Privacy Policy

Bintel Inc. · Effective September 14, 2026 · Terms of Use · Accessibility

This Privacy Policy explains what information Bintel Inc. (“Bintel”, “we”, “us”) collects when you use the Bintel online services, including https://cwpp.us, the public pages organizations publish there, the emails we send, and our field app when it is released (together, the “Services”); how we use and share it; how long we keep it; and the choices you have. It should be read with the Terms of Use.

In short: we collect what the Services need to work and to be kept secure; we record how pages are used so we can fix problems; we do not sell your personal information or use it for advertising; and many of the people and places in the Services belong to the organizations that use them, which decide what they collect.

1. Who we are

Bintel Inc. provides the Services from the United States. You can reach us about privacy at thomas.marsh@bintel.io, or by mail at Bintel Inc., 331 S 104th St, Suite 215, Louisville, Colorado 80027.

Organizations — for example fire districts, counties, conservation groups and their partners — use the Services to publish maps, advisories, forms and documents, to run email lists, and to meet in live rooms. When an organization does this, it decides what information is collected and why, and Bintel handles that information on the organization’s behalf. See “Information organizations control” below.

2. Information we collect

What we collect depends on how you use the Services. Some features are open to anyone; others need a Bintel Account.

Account and sign-in information. You sign in with Google or Microsoft. We receive your name, email address and, from Google, a link to your profile picture. These are kept in your sign-in cookie; we do not copy your Google or Microsoft profile picture into our database. We record which sign-in provider you used and when you signed in and out.

Profile and settings. Information you add yourself: a display name, job title, team, phone number and the organization you belong to; a profile photo if you upload one; your display preferences; the version and time you accepted the Terms of Use; and acknowledgements of an organization’s disclaimer.

Organization membership. The organizations you belong to and your role in each, including who invited you.

Content you create or upload. Maps, layers, data files and tables, documents, guides, advisories and their updates, viewpoints and their annotations, comments, and anything else you add to the Services.

Form responses. Answers to forms an organization publishes — the questions are the organization’s, and may ask for names, contact details, addresses, descriptions, a signature, a location or photographs. If you are signed in, your name and email address are attached to your response. Some public forms accept responses without signing in. We do not attach your IP address to form responses.

Photographs and the information inside them. See “Location information” below: the photographs you upload keep the location and other details your camera stored in them.

Location information, when you choose to provide it. See “Location information” below.

Live rooms. Your display name, colour, role and an optional device label; when you join, leave and move between rooms; chat messages, reactions and drawings; voice and video while you are on a call; recordings of presentations; and your location if you choose to share it. See “Recordings” and “Location information” below.

Email subscriptions. Your email address, whether and when you confirmed it, who added you to a list (you or an organization administrator), and when you unsubscribed. For each advisory update sent by email, a record of the addresses it was sent to and whether delivery succeeded.

Usage, device and log information. When you visit the Services — signed in or not — our servers and your browser send us information including your IP address; your browser and device type (user agent); the pages and files you request, including the full address and the page you came from; the date and time; your screen size, language and time zone; and your approximate location (country, region, city and approximate coordinates) derived from your IP address by our hosting provider. We also record how pages are used; see “Recordings” below.

Security and audit records. A record of significant actions — who signed in, who changed a map, granted a role, published an advisory or downloaded an export, and when. These records identify the person by email address; they do not contain IP addresses or the content of what was changed.

Communications with us. If you email us, the contents of your message and your contact details.

3. Where the information comes from

  • From you, when you sign in, fill in a form, upload a file, subscribe, share your location or join a room.
  • From your organization, when an administrator invites you, gives you a role, or adds your email address to an email list. Organizations must record where a list’s addresses came from.
  • From Google or Microsoft, when you sign in with them.
  • Automatically, from your browser or device, when you use the Services.
  • From other people, when they mention, invite or add you, or submit information that includes you.

