Privacy Policy
Last updated: August 4, 2026
Fieldpost LLC ("Fieldpost," "we," "us," or "our") operates the Fieldpost mobile application (available on iOS and Android), the Fieldpost web application at app.fieldposthq.com, and our related websites and services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Service.
When Fieldpost processes account, billing, support, security, website analytics, and similar business information, Fieldpost generally determines the purposes and means of processing. When we process photos, videos, contacts, notes, project addresses, precise location information, reports, and other content on behalf of a company workspace, the workspace customer generally controls that information and Fieldpost acts as its service provider or processor. If your information appears in customer-controlled content, please direct your request to the relevant customer; we will assist the customer as required by law and our agreement with it.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (required for registration and login)
- Name (optional, used for display within your team)
- Authentication credentials (passwords, when used, are hashed and managed by our authentication provider)
- Company or organization name (used to set up your workspace)
- Profile photo (optional avatar image)
1.2 Project and Content Data
When you use the Service, you create and upload content including:
- Photos and videos captured or uploaded from your device
- Project information (names, descriptions, locations, status)
- Notes and annotations added to photos and projects
- Reports you create and export
- Categories you define for organizing media
- Contacts you add to projects (name, email, phone)
1.3 Location Data
With your device permission, we collect precise GPS coordinates from your device. Precise location may be considered sensitive personal information under applicable law. Location data is used to:
- Geotag photos and videos at the time of capture
- Associate projects with physical locations
- Display your projects and media on a map
- Optionally stamp GPS coordinates onto photo images
Location access is requested when you use location-enabled features, such as the camera or project creation. You can deny or revoke location permission at any time through your device settings. The app functions without location access, but geotagging features will be unavailable. Depending on your settings, precise location may be embedded in media, displayed to members of your workspace, and included in reports or exported files. Copies that you or others export or share are outside our control and may retain that information.
1.4 Device and Usage Data
We may automatically collect:
- Device and browser information (device type, operating system, browser type and version, language, and app version)
- Identifiers and network data (IP address, device or installation identifiers, and push-notification tokens)
- Network connectivity status (to manage offline functionality)
- Usage and log data (pages or features used, referring pages, authentication and security events, and timestamps of actions such as uploads, note creation, and report generation)
- Diagnostic data (error logs, crash information, and performance data)
- Communications data (support requests, feedback, and delivery or engagement information for service emails and notifications)
We use cookies and similar technologies on our websites and web application to maintain sessions, remember preferences, and secure the Service. Within the authenticated Service, we also record limited account and product-interaction events linked to your account so we can understand usage, improve Fieldpost, and send relevant account-setup or product-engagement messages. We do not use session replay or automatic click capture. You can use browser controls or available opt-out tools to limit cookies, although some Service features require essential cookies.
1.5 Payment Information
If you subscribe to a paid plan, payment processing is handled entirely by Stripe, Inc. We do not store your credit card number, bank account details, or other sensitive payment information on our servers. We receive and store only:
- Your Stripe customer ID and subscription ID
- Subscription plan, billing interval, and seat count
- Subscription status (active, trialing, canceled, etc.)
- Trial and cancellation dates
Stripe's collection and use of your payment data is governed by the Stripe Privacy Policy.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Create and manage your account and company workspace
- Store and organize your photos, videos, notes, and projects
- Generate PDF reports from your project data
- Enable team collaboration and activity tracking within your company
- Process payments and manage subscriptions
- Send transactional notifications (team invitations, mentions, and account setup) and optional product-engagement messages
- Provide offline functionality and sync data when connectivity is restored
- Improve and develop new features for the Service
- Respond to support requests and communicate with you
- Detect, prevent, and investigate fraud, abuse, security incidents, and violations of our Terms
- Protect the rights, property, safety, and integrity of users, Fieldpost, and the public
- Comply with law, preserve evidence, and establish, exercise, or defend legal claims
3. Data Storage and Security
3.1 Cloud Storage
We host the Service using established third-party cloud infrastructure, database, and storage providers (see Section 4.3). We use encryption in transit and rely on our infrastructure providers' encryption-at-rest capabilities. Providers and storage locations may change as the Service evolves.
3.2 Local Device Storage
The mobile app stores limited data on your device:
- Authentication tokens (to maintain your login session)
- Camera preferences (timestamp stamping, GPS stamping, grid, level settings)
- Offline photo queue (photos captured while offline are stored locally until they can be uploaded)
Locally stored photos in the offline queue are automatically deleted from your device after successful upload.
3.3 Access Controls
Each company workspace is kept separate from other customers' workspaces, and we maintain technical and organizational safeguards designed to prevent unauthorized access to your information. Authorized personnel and service providers may access information when reasonably necessary to operate, support, secure, or investigate the Service, subject to appropriate access controls.
We take commercially reasonable measures designed to protect personal information. However, no method of transmission, storage, or security is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur.
4. Data Sharing and Disclosure
We do not sell your personal information for money. We disclose information in the following circumstances:
4.1 Within Your Company
All content you create (projects, photos, notes, reports) is visible to other members of your company workspace. Team activity is tracked and visible within your organization.
4.2 Shared Reports
When you publish or share a report, it becomes accessible via a unique link. Shared reports may include password protection and expiration dates that you configure. Anyone with the link (and password, if set) can view the report contents.
Workspace customers are responsible for providing required privacy notices, obtaining permissions or establishing another lawful basis for customer-controlled content, responding to requests concerning that content, and configuring workspace access and report-sharing settings. If you receive a link or invitation, the person or organization that sent it may also process information about your access.
