Privacy Policy
Last updated: May 21, 2026
1. What we collect
When you sign up, we collect your email and name (which you provide). When you use the service we store the data you submit: workshop name, orders, pieces, measurements, photos, notes, and conversations.
We log basic technical information about each request — IP, user agent, timestamp — for security and debugging. We don't track you across the web, we don't sell your data, and we don't run third-party ads.
2. How we use it
- To run the service for you (show your orders, send notifications).
- To bill you (paid plans only — handled by Stripe).
- To send transactional email — sign-up confirmation, password reset, trial-ending notice. We do not send marketing email unless you explicitly opt in.
- To investigate abuse, fraud, and outages.
3. Where it's stored
Field to Fab is built on Supabase (Postgres database + storage), hosted in the U.S. region by default. Photos uploaded to the app live in Supabase Storage. Card payments are handled by Stripe (we never see or store full card numbers). Transactional email goes through Resend. Site analytics use Plausible (privacy-respecting, no cookies, no personal identifiers).
4. Tenant isolation
Each shop's data is isolated at the database level. Other tenants literally cannot read your orders, photos, or messages — Postgres row-level security enforces it on every query.
5. Your rights
You can:
- Access, edit, or delete your data from inside the app.
- Export your data — email hello@fieldtofab.com and we'll send a JSON export within 30 days.
- Close your account from Settings — see Terms of Service §7 for what happens after.
If you're a resident of a jurisdiction with stronger privacy laws (EU/EEA, UK, California), you also have the rights granted by GDPR, UK GDPR, or CCPA respectively. Email us to exercise them.
6. Cookies & local storage
We use a session cookie for authentication and a few small entries in your browser's localStorage for preferences (theme, dismissed install prompt). We do not use third-party tracking cookies.
7. Data retention
Active accounts: data is kept as long as the account is active. Closed accounts: data is retained for 30 days after closure (export window), then permanently deleted.
8. Children
Field to Fab is for B2B use by HVAC professionals. It is not intended for and not directed at children under 16.
9. Changes to this policy
We may update this Privacy Policy. Material changes will be announced via email or in-app notice at least 14 days before they take effect.
10. Contact
Privacy questions? Email hello@fieldtofab.com.
Questions about privacy policy? Contact us at hello@fieldtofab.com.