Legal
Privacy Policy
Last Updated: September 7, 2026
1. Scope
This Privacy Policy explains how Ontario Engineering Solutions Inc., doing business as FieldWorks ("FieldWorks," "we," "us," or "our"), collects, uses, discloses, stores, and protects personal information in connection with the FieldWorks websites, authenticated application, external share-link workflows, communications, and related services (collectively, the "Service").
FieldWorks is a multi-tenant construction management platform that helps organizations manage project workflows, deficiencies, submittals and RFIs, job costs, inspections, specifications, files, team access, billing, and external collaboration. FieldWorks is operated from Ontario, Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA) is the primary privacy law that applies to us, and this Privacy Policy also describes rights that may apply to you under provincial Canadian laws, the GDPR, the UK GDPR, and US state privacy laws, depending on where you are located.
2. Roles and Responsibilities
If you use FieldWorks on behalf of an organization, that organization controls the project data, files, comments, and workflow records it submits to the Service. In those situations:
- your organization is generally the data controller, business, or equivalent decision-maker for that customer data;
- FieldWorks generally processes that customer data on the organization's behalf in order to provide the Service; and
- your organization decides who can see its data, including through team membership, external share links, cross-organization guest access, and document exports.
If your request relates to customer-controlled project data, we may direct you to the relevant organization administrator or coordinate with that organization as required by law and contract. Additional processing terms for business customers are addressed in our Data Processing Addendum.
3. Information We Collect
We collect information directly from users, automatically through the Service, from organizations that use FieldWorks, and from service providers used to deliver the Service.
A. Account and Profile Information
We may collect:
- name
- email address
- account credentials and password hashes
- profile image
- timezone (used to format timestamps, audit records, and logs in your local time)
- account verification status
- authentication settings such as passkeys or multi-factor authentication data
B. Organization and Team Information
We may collect:
- organization name
- membership and role information
- invitations, acceptances, and team administration records
- organization billing ownership and account administration details
- tool assignments and related entitlement records
C. Project and Workflow Information
Organizations and users may submit or generate:
- project names, numbers, descriptions, addresses, dates, and statuses
- deficiency, submittal, RFI, job cost, inspection, and specification records, including descriptions, locations, statuses, comments, and assignee information
- photos, audio recordings, documents, and other file attachments, together with related metadata, including approximate GPS coordinates or map pin locations where users choose to capture them
- rich-text documents, including specification content and embedded images
- activity logs and audit trails recording who did what and when, including actions taken by external share-link visitors (see Section 3.E)
- external dashboard and share-link configuration data
This information may contain personal information if users include personal details in project records, comments, attachments, or free-form text. Organizations are responsible for what their users put into project content.
D. Billing and Commercial Information
If your organization purchases paid subscriptions, we may collect or receive:
- customer and billing identifiers
- plan, pricing, interval, and seat information
- purchase and invoice history
- transaction and refund status
- Stripe customer IDs, subscription IDs, and related commercial records
We do not store full payment card numbers in FieldWorks. Payment card data is collected and processed by Stripe.
E. External Share Link Information
FieldWorks allows organizations to create password-protected external share links so that people outside the organization can view or contribute to specific project data without creating an account. In connection with those links, we collect and store:
- share-link tokens, access scopes, labels, and configuration
- hashed link passwords (we store a hash, not the password itself)
- expiration and revocation status
- content submitted by external visitors, including uploads, comments, and status updates
- audit events recording actions taken through a share link, marked as external activity together with the optional label the organization assigned to the link (for example, a company or crew name)
External visitors do not need to create an account, and we do not require them to identify themselves. Our audit records attribute external actions to the share link and its label rather than to a verified individual. As with any web service, our hosting infrastructure processes IP addresses and browser information in transient server and security logs when a page is requested; we do not attach that information to external audit records. When an external visitor enters a share-link password, the password is held in that browser tab's session storage only, so the visitor does not have to re-enter it on every page; it is not written as a cookie and is discarded when the tab is closed.
The organization that created the share link controls what data is exposed through it and for how long. If you are an external visitor and have questions about the project data you can see, contact the organization that sent you the link. This Privacy Policy applies to the information FieldWorks itself processes when you use a share link.
F. Cross-Organization Guest Access
An organization can grant a user of another FieldWorks organization guest access to one of its projects. When it does:
- the granting organization instructs us to make that project's data visible to the named guest;
- the guest accesses the shared project under their own account and organization identity; and
- if the guest's role permits copying, the guest's organization can copy the project's configuration and files into its own workspace. The recipient organization then controls its copy, and the copy is governed by the recipient organization's own decisions and administrators.
Guest grants are created, managed, and revocable by the granting organization's administrators.
G. Marketing Attribution and Affiliate Information
- Marketing attribution. If you consent to all cookies, we record campaign parameters (UTM values) and the Google click identifier (gclid) from the link that brought you to our site, and we persist those values to your user record when you sign up. We use this to understand which marketing channels lead to signups.
- Affiliate referrals. When you arrive through an affiliate referral link, we set attribution cookies (see our Cookie Policy) and record a server-side click log containing the affiliate, a one-way SHA-256 hash of your IP address (we do not store the raw IP address in this log), a truncated browser user-agent string, the referring page, and a country code derived from the request. We use this log to pay affiliate commissions correctly and to detect abuse of the affiliate program.
H. Technical, Usage, Device, and Support Information
We automatically collect limited technical and operational information, such as:
- IP address and request metadata in transient hosting, security, and error logs
- browser type, device, and operating system information
- session identifiers and authentication tokens
- access timestamps and referrer information
- security and audit event records
- error, crash, and performance telemetry (our error monitoring is configured not to capture personal information by default)
- support requests, contact form submissions, and newsletter signup details you provide to us
I. Public Standards Catalog Usage
FieldWorks maintains a public catalog of construction standards reference metadata (publishers, standard numbers, titles, and versions). This catalog contains reference information about published standards, not customer data. In connection with the catalog we collect:
- Feedback. If you submit feedback on a catalog entry (for example, reporting an outdated version or suggesting a missing standard), we store your message together with your organization and user context so we can follow up and improve the catalog.
- Usage analytics. We record product analytics events when organizations select or link catalog standards, including the standard selected, the organization, and optionally the acting user. We use these events to understand which standards matter to our customers and to prioritize catalog maintenance. These records are internal product analytics and are not shared with other customers in identifiable form.
J. Supplier Verification Requests
FieldWorks allows a person who represents a supplier listed in the Approved Products Directory (or a new supplier) to request a free supplier account. In connection with a verification request, we collect:
- the company name and the requester's business contact details, including a registration email address and, optionally, a name and phone number
- service areas the requester wants associated with the supplier
- proof documents the requester uploads to demonstrate that they represent the company
- the IP address the request was submitted from, retained for abuse prevention
We use this information to review whether the requester reasonably represents the named company, to operate the resulting free supplier account (including the supplier's profile, product listings, and any corrections the supplier files), and to send the requester an email approving or declining the request. Uploaded proof documents are deleted approximately 90 days after we decide the request; we keep the remaining request record for as long as the associated account exists. A verified supplier chooses whether their business contact details are shown publicly; until a supplier verifies and turns that on, their contact details and website are not shown on the public-facing listing.
