This policy explains what personal data FieldShield collects across its mobile app, its web app and its back-office, why we collect it, who we share it with and how you can control it.
This policy applies to every FieldShield surface: the mobile applications for iOS and Android, the web application at app.fieldshield.app, the public marketing site at www.fieldshield.app and the back-office at backoffice.fieldshield.app.
All these surfaces are operated by the same publisher and share a single backend, so the rules below apply uniformly no matter where you sign in.
We collect the following categories of information. Some are strictly required to run the service, others depend on features you enable or consents you grant.
First name, last name, professional email, hashed password (bcrypt), optional phone number, optional profile picture, role and entity type (project owner / EPC), language and time-zone preferences.
Projects, sites, tasks, RFIs, submittals, change orders, budget entries, forms, plans, PDF files, images, photos, sketches, plan annotations, comments and chat messages between project members, activity logs.
When you take a picture from the mobile app with the location permission granted, GPS coordinates and EXIF metadata are preserved so the photo is geo-tagged inside the project. Location capture is optional and can be revoked in your device settings.
If you accept the contacts permission on mobile, your address book is read locally to pre-fill project invitations. The list is never uploaded to our servers — only the invitations you actually send leave the device.
IDFA on iOS (subject to the App Tracking Transparency system prompt) and Android Advertising ID (AD_ID). Collected only when you have accepted the "Advertising" category of our consent banner and, on iOS, granted ATT.
Firebase Analytics events such as first_open, welcome_screen_viewed, register_screen_viewed, sign_up_attempted, sign_up, sign_up_failed, onboarding_completed and login. Meta App Events such as fb_mobile_activate_app and fb_mobile_complete_registration. UTM parameters (utm_source, utm_medium, utm_campaign) captured from campaign links. Sent only if you consented to "Analytics" and/or "Advertising".
IP address (transient, request-scoped), device model, operating system version, app version, browser identifiers, session timestamps, error diagnostics and Firebase Cloud Messaging (FCM) push token needed to deliver notifications.
Subscription history handled by Stripe for web checkout and by RevenueCat / Apple StoreKit / Google Play Billing for in-app purchases. Invoice details (name, billing address, VAT number where applicable) are stored for legal record-keeping.
Every processing operation is anchored to a legal basis under Article 6 of the GDPR. We rely on the following:
Authenticate you, sync projects across devices, run the collaboration features (tasks, RFIs, chat, files, plans), send transactional notifications (invitations, password reset, plan-limit alerts).
Alert you when a new task, message or activity concerns you inside a project you already belong to. Can be turned off in the app settings at any time.
Measure aggregate usage, understand which features work, spot regressions and prioritise the roadmap. Turned on only if you accept the "Analytics" category of the consent banner.
Attribute installs to campaigns, build lookalike audiences and re-engage users who signed up but never activated the app, on Meta, Google, LinkedIn and YouTube. Turned on only if you accept the "Advertising" category of the consent banner and, on iOS 14.5+, grant ATT.
Store invoices and payment history for the retention period required by tax and accounting regulations in France and the EU.
Detect abuse, rate-limit suspicious traffic, investigate incidents and enforce our Terms.
Answer your support requests and troubleshoot issues on the account you contact us from.
On first launch the mobile app displays a GDPR-compliant consent banner offering three options: "Accept all", "Reject all", or "Customise". The banner distinguishes three categories: Functional (always on, needed to run the service), Analytics (optional) and Advertising (optional).
You can revisit your choices at any time from Settings > Privacy inside the app. Refusing Analytics or Advertising does not restrict any core feature — the service still runs on the contractual basis.
On iOS 14.5 and above, a second consent layer is added by Apple's App Tracking Transparency (ATT) system prompt. If you decline ATT, the advertising identifier (IDFA) is never used, regardless of what you selected in our banner.
We retain personal data only for as long as it serves the purpose for which it was collected, or as required by law:
For the entire lifetime of the account. You can update your data at any time from Settings > Profile.
A 30-day grace period during which the account can be restored; personal data is then purged from live systems and from encrypted backups within 90 days.
Kept for 10 years, as required by French and European tax and accounting rules.
Retained for 14 months (default GA4 setting) then aggregated.
Retained by Meta according to its own policy (typically up to 2 years).
Kept until revoked or until 60 days of inactivity.
Kept for 90 days.
Rotated every two weeks; never retained by LinkedIn for more than 90 days.
Under the GDPR, and equivalent laws elsewhere, you have the right to access, rectify, delete or export your personal data, to restrict or object to certain processing, and to withdraw a consent at any time.
You can also lodge a complaint with a supervisory authority. In France, this is the CNIL (Commission Nationale de l'Informatique et des Libertés — www.cnil.fr). To exercise your rights, email help@fieldshield.app; we respond within 30 days. Account deletion can also be triggered directly from Settings > Account > Delete my account inside the app.
Data in transit is encrypted with TLS 1.2 or higher. At-rest storage is encrypted at the volume level. Passwords are hashed with a modern KDF (bcrypt). JWT access tokens are short-lived and rotated via refresh tokens. Back-office access is restricted, MFA-protected and audited. Backups are encrypted and run daily.
No system is perfectly secure — please contact help@fieldshield.app if you suspect an incident.
FieldShield is a B2B construction-management platform intended for professional use. The service is not directed at minors under 16. If we become aware that a minor has created an account, we will delete it and purge the associated personal data.
We may update this Privacy Policy as the product evolves. When we make a material change we will notify account admins by email and update the effective date at the top of this page. This version (July 17, 2026) reflects the introduction, in mobile app version 2.0.8, of the GDPR consent banner, of Meta App Events, of Firebase Analytics tracking and of Universal Links / App Links UTM capture. Continued use after such notice constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy, need to exercise a right or want to reach our Data Protection contact, please email the FieldShield privacy team: