privacy background

Privacy Policy

Learn how Station Clipboard collects, stores, and uses information when you interact with our Fire & EMS software and website.

Last Updated: July 31, 2026

Privacy Policy

How StationClipboard collects, uses, protects, and shares information across our website and the Department Portal.

StationClipboard is owned and operated by Station Automation Solutions LLC ("StationClipboard," "we," "us," or "our"). This Privacy Policy explains how we collect, use, store, protect, and share information when you use StationClipboard, the StationClipboard Department Portal, the Station Clipboard iOS application, stationclipboard.com, and related services, features, modules, websites, and communications.

StationClipboard provides software built for Fire, EMS, and public safety organizations. The platform may be used for personnel management, scheduling, timekeeping, training, certifications, policy acknowledgments, engagement tracking, station boards, assets, incident reporting, and related department operations.

Our privacy-first promise: We do not sell personal information, use your information for behavioral advertising, or use the public website to build advertising profiles. We collect only what we need to operate the site, respond to you, provide the Department Portal, protect the service, and understand whether the site is useful.

1. Our Role

Most information inside a department's StationClipboard portal is controlled by the fire department, EMS agency, organization, district, company, or other entity that uses StationClipboard ("Organization" or "Department").

For Organization portal data:

  • The Organization decides what information is collected, who may access it, how long it is retained, and how it is used.
  • StationClipboard processes that information to provide the platform and support the Organization.
  • Authorized Organization administrators control member accounts, roles, permissions, records, modules, and settings.

For information collected directly through our public website, contact forms, sales inquiries, demo requests, billing communications, or support communications, StationClipboard controls that information.

2. Information We Collect

The information collected depends on which modules and features your Organization enables.

A. Organization and Customer Information

We may collect information about your Organization, including:

  • Organization name
  • Department name
  • Organization ID, slug, or portal identifier
  • Time zone
  • Mailing address
  • Primary contact name
  • Primary contact email address
  • Phone number
  • Organization logo
  • Billing, subscription, plan, and account status information
  • Enabled modules and Organization-level settings

This information is used to create, manage, operate, support, and secure the Organization's StationClipboard account.

B. Account and Profile Information

Member accounts may include:

  • First name and last name
  • Username
  • Email address
  • Phone number, if provided
  • Profile photo or avatar, if uploaded
  • Role and permission assignments
  • Station, shift, rank, house, or assignment details
  • Account status, such as active, disabled, or removed
  • Organization-defined custom fields
  • Login credentials

Passwords are stored only as one-way hashes. We do not store readable passwords.

If kiosk PINs are used, they are stored as one-way hashes and are not stored in readable form.

C. Personnel and Department Records

Depending on the modules enabled by your Organization, StationClipboard may store personnel-related information such as:

  • Personnel roster information
  • Department assignments
  • Rank or position
  • Certifications
  • Training records
  • Attendance records
  • Policy acknowledgments
  • Uploaded files
  • Administrative notes
  • Member status
  • Activity history
  • Department-defined custom fields, such as radio ID, apparel size, internal ID, or similar operational fields

Your Organization controls what personnel information it chooses to enter into StationClipboard.

D. Timekeeping and Attendance Data

If your Organization uses the Clock-In or Time Clock module, we may collect and process:

  • Clock-in and clock-out times
  • Shift duration
  • Station or location label selected by the user or kiosk
  • Clock-in method, such as web portal, kiosk, PIN, password, Face ID, or administrator override
  • Member notes
  • Administrator notes
  • Corrections, edits, approvals, and review status
  • Missed clock-out flags
  • Audit history showing who modified a record and when

Timekeeping data is controlled by your Organization and may be used by your Organization for attendance, staffing, reporting, payroll support, compliance, and internal records.

E. Scheduling and Availability Data

If your Organization uses Scheduling, we may collect and process:

  • Shift assignments
  • Availability submissions
  • Time-off requests
  • Shift trades
  • Shift pickups
  • Open shifts
  • Schedule periods
  • Staffing rules
  • Hour caps
  • Assignment history
  • Approval or denial history
  • Notes related to scheduling actions
F. Training, Certifications, and Compliance Records

If your Organization uses Training, Certifications, or related compliance features, we may collect and process:

  • Certification names
  • Issuing organizations
  • Issue dates
  • Expiration dates
  • Uploaded certificate files
  • Training sessions
  • Attendance records
  • Continuing education hours
  • Instructors
  • Course descriptions
  • Training topics
  • Exported training reports
  • Notes and administrative review history
G. Policies, Acknowledgments, and Electronic Signatures

If your Organization uses the Policies module, we may collect and process:

  • Uploaded policy documents
  • SOPs, SOGs, notices, and related documents
  • Policy versions
  • Assigned users or roles
  • Acknowledgment status
  • Signature status
  • Electronic signature records
  • Timestamps
  • IP address or device-related technical records associated with acknowledgment or signing, where applicable
  • Administrative review and audit history

Electronic acknowledgments and signatures are used to help Organizations track member receipt, review, and acceptance of documents. Your Organization is responsible for deciding when electronic acknowledgment or signature is appropriate for its records.

H. Credits and Engagement Data

If your Organization uses Credits & Engagement, we may collect and process:

  • Activity titles
  • Activity categories
  • Credit values
  • Dates
  • Statuses such as pending, approved, denied, or voided
  • Member notes
  • Administrator notes
  • Approval or denial history
  • Leaderboard or engagement display settings, if enabled by your Organization
I. Announcements, Notifications, and Communications

StationClipboard may process internal communication records such as:

  • Announcements posted by administrators
  • Required acknowledgment status
  • In-app notifications
  • Email notifications
  • Notification title, body, type, and priority
  • Read status
  • Delivery status
  • Records showing who created, received, read, or acknowledged a communication

These communications are scoped to the Organization and are not shared with unrelated Organizations.

J. Station Board Data

If your Organization uses Station Board, we may process:

  • Board names
  • Board layouts
  • Widgets
  • Schedules displayed on boards
  • Staffing information displayed on boards
  • Weather, news, alert, or integration widgets
  • Public or launch links
  • Display settings
  • IP restrictions or access settings, if configured

Organizations control what information they choose to display on Station Boards.

K. Incident Reporting and NERIS-Related Data

If your Organization uses Incident Reporting or NERIS-related reporting features, we may process incident-related information entered by the Organization, such as:

  • Incident numbers
  • Incident dates and times
  • Incident type
  • Apparatus or unit information
  • Personnel involved
  • Narrative fields
  • Review, approval, rejection, or audit history
  • Attachments or files uploaded by authorized users
  • Report status and administrative notes

StationClipboard is not a dispatch system, 911 system, CAD replacement, medical charting system, or emergency response command system unless expressly stated in a separate written agreement.

Organizations are responsible for ensuring incident reports, public records, retention rules, and compliance submissions meet applicable legal and agency requirements.

L. Assets and Equipment Data

If your Organization uses Assets, we may process:

  • Equipment records
  • Inventory records
  • Serial numbers
  • Assigned personnel
  • Locations
  • Status
  • Inspection records
  • Maintenance notes
  • Uploaded files
  • Audit history
M. Integrations

If your Organization enables integrations, StationClipboard may process information needed to connect, display, or synchronize data with outside services.

Examples may include:

  • Weather feeds
  • News feeds
  • Calendar feeds
  • Email delivery services
  • File storage providers
  • Authentication or security services
  • Other Organization-approved integrations

Third-party services may have their own privacy policies and terms.

N. Uploaded Files

Users and administrators may upload files such as:

  • Profile photos
  • Organization logos
  • Certification documents
  • Policy documents
  • Training records
  • Asset files
  • Incident-related attachments
  • Other Organization-approved files

Files are associated with the Organization and are accessible only to users with proper permissions, unless the Organization intentionally makes certain content public, such as through a public board link or published page.

O. Website, Contact, and Sales Information

When you visit stationclipboard.com, request a demo, submit a contact form, subscribe to communications, or contact us directly, we may collect:

  • Name
  • Organization name
  • Email address
  • Phone number
  • Message content
  • Demo request details
  • Sales or support communication history
  • Technical information needed to deliver the request and protect the service, such as browser type, IP address, device information, and request timestamps
P. Website Analytics

The public website does not currently use a website analytics tracker. Server logs may record basic technical information (such as IP address, browser type, and requested pages) for security and operations.

The analytics collector may receive an IP address from the request so it can apply abuse controls and derive approximate location. IP information is used to create rotating, pseudonymous session identifiers and is not presented in the dashboard as a person's identity. We do not ask the public tracker to identify you by name.

The public analytics script does not use advertising cookies. It is configured to honor a browser's Do Not Track signal. You can also block JavaScript or analytics requests in your browser or privacy tool; doing so does not prevent you from reading the public site.

3. Biometric Data and Face ID Clock-In

StationClipboard may offer an optional Face ID clock-in feature. This feature allows a member to clock in or out at a kiosk using face recognition.

Face ID is optional and must be enabled by the Organization. Members must have an alternative method available, such as PIN, username/password, or another Organization-approved clock-in method.

What We Collect

When a member enrolls in Face ID, the system creates a numerical faceprint based on facial geometry. This faceprint is a mathematical descriptor used to verify identity for clock-in purposes.

We may also store enrollment metadata, such as:

  • Enrollment status
  • Date of enrollment
  • Last training or update date
  • Whether enrollment was completed by the member or an administrator
  • Number of training samples used
  • Face ID enabled or disabled status
What We Do Not Do

StationClipboard does not sell biometric data.

StationClipboard does not use biometric data for advertising.

StationClipboard does not use Face ID data to track members outside the clock-in feature.

StationClipboard does not share biometric data with third parties for their own independent use.

StationClipboard does not store raw face images for biometric matching. If a profile photo is uploaded, it is treated as a profile image and not as a stored biometric faceprint.

How Faceprints Are Used

Faceprints are used only to verify identity for the Face ID clock-in feature.

Faceprints are not used to create public profiles, advertising profiles, unrelated tracking, or cross-Organization identification.

How Faceprints Are Protected

StationClipboard protects faceprints using security measures designed for sensitive data, including encryption at rest using AES-256-GCM and access controls.

Faceprints are scoped to the member's Organization and are not exposed to other users.

Consent and Organization Responsibilities

Organizations are responsible for obtaining any required notice, consent, or authorization before enrolling members in Face ID.

Members should not be forced to use Face ID where an alternative method is required by law or Organization policy.

Members may request that their Organization disable or delete their Face ID enrollment. Once deleted, the faceprint cannot be recovered.

Biometric Data Retention

Faceprints are retained only while the Face ID feature is enabled for the member and while the purpose for collection remains active.

Unless a longer retention period is required by applicable law or a specific written agreement, biometric data should be deleted within a reasonable time after the purpose for collection expires, and no later than one year after that purpose expires where required by applicable law.

For members using Face ID in an employment or department service context, the purpose for collecting the faceprint generally ends when the member separates from the Organization, the Organization disables Face ID, or the member's Face ID enrollment is deleted.

4. Information We Do Not Intentionally Collect

StationClipboard is not designed to collect or store:

  • Social Security numbers
  • Full government-issued identification numbers
  • Full payment card numbers
  • Patient medical records or EMS patient care reports
  • Protected health information, unless expressly authorized by a separate written agreement
  • Criminal justice information requiring CJIS compliance, unless expressly authorized by a separate written agreement
  • GPS or real-time location tracking of members
  • Advertising tracking profiles

Users should not upload sensitive information unless their Organization has determined that it is appropriate and lawful to do so.

