Medstar Ambulance of Mendocino County, Inc.
A California 501(c)(3) Nonprofit Corporation
Applies to: medstarmendocino.org and all associated digital services, platforms, and physical systems
Medstar Ambulance of Mendocino County, Inc. (“Medstar,” “we,” “our,” or “us”) is a California 501(c)(3) nonprofit corporation providing emergency and non-emergency ambulance services in Mendocino County, California. We do not sell your personal information. We are committed to protecting the privacy and security of the information we collect through our digital services, physical systems, and operational activities.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights with respect to it. It applies to:
By using our services or interacting with any of the above, you acknowledge this Privacy Policy. If you have questions, contact us at [email protected] or at the address in Section 14.
We collect personal information you voluntarily provide through forms, applications, and communications, including:
When you visit our website, we may automatically collect:
Our telephone system may record calls for quality assurance, training, and operational purposes. Calls to or from Medstar may be recorded. Caller ID information and call metadata (date, time, duration) are logged by our phone system and underlying telecommunications providers. Call recordings are stored on our secure systems.
When you interact with our SMS campaigns or respond to text messages, we collect your mobile phone number, message content, timestamps, and delivery status. Our SMS services are registered under applicable 10DLC (10-Digit Long Code) campaign requirements with The Campaign Registry (TCR).
We operate password-protected guest Wi-Fi networks at our facilities and in our vehicles. These networks are not public hotspots; access is limited to individuals with the network password. When you connect to a Medstar guest Wi-Fi network, we collect connection data including your device MAC address, device name, connection timestamps, and bandwidth usage.
Notice regarding deep packet inspection (DPI): Our network infrastructure, including guest Wi-Fi networks, utilizes deep packet inspection technology. DPI analyzes the characteristics and metadata of network traffic for purposes of network security, threat detection, bandwidth management, and operational integrity. DPI is used for network management and security purposes only — not to monitor, read, or log the content of personal communications beyond what is necessary for those purposes.
Use of our guest Wi-Fi constitutes acknowledgment of these network monitoring practices. If you prefer not to have your traffic subject to DPI, we recommend using your cellular data connection instead.
NOTICE: Video recording is in operation at and around Medstar facilities, including parking areas and building exteriors. Recording occurs continuously or on motion detection. Audio recording is disabled on all facility security cameras. The areas monitored are not private spaces, and signage is posted at facility entrances providing notice of video recording. Recordings are used for security, safety, and operational purposes only.
AI-assisted motion detection: Facility security cameras use AI-assisted motion detection to classify movement within defined areas as persons, vehicles, or animals for alert and notification purposes. This classification does not involve facial recognition, individual identification, or the creation of any persistent biometric identifier.
NOTICE: One or more Medstar Ambulance vehicles are equipped with dual-facing video recording and AI-assisted behavior monitoring systems. Cameras record both the road-facing exterior environment and the vehicle cab interior, including the driver and front seat passenger. Audio recording is disabled on in-vehicle cameras. Vehicle cameras are not positioned or intended to capture the patient care compartment and are not expected to capture PHI related to patient care.
AI-assisted monitoring and video capture events: In-vehicle cameras use artificial intelligence to continuously analyze driver and front seat passenger behavior in real time and automatically capture and upload a video clip to the fleet management platform when any of the following events are detected:
Behavior and performance events: cell phone use while driving; distracted driving; driver seat belt undone; passenger seat belt undone; driver yawning (drowsy driving); smoking; tailgating; rolling stop; speeding (currently configured at 18 or more MPH over the posted limit to account for emergency vehicle operation); possible collision; lens obstruction; incorrect PIN entry; unauthorized device removal.
Vehicle and system events: battery drain; critical low tire pressure; engine abuse (RPMs over 7,000); camera button pressed. Vehicle and system events may still result in capture of footage of vehicle occupants.
Detection of driver behavior involves real-time analysis of eye movement, head position, and body position. Tailgating and collision detection use road-facing video analysis. This system does not create, store, or transmit persistent biometric identifiers or facial recognition templates. Video capture rules and detection thresholds are subject to change. When a capture event occurs, the system generates a record including the event type, timestamp, GPS location, vehicle ID, and an associated video clip, which is transmitted to and stored within our fleet management platform.
Recordings and behavioral event data are used for safety monitoring, driver coaching, quality assurance, incident review, insurance, and legal and compliance purposes. Crew members have been separately notified and have acknowledged in-vehicle recording and AI monitoring as a condition of employment or service.
We use the information we collect for the following purposes:
Medstar operates primarily in California and complies with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). As a nonprofit organization, certain CCPA provisions apply with limitations; however, Medstar voluntarily extends meaningful privacy rights to all individuals whose data we process.
We collect and process personal information based on one or more of the following:
We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising.
