Privacy Policy

Last updated: April 9, 2026

1. Information We Collect

When you use FieldForm, we may collect:

  • Account information: email address and name when you sign up via Google or magic link.
  • Form data: the forms you create and the submissions you collect, including photos, GPS coordinates, and signatures.
  • Usage data: basic analytics such as pages visited and features used to improve the product.
  • Payment information: processed securely by Stripe. We never store your credit card details.

2. How We Use Your Information

  • To provide and maintain the FieldForm service.
  • To sync your forms and submissions across devices.
  • To process payments and manage your subscription.
  • To send important service-related notifications.
  • To improve the product based on aggregated, anonymous usage patterns.

3. Legal Basis for Processing (UK GDPR)

If you are located in the United Kingdom or European Economic Area, we process your personal data under the following legal bases:

  • Contract performance: processing your account information, form data, and submissions is necessary to provide the FieldForm service you signed up for.
  • Legitimate interest: anonymous analytics to improve the product, and service-related communications.
  • Legal obligation: processing required to comply with applicable laws, such as maintaining payment records.

4. Data Storage & Security

Your data is stored locally on your device using IndexedDB and synced to our cloud infrastructure powered by Supabase (hosted on AWS). All data is transmitted over HTTPS. Photos and files are stored in secure cloud storage with access controls. Passwords are hashed and never stored in plain text.

5. Offline Data

FieldForm is designed to work offline. Data you enter while offline is stored locally on your device and only synced to our servers when you reconnect to the internet. You maintain full control over when syncing occurs.

6. Third-Party Services & Data Sharing

We do not sell your personal information. We use the following third-party services to operate FieldForm:

  • Supabase — cloud database, authentication, and file storage. See Supabase Privacy Policy.
  • Stripe — payment processing. We never store your credit card details. See Stripe Privacy Policy.
  • Vercel Analytics — a privacy-focused analytics solution that does not use cookies or collect any personal information. See Vercel Analytics Privacy Policy.
  • Your team members — if you use team features, only the forms and submissions you explicitly share.

7. International Data Transfers

Our services and third-party providers may process your data outside the United Kingdom or European Economic Area, including in the United States. Where such transfers occur, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms to ensure your data remains protected in accordance with UK GDPR.

8. Data Retention

We retain your account information and form data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain certain records (e.g., payment records for tax purposes).

9. Cookies

FieldForm does not use cookies. We do not use any third-party tracking cookies or advertising cookies. Our analytics provider (Vercel Analytics) is privacy-focused and operates without cookies.

10. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.
  • Export your form data and submissions (data portability).
  • Restrict or object to certain processing of your data.
  • Withdraw consent at any time, where consent is the basis for processing.

If you are located in the United Kingdom, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes via the email associated with your account.

12. Contact

For privacy-related questions or to exercise your data rights, contact us on the About page.