Fire or danger? Call 911 first. For everything else, we answer seven days a week.Call/text (201) 256-7642
SCSafety City CompliancePermit, fire & medical-gas compliance
Privacy policy

What we collect, why, and who sees it

This policy covers the public website, the intake form, the client portal, the private site-status and order-tracking pages, and the messages we send. It is written in plain language on purpose. If something here is unclear, call or email and we will explain it.

Effective date: [to be set when the attorney signs off]. Applies to Safety City Compliance LLC, Bergen County, New Jersey.

Draft for attorney review. This page describes what the system actually does today. It has not yet been reviewed by an attorney and may change before it is final. Questions: (201) 256-7642 or safetycitycompliance@gmail.com.

Who we are

Safety City Compliance LLC ("Safety City", "we") is a third-party compliance management company. We keep a compliance calendar and a site file for each client, coordinate permits, inspections, and service visits, and notify the people a client names when an alarm, fault, or service update comes in. Contact: (201) 256-7642, safetycitycompliance@gmail.com.

What we collect

We collect only what the service needs to run. In practice that is:

  • Intake answers. What you type into the intake form: the business's legal name and trade name, its type, billing address and billing email, insurance carrier and whether the policy has a protective safeguards endorsement, each site's address and municipality, counts and descriptions of equipment, current vendors and inspection history, the services you want, scheduling preferences, and the name you type as a signature. Drafts are saved as you go, so partial answers are stored too.
  • Contacts. Names, roles, email addresses, and phone numbers of the people a client lists, plus each person's notification choices (email, text, phone call, browser push) and escalation level. A contact may also give us their mobile carrier so texts can fall back to the carrier's email-to-text gateway.
  • Site and equipment records. Each site's address, alarm system details, equipment inventory (extinguishers, emergency lights, hood systems, cylinders, AEDs, and so on), obligations and due dates, permits and registration numbers, visit and service reports, fill-lot logs, and photographs taken during walkthroughs and visits.
  • Alarm and fault events. When an alarm panel, monitoring company, automation tool, or a person reports an alarm, trouble, supervisory, waterflow, discharge, communications fault, heartbeat, or restore for a site, we record the event, its time, its source, the zone or message it carried, who acknowledged it and when, and how it was resolved.
  • Service requests and orders. What you report or request (the category, urgency, description, preferred times, and the site), the contact name, email, and phone you give, and the order's timeline: status changes, scheduling, the assigned technician, and customer-visible notes.
  • Push subscriptions. If you turn on browser notifications, your browser gives us a subscription endpoint and keys. We store those so we can send push alerts to that browser. They identify a browser, not a person.
  • Sign-in codes and sessions. Signing in to the client portal sends a one-time code to your email. We store the code (hashed), the email it was sent to, when it expires, and whether it was used. Staff sign-in also uses a one-time code every time. A signed-in visit is tracked with one session cookie (see Cookies below).
  • Messages we send. Every email, text, phone call, and push notification we send is logged with the recipient, channel, time, delivery result, and any error the provider returned, so we can prove what was sent and retry what failed.
  • Server logs. Like any web server, ours records requests: the page or endpoint, the time, the IP address, the browser type, and errors. We use these to keep the service running, to enforce rate limits, and to investigate problems. We do not use them to build profiles.

We do not collect payment card numbers, bank details, or Social Security numbers through the website or portal. Invoices and payment are handled separately under the service agreement.

How we use it

  • Running the compliance service. Building and maintaining the site file, the compliance calendar, the calendar feed, permit and registration filings, visit reports, and the records an inspector or surveyor asks for.
  • Notifications. Sending alarm, fault, and escalation alerts, service-visit and order updates, calendar reminders, intake confirmations, welcome packs, and sign-in codes, by email, text message (SMS), voice call, and browser push, to the contacts a client has listed and according to each contact's choices.
  • Order tracking. Giving you an order number and a private tracking link so you can see the status, schedule, and timeline of a request.
  • Answering you. Calling or emailing back about a walkthrough request, an intake, a report, or a question.
  • Keeping the service safe and working. Rate limiting, detecting abuse of the public forms, debugging, and backups.

We do not sell personal information, and we do not use it for advertising. We do not send marketing text messages.

Text messages (SMS) and phone calls

We send text messages and automated voice calls only to phone numbers that were given to us for that purpose: on the intake form with the text-message consent box checked, by a client adding a contact and turning on texts or calls for that contact, by a contact changing their own preferences in the portal, or by a person giving a phone number when they report an issue or request service.

