Privacy Policy
Last updated: 1 July 2026
This Privacy Policy explains how FieldQ ("we", "us", "our") collects, uses and protects personal data when you use the FieldQ platform at fieldq.uk (the "Service"). We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
FieldQ is a construction snag management and site inspection platform operated in the United Kingdom. For any questions about this policy or your personal data, contact us at hello@fieldq.uk.
2. Data we collect
Account information
- Name, email address and phone number when you or your company administrator creates your account
- Company details (name, address, contact details) provided at registration
- Your role and team assignments within your company's account
Project and site data
- Content you upload or create while using the Service: snags, comments, inspection forms, photographs, drawings and documents
- Timestamps and user attribution on actions taken in the Service — this audit trail is a core feature required for Building Safety Act compliance records
- Time-tracking records where your company uses that feature
Payment information
- Payments are processed by Stripe. We never see or store your full card details — we hold only a reference to your payment method (such as the last four digits and expiry) and your billing history. Stripe's handling of your data is described in the Stripe Privacy Policy.
Technical data
- Standard server logs (IP address, browser type, pages requested) used for security and troubleshooting
- Session cookies strictly necessary to keep you signed in — we do not use advertising or third-party tracking cookies
3. How we use your data
- To provide the Service — operating your account, storing your project data and making it available to your team (lawful basis: performance of a contract)
- To process payments and manage your subscription (lawful basis: performance of a contract)
- To send service communications — notifications about snags assigned to you, form submissions, billing and important account changes (lawful basis: performance of a contract / legitimate interests)
- To keep the Service secure — monitoring logs, preventing abuse and fraud (lawful basis: legitimate interests)
- To comply with legal obligations — including tax and accounting requirements
We do not sell personal data, and we do not use your data for third-party advertising.
4. Who can see your data
Data you create in the Service is visible to other users within your company's account according to the role-based permissions your administrators configure. For example, subcontractors see only the defects assigned to them.
We share personal data only with service providers who help us run FieldQ:
- Stripe — payment processing
- Cloud infrastructure and storage providers — hosting the application and storing uploaded files (photos, drawings, documents)
- Email delivery providers — sending account notifications
These providers process data only on our instructions. We may also disclose data where required by law.
5. Data retention
We retain your data for as long as your company holds an active account. Because construction compliance records (including the Golden Thread) may need to be retained for the lifetime of a building, project data is kept until your company deletes it or closes its account. After account closure, we delete or anonymise personal data within a reasonable period, except where we must retain records to meet legal obligations.
6. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, email hello@fieldq.uk. If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
7. Security
All traffic to and from the Service is encrypted with TLS. Access to your data is protected by role-based permissions, and every action is logged in a tamper-evident audit trail. We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss or destruction.
8. Changes to this policy
We may update this policy from time to time. Material changes will be notified to account administrators by email or through the Service. The "Last updated" date at the top shows when the policy was last revised.