Privacy
What Fieldly stores, who can see it, and how to get it back or delete it.
Two kinds of people in this document
Fieldly is software a field-service company runs its business on. That means there are two relationships, and they work differently:
- The business using Fieldly — the owner and their staff. They have Fieldly accounts. We are their service provider.
- That business's customers — the households and properties being serviced. They did not sign up with us; their service company entered their details. That company decides what is collected and how long it is kept. We hold it on their behalf and do not use it for anything else.
If you are a homeowner who got a text or a portal link from a pest-control, lawn, or plumbing company, contact that company first — they control your record. We will help them help you.
What we store
| Category | Examples | Why |
|---|---|---|
| Staff accounts | Name, email, phone, role, hashed password | Signing in and deciding who can do what |
| Business customers | Name, service address, email, phone, plan, notes | Scheduling and billing the work |
| Jobs and visits | Date, time, assigned technician, service performed, service report | Running the schedule and the route |
| Compliance records | Chemical product, EPA registration number, rate, volume, target pest, treated areas | Regulatory records the operator is required to keep |
| Proof of service | Before/after photos, customer signature and the amount shown at signing | Disputes, warranty claims, and the customer's own history |
| Billing | Invoice amounts, issue and due dates, payment status | Getting the operator paid |
| Security logs | Sign-in events, and an audit record of any Fieldly staff access to an account | Accountability — see "When we look at your data" |
We do not collect card numbers. When card payments are enabled, the card is entered with the payment processor and never reaches our servers.
Location and tracking
The technician app plans a route from service addresses. It does not continuously track a technician's location, and there is no background location collection. When a technician taps "On My Way", the customer is told a technician is en route — that is a status change, not a live position.
The marketing site you are reading sets no advertising cookies and runs no third-party analytics.
Who else touches the data
Subprocessors we use, or will use as those features turn on. This list is kept current; ask us if you need it in writing for a vendor review.
| Provider | Purpose | Status |
|---|---|---|
| Amazon Web Services | Hosting, database, backups | In use |
| Anthropic | AI assistant features | In use where an operator enables it |
| Stripe | Card payments | Planned |
| Twilio | SMS reminders and notifications | Planned |
| SendGrid | Transactional email | Planned |
| A mapping provider | Geocoding service addresses for routing | Planned |
An operator may supply their own keys for the AI, SMS, and email providers, in which case that traffic goes to their account rather than ours. We do not sell data, and we do not share it with anyone not on this list.
When we look at your data
Rarely, and never invisibly. Fieldly staff can open a support session into an account to diagnose a problem. Every such session is recorded — who opened it, which account, and when — along with any change made during it. Access is time-boxed and granted per account rather than standing.
How it is protected
- Encrypted in transit (HTTPS everywhere) and at rest.
- Passwords stored as Argon2 hashes — we cannot read them, and neither can anyone who takes a copy of the database.
- Any third-party keys an operator saves in Settings are encrypted separately before being written to the database.
- Every record belongs to exactly one company, and every request is scoped to that company. One operator cannot see another's data.
- Sign-in links and emailed export links work once and then expire.
- Nightly database backups with point-in-time recovery.
No system is perfectly secure. If we discover a breach affecting an operator's data, we will tell them without delay, in plain language, and with what we know at the time rather than waiting for a complete picture.
How long it is kept
For as long as the operator's account is open, because this is their business record. Compliance records in particular often have a legal retention period the operator — not us — is responsible for meeting.
When an account closes: the operator can export everything first (always free, see Data export), and we delete the account data within 30 days of the request. Backups age out on their own cycle within a further 30 days.
Your rights
Depending on where you live you may have the right to see, correct, export, or delete your personal data, and to object to how it is handled. We honour those requests regardless of whether the law where you live requires it.
If you are a staff member of an operator, email us. If you are that operator's customer, ask them — they control the record, and we will act on their instruction promptly.
Changes
When this page changes materially we will email account owners rather than quietly editing the date at the top.
Questions
Email lou@fieldly.com. During the beta that reaches the founder directly, usually the same day.