4. How we use information

  • To provide the Services: to sign you in, show you what you are allowed to see, save your work, deliver forms and advisories, run live rooms, and send the emails you or your organization asked for.
  • To place things on a map, including photographs, form responses and tracks.
  • To keep the Services secure and available: to block abuse and automated attacks, limit request rates, investigate incidents, and keep audit records.
  • To find and fix problems and to improve the Services, including by watching recordings of how pages were used and by counting visits and page views.
  • To communicate with you about your account, changes to the Terms or this Policy, and the Services.
  • To comply with law, respond to lawful requests, and enforce our Terms.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for targeted advertising. We do not use your content to train artificial-intelligence models. We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.

5. Information organizations control

When an organization uses the Services to collect or hold information — its members’ profiles and roles, form responses, email lists, advisory subscriptions, room chat and recordings, and the files, maps and documents in its workspace — that organization decides what is collected and how it is used, and is responsible for having the right to collect it. For that information Bintel acts as a service provider (sometimes called a processor) on the organization’s behalf and uses it only to provide the Services to the organization and as described in this Policy.

Organization administrators can see and manage their organization’s content, including form responses and email lists. They can also see the profile details you add (name, title, team, phone and member organization) unless you turn off sharing with organization administrators in your account settings; sharing is on unless you turn it off.

If you have a question or request about information an organization holds — for example, to correct or remove a form response or be removed from its email list — please contact that organization. If you contact us, we will pass your request to the organization, and we will help it respond.

A public agency that uses the Services may be required by open-records laws to disclose information submitted to it.

6. Public content

Organizations choose whether what they publish is public, visible to their members, or private. Anything published as public — public maps, advisories, forms, documents, viewpoint collections, rooms and presentations — can be seen by anyone on the internet, can be found by search engines, and may be copied by others. That includes a public viewpoint’s location and the direction it faces, and the recording of a presentation that its organization makes public. Think before you add personal information to something public, and ask the organization if you want something removed.

7. Location information

Photographs. Most phones and cameras store information inside each photograph, which can include the precise place it was taken (GPS coordinates), the direction the camera faced, the time, and the camera’s make and model. When you upload a photograph to a form, a viewpoint collection, a guide or a document, we keep the original file as you uploaded it, including that information, and we read the location, direction and time to place the photograph on a map. The smaller copies of form and viewpoint photographs we show to people do not contain this information, and the original file can be downloaded only by members of the organization who have download rights. A photograph uploaded as a document, however, is shared as the file you uploaded — including that information — with whoever can see the document. The location and direction we read from a photograph are shown with it to anyone who can see it. If you do not want a photograph’s location used, remove it before uploading (many phones let you turn off location for the camera).

Your device’s location. The Services ask your browser or phone for your location only when you use a feature that needs it, and your device will ask for your permission first:

  • Answering a location question on a form, or taking a photograph in a form, saves your location (and, for photographs, its accuracy, altitude and compass heading) with your response.
  • “Show my location” on a map, and checking whether you are inside an advisory area, are worked out on your device and are not sent to us.
  • Recording a track saves your location points in your browser while you record. When you save the track it is stored in your account, where only you can see it, until you delete it.
  • Sharing your location in a live room sends it to the other hosts and participants in the room while you share it — and, during a public presentation in a public room, to its observers. Shared locations are kept with the room’s records and included in its archive.
  • Our field app, when released, can record a track in the background while you choose to record, with a notification showing while it does.

Approximate location. We derive an approximate location — country, region, city and approximate coordinates — from your IP address, as described under “Information we collect”.

8. Recordings

Recordings of how pages are used. To find and fix problems, the Services record how pages are used, for visitors who are signed in and those who are not. A recording captures what the page showed, including its text, and what you did on it — mouse movements, scrolling, clicks and page changes — together with the page address, the page you came from, your browser, screen size, language, time zone and approximate location, and, if you are signed in, your email address. What you type into fields is replaced with asterisks by default, and passwords are never recorded. Maps are not recorded. Recordings are stored by Bintel on our own hosting (they are not sent to an analytics company), can be watched only by a small number of Bintel administrators, and are deleted after no more than 90 days.