We do not sell, rent, or trade personal information. We may share information only in the following circumstances:
We share data with vendors and platform partners who help us operate our services, subject to data processing agreements and confidentiality obligations. Current providers are listed below; this table will be updated as our vendor relationships change without requiring amendment to the substantive provisions of this Policy.
| Provider / Platform | Purpose | Data Categories Shared |
|---|---|---|
| Wild Apricot | Member database, website, event registration | Name, contact info, membership data, payment records |
| AffiniPay | Payment processing (PCI-compliant) | Name, billing address, payment card data |
| Jotform | Online forms and applications | Name, contact info, application data, consent records |
| Microsoft 365 | Productivity and document management | Documents, email, operational data |
| Voxtelesys | SIP trunking, hosted DIDs, SIP voice and SMS services; 10DLC campaign registration | Phone numbers, call metadata, SMS content |
| Twilio | SIP trunking, hosted DIDs, SIP voice and SMS services (redundant carrier) | Phone numbers, call metadata, SMS content |
| 3CX | Unified communications platform; telephone system, voicemail, and SMS messaging client | Call records, voicemail, call recordings, SMS message logs |
| Ubiquiti / UniFi | Guest Wi-Fi infrastructure and network management — facilities | Device identifiers, connection logs, DPI traffic metadata |
| Ericsson / Cradlepoint | Vehicle-based Wi-Fi infrastructure and network management | Device identifiers, connection logs, DPI traffic metadata |
| Geotab | Fleet management platform; AI-assisted driver behavior monitoring and vehicle telematics | GPS/location data, vehicle telematics, behavioral event records (alert type, timestamp, location, video clip) for enabled AI detections; no biometric identifiers or facial embeddings generated or stored |
| Aladtec | Employee shift scheduling, workforce management, and certification/qualification tracking | Employee name, contact info, schedule, availability, shift records, certifications, qualifications, and expiration dates |
| Vector Solutions / Target Solutions | Online employee training and certification tracking | Employee name, training records, completion status, certification history |
| Operative IQ | Vehicle maintenance, rig checks, and supply management | Employee name associated with rig check and maintenance records; vehicle and equipment data |
| Bryx 911 | CAD dispatch alerting application | Employee name, mobile device identifiers, dispatch notifications |
| SRFax | Online fax transmission service | Content of faxed documents; may include sensitive operational, HR, or clinical data |
| Google Workspace | Email, document storage, collaboration, and directory; primary identity provider (IdP) via OAuth/SAML for connected vendor platforms | Email content, documents, employee contact info, employee photos, authentication tokens, login activity, and user identity assertions shared with connected services |
| Amazon / Ring | Facility security cameras | Video recordings only (audio disabled) |
| ImageTrend Elite | Electronic patient care records (ePCR) — PHI | Governed separately by HIPAA NPP |
| ImageTrend Elite | Personnel and credentialing database; Medstar user administration | Employee name, contact info, and supplemental certifications added by Medstar; core EMT/paramedic certification and licensure records are maintained by CVEMSA (Coastal Valleys EMS Agency) as the local EMS agency under their ImageTrend contract |
| Intuit / QuickBooks Workforce | Payroll processing and employee pay portal | Employee name, SSN, compensation, tax records, W-2 data |
Note: Employee ID numbers — internally assigned identifiers used to distinguish personnel records — may be present across multiple platforms listed above. These numbers are not independently personally identifiable and are used solely as internal record-keeping references.
We may disclose information when required by law, court order, or government authority, including in response to valid subpoenas, public records requests under the California Public Records Act (where applicable), or lawful requests from law enforcement.
We may disclose information to protect the safety of individuals or the public in emergency situations, consistent with applicable law.
In the event of a merger, acquisition, consolidation, or transfer of substantially all assets of Medstar (including to another nonprofit organization), personal information may be transferred as part of that transaction. We will provide notice of any such transfer and the privacy protections that will apply to the transferred data.
Our website uses cookies and similar technologies to enable site functionality, remember preferences, and analyze usage. Cookie categories include:
Our website hosting platform may set its own cookies as part of the hosted service. You can control cookies through your browser settings; however, disabling certain cookies may limit site functionality. We do not use cookies for cross-site advertising or behavioral tracking.
Identity provider and single sign-on: Medstar uses Google Workspace as its primary identity provider (IdP), enabling employee authentication across connected vendor platforms via OAuth and SAML protocols. When you sign in to Medstar services or integrated vendor platforms using Google Workspace credentials — or using a “Sign in with Google,” “Sign in with Microsoft,” or “Sign in with Apple” option on any of our platforms or services — the respective identity provider (Google, Microsoft, or Apple) receives authentication signals including login activity, user identity, and the service being accessed. This authentication data is governed by the identity provider’s own privacy policy. Medstar does not control the data practices of these identity providers beyond the scope of our service agreements with them.
