User Data Deletion Policy
Last updated: January 23, 2025
At AACI Group, Inc., we respect your privacy and provide you with the ability to have your personal data removed from our systems. This User Data Deletion Policy explains how you can request the deletion of your personal information associated with the Wildfire Action Plan web application (the "Service") and how we handle such requests. It should be read in conjunction with our Privacy Policy and Terms of Service.
1. Data Covered by This Policy
This policy applies to personal data that we have collected from you and that is associated with your account or use of the Service, as described in our Privacy Policy. This includes:
Account Information: Data you provided during account registration or profile setup (e.g., your name, email address, phone number).
Plan and Usage Data: Information you entered into the Wildfire Action Plan application (such as details of your emergency plan, household information, or any notes and preferences), as well as records of your usage of the Service.
Communication Data: Any communications you've had with us (support emails, feedback submissions) that are tied to your identity.
Automatically Collected Data: Technical information and usage logs linked to your account or device (for instance, login timestamps, IP address history, etc., to the extent such data is considered personal information in combination with other identifiers).
When we perform a data deletion, we aim to remove or anonymize personal data in our active databases so that you can no longer be identified. However, please note that certain data may persist for a limited time in backups (see Section 3 below) or as part of aggregate statistics that do not identify you personally.
2. How to Request Data Deletion
If you wish to delete your account or remove your personal data from the Service, you may do so through one of the following methods:
In-App or Website Settings: If available, use the "Delete Account" or similar function within your account settings in the Wildfire Action Plan app/website. This is the quickest way to request deletion. The app may guide you through a confirmation process to ensure you intend to permanently delete your data.
Contact Us Directly: If the app does not provide a self-service deletion option, or if you prefer to make the request directly, please contact us via email at legal@wildfireactionplan.com with the subject line "Data Deletion Request." In the body of your request, include:
- The email address or username associated with your account.
- A clear statement that you want your personal data deleted (e.g., "I am requesting deletion of my account and all associated personal data.").
- Any specific data or services that you want deleted (if you do not want to delete your entire account but only certain information, please specify).
Important: For your security, the deletion request must come from the email address associated with your account (or we will need to verify that you are the account owner via other means). If someone else (an authorized agent) is making the request on your behalf, we will require written permission from you or other proof of authorization, as well as verification of your identity.
3. Verification and Processing of Deletion Requests
Once we receive your deletion request, we will take the following steps:
Identity Verification: We need to confirm that the person requesting deletion is actually the account owner (or a person authorized by the account owner). If you submitted the request through a logged-in session or from your account email, this typically serves as verification. If not, we may reach out to the email on record or ask for additional information to confirm your identity before proceeding. This is to prevent unauthorized deletion of data.
Timeline: After verification, we will begin the data deletion process. We strive to handle deletion requests promptly. In most cases, your data will be deleted from our active databases within 30 days of your request being verified. If for some reason the process takes longer (due to complexity or high volume of requests), we will let you know and keep you updated on the status.
Data in Backups: Personal data might remain in our encrypted backup systems for a period of time after deletion from active systems. These backups are maintained to ensure the integrity of our Service and for disaster recovery purposes. We do not use backup data for any active purpose other than restoration in case of emergencies. Any personal data in backups will be purged or overwritten in accordance with our regular backup retention schedule (typically within 90 days). During that retention period, your data is not accessible via the Service and is protected.
Confirmation: Upon completing the deletion (from active systems), we can confirm to you that your request has been honored. We will either send a confirmation email or provide a notice that your account has been deleted. After this point, you will no longer be able to log in to the Service with that account, and your personal data associated with it will be gone (subject to the exceptions in Section 4 below).
Keep in mind that deletion is irreversible. Once your data is deleted, we cannot recover it. If you simply wish to take a break from the Service, you might consider deactivating your account (if that option is available) instead of deletion.
