Privacy Policy

# Privacy Policy **Field Sales Companion** Version: 2026-07-24 · Effective: 24 July 2026 Previous version: 2026-03-01 (superseded for new acceptances) This Privacy Policy explains how Field Sales Companion ("Service", "we", "us", "Operator") collects, uses, shares, and protects personal data when you use our mobile application and web dashboard. The full text is published on the web at `/legal/privacy`. The mobile app may show a summary of key points before acceptance; the summary does not replace this Policy. In case of conflict, this full text prevails. --- ## 1. Who we are and roles under data protection law 1.1 **Your employer or client organisation ("Company")** typically decides why field-sales activity is recorded and how workers are supervised. For most visit, customer, route, balance, and account-request data you enter at work, your Company is the **data controller** (or joint controller with others in your corporate group), and we act as a **data processor** providing the platform under instructions from the Company. 1.2 We act as a **data controller** for certain limited purposes, including: creating and securing your login; storing legal-acceptance records; detecting abuse and securing the Service; communicating service-related notices; and complying with our own legal obligations. 1.3 If you are unsure who controls a particular dataset, start with your Company administrator or data-protection contact. We will assist your Company with technical fulfilment of requests where appropriate. 1.4 This Policy is drafted with the **UK GDPR** and the **Data Protection Act 2018** in mind. If you access the Service from another jurisdiction, additional local rules may apply; your Company remains responsible for lawful workplace monitoring in your country. --- ## 2. Personal data we collect ### 2.1 Account and profile data - Email address and authentication identifiers (via our auth provider). - Display name, phone number, and profile fields you or your Company provide. - Role and company membership used for access control. - Legal acceptance timestamps and the **legal version** you accepted (Terms and Privacy). ### 2.2 Field activity data - **Visits:** date/time, customer link, notes, outcome, optional **sale amount**, next-action text and due dates, optional photos, and **GPS coordinates** (and related metadata) captured when a visit is logged. - **Customers:** names, phones, addresses, notes, shop / venue type tags, geocoded coordinates, ownership / assignment within the Company, and related commercial fields. - **Routes:** planned stops, order, notes, and route-change messages. - **Offline queues:** pending visit or related payloads stored on your device until sync succeeds (may include the same fields as online visits, including sale amount and photo bytes). ### 2.3 Account request / KYC-style data - Business details submitted for new customer accounts (for example trading name, address, VAT or company numbers, credit limit requests, partner details — as configured by your Company). - **Identity document images** (for example passport or driving licence) uploaded for verification. These are sensitive and must be handled under strict Company instructions. ### 2.4 Balances / accounts receivable - Current balances, due dates, currency, and ledger entries (charges, payments, adjustments) with notes and actor identity — visible according to role-based access rules. ### 2.5 Suggest new shops / map discovery - When you run a nearby search, the app uses your **chosen search location** (often your current GPS position or a map centre) and a **radius**, plus selected **category filters**, to query public map APIs. - Search results (public OSM shop/amenity names and coordinates) may be shown on device; if you add a venue as a customer, that becomes Company customer data. - Local **dismiss / hide** preferences for suggested venues may be stored on your device (for example via on-device preferences) so hidden suggestions stay hidden on that device. ### 2.6 Technical and security data - Device type, OS, app version, IP address, approximate request metadata, and logs needed to operate, secure, and debug the Service (via hosting and database providers). - Middleware and session cookies / tokens required for authenticated web access. ### 2.7 Notifications - Local notification schedules on your device for follow-ups, overdue balances, or operational alerts. These are typically generated on-device and are not a substitute for a separate marketing consent regime. ### 2.8 What we do not intentionally collect - We do not intentionally collect special-category data **except** identity documents you upload in authorised account-request workflows, or other data your Company expressly configures and you are authorised to submit. - We do **not** sell personal data. - We do **not** run continuous background GPS tracking by default. --- ## 3. How we use personal data (purposes) We (and, where we process on behalf of your Company, your Company) use data to: - Provide visit logging, routing, dashboards, balances, team performance, account requests, and related features. - Verify visit location at check-in and display maps / history. - Discover nearby public venues via OpenStreetMap tooling when you use Suggest new shops. - Geocode addresses and show map tiles. - Show optional weather context near a location. - Send local notifications and in-app operational alerts. - Enforce roles, invitations, and security (including row-level access controls). - Store and evidence acceptance of Terms and Privacy versions. - Maintain, debug, and improve the Service; prevent abuse and fraud. - Comply with legal obligations and respond to lawful requests. **Legal bases (UK GDPR) — illustrative:** - **Contract / steps prior to contract** — providing the Service you and your Company signed up to use. - **Legitimate interests** — securing and operating a B2B SaaS field tool; preventing misuse; improving reliability (balanced against your rights). - **Consent** — where required (for example certain optional device permissions or marketing, if ever offered). - **Legal obligation** — where we must retain or disclose information by law. - Your Company determines the legal basis for **employee monitoring** and HR-related uses in your jurisdiction. --- ## 4. Location data in detail 4.1 **Visit check-in GPS** is captured when you save a visit (or equivalent action), not as an always-on track. 4.2 **Geocoding (Nominatim / OSM-based):** Address strings or coordinates may be sent to a geocoding service to place pins. Do not put unnecessary personal data into free-text address fields. 4.3 **Overpass (Suggest new shops):** Your search coordinates, radius, and category filters are sent to public Overpass endpoints to retrieve OSM features. Overpass operators receive technical request data (IP, User-Agent, query). Prefer searching only where you have a legitimate work need. 4.4 **Map tiles:** Loading a map causes your client to request tiles for the visible area from a tile provider; that typically reveals approximate viewport location to the tile CDN. 4.5 **Open-Meteo (or similar weather APIs):** Coordinates may be sent to obtain weather for display. 