5. How We Use Information

We use information to:

  • Provide, operate, maintain, and improve StationClipboard
  • Create and manage Organization accounts
  • Authenticate users
  • Enforce role-based permissions
  • Support timekeeping, scheduling, training, certifications, policies, assets, incident reporting, station boards, and other modules
  • Send transactional messages, reminders, alerts, and support communications
  • Maintain audit logs for security and accountability
  • Provide customer support
  • Troubleshoot technical issues
  • Protect against unauthorized access, abuse, fraud, or security incidents
  • Generate reports or exports requested by authorized Organization users
  • Comply with legal obligations
  • Enforce our agreements and policies

We do not sell personal information.

We do not use Organization portal data for third-party advertising.

6. How Information Is Shared

We may share information in the following limited circumstances:

Within Your Organization

Authorized administrators, officers, supervisors, or other users may access information according to the roles and permissions set by the Organization.

Members of one Organization cannot access another Organization's data unless expressly authorized through a valid system configuration or agreement.

With Service Providers

We use a limited set of service providers to operate the service. They process information only as needed to provide the function they support and under their own terms where applicable. These include:

  • Hosting and database infrastructure: providers that run the Station Clipboard website, application, and PostgreSQL database.
  • Discord: contact-form submissions are sent to a private Station Clipboard lead channel so our team can respond.
  • HubSpot: contact-form email addresses and related business-contact fields may be looked up, created, or updated in our customer-relationship system.

We do not send public-site analytics to Google Analytics or an advertising network. We do not permit service providers to use Organization portal data or contact information for their own advertising.

With Third-Party Integrations

If an Organization enables an integration, data may be shared with or received from that third-party service as needed for the integration to work.

For Legal, Safety, or Security Reasons

We may disclose information if required by law, subpoena, court order, government request, or if we believe disclosure is necessary to protect rights, safety, security, users, Organizations, StationClipboard, or the public.

Business Transfers

If StationClipboard or Station Automation Solutions LLC is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate protections.

7. Cookies, Analytics, and Technical Data

The public website does not intentionally use advertising cookies and does not run a third-party advertising pixel.

The Department Portal may use strictly necessary cookies and session technologies to keep authorized users logged in, protect accounts, maintain security, and remember required service state. Those technologies are not used to follow users around unrelated websites.

Standard technical logs may include:

  • IP address
  • Browser type
  • Device type
  • Operating system
  • Request timestamps
  • Error logs
  • Session-related data
  • Security and access logs

These logs are used for security, troubleshooting, performance, abuse prevention, and service reliability. They are not used to create advertising profiles.

Some pages currently request fonts from Google Fonts. That request may disclose your IP address and browser information to Google while the font files are delivered. We do not use Google Fonts for analytics or advertising, but Google may process the request under its own privacy practices.

8. iOS App and Mobile Device Data

The Station Clipboard iOS application is a mobile access point to the same department account and enabled modules available through the web portal. Information viewed, entered, uploaded, approved, or changed in the app may be synchronized with Station Clipboard servers and the applicable Organization account.

Device Permissions

The app may request device permissions only when needed for an available feature. Examples may include notifications, camera access, or photo-library access. A user may deny or later change a permission through iOS settings, but the related feature may not work without it.

The optional Station Clipboard face clock-in feature described in Section 3 is a department timekeeping feature and is separate from Apple Face ID used to unlock a device or authorize an Apple account. Station Clipboard does not receive a user's Apple Face ID template.

Station Clipboard does not intentionally collect precise GPS location through the iOS app under the practices described in this Policy. If a future feature requires location information, this Policy and applicable App Store disclosures will be updated before that information is collected.

Removing the app from a device ends local access but does not automatically delete Organization records already stored in Station Clipboard. Authorized Organization administrators control those records subject to applicable agreements, retention requirements, and law.

Apple may independently process information relating to App Store downloads, device services, diagnostics, or an Apple account under Apple's own terms and privacy practices. Station Clipboard does not control information collected directly by Apple.