K. Information from Other Sources
We may receive limited information from third-party sources, including:
- identity and authentication data from Google or Microsoft if you choose to use social sign-in
- payment status and transaction confirmations from Stripe
- email delivery metadata from Resend
- hosting, performance, analytics, and observability data from infrastructure providers such as Vercel and Sentry
- ArcGIS account identifiers, map-service metadata, and geocoding or basemap request data from Esri when map features are used or when a user links an ArcGIS Online account
4. How We Use Information
We use personal information and customer data to:
- provide, operate, maintain, and improve FieldWorks
- authenticate users and secure accounts
- create and manage organizations, memberships, permissions, and access controls
- deliver core product functionality, including project coordination, file handling, external sharing, guest access, document generation and export, dashboards, and audit trails
- process subscriptions, manage billing, administer trials and renewals, and support refunds or cancellations
- send transactional communications such as invitations, password resets, verification emails, billing notices, and service messages
- send newsletter or marketing communications where permitted, with the ability to unsubscribe
- attribute signups to marketing campaigns and affiliate referrals, and pay affiliate commissions
- maintain and improve the public standards catalog
- monitor performance, investigate incidents, prevent fraud, detect abuse, and enforce our agreements
- comply with legal obligations and respond to lawful requests
- generate aggregated or de-identified analytics to understand product usage and service performance
We do not sell personal information for money. We do not use customer project data for advertising purposes or cross-context behavioral advertising. FieldWorks does not currently use customer data to train artificial intelligence models and does not offer AI-generated content features.
5. Legal Bases for Processing
Where laws such as the GDPR or UK GDPR apply, we rely on one or more of the following legal bases:
- Contract performance to provide the Service, maintain accounts, process subscriptions, and support customer use of FieldWorks
- Legitimate interests to secure the Service, prevent misuse, improve reliability, analyze performance, administer our business, operate the affiliate program, and maintain support records where those interests are not overridden by your fundamental rights
- Consent where required by law, including for optional analytics, marketing attribution, and certain communications
- Legal obligation to comply with laws, court orders, tax obligations, accounting requirements, and lawful governmental requests
If we rely on consent, you may withdraw that consent where permitted by law. Withdrawal does not affect processing already carried out lawfully before withdrawal.
6. When We Disclose Information
We may disclose personal information or customer data in the following circumstances:
- Service providers and subprocessors. To vendors and service providers who process information on our behalf and need access in order to provide infrastructure, storage, email delivery, billing, analytics, error monitoring, mapping, or support services. See our Subprocessor List.
- Organization administrators. To organization administrators who manage your team's FieldWorks account, including for account, billing, membership, export, support, and content-administration purposes.
- External share-link recipients. When an organization creates an external share link, project data associated with that link is disclosed to anyone who has the link and its password, in accordance with the link's configured scope. The organization controls this disclosure.
- Cross-organization guests. When an organization grants guest access to a project, that project's data is disclosed to the named guest, and copies made under a copy-permitted grant transfer project configuration and files to the guest's organization. The granting organization controls this disclosure.
- Document exports. Organizations and authorized users can generate documents (PDF, Excel, CSV, and similar formats) containing project data. Once a document is downloaded, it is outside the Service, and its further distribution is controlled by the person or organization that exported it, not by FieldWorks.
- Legal obligations and proceedings. When we believe disclosure is reasonably necessary to comply with applicable law, regulation, legal process, governmental request, or court order.
- Protection of rights and safety. To investigate, prevent, or respond to suspected fraud, security incidents, violations of our terms, threats to safety, or other situations involving potential violations of law or risk to the rights, property, or safety of any person or entity.
- Business transfers. In connection with a merger, acquisition, financing, restructuring, asset sale, bankruptcy, or similar transaction involving all or part of our business.
- With consent or instruction. Where you, your organization, or another authorized party instructs us or consents to a specific disclosure.
- Aggregated or de-identified information. We may share information that has been aggregated or de-identified so that it can no longer reasonably identify an individual.