Voice, video and presentations in live rooms. Calls in a live room are carried by Amazon Web Services. A call is not recorded unless a presentation is being recorded. When a presentation is recorded — which is the default when a host starts one — the recording includes the call’s audio and video (including cameras and shared screens) and a replay of what happened in the room during it: pointers, chat, drawings, and shared locations. The room’s home page shows when a presentation is being recorded. Presentation recordings are deleted on the same schedule as recordings of how pages are used, no more than 90 days after the presentation ends; until then they can be watched by the room’s members or, if the organization makes the presentation and room public, by anyone. The rest of the presentation’s record — when it ran, who presented, and the replay of what happened in the room — is kept with the room. Recording laws in some places require everyone’s consent before a conversation is recorded; hosts are responsible for telling participants and obtaining consent where required.

Room chat and activity are kept with the organization’s room, and are included in the archive created when the room is closed.

9. Cookies and similar technologies

We use a small number of cookies, all of them needed for the Services to work, and no advertising or cross-site tracking cookies:

  • Sign-in cookies, which keep you signed in (for up to 30 days) and protect sign-in from forgery.
  • A short-lived cookie (two minutes) that lets your browser load the map tiles you are allowed to see.
  • A guest pass cookie, for up to seven days, when you join a room with an invitation link.

We also store preferences in your browser’s local storage — for example your panel sizes, the view you last used, device choices for calls, which advisories you have seen, and, if you are not signed in, that you accepted an organization’s disclaimer — and keep a recorded track or cached weather data in your browser until it is saved or expires. A session identifier for page recordings is kept only for the browser tab you have open.

Some pages include content from other companies, which your browser loads directly from them and which receives your IP address and browser information: website icons for outside links (from Google); videos and documents an organization embeds in a guide (from YouTube in privacy-enhanced mode, Vimeo or Google Docs, which may set their own cookies); link preview images and live radio streams in rooms (from the linked site or stream); and map imagery or data an organization has chosen from an outside provider. Their privacy policies apply to what they receive.

Your browser may send a “Do Not Track” signal or a Global Privacy Control signal. Because we do not sell personal information or use it for targeted advertising, there is nothing for those signals to opt you out of; we do not otherwise change how the Services behave in response to them.

10. How we share information

We share information only in these ways:

  • With your organization, and with the people you work with in it, as the Services are designed to do — for example, an organization’s administrators see its form responses, and people in a room see your name and messages.
  • Publicly, when you or your organization publish something as public.
  • With service providers who run parts of the Services for us under contract and may use the information only to do so: Amazon Web Services (hosting, storage, content delivery, security, email delivery through Amazon SES, and voice, video and recording through Amazon Chime), and Google and Microsoft (sign-in).
  • With the people you send things to — for example, a form response report you email to someone.
  • When required by law or legal process, or when we believe in good faith it is needed to protect the safety, rights or property of anyone, or to investigate fraud or security issues. Where the request concerns an organization’s information, we will refer it to the organization unless the law prevents us.
  • As part of a merger, acquisition, financing or sale of all or part of our business, in which case this Policy will continue to apply to the information transferred.
  • With your consent or at your direction.

11. Email

Emails from the Services are sent through Amazon SES. We do not track whether you open emails or click their links. Email-list and advisory messages include a way to unsubscribe. When you unsubscribe from an organization’s email list, we keep a record that you unsubscribed so that the address cannot be added back to that list; when you unsubscribe from an advisory, your subscription is deleted. Service messages about your account, and notices of changes to the Terms or this Policy, are sent while you have an account.

