Routine To Response Privacy Policy

Effective July 28, 2026 · Updated August 26, 2026

Summary: Routine To Response uses account, department, and training information to provide secure fire-service readiness tools. We do not sell personal information, use it for targeted advertising, or include third-party advertising trackers.

1. Who we are and what this policy covers

Routine To Response ("R2R," "we," "us," or "our") is operated by Ryan Thomann in North Carolina, United States. This policy explains how the Windows application, centralized application programming interface, support services, and related web pages collect, use, disclose, retain, and protect personal information.

Participating fire departments and other organizations decide which personnel and training records they place in R2R and who may access those records. For organization-managed information, the organization is responsible for its own notices, lawful authority, record-retention requirements, and user administration. Questions about the accuracy or authorized use of a department record should normally be directed to that department first.

This policy does not govern Microsoft Store, Microsoft Windows, Render, Supabase, or a participating organization's separate systems and privacy practices.

2. Information we process

CategoryExamples
Account and personnel informationName, email address, optional phone number, department, Access Profile, rank, role, shift, station, certifications, apparatus eligibility, account status, and internal user identifiers.
Authentication and security informationPassword hashes and salts, password-change status, unsuccessful sign-in and lockout information, signed-session identifiers, access permissions, and audit events. R2R does not store account passwords in readable form on the central service.
Training and exercise informationTabletops, Training tests, instructor statements, assignments, due dates, responses, scores, reviewer selections, comments, highlights, completion history, training dates, credit hours, instructors, locations, training types, attendance, approval status, rejection explanations, generated training-form PDFs, and limited focus-change/time-away records recorded while completing an assignment.
Department and administrative informationDepartment name and code, ranks, stations, roles, apparatus, category definitions, service status, administrator actions, and platform-owner audit records.
Content and filesImages, documents, videos, filenames, and other media deliberately uploaded or attached by an authorized user; Community Library submissions, descriptions, classifications, contributor department, moderation decisions, and reports about shared content. Uploaded content may contain personal information chosen by the user or organization.
Operational, scheduling, and notification informationDeployment identities, availability responses, equipment readiness and deficiencies, work rotations, roster assignments, open-shift bids and awards, time-off and trade requests and decisions, leave banks and ledger transactions, schedule publications and acknowledgements, Daily Board schedule items, station notes, staffing assignments, weather coordinates, operational tasks, operational periods, activity logs, ICS forms and messages, timestamps, authorship and edit history, in-app notification history, recipient matching, and delivery preferences.
Technical and support informationInternet Protocol address and request metadata available to hosting systems, application version, request/error identifiers, diagnostic records, and information included in a support request.
Pilot distribution statisticsAnonymous installer-link clicks, completed pilot-package responses, application version, event timestamp, and a randomly generated installation identifier reported once after the pilot application first launches. R2R does not associate this identifier with an account, department, IP address, or advertising profile.

R2R does not request precise location, contacts, financial account information, or health information as part of its normal operation. Users and organizations should not upload unnecessary sensitive information.

3. Information stored on a user's Windows device

The application stores limited preferences, such as the most recently used department code, on the user's device. If a user selects Remember me, the saved sign-in credential is protected through Windows Credential Manager for that Windows account. It is not placed in department data or stored as readable text by R2R. Users can clear remembered credentials by turning off Remember me or through Windows credential settings.

A portable/offline edition may store a department data file and backups in the folder selected for that edition. The person or organization controlling that device and folder is responsible for physical access, backups, and appropriate deletion.

4. How we use information

Where a legal basis is required, processing is performed as necessary to provide the requested service or fulfill an agreement, to serve legitimate interests in operating and securing the service, to comply with legal obligations, or with consent where consent is required.

5. How information is disclosed

We disclose information only as needed for the purposes described above:

We do not sell personal information. We do not share personal information for cross-context behavioral advertising and do not use third-party advertising SDKs.

6. Retention and deletion

Department and training records are retained while needed to provide the service and meet the participating organization's training, accountability, and recordkeeping needs. Authorized administrators can correct records, archive personnel, and—where permitted—permanently delete archived personnel. Community submissions, moderation decisions, and content reports are retained as needed to operate and protect the shared library. Platform operators can retire shared content and suspend or archive department access.

When an organization validly requests deletion or closes its service, primary data will be deleted or de-identified after any required export and a reasonable operational period, except where retention is required for security, dispute resolution, legal compliance, or enforcement. Residual copies may remain temporarily in encrypted or provider-managed backups until those backups rotate. Security, audit, and support records are retained only as long as reasonably necessary for their purpose.

7. Security

We use safeguards appropriate to the nature of the service, including HTTPS transport, salted password hashing, signed sessions, role-based access controls, department separation, request-size limits, rate limiting, audit logging, managed secret storage, restricted administrative functions, and hashed revocable station-display credentials. Remembered credentials use Windows Credential Manager. No system can guarantee absolute security, and users must protect their devices, credentials, and paired-display links.

If we discover a breach requiring notice, we will investigate and provide notice to affected organizations, individuals, regulators, or others as required by applicable law.

8. Choices and privacy rights

R2R notifications default to in-app delivery. A user may enable or disable email separately for their own notification events in My Notification Settings; selecting email is the user's opt-in, and turning it off stops future notification email for that event. Enabling email for Deployment ICS 213 expressly sends the complete recorded message through the configured email provider to the user's account address. Department administrators may choose which authorized users watch department events, but they cannot enable email delivery for another user.

Depending on location and applicable law, a person may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Users can update certain contact information in Profile. Other personnel and training records are managed by authorized department personnel.

To submit a privacy request, contact the department administrator responsible for the account or email rthomann@northchathamvfd.com. We may need to verify identity and organizational authority before acting. Some information may be retained when permitted or required by law. Users may also complain to an applicable privacy or data-protection authority.

9. Children's privacy

R2R is designed for fire-service and organizational training and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information without appropriate authorization.

10. International processing

The service is operated from the United States, and information may be processed in the United States or another location where a service provider operates. When required, we use appropriate contractual or legal safeguards for cross-border processing.

11. Changes to this policy

We may update this policy when the service, providers, or legal requirements change. The effective date above will be revised. Material changes will be communicated through the service, Store listing, participating organization, or other reasonable means before they take effect when required.

12. Contact

Routine To Response
Operator: Ryan Thomann
North Carolina, United States
Email: rthomann@northchathamvfd.com
Support: https://routine2response.com/support
Community guidelines: https://routine2response.com/community-guidelines