Privacy Policy

Last updated: 1 September 2026

FieldRadar ("we", "us", "the app") helps site managers capture defects, inspections and site evidence and produce reports. This policy explains what data we collect, how we use it, and your choices. It is written to be accurate to how the app actually works.

Who we are

FieldRadar is provided by FieldRadar Ltd. FieldRadar Ltd is the controller when it decides why and how personal data is used for its own service and business operations, including account administration, individual subscription and billing records, support, security, fraud prevention, audit, diagnostics and service communications. When a company customer decides why and how content is used in its company workspace, that customer is normally the controller and FieldRadar Ltd normally acts as its processor, on the customer's documented instructions and subject to the customer contract and, where applicable, a data processing agreement (DPA). The precise roles depend on the processing context and applicable law. For any privacy question or request, contact us at support@fieldradar.co.uk.

What we collect

Account information. When you register we collect your name, email address and (optionally) your company name, job title and company logo. Authentication is handled by our backend provider, Supabase.

Early access and company-pilot requests. If you use a website form, we collect the details you enter (which may include your name, work email, role, phone, company, project and team size, message and phone platform), a submission identifier, source page, IP-derived abuse-control value and basic request metadata. Cloudflare Turnstile is used to distinguish legitimate submissions from abuse, an append-only submission history is kept for delivery/reconciliation, and Team enquiry email is delivered through Resend.

Project invitation and comment-mention email. Resend is our transactional email-delivery provider. When an authorised user sends a project invitation, the recipient's email address and the message content are sent through Resend for delivery; that content includes the inviter's name or email, project name, assigned role and dashboard links. When a project member is mentioned in a comment, the recipient's name and email and the transactional message content are sent through Resend; that content includes the author's name or email, project name, action number and title, comment text and a link to the action. Resend also processes delivery and status metadata for those messages.

Content you create. Projects (including the site address and client details), plans and drawings, actions and pins, photographs, voice notes, inspections, permits, daily diaries, project documents and report records. This content may be stored locally on your device and, when you are signed in and online, synced to our cloud backend so you can access it across devices and share it with people you invite. When an authorised user asks FieldRadar to obtain diary weather, FieldRadar sends the project's site address and the requested date to WeatherAPI for that lookup; it does not send the rest of the project record for the weather request.

Shared project and company workspace data. If you invite people to a project, its content and your name/email may be visible to members according to the role granted to them. Company administrator and portfolio access is still undergoing cross-record and storage-policy validation, so Team and Team Plus are managed pilots arranged under a written scope rather than online checkout.

SharePoint links. On Teams-enabled projects, authorised users can record links and metadata for documents held in the organisation's Microsoft 365 SharePoint. The current integration stores the document link and descriptive metadata in FieldRadar; the linked file remains in the organisation's Microsoft 365 environment and is governed by its own access and retention settings.

Purchase and company billing information. Individual Pro purchases are processed by Apple or Google and RevenueCat manages subscription status. RevenueCat receives the FieldRadar account identifier plus product, status and store transaction/subscription identifiers; FieldRadar and RevenueCat do not receive app-store card details. Team and Team Plus are managed company pilots: before company payment is taken, the written order and this policy identify the billing information, VAT treatment and payment arrangement involved.

Device permissions. With your permission the app uses:

Technical, support and diagnostic data. The app creates a random persistent installation identifier to correlate FieldRadar writes during support, audit and security investigations; it is not an advertising identifier. Our backend keeps standard request, security and error logs. The mobile app sends crash and error diagnostic events to Sentry. Those events may include the error message and stack, app environment and version, device/operating-system information, a support reference and Expo update, runtime and channel identifiers, together with limited technical context needed to investigate the fault. FieldRadar configures Sentry with default personal-data sending and performance tracing disabled, but diagnostic information can still be personal data. If you start a support email from the app, its draft includes your account email, device/operating system, app version, native build and Expo update identifier so support can reproduce the problem; you can edit that email before sending it.