9. Data Security

We use reasonable technical and organizational safeguards designed to protect information, including:

  • Password hashing
  • PIN hashing
  • Encryption for sensitive biometric faceprints
  • Role-based access controls
  • Organization-level data isolation
  • Session-based authentication
  • Audit logs
  • Access restrictions
  • Cloud storage access controls
  • Monitoring and troubleshooting logs

No system can be guaranteed to be perfectly secure. Organizations and users are responsible for using strong credentials, protecting login information, assigning roles carefully, and promptly reporting suspected unauthorized access.

10. Data Retention

We retain information for as long as needed to provide StationClipboard, support the Organization, comply with legal obligations, resolve disputes, enforce agreements, and maintain business records. We do not promise a fixed retention period for public-site analytics; those records may be retained as reasonably needed for aggregate reporting, security, troubleshooting, and service improvement, and may be deleted or aggregated over time.

Organization portal data is generally retained while the Organization's account is active, unless deleted earlier by authorized administrators or pursuant to an applicable agreement.

When an Organization account is closed, we may delete, export, archive, or de-identify data according to the Organization's agreement, our retention practices, and applicable law.

Certain records may need to be retained by the Organization for legal, payroll, training, public records, employment, fire service, EMS, or compliance reasons. The Organization is responsible for determining its own legal retention requirements.

Contact-form information is retained only as long as reasonably needed to respond, manage a customer relationship, document support, comply with law, or resolve a dispute. You may ask us to delete a marketing or contact inquiry at any time, subject to records we must retain.

Biometric data retention is addressed separately in the Face ID section above.

11. Your Rights and Choices

Depending on your location and applicable law, you may have rights to:

  • Access personal information
  • Correct inaccurate information
  • Request deletion of personal information
  • Object to or restrict certain processing
  • Withdraw consent for optional biometric features
  • Request deletion of Face ID enrollment
  • Request information about how your data is used

If you are a member of an Organization using StationClipboard, most requests should be directed to your Organization administrator because the Organization controls your portal data.

You may also contact StationClipboard, and we will assist the Organization as appropriate.

If you contacted StationClipboard directly through our website, sales process, or support channels, you may contact us directly regarding that information.

To request access, correction, deletion, or analytics-related information, email hello@stationclipboard.com with the subject line Privacy Request. We may need to verify your identity and, for Organization portal data, coordinate with the Organization that controls the account.

12. Children's Privacy

StationClipboard is intended for use by Organizations and authorized personnel. It is not directed to children under 13.

If an Organization uses StationClipboard for junior members, explorers, cadets, students, or other minors, the Organization is responsible for obtaining any required parent or guardian consent and complying with applicable laws.

13. Public Agencies and Public Records

Some Organizations using StationClipboard may be public agencies or may be subject to public records, open records, employment, payroll, emergency services, or records retention laws.

StationClipboard provides software tools, but each Organization is responsible for determining what records must be retained, disclosed, withheld, exported, or deleted under laws that apply to that Organization.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time as our product, modules, practices, or legal obligations change.

When we update this Privacy Policy, we will update the "Last Updated" date. Material changes may be communicated through the platform, website, email, or other reasonable means.

Continued use of StationClipboard after an updated Privacy Policy becomes effective means you acknowledge the updated policy.

15. Contact Us

For privacy questions, data requests, or concerns, contact:

StationClipboard Owned and operated by Station Automation Solutions LLC Houston, Texas Email: hello@stationclipboard.com Phone: (979) 341-9333

If you are a member of an Organization using StationClipboard, you should also contact your Organization administrator for requests related to your department account or personnel records.

Transparency First

Our Legal Documents

Everything that governs how Station Clipboard works and how your information is protected — all in one place.

Privacy Policy

Learn how your data is collected, encrypted, and stored — including how biometric faceprints are protected with AES-256-GCM.

Read Policy

Terms of Service

Understand the terms that govern your department's use of the Station Clipboard platform and website.

Read Terms

Have a Question?

Reach out about data requests, biometric enrollment, or anything related to privacy and legal matters.

Contact Us