7. Service Providers, Subprocessors, and Integrations
We use third-party service providers to operate FieldWorks. Depending on your configuration and use of the Service, these include:
- Vercel for application hosting, deployment infrastructure, and consent-gated analytics and performance measurement
- Supabase for hosted PostgreSQL database infrastructure and S3-compatible object storage for uploaded files and documents
- Stripe for billing, subscriptions, checkout, invoicing, tax calculation, refunds, and customer portal services
- Resend for transactional and marketing email delivery
- Google for consent-gated Google Analytics 4 measurement and Google Ads conversion tracking, and for optional Google sign-in
- Microsoft for optional Microsoft sign-in
- Sentry for error monitoring and application observability, configured not to capture personal information by default
- Esri / ArcGIS for map basemaps, geocoding, and optional user-linked ArcGIS Online overlay layers when map features are used
- MapLibre demo tile service (OpenStreetMap-derived basemaps) as a fallback basemap source in environments where ArcGIS basemaps are not configured
We share only the information reasonably necessary for these providers to perform services for us. We maintain a public Subprocessor List describing key subprocessors and their functions.
When a user links an ArcGIS Online account, FieldWorks stores encrypted tokens and selected overlay preferences for that user. Linked ArcGIS overlay layers are visible only to that authenticated user and are requested directly from Esri; FieldWorks does not cache or re-serve them, and they are not shown in external share-link viewer mode.
8. International Data Transfers
FieldWorks is operated from Canada, and our infrastructure and service providers are located primarily in North America. Personal information may be processed in Canada, the United States, or other jurisdictions where our service providers operate. Data protection laws in those jurisdictions may differ from those in your home jurisdiction.
When required by applicable law, we use appropriate safeguards for international data transfers, which may include contractual protections, standard contractual clauses, adequacy-based transfer mechanisms, and vendor commitments designed to protect personal information.
9. Data Retention and Deletion
We retain personal information and customer data for as long as reasonably necessary to provide the Service, maintain account history and security logs, support billing and tax compliance, resolve disputes, enforce agreements, and satisfy legal or regulatory requirements. Specific practices include:
- Customer control. Organizations can delete projects and project data directly through the Service at any time. Deleting a project removes its associated records from the live Service.
- Archived projects. When an organization archives a project, an administrator selects a retention period of 1 to 24 months (12 months is suggested by default). The project is scheduled for permanent deletion when that period ends. Organizations can restore an archived project before its retention period expires.
- Scheduled cleanup. We run automated cleanup processes that remove operational records on a schedule, including expired sessions, stale verification tokens, expired invitations, resolved contact form submissions, revoked share links, and audit events older than our audit retention window.
- Account deletion. You may request deletion of your account. If your account authored work records that belong to an organization (for example, deficiencies or log entries you created for your employer), those records belong to the organization, and your account cannot be self-deleted until you are removed from the organization or the records are transferred. This protects organizations' business records while still allowing you to leave.
- Backups. Backup and disaster recovery copies are managed by our infrastructure providers and may retain deleted information for a limited period consistent with the provider's backup lifecycle before it is overwritten or expires.
We may retain limited records after account closure or service termination where necessary for fraud prevention, legal compliance, backup integrity, dispute resolution, or the establishment, exercise, or defense of legal claims.
10. Cookies and Similar Technologies
FieldWorks uses cookies and similar technologies that are necessary to operate the Service and, if you permit them, to measure usage and performance and attribute marketing campaigns.
We present a consent choice between necessary cookies only and all cookies. Analytics and measurement tools that use cookies or cross-site identifiers (Google Analytics 4 and Google Ads conversion tracking), and the marketing-attribution cookie described in Section 3.G, load only when you choose to allow all cookies. Vercel Web Analytics and Vercel Speed Insights, cookieless measurement tools that collect anonymous page-view, custom-event, and page-speed metrics with no identifiers and no cross-site tracking, run independently of the cookie banner and cannot be turned off by it. Affiliate referral cookies are an exception: when you arrive through an affiliate referral link, we set them at that moment to credit the correct affiliate, independently of the cookie banner. They are used only for affiliate attribution and abuse detection, not for advertising. For a complete list of the cookies we set, including these affiliate referral cookies, see our Cookie Policy.
