FieldPix
TermsPrivacyRefundsCookiesSign in

Legal

FieldPix Privacy Policy

Effective date: September 25, 2026 · Last updated: September 29, 2026

1. Who we are

This Privacy Policy explains how Los Gatos Taxi Innovators LLC, doing business as FieldPix ("we," "us"), collects, uses, and shares information when you use the FieldPix mobile app, the FieldPix web portal, the project pages your team shares with clients, and related services (the "Service").

2. Information we collect

Account and organization information: name, email address, and password (stored as a secure hash, never in plain text) when you register; your role within your organization (admin or crew) and which organization you belong to; optional profile information you choose to add.

Content you create — photos and videos: media you capture through the app, including embedded GPS location and capture timestamp metadata — a core, intentional part of how FieldPix works. Depending on your team's camera settings, this location and timestamp may be visibly burned into the image or video itself.

Content you create — audio: videos recorded in the app capture sound as well as picture, using your device's microphone. Photo capture does not use the microphone. Recording audio of other people may require their consent depending on where you are — see the Acceptable Use section of our Terms of Service.

Content you create — walkthrough recordings: if you use the Walkthrough feature, the app records audio from your microphone while you walk a job site — including while the screen is locked — until you pause or stop. The recording is uploaded to create your notes and is kept with the project until the walkthrough, project or organization is deleted.

Content you create — photos from your existing library: in some places the app lets you attach an existing photo instead of taking a new one (for example, adding a photo to a project or a checklist item, or uploading your company logo for report branding). A photo imported this way is uploaded with whatever metadata it already carries, which may include the location and time it was originally taken — potentially somewhere other than the job site.

Content you create — everything else: project and customer information your organization's admins enter (job address, customer name/phone/email), plus tags, labels, notes, checklist responses, comments, and the PDF reports generated from the above.

Electronic signatures: when someone signs an agreement or report through FieldPix, we store the signature image, the name they type, the time they signed, their IP address, a description of their device or browser, and a fingerprint (SHA-256 hash) of the document they signed. These details are printed on a certificate page attached to the signed PDF.

Your clients: when your team shares a project page, the client can view what you've shared, comment, upload photos, sign documents and pay payment requests. We store what they submit, the name they give, and standard request information such as IP address.

Billing information: subscriptions bought in the iPhone or iPad app are processed by Apple — we receive only a transaction record confirming the plan, never your payment details. Subscriptions bought on the web, and payments your clients make to your organization, are processed by Stripe; card entry happens on Stripe's own secure pages or, with Tap to Pay on iPhone, is read by Apple and Stripe directly from the card or wallet. We never receive card numbers — only limited metadata back (like subscription status, plan, payment status, and who on the team took a payment). Payments recorded by hand (cash, check) store the amount, method, any note you add, and who recorded it. See Apple's and Stripe's privacy policies for how they handle payment data.

Device and usage information: a device push-notification token if you enable push notifications, used only to deliver in-app notifications like new comments; standard technical/request logs used for debugging and security, not advertising; and crash and error reports sent to Sentry (app version, device model and operating system, and the technical details of the error) so we can find and fix bugs — these aren't used for advertising and the app doesn't attach your name or email to them. Face ID / biometric login, where offered, is handled entirely by your device's own operating system — we never receive, see, or store any biometric data ourselves.

Device permissions we ask for: camera and microphone (to capture photos and videos, and to record walkthroughs), location (to geotag captures), photo library access (to save captures to your camera roll if you turn that on, and to attach existing photos), and biometrics (only if you turn on Face ID login). You can decline or later revoke any of these in your device settings; declining a permission disables the feature that needs it rather than blocking the app entirely.

What we don't do: we don't run advertising trackers or third-party analytics in the app or the web portal, we don't track you across other companies' apps or websites, and we don't sell your data to data brokers or advertisers.

Cookies and similar storage. We don't use advertising or cross-site tracking cookies. The web portal uses one strictly necessary sign-in cookie and stores a few preferences (like light or dark appearance) in your browser; payment pages served by Stripe use Stripe's own cookies for fraud prevention. Our website analytics, where enabled, are cookieless and don't identify you. See our Cookie Policy at fieldpix.org/cookies.html.

3. How we use your information

We use the information above to: provide the core Service (storing and organizing your photos/videos/projects, generating reports, syncing offline captures); operate your account and organization, including team membership and role-based permissions; process billing through Stripe and manage your subscription; send you service-related communications (password reset emails, billing receipts, or comment notifications you've opted into); maintain the security and reliability of the Service; and comply with legal obligations.

AI features. The AI features are optional, and the app asks your permission before first using them. When you use one, we send the audio you recorded, the photos you include, and the project's name, address and client name to OpenAI, which transcribes the audio and drafts the document. OpenAI processes this data to return the result to us; under OpenAI's API terms it isn't used to train OpenAI's models, and OpenAI may keep it for up to 30 days to monitor for abuse before deleting it.

We do not use your Customer Content (photos, project data, etc.) to train any AI models, and we do not use it for any purpose beyond providing the Service to your organization.

