FieldFlow

Privacy Policy

Version 2026-07-31 · Effective July 31, 2026

This Privacy Policy explains what information FieldFlow collects, why we collect it, who we share it with and the choices you have.

1. Information we collect

We collect only what is needed to schedule, deliver and document a field service:

  • Identity and contact details: name, email address, phone number, service address.
  • Booking details: service selected, appointment window, access notes, order and payment status.
  • Health-related details you provide for a clinical booking, such as the ordering provider, requisition or test panel.
  • Identity verification artifacts captured for notarial acts, including ID images and signatures.
  • Location data: professional GPS position while an appointment is active, used for live tracking and arrival estimates.
  • Device and usage data: IP address, browser type, pages viewed and consent events.

2. How we use information

We use information to:

  • Match your booking to qualified professionals in your area and dispatch the assignment.
  • Process payments, refunds and professional payouts.
  • Send transactional messages about your appointment by email and, if you opt in, SMS.
  • Maintain chain-of-custody, notarial journals and compliance records required by law.
  • Detect fraud, secure the platform and resolve disputes.

3. We do not sell your data

FieldFlow does not sell personal information and does not share it with third parties for cross-context behavioral advertising.

4. Who we share with

We share the minimum necessary with:

  • The independent professional assigned to your appointment — and only that professional.
  • The laboratory, ordering provider or recipient you designate.
  • Service providers acting on our instructions: Stripe (payments), Twilio (messaging), Supabase (hosted database and storage), and Resend (email).
  • Law enforcement or regulators when legally compelled.

5. Security

Access to customer records is enforced at the database level with row-level security so that only you, the professional assigned to your job and authorized administrators can read your record. Documents and identity images are stored in private buckets. Data is encrypted in transit and at rest, and offline field data is encrypted on-device using AES-GCM.

6. Retention

Booking and payment records are retained for seven years to satisfy tax and audit obligations. Notarial journal entries are retained for the period required by the commissioning state. Identity images captured for a notarial act are retained only as long as that state requires and are then deleted. Marketing and analytics data is retained for 24 months.

7. Your rights

Depending on where you live, you may request access, correction, deletion, portability or restriction of your personal information, and you may appeal a decision. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas and other states with comprehensive privacy laws have these rights and will not be discriminated against for exercising them.

Submit a request to recruiting@fieldflowlab.com. We respond within 45 days. Some records — notarial journals and chain-of-custody documentation — cannot be deleted where retention is required by law.

8. Children

The platform is not directed to children under 13, and we do not knowingly collect their information except as part of a service booked by a parent or legal guardian.

9. Changes and contact

We will post any changes here with a new effective date. Contact recruiting@fieldflowlab.com with questions.