Privacy
Privacy Policy
What we handle, why we handle it, and the choices you have — in plain language.
Effective and last updated: August 28, 2026Scope and approach
This policy covers the IncidentMTL iPhone app, incidentmtl.com, and messages sent to support.
No name, email address, or Apple ID is required to use the app. IncidentMTL has no advertising, behavioural analytics, or cross-app or cross-site tracking. The website sets no advertising or analytics cookies.
Information handled
- Anonymous technical account: a random UUID and a hash of the authentication token when Plus or a server feature needs one.
- Notifications: the APNs token and app language if you allow notifications.
- Alert areas: the chosen name, centre coordinates, radius, categories, preferences, and technical delivery history.
- Subscription: product, entitlement status and dates, transaction identifiers, and Apple-signed purchase, renewal, or cancellation notices.
- Support and operations: your address and message when you email us; our providers may also temporarily process IP address, device, browser, and request time to deliver and protect the service.
Location and saved places
Location supplied by iOS is used on your device to centre the map and calculate proximity. IncidentMTL does not receive a trail of your movements and does not continuously track you or use background location.
Saved places, filters, and onboarding choices stay on your device. If you create an alert area from a place or the suggested position, the centre you confirm is sent to the server with that area’s settings so alerts can work.
Uses and service providers
We use this information only to provide requested features, validate IncidentMTL Plus, deliver notifications, secure the service, answer support, and meet our obligations. We do not sell it or use it for advertising or profiling.
- Apple processes purchases, receipts, and APNs notifications.
- Railway hosts the app API and database in the United States.
- Cloudflare delivers and protects the website and routes IncidentMTL email.
- Our email provider processes support messages you send us.
Retention and deletion
When information is no longer needed, we destroy or de-identify it where the law permits.
- The technical account, alert areas, and delivery history remain until you use Delete My Data.
- The APNs token is removed when you delete your data or Apple reports that it is no longer valid.
- Apple transaction and notification records remain only as long as reasonably needed to administer subscriptions, prevent fraud, keep accounting records, resolve disputes, or meet legal requirements. Some of these records may therefore remain after the primary account is deleted.
- Support messages remain as long as needed to respond, handle follow-up, and maintain necessary business records. You may request their deletion.
Your choices and rights
- You can withdraw location or notification permission in iOS Settings.
- Settings → Delete My Data removes the primary technical account and alert areas from the server, then clears local app data.
- Deleting data does not cancel a subscription billed by Apple; manage that subscription separately in your Apple Account.
- You may ask to access, correct, or delete information, withdraw consent, or make a complaint by emailing us.
Security and processing outside Québec
Connections use HTTPS, the access secret is stored in the iOS Keychain, and the server keeps only its hash. We limit access to information and select providers required to protect it and use it only to provide their services.
Railway hosts app data in the United States. Apple, Cloudflare, and our providers may process information in other territories, where it can be subject to local laws.
Privacy officer and changes
IncidentMTL’s Privacy Officer can be reached at bonjour@incidentmtl.com. We publish the updated date here and will clearly communicate material changes.
A question about your information?
Email IncidentMTL’s Privacy Officer. Replies are available in French or English.
bonjour@incidentmtl.com