Last updated 10 August 2026

Privacy Policy

1. Who We Are

EmergencyAPI is operated by SEY Solutions (ABN 13 531 353 123), a registered Australian business.

Contact: jack@seysolutions.com.au

2. What We Collect

When you create an account, we collect:

  • Full name
  • Email address
  • Password (hashed by Supabase, we never see or store it in plain text)
  • Company or organisation (optional)
  • Country
  • Intended use case

When you use the API, we also collect:

  • API usage data: which endpoint each of your API keys calls, how many times per day, and the response format requested. We do not record the other search parameters you send (locations, dates, states, categories), or the responses you receive.

When you sign up, log in, or confirm your email address, we also record:

  • Your IP address and the browser user agent the request was sent with. These are used for two things: rate limiting, and checking whether one person has created several accounts to obtain more than one free allowance, which the Terms of Service do not allow.

A shared IP address is never treated as proof on its own. Households, offices, universities, mobile networks and VPNs routinely put unrelated people behind a single address. It is only ever a prompt for a person to review an account, and no account is ever restricted automatically on that basis.

3. Why We Collect It

  • Account management: To create and maintain your account and API key.
  • Rate limiting: To enforce fair usage and prevent abuse.
  • Service improvement: To understand how the API is used and where to focus development.
  • Communication: To contact you about your account or service changes, and occasionally about EmergencyAPI plans and offers available to you as a registered user. Every offer email carries an unsubscribe link that stops them permanently. Notices about your account itself are always sent.

4. How We Store It

All account and usage data is stored in Supabase, hosted in the Sydney region (ap-southeast-2), Australia. Data is encrypted at rest and in transit.

The website and API are hosted on Vercel with global CDN distribution. No personal data is stored on Vercel beyond what is needed to serve requests.

5. Who We Share It With

We never sell or trade your personal data, and we do not share it with anyone for their own purposes. It reaches the following providers only because they run part of the service on our behalf:

  • Supabase - database and authentication, hosted in Sydney. Holds your account record, API keys, and your usage counts including which endpoints you call.
  • Vercel - website and API hosting.
  • Stripe - payments. Receives your name, email address and company name when you subscribe, and handles your card details directly. We never see or store a card number. Free accounts are never sent to Stripe.
  • Google Workspace - email delivery. Carries account emails such as sign-up confirmation, password resets and service notices, which means it necessarily carries your email address.
  • Google Analytics - traffic measurement on our public pages. See section 7.

Each processes data on our behalf under its own terms. Stripe and Google Analytics operate outside Australia, so data handled by those two leaves the country. Your account record, API keys and usage data stay in Sydney.

6. Cookies

We set two kinds of cookie:

  • Supabase session cookies - strictly necessary to keep you logged in. They carry no tracking data.
  • Google Analytics cookies (_ga and similar) - set on our public pages to count visitors. They are not set on the dashboard, settings or any signed-in account page.

We do not use advertising cookies, and we do not sell or share cookie data for advertising.

7. Analytics

We use Google Analytics to count visits to our public pages: the homepage, the map, documentation, pricing and the guides. It sets cookies, records your IP address and is operated by Google outside Australia.

It is not loaded on any signed-in page. The dashboard, settings, API key management and the operator console carry no analytics at all, so what you do inside your account is never sent to a third party.

You can opt out with Google's browser add-on, or any tracker-blocking extension. Doing so has no effect on the service or the API.

8. Your Rights

Under the Australian Privacy Act 1988, you have the right to:

  • Access the personal data we hold about you
  • Correct any inaccurate information
  • Delete your account and all associated data

To exercise any of these rights, email jack@seysolutions.com.au. We will respond within 30 days.

9. Data Retention

We retain your data for as long as your account exists. If you delete your account, all personal data is removed, including your usage history.

Per-endpoint usage records are kept for 400 days, then deleted automatically. That is long enough for one year-on-year comparison and no longer.

IP addresses and browser user agents recorded at signup, login and email confirmation are kept for 90 days, then deleted automatically. They are also deleted immediately if you delete your account.

You can request deletion at any time by emailing jack@seysolutions.com.au.

10. Emergency Incident Data

EmergencyAPI aggregates emergency incident data from official Australian government feeds. This data describes incidents (location, type, status) and does not contain personal information about individuals involved in those incidents.

We do not collect, store, or process any personal data about people affected by emergency incidents.

11. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page will always reflect the most recent version. Significant changes will be posted here.

12. Contact

If you have questions about this privacy policy or how we handle your data:

SEY Solutions

Email: jack@seysolutions.com.au

ABN: 13 531 353 123