4. Exceptions and Data Retention Obligations
While we will make every effort to comply with your deletion request, there are certain circumstances where we may retain some information, despite a deletion request, due to legal or legitimate business obligations:
Legal and Regulatory Requirements: We may retain certain data if necessary for legal compliance. For example, we might keep records of transactions or payments (if any) for accounting/tax purposes, or information needed to comply with consumer protection or data privacy laws (such as keeping a record that we fulfilled a deletion request). Another example is retaining data if required by law enforcement or a court order. In all such cases, we will retain only the minimum amount of data necessary and only for the duration required by law.
Security, Fraud Prevention, and Abuse: If we believe a user has violated our Terms of Service or engaged in malicious behavior (fraud, harassment, spamming, etc.), we might retain certain information to protect our interests, address disputes, or enforce our policies. For instance, we may keep records to identify that user to prevent them from creating a new account and repeating the behavior. Similarly, data needed to detect security incidents or protect against fraudulent or illegal activity may be retained.
Direct Communications: Emails or communications you send to us might be retained in our email archives, especially if they are needed for future reference (for example, a record of customer support correspondence). These archives are typically separate from the main user database, and we may retain them for a period even after your account is deleted, but we will not contact you or use those communications except as necessary for legal or internal record-keeping purposes.
Anonymous or Aggregated Data: We may continue to use data that has been anonymized or aggregated in a way that it no longer identifies you personally. For example, after deleting your personal information, we might still keep aggregated statistics like "X number of users created wildfire plans in 2025" or "percentage of users in each region". These statistics do not contain any personal data and are only used for analytical or business purposes.
Backup Retention: As noted, your personal data may remain for a time in our encrypted backups. These are inaccessible in the normal course of business and are only used for disaster recovery. We will let backups containing personal data age out and be deleted/destroyed on our regular schedule.
In all scenarios above, any retained data will continue to be protected in accordance with our Privacy Policy and applicable laws. We will not use retained data for any new purposes not disclosed in our Privacy Policy.
5. Third-Party Platforms and Services
The Wildfire Action Plan Service might interact with third-party platforms or services in certain cases. For example, you might have the option to log in using a third-party account (like Google or Facebook), or our app might use third-party APIs (such as mapping services or notification services). It's important to understand that deleting your data on our Service does not automatically delete data held by those third-party services.
If you used an external account to sign up or log in (e.g., "Sign in with Google"), you should also check that third-party account's settings for any connected permissions or data storage. Similarly, if you integrated our Service with another (for example, linking it to a cloud storage or social media account), you may need to disable or remove those connections from the third-party service's side.
We will notify any third-party processors that are fully under our control (i.e., those who process data solely on our behalf, like our cloud hosting provider) of the deletion request so they can also remove your data from their systems. However, for independent data controllers (like a payment processor, if you made a purchase, or a login provider), you may need to contact them separately. Please refer to the privacy policies of any third-party services you use in connection with Wildfire Action Plan for their data deletion processes.
6. Changes to This Policy
We may update this User Data Deletion Policy from time to time. Changes may be needed to reflect updates in our Service, practices, or for legal reasons. When we make changes, we will revise the "Last Updated" date at the top of this policy. If changes are significant, we may also provide a more prominent notice or email notification about the update.
We encourage you to review this policy periodically, especially before requesting data deletion, to stay informed about how we manage deletion requests. Your continued use of the Service after the effective date of an updated policy will signify your acceptance of the changes. If you do not agree to any revised terms, please refrain from using the Service and contact us to delete your data.
7. Contact Us
If you have any questions about this User Data Deletion Policy, or if you wish to follow up on a deletion request, please contact us. We are here to help.
Email: legal@wildfireactionplan.com (Please include "User Data Deletion" in the subject for quicker routing)
Mail: AACI Group, Inc. – Privacy/Data Deletion Request, 2001 Clayton Road, Suite 200, Concord, CA 94520
Additional Contact Options: If we offer in-app support or a contact form, you may also use those to reach out regarding data deletion.
Please note that for your security, we may not discuss specifics of an account deletion unless we have verified that we are communicating with the account owner or their authorized agent.
Thank you for using Wildfire Action Plan. We value your trust and are committed to protecting your privacy.