Product activation milestones. To understand whether new users can complete the core setup journey, FieldRadar records the first time a signed-in account reaches a small fixed set of milestones, such as signing in, creating and syncing a project, adding a plan or first record, creating a diary, exporting a report, viewing the upgrade screen or completing a purchase. These records include the account identifier, platform, app version, update identifier and time. They do not include project names, addresses, descriptions, photographs, device or advertising identifiers, or other free-form content, and repeated interactions are not recorded as a clickstream.

Website performance data. Our public website uses Cloudflare Web Analytics to collect aggregate page-view and performance measurements. Cloudflare states that this service does not collect or use personal data, fingerprint visitors, or track individual users across websites.

We do not use third-party advertising or cross-site tracking, and we do not sell your personal data.

Where your data is stored

Content synced to FieldRadar is stored using Supabase; the configured database and file-storage region is eu-west-1 in the European Union. Photos, voice notes and uploaded project documents use private storage with database/storage access policies that are currently being unified and re-tested across company and portfolio roles.

A copy of recent data and media may be cached locally so the app works offline. Signing out does not itself securely erase every local database or media file from a shared device. Anyone using shared hardware should remove app data or the app after use and avoid unpermissioned live project data until account-partitioning and shared-device evidence is complete. SharePoint-linked files remain in the customer's Microsoft 365 environment.

How we use your data

The basis depends on the activity. We use contractual necessity where processing is needed to provide a service you requested; legitimate interests for proportionate security, reliability, enquiry handling and product operations; and consent where the law requires a choice, such as optional device permissions. FieldRadar Ltd remains the controller for the account, individual subscription and billing, support, security, audit, diagnostic and service-communication data for which it determines the purposes and means. For content in a customer company workspace, the company customer normally determines the purposes and means and is therefore normally the controller; FieldRadar Ltd normally acts as its processor under the customer's documented instructions, the applicable customer contract and, where applicable, a DPA. We do not treat device permission prompts as blanket consent for unrelated processing.

Processors and external services

Some providers are international organisations and may process support, security or service metadata outside the UK even where primary project storage is configured in the EU. The supplier contract, subprocessor and international-transfer register is still being completed and will be specialist-reviewed before a company plan begins. Contact us for the current scope before placing live personal data into a managed pilot.

Data retention and deletion

We generally keep personal-workspace content while the account is active, subject to legal obligations and an applicable written agreement. In Settings you can start account deletion. The authentication account is removed immediately and FieldRadar-controlled database records and storage objects associated with the individual account are queued for durable cleanup; storage cleanup may therefore continue after sign-in has stopped. Support can confirm the recorded outcome. Deleting the FieldRadar account does not cancel an Apple or Google subscription.

Deleting an individual user's FieldRadar account, or removing or offboarding that user from a company workspace, does not by itself delete the company-controlled workspace or its records. Those records remain under the company customer's control and are retained, returned, exported or deleted on that customer's documented instructions, subject to the customer contract, any applicable DPA, applicable law and necessary backup-cleanup cycles. An individual may therefore lose access while the company record remains. Deleting FieldRadar data also does not delete a file retained in an external Microsoft 365 environment.

Apple, Google and RevenueCat may retain store transaction, billing, tax, fraud-prevention and refund/dispute records under their own legal obligations and terms. Early-access and enquiry details, append-only submission/delivery history, security logs and diagnostic records are kept only for their operational, security or legal purpose. The final documented retention schedule is a launch gate and is not yet represented as a fixed public period. You can ask what is currently held or request deletion; we will explain any information that must be retained.

Use the external account-deletion page or contact support@fieldradar.co.uk.

Your rights

Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact support@fieldradar.co.uk.

Children

FieldRadar is a professional tool intended for construction and site-management use. It is not directed at children and we do not knowingly collect data from anyone under 16.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated in the app.

Contact

FieldRadar Ltd. support@fieldradar.co.uk. Security reports can use our responsible reporting route.

This policy is governed by the laws of England and Wales.