Back to sign in

Privacy Policy

# Privacy Policy **Field Sales Companion** Version: 2026-03-01 · Effective: 1 March 2026 This Privacy Policy explains how Field Sales Companion ("Service") collects, uses, and shares personal data when you use our mobile app and web dashboard. We process data as a **data processor** on behalf of your employer ("Company") for most field-sales activity, and as a **data controller** for certain account and platform operations. Your Company may also act as a **data controller** for employee and customer data you enter at work. --- ## 1. Data we collect ### Account data - Email address, authentication identifiers, profile name and phone (if provided). ### Field activity data - Visit records: date/time, GPS coordinates at check-in, customer linked, notes, outcome, photos, next-action text and due dates. - Planned routes and stop order. - Customer names, phone numbers, addresses, and notes you or colleagues enter. ### Account request data - Business details submitted for new customer accounts, including payment terms and partner information where applicable. - Identity document photos uploaded for verification (sensitive data). ### Technical data - Device type, app version, IP address, and logs needed to operate and secure the Service (via Supabase and hosting providers). We do **not** intentionally collect special category data except ID documents you upload in the account-request workflow. --- ## 2. How we use data - Provide visit logging, routing, dashboards, notifications, and account-request workflows. - Verify visit location at the time of check-in. - Send local push notifications for follow-ups and in-app alerts (e.g. route changes, request decisions). - Maintain security, debug issues, and improve the Service. - Comply with legal obligations. **Legal bases (UK GDPR):** performance of contract, legitimate interests (operating a B2B field-sales tool), and consent where required (e.g. optional notifications). Your Company determines the legal basis for employee monitoring in your jurisdiction. --- ## 3. Who can see your data | Viewer | What they may see | |--------|-------------------| | **You** | Your own visits, routes, and submissions within your Company. | | **Your Company (managers/admins)** | Team visits, routes, customers, account requests, and dashboards for business management. | | **Service Operator (us)** | Data stored in our systems to run the Service (limited access, infrastructure). | | **Sub-processors** | Supabase (database/auth/storage), hosting (e.g. Vercel), OpenStreetMap tiles — only as needed to deliver the Service. | We do **not** sell your personal data. --- ## 4. Location data GPS is captured when you log a visit (or when the app geocodes an address), not as continuous tracking by default. Your Company may use visit locations to verify field activity and plan routes. --- ## 5. Retention - Active account data is kept while your account is active and as needed for your Company's business records. - When your account is deactivated, we or your Company may delete or anonymise data within a reasonable period, subject to legal retention requirements. - ID photos for account requests should be deleted or archived according to your Company's policy once verification is complete. --- ## 6. International transfers Data may be processed in the UK, EEA, or other countries where our sub-processors operate. We rely on appropriate safeguards (e.g. UK IDTA/SCCs) where required. --- ## 7. Your rights Depending on your location, you may have rights to access, rectify, erase, restrict, or port your data, and to object to certain processing. You may also withdraw consent where processing is consent-based. - **Employees:** Contact your Company first (they often control HR/field data). We will assist your Company with technical requests. - **Direct requests to us:** Use the contact details in the app or dashboard. You may lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority. --- ## 8. Security We use industry-standard measures including encrypted connections, row-level security in the database, and access controls. No system is 100% secure; report suspected breaches to your Company and us promptly. --- ## 9. Children The Service is not intended for users under 18. --- ## 10. Changes We may update this Policy. Material changes will be communicated via the app or email, and we may require re-acceptance. The accepted version is stored on your profile. --- ## 11. Contact For privacy questions, contact your Company administrator or the Service Operator via details provided in the application.