4.6 Your Company may use visit locations to verify field activity, coach teams, and plan routes. If you object to workplace location processing, raise it with your Company (employment / data-protection channels) as well as with us where we are controller. --- ## 5. Who can see your data | Viewer | What they may see | |--------|-------------------| | **You** | Your own profile and the field data your role permits (often your visits/customers; executives may see more). | | **Company executives / admins** | Company-scoped operational data needed to manage the team (visits, customers, requests, balances, performance), subject to configured roles. | | **Supervisors** | Typically broad **read** access to company field data without certain write privileges (as configured). | | **Field representatives** | Primarily their own customers/visits, plus any shared features your Company enables. | | **Service Operator (us)** | Infrastructure-level access as needed to run, secure, and support the Service; not for unrelated secondary marketing. | | **Sub-processors** | Only as needed to deliver the Service (see Section 6). | Access is enforced with authentication and database **row-level security** policies. Misconfiguration risk can never be zero; report suspected unauthorised access immediately. --- ## 6. Sub-processors and third-party recipients We use service providers to operate the Service. Categories include: | Category | Examples (current / typical) | Data involved | |----------|------------------------------|---------------| | Database, auth, file storage | **Supabase** (or successor) | Account, field data, photos/ID files in storage buckets, logs | | Web application hosting | **Vercel** (or successor), where the dashboard is deployed | Web request data, cookies/tokens as needed | | Map geodata query | **Overpass API** public instances | Search coordinates, radius, category query, IP/User-Agent | | Geocoding | **Nominatim** / OSM-based geocoders | Address or coordinate lookups, IP/User-Agent | | Map tiles | **OpenStreetMap** tile servers or equivalents | Tile requests for map viewport | | Weather | **Open-Meteo** (or equivalent) | Coordinates for forecast/context | | Device OS | Apple / Google notification and location frameworks | Permission-gated device services | We do not sell personal data to data brokers. Third parties process data under their terms and, where they act as our processors, under appropriate contracts / safeguards. **OpenStreetMap notice:** OSM data is publicly contributed and licensed (typically ODbL). Suggested shops are public map features, not a private credit file. --- ## 7. International transfers Data may be processed in the **United Kingdom**, **European Economic Area**, and other countries where our sub-processors operate. Where required, we rely on appropriate transfer safeguards (for example UK International Data Transfer Agreement / Addendum, Standard Contractual Clauses, or adequacy decisions). --- ## 8. Retention 8.1 **Active accounts:** Data is retained while your account and Company workspace remain active and as needed for the Company's business records. 8.2 **After deactivation:** We or your Company may delete or anonymise personal data within a reasonable period, subject to legal retention (tax, dispute, security) and your Company's instructions. 8.3 **ID photos:** Should be retained only as long as needed for verification and Company policy; ask your Company for its KYC retention schedule. 8.4 **Device-local data:** Offline queues and local dismiss lists remain on your device until cleared by the app, OS uninstall, or a future sync feature. 8.5 **Logs:** Security and application logs are kept for a limited operational period unless needed longer for investigations. --- ## 9. Security We use industry-standard measures appropriate to a small B2B SaaS product, including encrypted transport (HTTPS/TLS), authenticated APIs, role-based access, and database row-level security. Identity documents and photos should be stored in restricted storage with policies limiting who can read them. No system is 100% secure. You must use strong unique passwords, protect your device, and report suspected breaches to your Company and us promptly. Your Company may enable additional Auth protections (for example leaked-password protection) on the identity provider. --- ## 10. Your rights Depending on your location and whether we or your Company is controller for the relevant processing, you may have rights to: - Access your personal data; - Rectify inaccurate data; - Erase data in certain circumstances; - Restrict or object to certain processing; - Data portability; - Withdraw consent where processing is consent-based; - Lodge a complaint with the **UK Information Commissioner's Office (ICO)** or your local supervisory authority. **Employees and contractors:** Contact your **Company first** for most field-activity and HR-related requests. We will assist the Company with technical steps (exports, deletion within the platform) where feasible. **Direct requests to us (controller purposes):** Use the contact channels published in the app or dashboard. We may need to verify your identity and may refuse requests that are manifestly unfounded, excessive, or that would unduly infringe others' rights or our legal obligations. --- ## 11. Children The Service is not directed at individuals under 18. We do not knowingly collect children's data. If you believe a minor has created an account, contact us and your Company so we can delete it. --- ## 12. Automated decision-making The Service does not make solely automated decisions that produce legal or similarly significant effects about you (such as automated hiring or credit scoring of individuals). Operational filters, maps, and performance dashboards are tools for human decision-makers in your Company. --- ## 13. Cookies and similar technologies (web) The web dashboard uses cookies or local storage as needed for authentication sessions and basic app function. We do not use the Service as a third-party advertising network. Browser controls may limit cookies but can break login. --- ## 14. Changes to this Policy We may update this Policy. Material changes will be published with a new version identifier and may require re-acceptance in the app and/or web. The accepted version is stored on your profile. --- ## 15. Contact For privacy questions: 1. Contact your **Company administrator** or data-protection contact first for workplace / field data; then 2. Contact the **Service Operator** via details provided in the application or web dashboard. UK supervisory authority: Information Commissioner's Office — [https://ico.org.uk](https://ico.org.uk) --- ## 16. Language This Policy is provided in English. If a translation is supplied for convenience, the English version controls unless mandatory local law requires otherwise.