Field Wizard — Privacy Policy
Effective date: 2026-09-02 Last updated: 2026-09-06
Field Wizard is a field-service data platform for contractors, operated at gofieldwizard.com. This policy explains what we collect, why, who we share it with, and what you can do about it.
Two different kinds of people are covered here, and it matters which one you are:
- Customers — the contracting businesses that subscribe to Field Wizard, and
their employees who log in. We are the controller of your account data.
- Your customers' data — the homeowners and businesses whose jobs, forms,
photos, and invoices you record in Field Wizard. You decide what goes in and how it is used. We are only the processor, acting on your instructions.
If a homeowner wants their record removed, ask the contractor who holds it. They can delete it themselves in the app.
1. Information we collect
1.1 From you, when you sign up and use the product
- Account information — name, email, company name, password (stored only as
a bcrypt hash — we never see or store your actual password), industry, phone, logo.
- Team information — names, emails, roles, and, if you enter them, phone
numbers, skills, and hourly rates for your employees.
- Business content you create — customers and contacts, jobs, form templates
and submissions, invoices, estimates, inventory, timesheets, safety records, and custom data tables.
- Files you upload — job photos, captured signatures, PDFs, and documents.
If a photo is captured in the app with location enabled, GPS coordinates are stored with it.
- Support communications — what you send us when you get in touch.
1.2 Automatically, when you use the service
- Technical data — IP address, browser type, and device information.
- Audit records — which user took which action on which record, from which
IP address, and when. This is a security feature, and it is available to you in-app.
- Error data — when an error occurs, a stack trace and request context, so
we can fix it.
1.3 What we do not collect
- We never see your payment card number. Card details go straight to Stripe.
We hold only Stripe's identifiers and your subscription status.
- We do not use advertising trackers or third-party marketing pixels in the
application.
- We do not buy personal information about you from data brokers.
- We do not track your location in the background. Location is captured only when
a photo is taken in the app with location permission granted.
2. How we use information
We use it to:
- Provide the service — run your account, store your records, generate your
PDFs, send your invoices.
- Authenticate you and keep your account secure, including rate limiting and
the audit log.
- Send transactional email — verification, password resets, portal links, and
documents you asked us to send.
- Bill you, and handle the subscription.
- Support you when you ask for help.
- Fix bugs, monitor reliability, and improve the product.
- Meet legal and tax obligations.
We do not sell your personal information. We do not share it with advertisers. We do not use your business data to train AI models — see §4.
The legal bases, where GDPR applies, are: performance of a contract (running the service), legitimate interests (security, fraud prevention, product improvement), legal obligation (tax and accounting records), and consent (optional integrations and marketing email, which you can withdraw).
3. Who we share it with
Only with the service providers we need to run the product. Each one is listed in our subprocessor list with what it does, what data it sees, where it operates, and a link to its own security page. In summary:
- Always: Railway (hosting), MongoDB Atlas (database), Cloudflare (DNS, TLS,
CDN), Resend (transactional email).
- Only if you enable them: Stripe (billing), Twilio (SMS), Anthropic (AI
assistant), Intuit/QuickBooks (accounting sync), Sentry (error tracking).
We will also disclose information if we are legally required to — a valid subpoena, court order, or lawful government request. Where we are permitted to tell you first, we will.
If Field Wizard is ever acquired or merged, your data may transfer as part of the business. You will be notified before that happens, and this policy continues to apply until you are given notice of a new one.
We give 30 days' advance email notice before adding a new subprocessor that handles customer-confidential data.
4. The AI assistant
The in-app AI assistant is optional. If you use it:
- Only the content of your conversation with the assistant, plus the specific
business context that request needs, is sent to Anthropic. Not your whole database.
- Under Anthropic's commercial terms, API inputs and outputs are not used to
train their models.
- If you never use the assistant, no data goes to Anthropic.
Do not paste anything into the assistant that you would not want processed by a third-party provider under those terms.
5. Security
The detail is in our security overview, which we publish deliberately — including the parts that are not finished. The short version:
- HTTPS everywhere, with HSTS,
X-Frame-Options: DENY,nosniff, and a strict
referrer policy.
- Passwords hashed with bcrypt, under an enforced strength policy.
- Short-lived (30-minute) access tokens with refresh tokens.
- Every database query scoped to your company. Deny-by-default role permissions.
Cross-tenant isolation covered by automated regression tests, run on every change.
- Rate limiting on registration, login, password reset, and portal login.
- Uploads restricted by file type and size, with server-generated filenames, and
downloads checked against your company.
- Data encrypted in transit and at rest.
- 1,300+ automated tests, plus dependency and secret scanning, run on every change
before it can ship.
And what we do not have yet, said plainly: multi-factor authentication for Field Wizard logins is not available yet; logging out does not revoke an already issued token (it expires on its own within 30 minutes); we have not had a third-party penetration test; and we are working toward SOC 2 readiness but have not been audited and hold no SOC 2 report or certification. The full list is in our security overview §12.
No system is perfectly secure, and anyone who tells you otherwise is selling something.
6. How long we keep it
The full schedule is in our data-retention schedule. Headlines:
- Your business records: for as long as your account is open. We do not age
out your operational history on a schedule you did not choose.
- Audit log: 400 days, enforced automatically by the database.
- Billing records: 7 years, for tax purposes.
- After account deletion: production data removed within 30 days, and it
ages out of backups within a further 30 days.
7. Your rights
Whatever jurisdiction you are in, you can:
- Access and export — download your entire dataset at any time, from inside
the product, in CSV and JSON. One action, no fee, no waiting.
- Correct — edit anything in the app.
- Delete — delete individual records or your whole account.
- Object or restrict — tell us and we will act.
- Complain — to us at privacy@gofieldwizard.com, or to your data protection
authority.
Written requests are answered within 30 days.
GDPR
Field Wizard is operated from the United States and our infrastructure is US-based. We are not primarily targeted at the EU or UK, but we honour these rights for everyone.
For data your business records about your customers, you are the controller and we are the processor. We process it only to provide the service, only on your instructions. If you need a Data Processing Agreement, email privacy@gofieldwizard.com and we will provide one.
California (CCPA/CPRA)
California residents may request disclosure of the categories of personal information collected and the purposes, request deletion, request correction, and opt out of sale or sharing.
We do not sell or share personal information as those terms are defined by the CCPA, and we have not in the preceding 12 months. There is nothing to opt out of. We do not knowingly collect personal information from anyone under 16.
We will not discriminate against you for exercising any of these rights.
Other states
We apply the same rights to residents of Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy laws. One standard, applied to everyone, is simpler to operate and harder to get wrong.
8. Cookies
We use cookies and browser local storage for the things the app cannot work without: keeping you logged in, remembering your preferences, and holding form data offline so a technician can keep working without signal and sync later.
No advertising cookies. No third-party tracking pixels. No cross-site tracking.
9. Children
Field Wizard is a business tool. It is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has ended up in our systems, email privacy@gofieldwizard.com and we will delete it.
10. International users
Our servers are in the United States. If you use Field Wizard from elsewhere, your data is transferred to and processed in the US. By using the service you consent to that transfer.
11. Changes to this policy
We will post any change here and update the "last updated" date. For material changes we will email account holders at least 30 days before they take effect.
12. Contact
| Purpose | Address |
|---|---|
| Privacy questions, DPA requests, data-subject requests | privacy@gofieldwizard.com |
| Security issues | security@gofieldwizard.com |
| General support | support@gofieldwizard.com |
Field Wizard
Questions about this document
Email Support@gofieldwizard.com and a person will answer. Our security controls and subprocessor list are published at the Trust Center.