  • What the texts are. Alarm and fault alerts, escalation notices when nobody has acknowledged an alert, service-visit and order updates, calendar reminders, and replies to something you asked for. Frequency varies with what happens at your sites. We never text marketing.
  • Message and data rates may apply. Your carrier's normal charges apply to texts and calls you receive.
  • To stop. Reply STOP to any text and that number stops receiving texts from us. You can also tell us by phone or email, or change the contact's settings in the portal. Stopping texts does not turn off email, phone calls, or push unless you ask for that too, and it does not stop the people you have listed from being paged.
  • For help. Reply HELP to any text, call (201) 256-7642, or email safetycitycompliance@gmail.com.
  • Voice calls. The "pager" is an automated call that reads the alert out loud. It is used for alarms and faults and, if a contact chooses it, for escalation. It is not used for sales.

Carriers and our messaging provider are not responsible for delayed or undelivered messages. If a text cannot be delivered, we still record it and try the other channels the contact has turned on.

Who we share it with

We share personal information only with the companies that carry the service for us, and only what each one needs:

  • Email delivery. The email provider we send through (currently Google's mail servers; possibly a transactional email service such as Resend or SendGrid) sees the recipient address and the message.
  • Text messages and voice calls. Twilio delivers our texts and places our automated calls. It sees the phone number and the message text, and it handles STOP and HELP replies.
  • Hosting. The company that hosts our server and database (for example Fly.io, Render, or Vercel with a hosted Postgres database) stores the data on our behalf. Web push notifications pass through your browser maker's push service (Google, Apple, or Mozilla).

Beyond that, we share a client's records with the fire official, another authority having jurisdiction, an insurer, a surveyor, or another vendor only at the client's direction, for example when a client asks us to send the inspection file to the fire official or a certificate to the insurance carrier. We will also disclose information if the law requires it (a subpoena or court order) or to protect someone's safety, and we will tell the client when we are allowed to.

If Safety City is ever sold or merged, client records would transfer to the new owner under this same policy, and clients would be told beforehand.

How long we keep it, and whose it is

  • Client records belong to the client. The site file, calendar, reports, photographs, and inspection history are yours. At any time, and especially when an agreement ends, you can ask for a full export in a format the next company can read, and we provide it.
  • Deletion on request. Ask and we delete your records, except for what we must keep to satisfy a legal obligation, resolve a dispute, or document work already done (for example a service report that a fire official may later ask about). We will tell you what, if anything, is kept and why.
  • Intake drafts that are never submitted, and walkthrough or service requests from people who never become clients, are kept only as long as they are useful to answer you and are then removed.
  • Sign-in codes expire minutes after they are issued and are removed on a schedule.
  • Message logs and server logs are kept for a limited time for troubleshooting and to prove what was sent, then removed.
  • Backups of the database are taken daily and kept for a rolling period of about two weeks. Deleted records can remain in those backups until they age out.

Security

  • Everything travels over HTTPS. Sign-in uses one-time codes sent to a verified email; there are no customer passwords to leak.
  • Sessions are kept in a signed, HTTP-only cookie that is not readable by page scripts and that is marked secure on the live site.
  • Site-status pages, order-tracking pages, alert-acknowledge links, and intake resume links are private links: anyone who has the link can see or act on what it points to. Keep them private; a client can ask us to rotate a site's links at any time.
  • Alarm webhooks are per site and protected by a secret; the public status page shows only counts, never a site's name.
  • Access to the staff portal is limited to Safety City staff with a password plus an emailed code each time.

No system is perfectly secure. If we learn of a breach that affects your information, we will tell you and any authority we are required to notify, without unreasonable delay.

Cookies and browser storage

  • One cookie. The portal sets one cookie, scc_session, only after you sign in. It keeps you signed in and nothing else. There are no advertising or analytics cookies on this site.
  • Local storage on your device. The intake form keeps a copy of your draft in your browser so you do not lose it if the connection drops; the report, contact, and tracking pages remember your last order number so the tracking page can find it; the site-status page remembers whether you turned on push notifications for that site. This stays on your device and is not sent anywhere except back to us when you submit or resume. Clear your browser's site data to remove it.
  • We do not use third-party trackers, pixels, or embedded social widgets.

Children

The website and portal are for businesses, facilities, and emergency-services agencies. They are not directed to anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has given us information, tell us and we will remove it.

Your choices

  • See, correct, export, or delete the information we hold about you or your business: call or email us.
  • Change which notifications you get: sign in to the client portal and edit your contact, or ask us.
  • Stop texts: reply STOP. Stop push: turn it off in your browser or on the site-status page.

We will answer within a reasonable time and never charge for it.

Changes to this policy

When we change this policy we update the effective date at the top and, for changes that matter, tell current clients by email. Continuing to use the service after a change means you accept it.

Contact

Safety City Compliance LLC · Bergen County, New Jersey
Call or text (201) 256-7642
safetycitycompliance@gmail.com

See also the terms of use.

Draft for attorney review. Not final until the effective date above is set.