Privacy Policy

MFB Case Monitor mobile application

App name: Case Monitor
App version: 1.0.1
Policy version: 1.1
Last updated: July 13, 2026
About this app: MFB Case Monitor (display name: Case Monitor) supports emergency response and case monitoring for authorized Mumbai Fire Brigade (MFB) personnel. Features include events, units, maps, messaging, push notifications, contacts, and an operational dashboard.

Introduction

This Privacy Policy explains how MFB Case Monitor collects, uses, stores, and protects personal information on Android and iOS. The App is for authorized MFB personnel only and requires organizational credentials.

1. Information We Collect

1.1 Account Information

1.2 Location

Foreground only: Location is collected only while you actively use the App (Map/Events). We do not track location in the background.

1.3 Contacts

1.4 Communication & Operations

1.5 Device & Technical Data

1.6 Not Collected

2. How We Use Your Information

PurposeDataRequired?
Login & authenticationCredentials, OTP, device ID, FCM tokenYes
Case monitoringEvents, units, coordinatesYes
MessagingChat content, user IDsYes
Push alertsFCM token, notification contentOptional
MapsForeground location, tile requestsOptional
ContactsLocal device contactsOptional
DashboardAuthenticated WebView sessionOptional

3. Data Security and Protection

3A. Data Retention Timelines

CategoryPeriod
Account dataWhile authorized; deleted/anonymized within 90 days of deactivation
Auth/session logsUp to 180 days
Messages/notificationsUp to 90 days unless legally required
Case/incident recordsUp to 5 years or per MFB policy
Foreground locationActive session only
Local device dataUntil uninstall or app data cleared
Security logsUp to 180 days

4. Third-Party Services

4.1 Firebase Cloud Messaging (Google)

Purpose: push notifications. Data: FCM token, platform, anonymized identifiers. Privacy policy

4.2 OpenStreetMap

Purpose: map tiles. Data: tile requests (no personal data). Tiles may be cached locally. Privacy policy

4.3 Backend Services

Case Monitor API and Message Service API — operated under MFB authorization.

5. Data Sharing and Disclosure

We do not sell data, share with advertisers, track background location, upload contacts, or share messages with unauthorized parties.

We may share data when required by law, for emergency response, to prevent fraud/abuse, with your consent, or with service providers (Firebase, map tiles) solely to deliver App functionality.

6. Your Rights and Control

Under the DPDP Act, 2023 you may request access, correction, erasure, portability, consent withdrawal, and grievance redressal.

  1. Use the Profile screen (password, contacts)
  2. Adjust permissions in device Settings
  3. Email jatin@scstechindia.com
  4. Contact your MFB administrator for account deletion

7. Children's Privacy

For authorized personnel aged 18+. We do not knowingly collect data from children under 13.

8. Permissions Explained

PermissionPurposeRequired?
InternetAPIs, Firebase, mapsYes
Location (foreground)Map and Events screensOptional
NotificationsFCM alertsOptional
ContactsLocal emergency lookupOptional
Camera / Mic / Background location / Call logs / SMSNot usedNo
Android note: Background location may appear in the manifest but is not requested or used by the App code.

9. Contact Information

Email: jatin@scstechindia.com

Phone: +91 9004373334

Address: Patel Chambers, 101, 13, Shrimad Rajchandraji Marg, Opera House, Girgaon, Mumbai, Maharashtra 400004, India

Developer: SCS Tech India

DPO / Grievance Officer (to be formally appointed):

Name: [To be updated]

Email: [To be updated]

Phone: [To be updated]

9A. Grievance Redressal Procedure

  1. Contact the DPO (Section 9) with subject Privacy Grievance - MFB Case Monitor.
  2. Acknowledgement within 48 hours; resolution within 30 days.
  3. Escalation to Data Protection Board of India (DPBI) if unresolved.

10. Changes to This Privacy Policy

Material changes communicated via in-app notice (7 days prior), email, and updated date above.

Complies with DPDP Act 2023, IT Act 2000, IT Rules 2011, GDPR principles where applicable, and App Store / Play Store requirements.

11A. Incident / Data Breach Notification

  1. SCS Tech notifies DPO within 24 hours of discovery.
  2. DPBI notified per statutory timelines.
  3. Affected users notified via in-app and/or email.
  4. Root cause analysis within 30 days.

12. Policy Version Control

VersionDateSummary
1.0Feb 2026Initial publication
1.1Jul 2026MCGM advisory updates; aligned with App v1.0.1 features and permissions