Back to Flag & Forge
F&F / LEGAL / 001

Privacy standard

Clear about data.
Deliberate by design.

This policy explains how Flag & Forge handles information across our apps, website, support, team portal, agency services, subscriptions, and commerce. We wrote it to be read—not merely accepted.

EffectiveAugust 26, 2026
Last updatedAugust 26, 2026
Applies toFlag & Forge services

Plain-language brief

The short version

No behavioral advertising

We do not sell personal information or use app activity to build advertising profiles.

Local-first field tools

TCEMS Pro+ is designed to operate offline and without a user account.

You choose what reaches us

Information enters our systems when you contact us, buy something, subscribe, or use an expressly connected service.

Patient records do not belong here

Our current apps are not electronic patient-care records and are not designed to receive uploaded PHI.

01 / SCOPE

Who this policy covers

This Privacy Policy applies to Flag & Forge websites, mobile and wearable applications that link to this policy, customer support, agency or organizational services, subscriptions, newsletters, and merchandise transactions (collectively, the “Services”). “Flag & Forge,” “we,” “us,” and “our” refer to Flag & Forge, an Oregon-based operator in the United States.

A product-specific notice shown inside an app or at the point of collection may provide more detail. If that notice conflicts with this policy, the more specific notice controls for that product and information.

02 / CURRENT APP PRACTICE

TCEMS Pro+ and other local-first apps

Current productTCEMS Pro+
Local-first
Account required
No
Core internet connection
No
In-app advertising
None
Cross-app tracking
None
Sale of app data
None
Primary storage
On device

TCEMS Pro+ is designed for offline access to reference material and operational tools. Timer events, session history, user settings, and similar working data are stored locally on the device. When companion Apple devices are used, operational data may pass directly between paired devices using Apple-provided connectivity. Flag & Forge does not receive that locally stored content through the app’s ordinary operation.

Apple may process App Store transactions, installation information, and device diagnostics under Apple’s own terms and privacy choices. Depending on a user’s device settings, Apple may provide developers with aggregated performance information or diagnostic reports. We use any such information only to maintain reliability, investigate defects, and improve safety.

Clinical-data boundary

TCEMS Pro+ is a reference and operational-support tool, not an electronic patient-care record. Do not enter patient names, dates of birth, medical-record numbers, photographs, narrative histories, or other identifiable patient information into custom labels or notes. If an employer or agency authorizes a particular workflow, follow its privacy, security, documentation, and device-management policies.

If a future version adds cloud sync, accounts, analytics, remote agency administration, or another network service, we will update this policy and provide a product-specific notice before that collection begins.

03 / COLLECTION

Information we collect

We collect only the information reasonably needed for the Service you choose to use.

ContextInformationWhy
WebsiteIP address, browser/device type, request time, pages requested, security events, and similar routine server records.Deliver, protect, debug, and understand basic operation of the site.
Support & contactName, email, organization, message, attachments, and details you choose to provide.Answer questions, investigate defects, and maintain a support record.
PurchasesContact, billing and shipping details, order contents, transaction status, and tax records. Payment providers process full card data.Complete orders, prevent fraud, provide service, and meet accounting obligations.
SubscriptionsEmail, consent record, preferences, and engagement needed to deliver requested communications.Send the updates you requested and manage opt-outs.
Agency servicesOrganization, administrator identity, professional contact information, contract records, and agency-provided resource directories.Configure, maintain, secure, and support the agency’s service.
Team portalIdentity; volunteer, agency, and stakeholder contact details such as name, email and phone; messaging-readiness status; access role; group assignments; encrypted-at-rest message content; recipients; timestamps; read state; sessions; and security activity.Operate and secure company communications, volunteer rosters, organizational directories, permissions, audit records, and app synchronization.

We do not intentionally collect precise location, biometric identifiers, government identification numbers, full payment-card numbers, or patient health information through the current website or ordinary operation of TCEMS Pro+.

Cookies and similar technology

Our public site may use strictly necessary cookies or comparable storage for security, routing, accessibility, or a feature you request. We do not currently use third-party advertising cookies or cross-site behavioral trackers. If optional analytics or marketing technology is introduced, we will provide notice and any consent or opt-out controls required by law.

04 / USE

How we use information

  • Provide, fulfill, maintain, and improve the Service you requested.
  • Respond to support requests and communicate about material service, safety, or policy changes.
  • Process transactions, subscriptions, renewals, refunds, and required records.
  • Configure and maintain agency contact directories and organization-specific resources.
  • Deliver role- and group-controlled team communications, invitations, access management, and operational synchronization.
  • Protect users, investigate misuse or defects, and secure our systems.
  • Comply with law, enforce agreements, and establish or defend legal claims.
  • Send marketing only when permitted, with a clear way to unsubscribe.

We do not use clinical-tool activity to make employment, insurance, credit, housing, or other high-impact eligibility decisions. We do not use patient information to train artificial-intelligence models.