12. How long we keep information

  • Account, profile and membership information: while your account exists, and deleted within 90 days after it ends, as described in the Terms of Use.
  • Content, form responses, rooms, chat and room archives: for as long as the organization that owns them keeps them, or until they are deleted; after an organization’s use of the Services ends, as described in the Terms of Use.
  • Your recorded tracks and your profile photo: until you delete them, or your account ends.
  • Recordings of how pages are used, and the audio and video recordings of presentations: no more than 90 days (for a presentation, after it ends). Both are deleted on the same schedule.
  • Server and security logs, including IP addresses and user agents, and the per-visitor details in our usage statistics: 90 days. Usage statistics that do not identify anyone (counts of visits and pages) may be kept longer.
  • Email-list unsubscribe records: for as long as the list exists, so that we can keep honouring your choice.
  • Security and audit records: for as long as needed for security, compliance and legal purposes, which may be several years.
  • Backups and records we must keep by law, or to resolve disputes and enforce our agreements: for as long as those purposes require.

13. Security

We use reasonable administrative, technical and physical safeguards designed to protect information, including encryption in transit (HTTPS) and at rest, access limited by role and checked on every request, blocking public access to stored files, web application firewall protection, and audit records of significant actions. No method of transmission or storage is completely secure, and we cannot guarantee security. If we learn of a breach affecting your personal information, we will notify you and others as the law requires.

14. Your rights and choices

Choices you can make yourself in the Services:

  • Update your profile, turn off sharing your profile with organization administrators, and upload or delete your profile photo in your account settings.
  • Delete your recorded tracks.
  • Decline or stop sharing your location, and control location access in your browser or phone settings.
  • Unsubscribe from any email list or advisory using the link in the email.

Requests you can make of us. Depending on where you live, you may have the right to ask us to confirm whether we process your personal information; to access it and receive a copy in a portable format; to correct it; to delete it; and to opt out of its sale, of targeted advertising, and of profiling that produces legal or similarly significant effects (we do none of these). Some state laws also give you the right to appeal our decision about your request, and to use an authorized agent.

Where these laws apply. US state privacy laws, including the Colorado Privacy Act and the California Consumer Privacy Act, apply to businesses that meet thresholds based on revenue or on the number of state residents whose information they process — for example, under the Colorado Privacy Act, controllers that process the personal data of 100,000 or more Colorado consumers in a year, or 25,000 or more while deriving revenue or discounts from selling personal data; and under the California law, businesses with annual gross revenue above an inflation-adjusted threshold (about $26.6 million), or that buy, sell or share the personal information of 100,000 or more California consumers or households, or earn half or more of their revenue from selling or sharing it. Bintel is a small company and may not currently meet these thresholds. We will nonetheless honour the requests described above from anyone, wherever they live, as far as we reasonably can.

How to make a request. Email thomas.marsh@bintel.io and tell us what you are asking for. We will confirm your identity — usually by corresponding with you at the email address on your account — before acting, and will respond within 45 days (or tell you if we need up to 45 more days and why). If your request concerns information an organization controls, we will pass it to that organization. If we decline your request, we will explain why, and you may appeal by replying to our decision with the word “Appeal”; we will respond to an appeal within 45 days. If you are in Colorado and are not satisfied with the outcome of your appeal, you may contact the Colorado Attorney General. We will not discriminate against you for exercising your rights.

15. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Bintel Accounts are for people 18 and older. If you believe a child under 13 has given us personal information — for example by submitting a public form or subscribing to email — contact us at thomas.marsh@bintel.io and we will delete it.

16. Where information is processed

Bintel is based in the United States, and the Services are hosted by Amazon Web Services in the United States. If you use the Services from outside the United States, your information will be transferred to, stored and processed in the United States, whose data protection laws may differ from those where you live. The Services are intended for organizations and people in the United States.

17. Changes to this Policy

We may update this Policy as the Services change. We will post the updated Policy here with a new effective date. If we make a material change — for example, to collect a new category of information or use information in a new way — we will tell account holders by email to the address on their account, and by a notice in the Services, before the change takes effect. Where the law requires your consent to a change, we will ask for it.

18. Contact

Questions, requests and complaints about privacy go to thomas.marsh@bintel.io, or by mail to Bintel Inc., 331 S 104th St, Suite 215, Louisville, Colorado 80027.

Bintel