StationCommand Privacy Notice
Last updated August 29, 2026
Public analytics
StationCommand uses first-party analytics to understand public statistics and incident-display use. It may record pages/screens viewed, approximate session duration, referrer, browser/device information, and coarse geographic information when supplied by the hosting network. The public analytics system does not retain the visitor's full IP address and does not request GPS location.
Global Privacy Control and Do Not Track signals reduce public analytics. StationCommand does not use analytics for advertising profiles, fingerprinting, or sale of visitor information.
Security and audit logging
Protected services maintain security/audit records including login successes and failures, account identifier when known, authentication provider, date/time, full source IP address, coarse network-supplied location, browser user agent, authorization failures, logout, and protected actions. Passwords, OAuth tokens, GPS coordinates, and dispatch narratives are not intentionally stored in security logs.
Retention
Public detailed analytics and security/audit records are retained according to the configured records-retention policy. Legal holds, investigations, public-records requirements, or other legal obligations may require longer preservation.
Location
StationCommand does not request device GPS/geolocation permission. Approximate location may be derived from the source IP address. By default this can be performed locally with a department-provided MaxMind City database or from trusted hosting-provider geography headers. If the administrator explicitly configures the optional official MaxMind web-service fallback, the source IP is sent to MaxMind solely to obtain an approximate network location. StationCommand does not retain full public-visitor IP addresses after analytics processing; security-event IP retention follows the configured audit-retention policy.
Optional private Active911 device tracking: An administrator may enable apparatus tracking and/or responder tracking for authenticated private operational maps: the incident response screen and EOC mode. Both are disabled by default. Apparatus locations may be requested from Active911 while the private incident response screen or EOC map is active regardless of apparatus response status. Responder tracking additionally requires the individual StationCommand user to opt in and is requested only while that responder's linked Active911 device is marked RESP or ARRIV on the displayed incident, or on at least one active EOC incident while EOC mode is active. Exact Active911 device coordinates are held only in temporary server memory for the live map; they are not stored in StationCommand's database, analytics, audit log, incident history, or public display/API. StationCommand does not request browser/device GPS permission for this feature; the location is supplied by Active911 according to the device's Active911 GPS settings.
Audible incident announcements
Administrators may optionally enable private audible incident announcements. This feature is disabled by default. When enabled, the private station display can play an administrator-uploaded tone and use the browser's built-in speech-synthesis capability to read configured incident fields such as department name, incident type, title, address, cross streets, narrative, station name, responder information, address-history summary, and weather-alert text. The announcement feature is not exposed on the public display. Speech synthesis is provided by the browser/operating system, so voice processing behavior depends on the platform and selected system voice.
Public analytics and security logging
StationCommand uses first-party analytics to count public visits, viewed screens, approximate session duration, and coarse IP-derived geographic area. It does not request browser GPS. Public analytics are reduced when supported privacy signals are received. Full IP addresses are retained for security events and authorized audit activity according to the department's retention configuration.
Public incident information is intentionally generalized. For public map incident records, StationCommand exposes only the normalized call type, a nearest-100-block address, named intersection, or road-only AREA OF label when no safe civic number is available, and the incident time rounded to the nearest 30 minutes. Configured fire-station names, addresses, and map locations may also be shown publicly and are not treated as incident-location data. The map also receives privacy-safe latitude/longitude geometry needed to draw the generalized marker; those coordinates are generated from the generalized block/intersection rather than the exact CAD coordinates. Exact incident addresses, apartment/unit information, CAD/internal identifiers, narratives, responder identities, response statuses, agency/unit assignments, notes, timelines, exact timestamps, and exact CAD coordinates are not exposed through the public incident APIs.
For non-intersection addresses, StationCommand geocodes the generalized 100-block, applies a stable privacy displacement, and uses a road snap only when the result can be identified as the same street. If a reliable same-street snap cannot be produced, the displayed point is displaced independently north/south and east/west by roughly 525–1,000 feet from the generalized block location. Named intersections are shown at the geocoded intersection without random displacement.
Public map cache fallback: if a generalized 100-block point has not been cached yet, StationCommand may temporarily derive a public map point from the CAD coordinate entirely on the server, then independently displace it roughly 525–1,000 feet north/south and east/west before anything is returned to the browser. The raw CAD coordinate is never included in the public response, and the temporary point is replaced by the preferred generalized 100-block/intersection result when available.