4. Who we share information with

We share information only as needed to run the Service:

  • Stripe (payment processing) — receives the billing and subscription information needed to process web subscriptions, and processes payments your clients make to your organization's own connected Stripe account.
  • Apple — processes subscriptions bought in the iPhone or iPad app and confirms them to us.
  • Cloudflare R2 (our cloud storage provider) — stores your uploaded photos, videos, thumbnails, and generated PDF reports. Files are held in a private bucket and served only through temporary signed links.
  • OpenStreetMap's Nominatim service — when you look up or confirm a project address on the map, that address text is sent to Nominatim's geocoding service to find its coordinates. This lookup runs from our servers rather than from your device, so your device's IP address isn't shared with Nominatim.
  • Expo's push notification service (exp.host) — if you enable push notifications, your device's push token is sent through Expo's infrastructure to deliver notifications.
  • OpenAI — only when you use the AI features: receives the recordings, selected photos and project details described in Section 3, to transcribe them and draft the document.
  • Resend (our email provider) — receives your email address and the content of service emails we send you, such as password resets and notifications you've turned on.
  • Sentry (crash reporting) — receives crash and error reports as described in Section 2.
  • Your organization's other members, according to normal use of the Service — for example, a project's photos are visible to your teammates per their role.
  • Your organization's clients — when your team shares a project page, signing request or payment request, the client sees what your team chose to share.
  • A CRM or other system your organization chooses to connect (optional, org-by-org) — if enabled, relevant project data is sent to that connected system. We're not responsible for how that external system handles data once it arrives there.

We do not sell your personal information. We only disclose information beyond the above if required by law or to protect the rights, property, or safety of FieldPix, our users, or the public.

5. Data retention and deletion

We retain your account and Customer Content for as long as your organization's account is active. If your organization cancels its subscription or an account is closed, we retain data for 90 days afterward to allow for account recovery, after which it may be deleted.

What you can delete yourself, from the app or the web portal:

  • A single photo or video — press and hold it in a project's grid, or use Delete in the photo viewer on the web. Available to anyone on the team, not just whoever captured it. It moves to Recently deleted.
  • A whole project, with all of its photos, videos, reports and comments (admins). It moves to Recently deleted.
  • A generated report, including its PDF — removed immediately.
  • Your account — Settings → Delete account. If you are the only person on your team, this also deletes your organization and everything in it. If your team has other members, your personal account is erased (name, email, password and push token are all destroyed and you can no longer log in) while the photos and comments you contributed stay with your organization, which owns them; your name is removed from them.

Deleted photos, videos and projects are hidden from everyone right away and kept in Recently deleted for 30 days, so an accidental deletion can be undone: anyone on the team can restore a photo, and an admin can restore a project. After 30 days — or immediately, if an admin chooses Delete forever — the records and the underlying files in our cloud storage are permanently erased. Account deletion and report deletion are immediate. To protect against data loss, we keep backups of stored files and the database; anything you delete is purged from those backups within 30 days (database backups within 14 days), and we only use backups to recover from a system failure or to reverse an accidental deletion at your request. If you would prefer us to handle a deletion for you, or you want something removed that the app does not cover, contact us (Section 11).

6. Data security

We use industry-standard measures to protect your information, including encrypted connections (HTTPS only) between the app, the website and our servers; hashed password storage (bcrypt); rate limits on sign-in; and access controls that keep one organization's records separate from another's — every request is checked against the organization the requesting account belongs to, and the database itself enforces the same separation (row-level security). Your clients' contact details (names, phone numbers, email addresses) and the details recorded with electronic signatures are additionally encrypted at rest in our database. On the web portal, your sign-in is kept in a secure, HttpOnly cookie that page scripts cannot read.

Your photos, videos and PDF reports are held in private cloud storage that is not publicly readable. When the app shows you a photo, it requests a temporary signed link that works for a limited time and then stops working, so a link that leaks or is forwarded does not grant permanent access to your files. One exception worth knowing about: a link embedded inside a generated PDF report (the "tap to play" link on a video) is signed for a longer period, up to seven days, because the PDF is a file you keep — after that it expires and the video must be opened in the app.

No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable steps to protect your information and will notify affected users as required by law in the event of a breach affecting their data.

7. Your rights and choices

Depending on where you live, you may have rights to access, correct, or request deletion of your personal information. You can update your profile information directly in the app; delete a whole project from within the app if you're an admin (see Section 5 for what that does and doesn't remove); or contact us (Section 11) to request a copy of your data, or to request deletion of your account and associated data, subject to our legitimate need to retain certain records (e.g., billing history) as required by law.

Photos, projects and other Customer Content belong to your organization, which decides what's collected and kept. If you're a client or other person whose information a FieldPix customer recorded, you can contact that company directly, or contact us and we'll pass your request on.

California and other U.S. state residents: depending on your state, you have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, and to not be discriminated against for exercising these rights. We don't sell personal information, we don't share it for cross-context behavioral advertising, and we don't use sensitive personal information to infer characteristics about you. To make a request, email support@fieldpix.org; we'll verify it's you and respond within the time the law requires. You can use an authorized agent to make a request on your behalf.

EU and UK residents: we process your information to provide the Service under our contract with you or your organization, for our legitimate interests in keeping the Service secure and working, and with your consent where we ask for it (for example, before you first use the AI features). In addition to the rights above, you can object to or restrict our processing, ask for a portable copy of your data, withdraw consent at any time, and complain to your local data protection authority.

8. Children's privacy

FieldPix is a business tool intended for use by adults on behalf of a company. It is not directed at children, and we don't knowingly collect information from anyone under 18. If we learn we've collected information from a child, we'll delete it.

9. International users

FieldPix is operated from the United States, and our servers and service providers are located primarily in the United States. If you use FieldPix from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those where you live.

10. Changes to this policy

We may update this Privacy Policy from time to time. We'll notify you of material changes (for example, via email or an in-app notice) before they take effect.

11. Contact us

Questions about this Privacy Policy, or want to make a data access/deletion request? Contact us at support@fieldpix.org.

This policy describes FieldPix's actual data practices as of the date above.