Legal
Privacy Policy
Effective September 11, 2026. This policy is a working draft prepared for Worldwide Wilderness and should be reviewed by your attorney before the site goes live — in particular against the requirements of any state privacy law that applies to your users.
1. What we collect
Everyone: the pages you request and standard server logs (IP address, browser, time). We don't run third-party analytics or advertising trackers; fonts load from Google Fonts, which sees your IP address when they're fetched. Searches on the job board are logged (with your account ID if you're logged in) so alert emails can match what people look for.
Providers (job seekers): name, email, password (stored only as a bcrypt hash), job-alert preferences and the certifications you say you hold, your Clinical Profile (highest certification, specialized training, operational experience), and — if you choose to be verified — the credential documents you upload (state license or NREMT card, wilderness upgrade certificate, BLS card, board certificates) with the credential type, issuer, number, name on the document, and dates. For rapid deployment: your mobile number, SMS consent and its timestamp, and your availability toggle. For the public registry: a random registry ID and your publish setting.
Contractors: company and contact name, email, phone, password hash, the vetting packet you upload (one PDF: medical-director agreement, SAM.gov profile, state EMS license, certificate of good standing, certificate of insurance, MEDEVAC SOP and PACE plan) and the numbers you enter for lookups (Medical Director's MD/DO license and DEA registration, CAGE code, SAM UEI, state EMS license, EIN), your public profile text and logo, the crew calls you draft and broadcast, and the roster commitments you receive.
Employers posting listings: the listing, a contact email, optional company name and logo, and which upgrades were bought. Payment card details go directly to Stripe; we receive only a payment reference, the amount, and your email.
2. How we use it
To run the Platform: publish listings, email job alerts you asked for, verify credentials and contractors, match crew calls to providers, send deployment texts you consented to, build compliance manifests, draw registry cards and badges, process payments and refunds, and notify you about your account. We use email and SMS only for the transactional messages described here and any alerts you subscribed to (job alerts, a contractor's alerts); you can turn each off on your Account page.
3. Who sees what
Your credential documents and numbers are visible to you and to Platform administrators, and to a contractor only after you accept one of their crew calls — that acceptance releases your verified documents into that contractor's compliance manifest for that deployment. They are never shown on your public registry page, your badge, or your preview card. Your public registry profile (if you switch it on) is public: name, highest credential, status, specialized training, and each verified credential's type, issuer, expiry, and verification date. Contractor vetting packets and lookup numbers are visible only to the contractor and administrators; a published Verified Contractor Profile shows the company name, logo, description, Medical Director name and board certification, protocol level, federal agreements, gear standards, CAGE code, and live listings — not license, DEA, EIN, or insurance details. Providers who subscribe to a contractor's alerts are counted on that contractor's profile; their identities are not shown to the contractor.
Service providers who process data for us: our web host (cPanel/PHP/MySQL), Stripe (payments), Twilio (SMS delivery — they receive the mobile number and message text), and Google Fonts. We don't sell personal information and don't share it for advertising. We'll disclose information if the law requires it or to protect the safety of a user — for example, reporting falsified medical credentials to the issuing body.
4. SMS consent
Deployment texts are sent only to numbers whose owner ticked the consent box on their Account page. Consent is recorded with a timestamp. Reply STOP to any message to block further texts at the carrier level, or clear the box on your Account page; either stops us from including you in future broadcasts. Message frequency varies with incident activity; message and data rates may apply.
5. Retention and security
Account data is kept while your account is open. Credential documents are kept while your account is open so an expired credential can be re-verified; you can replace a document at any time by re-uploading. Contractor vetting packets are kept while the account is open. Crew-call and roster records, listing and payment records, and verification decisions are kept as business records after an account closes. Uploaded documents are stored outside direct web access and can be read only through authenticated endpoints; passwords are bcrypt-hashed; links in emails and texts use random single-purpose tokens stored only as hashes. No system is perfectly secure, and if we learn of a breach affecting your data we'll notify you as the law requires.
6. Your choices and rights
You can edit your profile, preferences, availability, consent, and public-registry setting on your Account page at any time, and a contractor can edit or unpublish its profile from the dashboard. To access, correct, export, or delete your personal information, or to close your account, email dfsn@3-w.org; we'll respond within 30 days, subject to records we must retain. Depending on where you live you may have additional rights under state privacy law, which we'll honor.
7. Children, changes, contact
The Platform is for adults and we don't knowingly collect information from anyone under 18. We may update this policy; material changes will be posted here with a new effective date. Questions or requests: dfsn@3-w.org.