On this page
- 01We never sell your data
- 02The data belongs to your company, not to us
- 03Your account and your company
- 04Your location
- 05Live tracking and its limits
- 06Hours, clock-out answers and injuries
- 07Photos and files
- 08The File Vault, and who opened what
- 09Company files, your employee file and your Social Security number
- 10Looking at a drawing together
- 11Dictating a daily log
- 12Phone numbers and text messages
- 13Pay rates and job money
- 14The phone you work on
- 15What FieldLink AI reads and what it does not
- 16Email in and out
- 17Visiting our website
- 18Cookies and browser storage
- 19Signing in and staying signed in
- 20Who sees what inside your company
- 21The companies that help us run it
- 22How long we keep it
- 23Getting a copy of your data, or deleting it
- 24Keeping it safe
- 25Children and changes to this page
01 // Where we stand
We never sell your data
FieldLink is sold to contractors for one flat price, and that is the only way we make money. The information in it is not a second product, and there is no version of this product in which it becomes one.
We do not sell personal information. Not to a data broker, an advertiser or anyone else, at any price. We do not rent it, trade it or include it in a deal, and there is no anonymized copy of your records for sale.
No advertising and no trackers. No advertising network, no tracking pixel, no third-party analytics package and no crash-reporting service in FieldLink - not on the website and not in the phone apps. We count page views on our public pages without storing your IP address or knowing who you are, as explained below.
Your company owns its records. We only process them. We hold them to run FieldLink for your company and to help when someone asks. We do not mine them to build a profile of anyone, and we do not sell such a profile as "insights".
Who sees it: the people at your company, according to their role and permissions, and FieldLink support. A named FieldLink administrator can enter your company’s account to help you. Support staff get the same access as one of your admins, never HR, and every entry and exit is recorded under their name.
The outside companies we use are suppliers, not customers. The suppliers run parts of the service for us: the database, email, the robot check, FieldLink AI that reads receipts, the maps and address lookups, the weather service and any accounting software your company connects. Every supplier gets only what it needs for its job. None of them pays us in your data or may sell it on. The suppliers are listed below, with what each one gets.
Location has firm limits. FieldLink reads your GPS when you punch. FieldLink shows your position on your company’s live map only if your company turns that on, only if you agree and only while you are clocked in with the app open. Nothing is tracked off the clock or on a day you do not work. We are not building a record of where anyone goes, and we would not sell one if we had it.
We never volunteer anything to a government. Nothing is handed to any federal, state, county or city agency without valid legal process served on us: a warrant, a subpoena or a court order. No standing arrangement with anyone, no bulk feed and no back door in FieldLink.
When a legal demand arrives, we narrow it to exactly what the law compels and hand over nothing beyond that. We push back on any demand that reaches past a fair reading. Wherever the law allows, we tell the company whose records are being demanded.
We have no interest in being a source of information about people. The best protection we can offer is not collecting or keeping information for that purpose in the first place, which is what most of this page is about.
02 // Whose data
The data belongs to your company, not to us
FieldLink is software your company rents. Everything entered into it (hours, photos, receipts, customers, job records) belongs to your company, and we hold it for your company. In privacy law terms, your company is the controller of that information and we are the processor.
If you work for a contractor, the records FieldLink holds about you belong to your employer, so your employer decides what happens to them. We will help one of you find out what is held, and we never hand one company’s records to anyone else.
Every record in FieldLink is tagged with the company it belongs to, and the database refuses to give it to anyone outside that company. The separation is a rule in the database itself, not a setting anyone can switch off, and we test it on every release.
03 // Accounts
Your account and your company
FieldLink keeps what your company needs to run its crew, and no more. No place in FieldLink for your date of birth, your home address, a bank account or card number, or a driver’s license number. The one government number it can hold is your Social Security number, and only if your company enters it (see Company files, your employee file and your Social Security number, below). Your company’s own records can still show things like these: a customer’s service address is often a home, and a document your company files in your employee file can show a date of birth or an address.
Your name, work email and phone number. Your email is how you sign in and how we reach you. The phone number is optional for most people and lets your company reach you about work.
Your password. Our hosting provider’s sign-in service stores it only as a scrambled hash. Nobody at FieldLink or at your company can read it. An owner or admin can only send you a reset link or set a new password.
Your profile picture, if you add one. The picture is kept in private storage and never shown on a public page.
Your role and permissions. The role and permissions decide what you can open. An owner or admin can switch a module off for you.
Your company’s own details: its name, trade, logo, business address, phone number, email address and website, plus its web address on sagetechfieldlink.com, the crew size it signed up for and the settings it chooses. Its name, logo and contact details are printed at the top of the reports your company sends its customers and general contractors.
When you were last active. While the app is open, it marks the time on our server. The stamp is how your office sees who is online and how we tell a quiet account from a busy one. The mark is a timestamp and nothing else: it does not say which screen you were on. The places FieldLink records you opening something are the File Vault, Company files and the documents in an employee file, described below.
04 // Location
Your location
FieldLink records your location when you punch. Your company can switch on live tracking, which shows where you are while you are clocked in, but only after you agree and only while the app is open in front of you. Two things read your location between clock-in and clock-out, and those two do not start by themselves: driving to your next job (below) and live tracking (next section). Nothing is read while the app is shut or the phone is in your pocket, and nothing at all when you are off the clock.
At clock-in and clock-out, the app reads one GPS fix and stores it on the punch, with how accurate the phone said it was. The fix shows where you were when you punched, and it is what the job site’s geofence is checked against.
If you punch outside a job site’s geofence, the app asks why. The reason you type is kept on the punch, and nobody, including the office, can edit it afterward.
Driving to your next job, you can tell the app you are leaving. Your hours move to the next job right away and count as drive time until you arrive. On the way, the app checks your position against that one job site and asks our server whether you have arrived. When you have, the same punch carries on as time on the job and your phone tells you. You start it and you can cancel it. The drive check runs only while the app is open in front of you, and all it leaves behind is the punch itself: how much of it was driving and when FieldLink saw you arrive. Driving between jobs is paid and counts toward your overtime.
When your employer pays the drive from home or back, the app offers Driving from home at your first clock-in when the drive there is paid, and Drive home at your last when the drive back is paid. FieldLink keeps when each drive started and ended, and how each was paid. FieldLink never keeps where your home is: starting that drive and saying you are home send no position, and live crew positions pause from the moment you set off until you reach the job, and again from Drive home. If FieldLink never sees you reach the job, the whole punch counts as work until the office says when you got there; that change is kept with its reason, and you are told. A drive your employer does not pay is not clocked at all.
On the office’s live map, a pin is where someone clocked in. The pin shows a newer position only if your company has switched on live tracking and you have agreed to it (next section). When the punch is closed, its location drops off the map. Only owners, admins, the office, and anyone an owner or admin has given the live map permission can open that map.
A few other moments. A location is saved where the record needs it: a photo taken on a service call or in a daily log, a tool handed over or scanned, and the spot where a customer signs for completed work.
When you file a fuel purchase from a pump photo, a photo you take uses this phone's location once, while the photo is prepared and sent, when location is already allowed, so the station can be named. A photo you choose from the library uses the location the photo library keeps for that photo, when it has one. The time saved in the photo, when it has one, is used as the time of the receipt. When the library has none, the location written in the file is used. FieldLink AI reads the street, city, state and ZIP printed on the picture. When a line is missing, FieldLink's own server sends that point to OpenStreetMap to look up the station's name and the missing lines. When no station is found, or that search does not answer, the same point fills the street, city, state and ZIP. When a US ZIP comes back with no city, the server then sends the five-digit ZIP to Nominatim's postal search so the city can be named. The point is kept on the receipt with how it was found. The station's ZIP is kept on the receipt with the address when one is known. The pump photo lookup is not live tracking, and it does not run in the background. If there is no location, or the map does not answer, the brand read from the pump is put in the station box until someone types over it or the map answers.
Inside a work photo, only if your company chooses. If your company turns off "Remove photo details", a work photo keeps the location your phone saved in the file, if it saved one. For a pump or receipt photo chosen from the library, the location the photo library keeps for it is written into the uploaded copy. Your company can read it, and so can anyone it sends the photo to, in a report or its accounting program. Everyone in your company is told in FieldLink the moment it is turned off, before any photo of theirs keeps its location, and told again if it is turned back on. With that switch on, as every company starts, no photo carries a location inside it (see Photos and files).
Anything else that reads your location, beyond clocking in, live tracking you agreed to, and filing a fuel receipt from a pump photo, will start switched off. Your company will have to turn it on. Your crew will be told before it is turned on, and this page will say so first.
05 // Live positions
Live tracking and its limits
Your company can switch on a live map showing where each person is while they are clocked in. Live tracking is the most sensitive thing FieldLink does with anyone’s information, so here are its limits.
Only while you are clocked in. Clocking out stops it. Nothing is reported off the clock, even with the app open.
Only while the app is open in front of you. Nothing is collected while the app is in the background or the phone is in your pocket with the screen off. FieldLink does not ask for "Always" location and has no background location mode on iPhone or Android.
You agree to it once, before anything is reported. A screen explains what would be shared and asks whether you agree. You can withdraw your agreement at any time in Account settings. Reporting stops at once, and the positions already stored for you are deleted.
Saying no does not stop you working. You clock in as usual. The only difference is that your company sees no live position for you.
You can see when it is on. While it is reporting, the Clock page shows a visible indicator the whole time.
