOC reports as NERIS data, for the years before NERIS enrollment; check each upload's completeness and consistency before it is used
Web analytics Understand how the platform is used; improve features; measure marketing effectiveness
Free-page email signups (email, department, signup date) Send profile-update notices for the department you signed up from and occasional Arborlook announcements; a few emails a year, unsubscribe in every email

We do not sell personal data to third parties. We do not use your data for targeted advertising.

4. Third-Party Services

We use the following third-party services to operate the platform:

Service Purpose Data shared
Supabase Database, authentication, and Edge Functions Account and organization data, dashboard metrics, and the status and validation summary of each upload
Stripe Payment processing and subscription management Email address, billing address, payment method details
Resend Email delivery (Weekly Intelligence Brief, account notices, profile-update notices, announcements) Name, email address, email content
Cloudflare R2 Private object storage NERIS incident records, uploaded history files and the history built from them, generated reports
Cloudflare Pages Static site hosting and CDN Standard web request logs (IP, user agent), subject to Cloudflare's privacy policy
Google Analytics (GA4) Web analytics Anonymized usage data; IP addresses are anonymized before transmission
HubSpot Customer relationship management and website visit tracking Pages visited and cookie identifiers for site visitors; name, email address, organization, and correspondence for people who contact us and for customers
GitHub Actions Automated pipeline for NERIS data pulls, history imports, report generation, and scheduled emails Incident records and subscribers' email addresses are processed while a job runs and are not kept there after the job ends

Each of these services operates under its own privacy policy and data processing agreements. We enter into Data Processing Agreements with sub-processors where required.

5. Incident Data

NERIS incident data is accessed through Arborlook's registered API integration with the National Emergency Response Information System (NERIS), operated by FSRI. Access is granted when your department adds Arborlook as an authorized integration in the NERIS portal.

Incident records are stored in private cloud storage (Cloudflare R2) and are used exclusively to generate the analytics shown on your dashboard and in your reports. They are not shared with other subscribing departments, not used for advertising, and not sold. One narrow exception exists, described below: department-level analytics visible to a regional partner if you share with one or your access is sponsored by one.

We pull new incident data nightly while your subscription or trial is active. After your trial expires or your subscription is canceled, a limited nightly retrieval continues solely to compute the aggregate data-quality statistics that power the free Data Quality assessment on your dashboard: counts of records with and without required fields such as timestamps, locations, and incident types. Incident records retrieved after your trial or subscription ends are processed transiently for this purpose and are not stored, and no operational analytics are generated from them. Historical records from your active period are retained for 90 days after trial expiration or cancellation and then deleted; the aggregate data-quality statistics (which contain no incident details) are retained so the free assessment stays available. The same applies to incident history your department uploaded: it is deleted 90 days after trial expiration or cancellation, and the aggregate data-quality statistics computed from it, which contain no incident details, are retained with the rest of your data-quality statistics.

You may revoke NERIS access at any time by removing Arborlook from your authorized integrations in the NERIS portal. Revoking access stops future pulls but does not automatically delete previously retrieved data. To request deletion, contact us.

Your department's administrators can delete an upload from the dashboard at any time. Deleting it removes the uploaded history and every figure built from it.

6. Regional Data Sharing

Regional data sharing is a separate choice that lets a regional partner see your department's analytics identified by department.

A regional partner is an organization with jurisdictional or coordinating responsibility across multiple departments, such as a state fire marshal's office, a county fire authority, or a regional compact. If you subscribe independently, this sharing is off unless you turn it on in your account settings, and you may turn it off again at any time. If your access is sponsored under a regional partner's plan, sharing with that sponsoring partner is part of the arrangement and stays on while the sponsorship lasts; the setting is still shown to you, along with the reason it is locked.

Sharing is limited to the specific partner or partners your department belongs to. A regional partner cannot see departments outside its own region, and other subscribing departments cannot see your data through this mechanism. What is shared is the operational analytics we already generate for your department. This includes analytics built from incident history your department has uploaded. Regional sharing does not change what we collect, how long we retain it, or your right to request deletion.

Regional partners are typically public agencies. Once your data is held by one, it may fall under that jurisdiction's public records or open records law, and the agency decides how to respond to a request. That is outside our control, and we cannot restrict a public agency's disclosure obligations. If it matters to your department, raise it with your regional partner before enabling sharing or accepting a sponsored seat.

7. Analytics & Cookies

We use Google Analytics 4 (GA4) to understand how the platform is used. GA4 uses first-party cookies to track sessions and page views. IP addresses are anonymized before being stored by Google.

We also use HubSpot, the customer relationship management service behind our sales and customer support. HubSpot's tracking code runs on our pages and sets its own cookies to record which pages a browser visits. If you contact us or become a customer, HubSpot may connect those page visits to your contact record. You can block or delete these cookies in your browser settings.

We do not use advertising cookies or third-party tracking pixels beyond Google Analytics and HubSpot.

You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on. Free tier pages can be accessed without any account or cookies (beyond analytics).

Authentication sessions for paid subscribers use Supabase's secure session tokens, stored in your browser's local storage. These tokens are used solely for authentication and are not used for tracking or advertising purposes.

8. Data Security

We implement reasonable technical and organizational measures to protect your data:

  • All data in transit is encrypted via TLS
  • Database access requires authentication; row-level security (RLS) policies ensure subscribers can only access their own organization's data
  • API keys and credentials are stored as environment variables, never committed to source control
  • Stripe handles all payment card data. We never store full card numbers.
  • Uploads go directly from your browser to a private storage bucket through a short-lived upload link. Only your department's administrators can upload, and uploaded files are never publicly accessible.
  • Access to production systems is limited to authorized personnel

No method of internet transmission or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you within 45 days, as required by applicable law.

9. Data Retention

  • Account data: Retained while your account is active and for 90 days after deletion
  • Incident data (NERIS and uploaded history): Retained while your subscription or trial is active and for 90 days after trial expiration or cancellation, then deleted by a scheduled purge. Incident records retrieved after lapse for the free Data Quality assessment are processed transiently and never stored
  • Uploaded files: The file as uploaded is deleted 30 days after it is accepted into your history, 14 days after upload if it is never accepted, and at once if your department deletes the upload. The history built from it follows the incident data rule above
  • Aggregate data-quality statistics: Monthly field-completeness counts from NERIS and from uploaded history (no incident details) retained while your account exists so the free Data Quality assessment remains available; deleted upon account deletion or on request
  • Free-page email signups: Retained until you unsubscribe or request deletion; unsubscribed addresses are kept only as a suppression record so we do not email them again
  • Payment records: Retained as required by tax and accounting regulations (typically 7 years)
  • Analytics data: Google Analytics retains data per their standard retention settings (default 14 months for user/event data)

You may request deletion of your account and associated data at any time. See Section 10.

10. Your Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and personal data (subject to legal retention requirements)
  • Data portability: Request an export of your analytics data in a machine-readable format
  • Opt-out of marketing emails: Unsubscribe from non-transactional emails via any email footer or by contacting us

California residents may have additional rights under the California Consumer Privacy Act (CCPA). Contact us to exercise them.

To exercise any of these rights, email [email protected] with the subject line "Privacy Request." We will respond within 30 days.

11. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes that affect how we use your personal data, we will notify paid subscribers by email before the changes take effect. The effective date at the top of this page will be updated.

Continued use of the Service after any changes constitutes your acceptance of the updated policy.

13. Contact

For privacy questions, data requests, or concerns, contact:

Arborlook Insights, LLC
Email: [email protected]
Subject line: Privacy Request

See also our Terms of Service.