4.3 Third-Party Service Providers
We use service providers to operate, secure, communicate about, analyze, and improve Fieldpost, including:
- Supabase — Database hosting and authentication (Supabase Privacy Policy)
- Cloudflare — File storage, content delivery, and security (Cloudflare Privacy Policy)
- Stripe — Payment processing and subscription management (Stripe Privacy Policy)
- Resend — Transactional email delivery (Resend Privacy Policy)
- PostHog — Authenticated product analytics and lifecycle email delivery (PostHog Privacy Policy)
- Expo — Mobile application services and push-notification delivery (Expo Privacy Policy)
- Google Places API — Location search and autocomplete when creating projects (Google Privacy Policy)
- OpenStreetMap / Leaflet — Map rendering on the web application
These providers receive information only as reasonably necessary to perform services for us and are subject to their own privacy terms and applicable contractual obligations. We may change providers as our business evolves and may also use hosting, monitoring, customer-support, professional-adviser, and security providers not individually listed here.
4.4 Legal Requirements
We may preserve, access, use, or disclose information when we reasonably believe it is necessary to comply with applicable law, legal process, or valid government requests; enforce our agreements; investigate fraud, abuse, security incidents, or Terms violations; protect the rights, property, or safety of Fieldpost, our users, or the public; respond to an emergency involving danger to a person; report suspected illegal content or activity; or establish, exercise, or defend legal claims. Where legally permitted and appropriate, we may notify the relevant workspace customer or user.
4.5 Business Transfers
We may disclose or transfer information in connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar business transaction, subject to appropriate confidentiality protections where required.
5. Mobile App Permissions
The Fieldpost mobile app requests the following device permissions:
- Camera — To capture photos and videos for project documentation
- Photo Library / Media Library — To select existing photos and videos from your device
- Location (When In Use) — To geotag photos and associate projects with locations. Not used for background tracking.
- Network State — To detect connectivity and manage offline-to-online sync
All permissions are optional. You can deny or revoke any permission through your device settings. Some features may be limited without certain permissions.
6. Data Retention and Deletion
We retain information for as long as reasonably necessary to provide the Service, maintain customer workspaces, fulfill the purposes described in this policy, and meet our legal and business obligations. Retention depends on the type of information, the customer's instructions, account status, contractual commitments, security and fraud-prevention needs, and applicable law.
- Active systems: Deleted photos, videos, projects, and associated records are scheduled for removal from active systems.
- Backups and logs: Residual copies may remain for a limited period in backups, caches, logs, and disaster-recovery systems until overwritten or deleted through ordinary cycles.
- Required retention: We may retain billing, tax, security, fraud, abuse, legal-hold, dispute, and compliance records as reasonably necessary or required by law.
- Customer-controlled records: Content may remain in an organization's workspace after an individual user deletes an account, and copies exported or shared by customers or third parties are outside our control.
- Offline queue: The mobile app is designed to remove locally queued media after successful upload, but files may also exist in device backups or copies you create.
Account Deletion
You can delete your account directly within the app under Settings > Account > Delete Account.
- Members: Deleting your account removes your personal profile and data from the organization. Your organization's administrator will be notified.
- Administrators: If you are the sole administrator of an organization, you will be asked to either promote another member to administrator before deleting your account, or delete the entire organization and all associated data. All affected members will be notified.
Account deletion removes or de-identifies your personal profile from active systems, subject to the retention exceptions above. Content you created within an organization (photos, notes, reports) may be retained as part of the organization's project records unless the organization directs us to delete it or the entire organization is deleted.
You may also contact us at hello@fieldposthq.com for assistance with account deletion.
7. Children's Privacy
The Service is intended for business use and is not directed to children under 16. Users must be at least 18, except that an organization may authorize an employee who is at least 16 to use the Service where lawful and under appropriate supervision. We do not knowingly allow children under 16 to create accounts. Customer-uploaded jobsite content may incidentally depict minors; the workspace customer is responsible for having a lawful basis and providing any required notices or permissions for that content. If you believe a child has created an unauthorized account or that child-related content is unlawful, contact us promptly.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Request a portable copy of your data
- Withdraw consent for location tracking at any time
- Opt out of certain sales, sharing, or targeted advertising, where applicable
- Limit certain uses of sensitive personal information, where applicable
- Appeal our denial of a request, where applicable
To exercise a right, contact us at hello@fieldposthq.com. We may need to verify your identity and authority before completing a request. You may use an authorized agent where applicable; we may request proof of the agent's authority and verification directly from you. We will not discriminate against you for exercising applicable privacy rights.
If your request concerns content controlled by a Fieldpost customer, please contact that customer first. We may refer the request to the customer and assist it in responding. Rights are subject to exceptions and limitations under applicable law.
9. U.S. State Privacy Rights
Residents of California and certain other U.S. states may have additional rights if and to the extent the applicable state privacy law applies to Fieldpost. These may include rights to know, access, correct, delete, or obtain a portable copy of personal information; opt out of certain sales, sharing, targeted advertising, or profiling; limit certain uses of sensitive personal information; use an authorized agent; appeal a decision; and receive equal service and pricing after exercising a right.
Fieldpost does not sell personal information for money. We do not use customer-controlled content for cross-context behavioral advertising. We use authenticated product analytics as described above and do not use that information for third-party targeted advertising. Where required, we will honor applicable opt-out signals and provide appropriate controls.
10. International Data Transfers
Fieldpost and our service providers may process information in the United States and other countries where privacy laws may differ from those in your jurisdiction. Where required, we use appropriate safeguards for cross-border transfers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page, update the "Last updated" date, and provide additional notice of material changes when required by law.
12. Contact Us
If you have questions, a privacy request, or a concern about unlawful or abusive content, contact us at:
Fieldpost
Email: hello@fieldposthq.com