1. Scope and roles
AppWrapp, LLC, with its registered office at 651 N Broad St, Suite 201, Middletown, DE 19709, United States, is the controller for Fielduro account, billing, support, security, consent, and optional analytics data. Privacy requests can be sent to privacy@fielduro.com. When a business uses Fielduro to store its own customers, documents, addresses, services, and payment records, that business is the controller and AppWrapp generally acts as its processor.
2. Data we collect
- Account data, such as email, authentication identifiers, consent evidence, and account status.
- Business profile data, such as business name, contact details, address, website, tax identifier, country code, and logo.
- Customer and document data submitted by the business, including contact details, service addresses, line items, notes, status, secure links, and customer responses or questions submitted through those links.
- Recipient verification data, including the intended recipient email, verification request and completion times, an expiring browser-session record, and related security metadata. Verification secrets are stored as one-way hashes.
- Billing and payment data, including Stripe and RevenueCat customer identifiers, subscription state, purchase history, invoice-payment status, manual payment records, and optional payment proof. We do not receive complete card numbers.
- Support, security, and diagnostic data, such as correspondence, request metadata, device or browser information, rate-limit records, and minimized error reports.
- Optional analytics and session replay only after consent, including the visible screen content described in section 8.
- Push notification data, such as app installation identifiers, device metadata, notification preferences, and delivery tokens.
3. Why we process data
We process data to provide and secure the service, authenticate users, create and deliver documents, operate subscriptions and payments, respond to support, prevent fraud and abuse, comply with law, and establish or defend legal claims. For EEA and UK users, our legal bases include performance of a contract, legitimate interests in secure and reliable operations, compliance with legal obligations, and consent for optional analytics.
4. Sharing
We share data only with service providers needed to operate Fielduro, with professional advisers under confidentiality, when required by law, to protect rights and safety, or as part of a corporate transaction. The current provider list is on our Subprocessors page. We do not sell personal data or share it for cross-context behavioural advertising.
5. International transfers
Fielduro and its providers may process data outside your country. Where required, we rely on adequacy decisions, the European Commission’s Standard Contractual Clauses, the UK Addendum, and supplementary safeguards provided by our vendors.
6. Retention
Active account data is retained while the account is open. Recipient verification links expire after 15 minutes and verified browser sessions expire after 30 days or sooner when revoked. Deleted account content is removed from active systems through the account-deletion process. Limited records may remain temporarily in encrypted backups, security logs, billing records, email-delivery logs, or legal records where needed for recovery, fraud prevention, tax, accounting, dispute, or legal obligations. We minimize retention and review the applicable periods as our systems mature.
7. Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Signed-in users can export and delete account data in Settings. You may also contact privacy@fielduro.com. We may verify identity before completing a request. EEA and UK users may complain to their local supervisory authority, including the Spanish Data Protection Agency where applicable.
8. Analytics and cookies
Optional Amplitude analytics on the website and optional UXCam analytics and session replay in the iOS and Android apps remain off until you consent. UXCam records navigation, taps, and screen content to help us understand usability. Recordings are not globally blurred and may include visible business and customer contact details, documents, financial amounts, uploaded images, and search text. Automatic widget-label events and network logging are disabled, and separate custom event properties exclude customer details, document content, search text, financial amounts, and access tokens. UXCam also processes device identifiers, approximate location, and an internal account identifier. You can reject or withdraw through Cookie settings on the website or Consent & privacy under More in the mobile app without losing core features. UXCam recording is not enabled in the macOS app. See our Cookie Policy.
9. Security
We use safeguards appropriate to the service, including encrypted transport, access controls, database ownership policies, private file storage, signed webhooks, expiring links, email verification before customer responses, HttpOnly browser-session cookies, secret management, and monitoring. No service can promise absolute security. See our Security page for verified controls and reporting instructions.
10. Automated decisions and children
Fielduro does not make automated decisions that produce legal or similarly significant effects. The service is for business users aged 18 or older and is not directed to children.
11. Business customers as controllers
If a Fielduro customer has stored your information in a document, contact that business first because it decides why your data is used. We assist customers with verified privacy requests under our DPA.
12. Changes
We will post updates here with a revised effective date and provide additional notice when a material change requires it.
Questions
Contact legal@fielduro.com.