05 / DISCLOSURE

When information may be shared

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

We may disclose limited information in these circumstances:

  • Service providers: hosting, email, support, payment, commerce, fulfillment, security, and professional-service providers working under contractual restrictions.
  • Your organization: agency account and configuration information may be available to administrators authorized by that organization.
  • At your direction: when you ask us to send information to another person or service.
  • Legal and safety reasons: when reasonably necessary to comply with law, protect rights or safety, investigate fraud, or respond to valid legal process.
  • Business transition: as part of a merger, financing, reorganization, or sale, subject to appropriate confidentiality and continued notice.

Providers are permitted to process information only for the services they perform for us and must apply protections appropriate to the information. We do not authorize them to use it for their own advertising.

06 / ORGANIZATIONS

Agency and professional contact data

An agency subscription may include a maintained directory of professional resources such as medical control, hospitals, coroners or medical examiners, operational contacts, and other locally relevant services. These directories are business and professional reference data supplied or approved by an authorized agency administrator. They are not patient records.

The agency controls which contacts are submitted and who may access its configured resources. Flag & Forge uses that information to configure, update, and support the agency service. Agencies must not upload patient information, personnel medical information, criminal-justice information, or other restricted records unless a separate written agreement expressly authorizes the data type and establishes required safeguards.

The Flag & Forge Team Portal stores company messages and related delivery, read, session, and activity records. Access is limited through assigned roles and operations groups, and authorized administrators may review company records for security, continuity, compliance, and operational management. Portal messages are protected by TLS while transmitted and encrypted at rest; the current portal messaging service is not represented as end-to-end encrypted. Do not use it for patient information, criminal-justice information, passwords, payment-card data, or other restricted records unless Flag & Forge has expressly approved the workflow and required safeguards in writing.

Authorized administrators may import professional contact cards into an encrypted organizational directory, classify them as Volunteer, Agency, or Stakeholder, and mark Volunteer records active or inactive for ordinary communications. An authorized Volunteer All Call may include inactive Volunteer records. Administrators are responsible for importing only contacts they are permitted to use for legitimate Flag & Forge organizational purposes and for honoring applicable consent, opt-out, and communications requirements.

Where we process personal information solely on behalf of an organization, individual requests may need to be directed to that organization. We will assist the organization as required by our agreement and applicable law.

07 / CONTROL

Your choices and privacy rights

Device-local app data

You control locally stored app data through in-app controls, device settings, and removal of the app. Deleting an app may permanently delete its local data; back up only through methods approved by your organization.

Communications and cookies

You may unsubscribe using the link in a marketing message or by contacting us. Transactional, safety, or service messages may continue when necessary. Browser settings can restrict cookies, although strictly necessary features may be affected.

State privacy rights

Depending on where you live and whether the applicable law covers our activity, you may have rights to access, confirm, correct, delete, or obtain a portable copy of personal information; learn the categories of information processed or disclosed; opt out of sale, targeted advertising, or certain profiling; withdraw consent; and appeal a denied request. Because we do not sell personal information or use it for targeted advertising, those opt-outs are our default practice.

We recognize legally required browser-based universal opt-out signals, including Global Privacy Control, where they apply. We do not respond differently to legacy “Do Not Track” signals because no common legal or technical standard governs them; our no-sale and no-behavioral-advertising practices remain the same.

Making a request

Email privacy@flagandforge.com with “Privacy Request” in the subject line and describe your request and the Service involved. We may verify your identity using information reasonably related to your interaction with us. We will not discriminate against you for exercising a privacy right. An authorized agent may submit a request where permitted by law, subject to verification of authority.

If we deny a request, our response will explain the reason and, where applicable, how to appeal. Appeals may be submitted to the same email address with “Privacy Appeal” in the subject line.

08 / STEWARDSHIP

Retention and security

Device-local data remains under the user’s control and is retained according to the app’s controls, device behavior, and backup settings. Information we receive is retained only as long as reasonably necessary for the purpose described, including providing the Service, honoring user choices, maintaining security and support records, resolving disputes, and meeting tax, accounting, contractual, or legal obligations. We then delete, de-identify, or securely dispose of it when reasonably practicable.

We use administrative, technical, and physical safeguards appropriate to the nature of the information. No system or transmission method can be guaranteed completely secure. Do not send patient records, passwords, payment-card numbers, or other highly sensitive information through ordinary email or support channels. If a security incident creates a legal notice obligation, we will provide notice as required by applicable law.

Team Portal messages, recipient records, access decisions, and activity logs may be retained as company operational records for continuity, security review, contract performance, and legal obligations. Retention periods may vary by activation, customer agreement, record category, and administrator-approved policy.

09 / AUDIENCE

Children and international use

The Services are intended for adults, professionals, agencies, and general merchandise customers. They are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and delete it when required.

Flag & Forge operates from the United States. If you use the Services from another country, information you intentionally provide may be processed in the United States or other places where our service providers operate, subject to applicable safeguards and law.

10 / UPDATES & CONTACT

Changes to this policy

We may update this policy as our products, providers, and legal obligations change. We will post the revised policy here and change the “Last updated” date. If a change materially affects how we use information already collected, we will provide additional notice or obtain consent when required.

Privacy contact

Flag & Forge

Oregon, United States

privacy@flagandforge.comPlease do not include patient information or other sensitive records in your email.