1. Information We Collect
FieldFox Pro ("we", "our", "the Platform") collects information necessary to provide field service management services:
- Account Information: Name, email address, role, and organization details provided during registration.
- Service Data: Work orders, invoices, timesheets, client records, messages, and other operational data created within the platform.
- Usage Data: Login timestamps, feature usage metrics, and session information for platform improvement.
- Device Information: Browser type, IP address, and device identifiers for security and compatibility.
2. How We Use Your Information
- To provide, maintain, and improve our field service management platform.
- To authenticate users and enforce role-based access control (RBAC).
- To generate invoices, reports, and operational analytics for your organization.
- To send service-related notifications and communications.
- To detect and prevent security threats, fraud, and unauthorized access.
3. Data Storage and Security
All data is stored in encrypted databases hosted on secure cloud infrastructure (Supabase/AWS). We implement:
- Encryption at rest: AES-256 encryption for all stored data.
- Encryption in transit: TLS 1.3 for all network communications.
- Row-Level Security (RLS): Organization-scoped data isolation ensuring tenants cannot access each other's data.
- Multi-Factor Authentication (MFA): Optional TOTP-based 2FA for enhanced account security.
- Audit Logging: All administrative actions are logged for accountability.
4. Data Sharing
We do not sell, rent, or share your personal data with third parties except:
- With your organization's administrators as permitted by your role.
- With service providers necessary to operate the platform (cloud hosting, email delivery).
- When required by law, regulation, or valid legal process.
5. Multi-Tenancy and Data Isolation
Each organization's data is logically isolated through Row-Level Security policies. Users can only access data belonging to their organization. Platform administrators have access to aggregated, non-identifiable metrics for service management.
6. Data Retention
We retain your data for as long as your organization maintains an active subscription. Upon account termination, data is retained for 30 days to allow for recovery, then permanently deleted. Audit logs are retained for 1 year for compliance purposes.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of your personal data.
- Correction: Update inaccurate personal information.
- Deletion: Request deletion of your personal data.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing of your data for certain purposes.
To exercise these rights, contact us at privacy@contact.ipoctet.com.
8. Cookies
We use essential cookies only for authentication and session management. We do not use tracking cookies or third-party analytics cookies. See our cookie preferences in the footer.
9. Contact
For privacy-related inquiries: privacy@contact.ipoctet.com
FieldFox LLC, United States