Do Not Track Signals. Some browsers transmit "Do Not Track" signals. There is currently no universally accepted standard for how online services should respond to them. FieldWorks does not respond differently to DNT signals, but limits tracking as described in this Privacy Policy and our Cookie Policy.
11. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information and customer data, including:
- encryption of data in transit
- access controls and role-based permissions
- tenant isolation so that each organization's data is scoped to that organization
- time-limited signed URLs for file uploads and downloads
- hashed passwords and credential protections
- audit logging and monitoring
- controlled service-provider access
No method of transmission over the Internet or method of storage is completely secure, and we cannot guarantee absolute security. We commit to maintaining reasonable safeguards appropriate to the sensitivity of the information we hold.
If a security incident involving personal information triggers notification obligations under applicable law, we will provide the required notices to affected individuals, customers, and regulators within the timeframes required by law.
12. Automated Decision-Making
FieldWorks does not use automated decision-making or profiling that produces legal effects or similarly significant effects on users, and does not currently offer AI-generated content features. If that changes, we will update this Privacy Policy and provide any required notice and rights.
13. Your Rights and Choices
Depending on your location and applicable law, you may have rights relating to your personal information.
Canada
Under PIPEDA and applicable provincial laws, you may have the right to request access to, correction of, or information about our handling of your personal information, subject to legal limitations and identity verification requirements. You may also withdraw consent to certain uses of your personal information, subject to legal and contractual restrictions. You may direct a complaint to the Office of the Privacy Commissioner of Canada or the applicable provincial commissioner.
European Economic Area, United Kingdom, and Similar Jurisdictions
You may have the right to:
- access your personal information
- request correction of inaccurate information
- request deletion of certain information
- request restriction of processing
- object to certain processing
- request data portability where applicable
- withdraw consent where processing is based on consent
You may also have the right to lodge a complaint with a competent supervisory authority.
California and Certain United States State Privacy Laws
Subject to applicable law, you may have rights to:
- know the categories of personal information we collect and the categories of sources from which that information is collected
- know the categories of personal information disclosed for business purposes
- request access to certain personal information
- request deletion of certain personal information
- request correction of inaccurate personal information
- request a portable copy of certain information where required by law
- not be discriminated against for exercising applicable privacy rights
The categories of personal information described in Section 3 are the categories we may collect. We collect those categories from users, organizations, devices and browsers, integrated service providers, and other parties described in this Privacy Policy. We disclose those categories to the recipients described in Sections 6 and 7 for business purposes.
FieldWorks does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined by applicable US state privacy laws. We do not use or disclose sensitive personal information for purposes other than those permitted by law.
How To Exercise Rights
To submit a privacy request, contact us at support@fieldworkshq.com. We may need to verify your identity and authority before fulfilling a request. If your request relates to organization-controlled project data (including data you can see as an external share-link visitor or cross-organization guest), we may direct you to the relevant organization administrator or coordinate with that organization as required.
We aim to respond to verifiable privacy requests within the timeframes required by applicable law. Many requests can be addressed within 30 days, but some jurisdictions permit extensions when reasonably necessary.
14. Children's Privacy
FieldWorks is intended for business and professional use in the construction industry. It is not directed to children under 16, and we do not knowingly collect personal information from children under 16 through the Service.
If you believe a child has provided personal information to us, contact us at support@fieldworkshq.com, and we will take appropriate steps consistent with applicable law.
15. Third-Party Services
FieldWorks may contain links to third-party websites, applications, or services that we do not own or control. This Privacy Policy does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party service before providing personal information to them.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we may provide notice through the website, within the application, by email, or by other appropriate means. The updated version becomes effective when posted unless otherwise stated.
17. Contact
For privacy questions or requests, contact:
Ontario Engineering Solutions Inc.
FieldWorks Privacy
21 Duke Street
St. Catharines, Ontario
Canada
support@fieldworkshq.com
