Privacy Policy

Effective September 29, 2026. This Privacy Policy explains how FieldCRM LLC ("FieldCRM," "we," "us," or "our") collects, uses, discloses, and protects personal information through fieldcrm.app, the FieldCRM application, and related support and communications.

01

Scope and our role

FieldCRM provides business software for field service companies. This policy applies to visitors, account owners, team members, and people who interact with FieldCRM support, public quote or invoice links, or other FieldCRM services.

A FieldCRM business customer controls the customer, contact, property, job, and other records entered into its workspace. When FieldCRM processes that information to provide the service, FieldCRM acts as a service provider or processor for that business. The business is responsible for its own privacy notices, permissions, and lawful use of personal information.

If your information was entered by a field service business that uses FieldCRM, contact that business first about its records. FieldCRM will assist the business with a valid request when required.

02

Information we collect

Account and workspace information may include names, email addresses, login and authentication records, business details, business type, services, team roles, preferences, and profile information.

Customer and operational content may include customers, contacts, service addresses, Work Orders, estimate line items, quote approvals, jobs, schedules, notes, photos, files, invoices, payment status, follow-ups, catalog items, and other information a business chooses to enter.

Billing and communications information may include the selected plan, subscription and transaction status, billing contact details, trial history, messages sent through FieldCRM, contact-form submissions, support requests, and email delivery records.

Technical and usage information may include IP address, device and browser details, operating system, language, approximate location derived from IP, timestamps, pages or features used, referring pages, diagnostic logs, security events, and cookie or similar-technology identifiers where permitted.

03

Sources of information

We collect information directly from people who visit the site, create or use an account, submit a form, communicate with us, or use a public customer link.

We also receive information from workspace owners and team members, from customers who review or act on a quote or invoice, automatically from browsers and devices, and from service providers such as Stripe when they confirm subscription or payment activity.

04

How we use information

We use information to provide and personalize FieldCRM; authenticate users; maintain customer, Work Order, estimate, quote, job, invoice, payment, and follow-up workflows; and operate public customer links.

We use information to manage trials, subscriptions, billing, and transactions; deliver account, security, service, and support communications; troubleshoot problems; prevent fraud and abuse; protect users and the service; and enforce applicable terms.

We may use information to understand performance, improve features and usability, develop new services, measure marketing, and show or evaluate advertising where permitted by law and consistent with the privacy choices described below.

We may also use information to comply with law, respond to lawful requests, establish or defend legal claims, complete corporate transactions, and create aggregated or de-identified information that does not reasonably identify an individual.

05

Payments

Stripe processes payment-card and billing information for FieldCRM subscriptions and supported payment flows. FieldCRM receives identifiers, plan details, and transaction or subscription status needed to operate the service, but does not store full payment-card numbers.

A business may also configure customer payment instructions or third-party payment options in its workspace. Those providers and the business may apply their own terms and privacy practices.

06

Scout AI preview

When a visitor chooses to use Scout in the public interactive demo, FieldCRM sends the visitor's question, recent Scout chat, and relevant fictional demo records to OpenAI to generate an answer. Do not enter personal, customer, payment, health, credential, or other sensitive information in Scout.

Scout requests are sent with response storage disabled. OpenAI states that API data is not used to train its models unless the API customer opts in, and that API inputs and outputs may be retained for abuse monitoring under its policies. Learn more at developers.openai.com/api/docs/guides/your-data.

FieldCRM records limited usage metadata to enforce public-demo limits and control costs. That usage ledger does not record the visitor's question, Scout's answer, recent chat, fictional record content, raw IP address, or the OpenAI API key.

Scout's public preview uses fictional records. Its answers and drafts may be incomplete or incorrect, must be reviewed before use, and do not send messages or change records.

07

Website analytics

FieldCRM automatically uses cookie-free Vercel Web Analytics on approved public marketing pages to measure basic traffic. It stores anonymized page-view information such as the page visited, referrer, general location, browser, operating system, and device type.

For eligible visitors in the United States, Google Analytics and Google Ads measurement also run automatically on approved public marketing pages with analytics and advertising storage denied. This default mode does not set analytics or advertising cookies; Google Signals and ad personalization remain off. In the interactive demo, Google measurement stays off until Allow all is selected.

Google's limited measurement may receive sanitized public page paths, page type and language, the referring site's origin, general device, network, and location signals, plus a cookie-free Google Ads trial-start conversion after Stripe confirms a card-backed trial. After Allow all, FieldCRM may additionally send sanitized section-view, navigation, trial-button, demo-engagement, contact-form-start, successful contact, checkout-start, Google Analytics sign_up, Meta CompleteRegistration, and Reddit PageVisit or ViewContent events. Demo engagement uses only a code-defined workspace view, never sample record content or visitor-entered text. Consenting users who are signed in to Google and have Ads Personalization enabled may also contribute to aggregated age-bracket, gender, and interest reporting through Google Signals. FieldCRM does not receive individual Google profiles, exact ages, or precise locations, and Google may withhold small samples to protect privacy. After a consented Stripe-confirmed card-backed trial, FieldCRM may also send Reddit a SIGN_UP event through its server API. These events use approved public or fixed synthetic paths and code-defined labels such as page section, link destination, inquiry type, or plan; they do not include account, customer, job, payment, email, user, business, billing identifiers, or raw Stripe identifiers.