Medstar operates SMS messaging campaigns for the following purposes, registered with The Campaign Registry (TCR) under applicable 10DLC requirements:
We send SMS messages only to individuals who have provided prior express written consent. Consent is obtained through:
Consent to receive SMS is voluntary. Denial of consent will not affect your ability to apply for employment or access our services.
You may opt out of SMS communications at any time by replying STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message from us. After opting out, you will receive a single confirmation and no further messages. Reply START to re-subscribe. Reply HELP for contact information. You may also email [email protected] to opt out or request assistance.
Medstar’s SMS service is available on most major U.S. carriers. Not all carriers or devices may support all features of the service. Message and data rates may apply; contact your wireless provider for details.
Medstar retains personal information for the periods listed below, or as otherwise required by applicable law. Retention periods reflect California EMS regulatory requirements, generally accepted nonprofit governance practices, and operational needs.
| Data Category | Retention Period | Legal / Regulatory Basis |
|---|---|---|
| Website analytics / cookies | 13 months | Standard analytics retention; CalOPPA compliance |
| Contact / inquiry form submissions | 3 years | Statute of limitations; operational records |
| Donation records | 7 years | IRS / nonprofit tax records; CA Revenue & Tax Code |
| Membership enrollment records | 7 years after membership ends | Nonprofit recordkeeping; statute of limitations |
| CPR / training class records | 5 years | Certification recordkeeping; liability |
| Employment applications (hired) | Duration of employment + 7 years | California Labor Code; EEOC requirements |
| Employment applications (not hired) | 3 years | EEOC / CA DFEH recordkeeping requirement |
| Payroll and HR records | 7 years after separation | California Labor Code § 1198.5; IRS requirements |
| Call records / metadata | 1 year | Operational; no specific EMS mandate |
| Call recordings | 90 days routine; indefinite if on hold | Quality assurance; legal hold policy |
| SMS consent records (opt-in documentation) | 5 years | FTC Telemarketing Sales Rule (16 C.F.R. § 310.5); TCPA compliance; maintained in form submission platform |
| SMS message logs (content and metadata) | 4 years | TCPA statute of limitations; maintained in telephone system archive on local file server |
| Wi-Fi connection logs / DPI metadata | 90 days | Network security and troubleshooting |
| Facility video recordings | 60 days routine; indefinite if incident | Security; Cal. Penal Code compliance |
| Vehicle dash cam recordings | 30 days cloud (Surfsight/Geotab platform limit); SD card loops continuously; incident recordings must be downloaded within 30 days of the event for preservation | Safety; quality assurance; legal hold |
| AI behavioral event data (Geotab/Surfsight) | 30 days cloud (Surfsight/Geotab platform limit); incident events must be downloaded within 30 days of the event for preservation | Driver safety; coaching; legal hold; insurance |
| Incident-related recordings | Indefinitely or until legal resolution | Litigation hold; regulatory investigations |
| PHI / Patient care records | Governed by HIPAA NPP | HIPAA; CA Health & Safety Code § 123111 |
Medstar implements reasonable administrative, technical, and physical security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:
On-premises data storage: Certain employee data — including photos used for identification and ID badge production, and employee names used for physical access control — is maintained exclusively on secure on-premises systems under Medstar’s direct control, including encrypted local file servers and locally installed software. This data is not transmitted to or processed by third-party cloud services.
No method of transmission or storage is 100% secure. In the event of a security breach affecting your personal information, we will notify affected individuals as required by California Civil Code § 1798.82 (California Data Breach Notification Law).
Under the CCPA/CPRA, California residents have the following rights with respect to their personal information:
To exercise your rights, contact us at [email protected] or by mail at the address in Section 14. We will respond within 45 days as required by law. We may need to verify your identity before processing requests. Authorized agents may submit requests on your behalf with written authorization.
Our online Services are not intended for or directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected personal information from a child under 13, we will delete it promptly.
We do, however, collect information regarding minors when voluntarily provided by a parent or legal guardian for the purpose of household membership enrollment. Such information is used solely in connection with the membership and is not used for marketing or shared with third parties beyond what is necessary to administer the membership. Medical information related to minors is governed by our HIPAA NPP. If you believe a child has had information submitted about them inappropriately, please contact us at [email protected].
Our website and services integrate with or link to third-party platforms. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through our website or forms. Links to external websites do not constitute endorsement.
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or operational systems. When we make material changes, we will update the “Last Revised” date at the top of this Policy and, where appropriate, provide additional notice such as a notice on our website or via email to members. Your continued use of our services following an update constitutes acceptance of the revised Policy.
For privacy questions, requests, or concerns, contact Medstar Ambulance of Mendocino County, Inc.: