Fieldstub › Privacy
Privacy Policy
This policy explains how PurelySearch LLC ("Fieldstub", "we", "us") handles personal data on fieldstub.com and app.fieldstub.com (the "Service"). For the plain-language version, including the full list of providers we use, see Trust and security.
1. Who we are#
The Service is operated by PurelySearch LLC, a limited liability company organized in Delaware, United States. For anything on this page, contact privacy@fieldstub.com.
2. Data we collect from our customers#
A Fieldstub customer is a general contractor with a Procore account. From them we hold:
- Account data: the email address of each person who signs in, read from your Procore company directory, and the time they last signed in. There are no passwords: sign-in is a single-use link sent by email.
- Configuration: the capture links you create, and the project each one belongs to.
- API keys: a hash of each key, a short non-secret prefix, who created it and when it was last used. The key itself is never stored.
- Access requests: if you ask for access before your company has installed the app, the name, email, company and note you submitted.
- Usage data: a thin set of allow-listed product events, described in section 7.
- Communications: anything you email us.
3. Data we hold about people who are not our users#
This section matters more than the last one, and most privacy policies do not have it.
The person who fills in a Fieldstub ticket is usually a subcontractor or a crew member. They have no Procore seat, no Fieldstub account, and no agreement with us. They scanned a code taped inside a gang box. What a submitted ticket can contain about a person is:
- The name and role of whoever signed the ticket, and an image of the signature they drew on the screen
- The name of whoever directed the work
- Photographs of the work, which on a jobsite may include people
- For each photo, the time it was taken and, only if the device offers it and the browser permits it, the coordinates
For all of this the general contractor is the data controller and Fieldstub is the processor. We hold it on their behalf, under the Data Processing Agreement, and we use it for exactly two things: showing the ticket to the reviewer, and filing it into that contractor's Procore when the reviewer approves it.
We do not build a profile of a field worker, link their submissions across tickets or across contractors, market to them, or use their data to improve anything. The capture form sets no cookie, loads no third-party script, and runs no analytics.
If you are a field worker and want to know what was recorded about you, ask the contractor whose code you scanned. They control the record. You can also write to privacy@fieldstub.com and we will help you reach them.
4. How we use data#
- To operate and secure the Service
- To decide who may sign in, by checking an address against your Procore company directory
- To show tickets to your reviewers and, on their approval, write change events into your Procore
- To send transactional email: sign-in links and notifications you enable
- To understand how the product is used, at the coarse level described in section 7
- To meet legal obligations and enforce our terms
We do not sell personal data, and we do not use your tickets, photos or signatures to train machine-learning models.
5. Legal bases (EEA and UK)#
Where the GDPR applies, we rely on performance of a contract for providing the Service, legitimate interests for securing and improving it, consent where consent is required, and compliance with legal obligations. For the field data described in section 3 the contractor is the controller and is responsible for establishing a lawful basis and giving notice to the people concerned.
7. Analytics#
We use PostHog. What reaches it is restricted by an allow-list in the code: every event is named individually and declares which properties may accompany it, so nothing travels by accident.
No ticket content is ever sent. Not descriptions, names, photos, signatures or amounts. An approved ticket sends how many lines it had and how many were unrouted, and nothing else.
Where an event relates to a person, the email address is replaced with a keyed HMAC rather than a plain hash, because a plain hash of an email address can be reversed by guessing. Rotating the key re-pseudonymises everyone, which is intentional.
The marketing site at fieldstub.com uses the standard PostHog browser snippet. The capture form does not, and never will.
Our server logs are masked too. Where a log line needs to identify somebody it records d*****@company.com rather than the address itself, so a copy of your directory does not build up in a hosting provider’s log retention. This reduces the exposure; it is not anonymisation, and the domain is still visible.
8. Retention#
We keep data while your account is active and for a reasonable period afterwards to meet legal and accounting requirements. You can request deletion at any time and we will confirm when it is done.
We do not currently run an automatic schedule that deletes old tickets on a timer. If your policy requires one, we will agree it with you in writing rather than pretend the software already does it.
9. Security#
Encryption in transit and at rest, no stored passwords, hashed and revocable API keys, per-request access checks against your Procore directory, and tenant isolation enforced in the service layer rather than bolted on. The detail is on the Trust and security page. No system is perfectly secure; report anything you find to security@fieldstub.com.
10. Your rights#
Depending on where you live you may have the right to access, correct, delete, export, or object to the processing of your personal data. Email privacy@fieldstub.com and we will respond within the time the law allows. California residents have rights under the CCPA including the right to know and the right to delete; we do not sell personal information.
If your request concerns data submitted from a jobsite, we will usually need to route it through the contractor who controls that record, and we will tell you that we are doing so.
11. International transfers#
We are based in the United States and our sub-processors process data in the United States. If you use the Service from elsewhere, your data will be transferred there. Where personal data comes from the EEA, UK or Switzerland, the parties rely on a lawful transfer mechanism such as the EU Standard Contractual Clauses.
12. Children#
The Service is not directed at children under 16 and we do not knowingly collect their data.
13. Changes#
We may update this policy. On a material change we will revise the effective date and, where appropriate, tell account holders. Continuing to use the Service after a change means you accept it.
14. Contact#
PurelySearch LLC · privacy@fieldstub.com
Put a code on one job and see what comes back.
Fieldstub turns a phone and a QR code into a signed Change Event in Procore. The field needs no login and no seat.
Start free