Privacy Policy

Last updated: September 10, 2026

Santa Rosa Valley Firewise (“SRV Firewise,” “we,” “our”) is a volunteer community coalition. This Privacy Policy explains what information we collect through srvisfirewise.org, why, and how we protect it.

What we collect

  • Newsletter subscribers: email address, first name, HOA affiliation (optional). Used only to send the monthly newsletter and event notifications. Managed via FluentCRM.
  • Contact form submitters: name, email address, message content. Used only to respond to your specific inquiry.
  • Firewise activity submitters: name, email address, property address, HOA, activity details. Used for community NFPA renewal reporting and to send a confirmation email.
  • Home assessment requesters: name, contact details, property address, HOA. Shared with your HOA’s designated home assessor to schedule.
  • Volunteer signup: name, contact details, HOA, role preferences. Used to match you to volunteer opportunities in your HOA.
  • At-Risk Resident Registry: name, contact details, address, HOA, emergency contact, and optional “special considerations” text field. This data is encrypted at rest in a custom database table, and access is strictly limited to your HOA’s designated phone-tree coordinator and SRV Firewise super administrators. Every read and write is logged.

What we do not collect

  • We do not sell or share personal information with third parties for marketing.
  • We do not use behavioral tracking cookies. We use Cloudflare Turnstile for anti-spam (privacy-friendly, no fingerprinting) and either Plausible Community Edition or Google Analytics 4 for anonymized aggregate site analytics.
  • We do not use any cookies that require GDPR/CCPA consent beyond a passive analytics banner.

Sensitive data — At-Risk Resident Registry

Data submitted to the At-Risk Resident Registry receives elevated security treatment:

  • Encrypted at rest using libsodium with a key stored outside the database.
  • Role-gated access. Only Super Admins and the HOA-specific phone-tree coordinator for the record’s HOA can read the plaintext contents. Access is enforced at the database query layer.
  • Audit-logged. Every read, update, and export of at-risk data produces an entry in a tamper-resistant audit log with user, timestamp, and action recorded.
  • Two-person export approval. CSV exports of at-risk data require two different administrators — one to request, a different one to approve.
  • Annual re-confirmation. Records are auto-flagged for renewal at 11 months and are automatically deleted after 30 days of “pending deletion” status.
  • Right to be forgotten. You can request full deletion of your at-risk record at any time.

Your rights

You may request a copy of what we hold about you, request correction or deletion, unsubscribe from the newsletter with one click from any email footer, or request that your at-risk registry record be deleted. Contact: [email protected].