Selecting Allow all enables Google Analytics and Google Ads storage on approved public pages, plus Meta Pixel, Reddit Pixel, and masked Microsoft Clarity heatmaps or session replays on approved public marketing pages only. The interactive demo never loads Meta Pixel, Reddit Pixel, Microsoft Clarity replay, or Vercel Web Analytics. Outside the United States, optional Google tags remain off until Allow all is selected. Selecting Necessary only keeps these optional tools off.

Routine analytics excludes login, signup, billing, secure quote or invoice links, the private CRM, and all other non-approved paths. FieldCRM limits measurement to sanitized public paths. Approved ad landing pages, including the interactive demo, may use ad-platform click IDs and a short approved list of source or medium labels; Reddit receives only a validated Reddit click ID and approved campaign labels on eligible marketing pages. Applicable public pages may also use limited, non-identifying routing controls, such as a contact topic or status, an English-content choice, or a fixed demo view and industry. FieldCRM removes those controls from Google's measured page URL. Unknown, duplicate, malformed, or potentially identifying values are rejected, and FieldCRM does not add account, customer, job, or payment identifiers.

Production and Sandbox use separate Google Analytics properties and separate Microsoft Clarity projects so testing activity is not mixed with production reporting. Meta Pixel and Reddit Pixel remain production-only until Sandbox has its own separate dataset; Sandbox Reddit server events also require a test event ID.

Visitors can select Allow all or Necessary only and can change that choice later through Privacy choices in the public footer. Necessary only does not disable cookie-free Vercel Web Analytics. Vercel, Google, Microsoft, Meta, and Reddit provide more information at vercel.com/docs/analytics/privacy-policy, policies.google.com/technologies/partner-sites, learn.microsoft.com/clarity/setup-and-installation/privacy-disclosure, facebook.com/privacy/policies/cookies, and business.reddit.com/policies/cookies.

08

How we disclose information

We disclose information to vendors that help provide FieldCRM, including Vercel for hosting and public-site analytics, Supabase for database, authentication, and storage services, Stripe for billing and payments, Resend for email delivery, OpenAI for visitor-requested Scout answers, and the analytics or advertising providers described above. These providers process information for the services they supply and under their own applicable privacy terms.

Information may be visible to the owner, administrators, and authorized members of the relevant business workspace. Public quote and invoice links may display the customer and work information that the business intentionally makes available to the link recipient.

We may disclose information to professional advisers, auditors, insurers, regulators, courts, law enforcement, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate misuse, or complete a merger, financing, acquisition, reorganization, or sale of assets.

FieldCRM does not sell personal information for money. Optional advertising and analytics technologies can involve disclosure of public-site activity that some laws define as targeted advertising, a sale, or sharing. Visitors can use Privacy choices in the public footer to keep optional technologies off or change a prior choice.

09

Legal bases

Where a law requires a legal basis for processing, we rely on the performance of a contract, steps requested before entering a contract, our legitimate interests in operating and improving a secure business service, consent for optional technologies or communications where required, and compliance with legal obligations.

When FieldCRM processes workspace content for a business customer, that business determines the applicable legal basis for collecting and using the information.

10

Retention

We retain personal information for as long as reasonably necessary to provide the service, maintain the account or workspace, complete transactions, honor user choices, meet contractual and legal obligations, resolve disputes, prevent abuse, and protect FieldCRM and its users.

Retention periods depend on the type of information, why it was collected, account status, legal or accounting requirements, and security needs. After deletion, information may remain for a limited period in backups or when retention is required by law. We may retain aggregated or de-identified information that no longer reasonably identifies an individual.

11

Security

FieldCRM uses administrative, technical, and organizational safeguards designed to protect personal information, including authenticated access and workspace-scoped data controls. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

Users are responsible for choosing strong credentials, protecting their devices and account access, limiting team permissions appropriately, and promptly reporting suspected unauthorized activity through the Contact page.

12

International processing

FieldCRM is operated from the United States. We and our service providers may process information in the United States and other countries where privacy laws may differ from those in your location. Where required, we use appropriate safeguards for international transfers.

13

Children's privacy

FieldCRM is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child provided personal information directly to FieldCRM, use the Contact page so we can investigate and take appropriate action.

Business customers should not place children's personal information in FieldCRM unless it is necessary for a legitimate service workflow and they have the authority and any required permission to do so.

14

Your choices and privacy rights

Account users may review and update certain profile and workspace information in FieldCRM. Visitors can manage optional analytics and advertising technologies through Privacy choices in the public footer. Marketing emails, if sent, will include an unsubscribe method; essential account, billing, security, and service messages may continue.

Depending on where you live and subject to legal exceptions, you may have rights to know or access personal information, correct it, delete it, receive a portable copy, restrict or object to processing, opt out of targeted advertising or certain sales or sharing, limit certain uses of sensitive information, or appeal a denied request.

Use the Contact page at fieldcrm.app/contact to submit a privacy request. We may need to verify your identity, account, authority, or request details. An authorized agent may submit a request where permitted by law, but we may require proof of authority. FieldCRM will not unlawfully discriminate against a person for exercising an applicable privacy right.

Requests about information controlled by a FieldCRM business customer should be directed to that business. We will support the business as required by law and our agreement with it.

15

Changes to this policy

We may update this Privacy Policy as FieldCRM, our providers, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when a change is material and applicable law requires it.

16

Contact

For privacy questions or requests, use the Contact page at fieldcrm.app/contact and select the most relevant topic. Please do not include passwords, full payment-card numbers, or unnecessary sensitive information in a request.

FieldCRM LLC's business address is 5485 Overbend Trail, Suwanee, GA 30024, United States.