Security and data

How FieldRadar handles your site data

A plain-English summary of where your data lives and how it is protected. We only describe what the product actually does.

Where your data is stored

Content you sync is stored using Supabase, with the database and file storage hosted in the European Union (eu-west-1). Photos, voice notes and uploaded project documents are kept in private storage and protected by project-level access controls.

Offline-first, on your device

FieldRadar captures core site records to your device first, in a local database, so the app works with no signal. When you are back online it syncs supported content to your account so it is available across your devices.

Encryption in transit

All traffic between the app and our backend is served over HTTPS/TLS.

Accounts and access

FieldRadar uses account, project-role and database row-level security controls. During pre-launch review, company administrator and portfolio access was found not to be applied consistently to every project record type and storage path. Those paths are being unified and tested. We therefore do not currently represent Team or portfolio access as a general self-service production service; Team and Team Plus are managed pilots arranged under a written scope rather than online checkout.

Managed pilot participants should use synthetic or explicitly permissioned project data while those paths are being unified. Access revocation and shared-device cache behaviour must be tested for the proposed users before any managed company pilot begins.

SharePoint boundary

SharePoint links are restricted to Teams-enabled projects. FieldRadar currently stores the link and document metadata; the linked file remains in the customer's Microsoft 365 environment and continues to follow that organisation's SharePoint permissions.

Subscriptions

Individual Pro purchases are processed by Apple or Google and subscription status is managed through RevenueCat, so FieldRadar will not receive app-store card details. Team and Team Plus are managed company pilots; company billing and VAT treatment are agreed in the written order and reflected in the privacy information before payment is taken.

Account and data deletion

You can start account deletion from Settings in the app or use the external deletion request page. The current deletion path removes the account and queues owned FieldRadar records and files for removal, but retry and reconciliation evidence for failed file deletion is still being completed. We do not currently promise immediate or infallible removal of every stored object.

Company-workspace records may need to remain with the contracting company, and files held separately in Microsoft 365 are controlled there. We will explain the scope and any required retention when handling an external request.

Third-party processors

See the privacy policy for what these services receive and the current transfer-review status.

Operational readiness

FieldRadar does not currently claim a security certification, audited service level, published uptime target, recovery-time objective or recovery-point objective. A public live-telemetry status service and completed restore-drill evidence remain launch gates. The status page explains the current communications route.

Report a security issue

Please use the responsible security-reporting route. There is no public bug bounty or guaranteed response time at present.

This page deliberately identifies controls that are still being validated. It is not a certification, penetration-test report, warranty or guarantee. For data collection and rights, see the privacy policy.