Privacy Policy
1. INFORMATION WE COLLECT
We collect information that you provide directly to us when you create an account and use FieldDeskOps (the "Service"):
- Account data: Email address, password (hashed; we never store plaintext), and authentication tokens.
- Profile data: Subscription status, plan tier, and billing identifiers linked to your account.
- Operational data: Job/project names, customer records (name, phone, email, address, notes), photos, captions, and digital SignOff contract/signature documents you create in the Service.
- Usage data: Resource counts (e.g., number of jobs, photos, contracts created) used to enforce plan limits.
- Device and log data: Browser type, operating system, IP address, pages visited, and timestamps collected automatically when you access the Service.
2. HOW WE USE YOUR DATA
We use the information we collect to:
- Provide, operate, and maintain the Service (SiteSnap photo documentation, SignOff contracts/e-signatures, and related account features).
- Process payments, manage subscriptions, and enforce plan limits.
- Authenticate your identity and protect your account.
- Send transactional emails (e.g., email confirmation, password reset).
- Respond to feedback or support requests you submit through the Service.
- Monitor usage patterns to improve performance, fix bugs, and develop new features.
- Comply with legal obligations.
We do not sell, rent, or trade your personal or operational data to third parties for marketing purposes.
3. THIRD-PARTY SERVICES
We use trusted third-party providers to operate the Service. They process data on our behalf under their own privacy policies:
- Supabase — Database hosting, authentication, and file storage (photos, documents). Data is stored in Supabase-managed infrastructure with row-level security.
- Whop — Payment processing and subscription management. We share your email and a user identifier with Whop to process payments. We do not store your credit card number; Whop handles card data under applicable payment-security requirements.
- Netlify — Application hosting, serverless functions, content delivery, and infrastructure logs needed to operate the Service securely.
- Sentry — Error monitoring used to capture crashes and diagnose reliability issues.
- Resend — Transactional email delivery (e.g., feedback submissions). Your email address may be included in messages routed through Resend.
We do not share your data with any other third parties except as required by law or to protect our rights.
4. COOKIES AND LOCAL STORAGE
We use the following browser storage mechanisms:
- Authentication cookies: Set by Supabase to maintain your login session. These are essential for the Service to function and cannot be disabled.
- Local storage: Used to save your UI preferences (e.g., theme, view mode). This data stays on your device and is not transmitted to our servers.
- Operational metrics: We may collect limited product usage signals (for example signup or upgrade clicks) if analytics are configured; hosting logs are always present for security and reliability.
We do not use advertising cookies or cross-site ad tracking pixels.
5. DATA STORAGE AND SECURITY
Your data is stored in Supabase-managed databases with row-level security (RLS) enabled, meaning each user can only access their own data. Photos and documents are stored in Supabase Storage buckets.
We use industry-standard security measures including:
- HTTPS encryption for all data in transit.
- Hashed passwords (never stored in plaintext).
- Row-level security policies so users can only read and modify their own records.
- Environment-variable-based secrets for API keys (never exposed to the client).
No system is 100% secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.
6. DATA RETENTION
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account and operational data: Retained until you delete your account or request deletion.
- Photos and documents: Stored in Supabase Storage until you delete them or your account is closed.
- Payment records: Our payment processor retains transaction history in accordance with their retention policy and applicable tax/legal requirements.
- Log data: Automatically generated server logs may be retained for up to 90 days for debugging and security purposes.
After account deletion, we will remove your data from our active systems within a reasonable timeframe. Some data may persist in encrypted backups for a limited period before being purged.
7. YOUR RIGHTS
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request that we delete your personal data and account. You can also delete individual jobs, photos, tools, and other records directly within the Service.
- Data portability: Request your data in a commonly used, machine-readable format.
- Objection: Object to certain processing of your data where applicable.
To exercise any of these rights, contact us at fielddeskops@gmail.com. We will respond within 30 days.
8. CHILDREN'S PRIVACY
The Service is not intended for anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date below and may notify you through the Service or by email. Your continued use of the Service after changes constitutes acceptance of the updated policy.
10. CONTACT
If you have questions or concerns about this Privacy Policy or how we handle your data, contact us at fielddeskops@gmail.com.
Last Updated: February 20, 2026
POWERED BY FIELDDESKOPS