Live tracking starts switched off, and your company has to turn it on. Turning it off again deletes the positions and the trail that went with them.
Who can see it: owners, admins and anyone they have given the live map permission. Nobody else in your company sees anyone’s position, unless an owner or admin has given them the live map permission, and your company can see who holds it.
What is stored: your latitude and longitude, how accurate the phone said the fix was, the time, the job site and whether you were inside its geofence. The day’s trail of points is kept, and it is purged every night.
None of this reaches your time off the clock: no tracking between shifts, none at night and none on a day you do not work.
06 // Time clock
Hours, clock-out answers and injuries
What a punch holds: when you clocked in and out and on which job, plus the cost code if your company uses cost codes. When a crew lead punches for you, it records who.
Whether you are salaried with no overtime. An owner or an admin can mark staff who run people or the office this way. The salaried mark is kept with the pay week it starts, and you are told when it changes. You and your office can see it; coworkers cannot.
Which shift you work. Your shift decides when your workday starts, so a late night counts for the day it started. Every change is kept with the day it starts, and a change that moves your workday is kept with the reason given for it. You are told when it changes. You and your office can see it; coworkers cannot.
Two questions at the end of the day, if your company turns them on: whether you were hurt today and whether your time is right. Your answers are yours, and nobody can change them later.
Your company’s own questions at clock-out. Your company can add up to eight of its own, such as whether you locked up the job or how many miles you drove your own vehicle. Your answers are kept with the punch in the words you were asked, even if the punch is later deleted. You and your office can read them; coworkers cannot. Nobody can change them afterward. A crew lead who clocks you out never answers them for you. You answer them yourself when you confirm that day.
An injury report. Answering "I was hurt" opens a draft incident report with what you typed, the day, the job and the punch. Owners, admins and anyone with the safety permission can read it and add office notes. The report holds no medical records and no photos.
Punches taken with no signal. The punch waits on your device and is sent when you have service. We keep the time and GPS as they were recorded, plus how far off your phone’s clock was, so a punch cannot be quietly back-dated.
Every change to a punch is recorded: who changed it, when and why, whether it was a clock-in, a clock-out, an automatic close, an office edit or a correction you asked for. You are told when someone changes your time, and a pay week you already signed has to be signed again.
07 // Photos
Photos and files
Your photo at clock-in and clock-out. Your company decides. The clock-in photo is on unless your company turns it off; the clock-out photo is off unless your company turns it on. The two photos are always taken live with the camera, on a phone or in a browser. You cannot pick a picture from your gallery, so nobody can punch for a coworker with an old photo of them.
Who sees a clock photo: you and your office, never another technician. A clock photo is never replaced or deleted from its punch. When a crew lead punches for you, no photo of you is taken; the app shows "clocked in by" and the lead’s name.
Job, receipt and daily log photos, and the files your office keeps for receipts, HR, safety, prints, branding, service reports, daily reports, each job’s File Vault, Company files and employee files, are kept in private storage. Nobody outside your company can open them. The one exception is a service report, which the customer it was written for can open.
Photos are made smaller and cleaned on your device before they are uploaded. Unless your company turns that off, the app shrinks each one and strips out every EXIF, XMP and GPS block, so hidden details like the location and the camera’s serial number never leave the device. Where a record needs a location, it is stored on the record where you can see it, not hidden inside the picture.
Your company decides for work photos. An owner or admin can turn off "Reduce photo size", and job, receipt, daily log and other work photos then go up at the size the camera took them. An owner or admin can turn off "Remove photo details", and those photos then keep the details your phone saved in them: where and when each one was taken, and the phone or camera that took it. Your profile picture, your clock photos and the photos a customer sends with a service request are always made smaller and always cleaned, whatever your company chooses.
Live Photos from an iPhone. While "Reduce photo size" is off, a Live Photo chosen from an iPhone’s photos for a daily log, a service call, a tool or a job’s File Vault keeps its short video and sound. Your phone makes a smaller copy of the video before it is uploaded. While "Remove photo details" is on, that copy leaves out where and when it was taken and which phone took it. The video is kept beside its photo, and exactly the people who can see the photo can play it. With "Reduce photo size" on, a Live Photo is saved as a plain picture. Any other short video a phone saves with a photo is never sent.
08 // Job files
The File Vault, and who opened what
A job’s paperwork can be filed on the job itself - prints, submittals, permits, spec sheets, install manuals, safety data sheets, change orders - in folders your office or the job’s crew lead makes and names, so the crew works from the current revision. FieldLink records who opens these files, and the same goes for Company files and employee files.
The office or the job’s crew lead decides, file by file, what the crew can open. A file nobody has decided about stays with the office, and keeping a file in the office keeps its older revisions there. The files are your company’s, like every other record in FieldLink, and are never shown to another company.
Every time one of these files is opened, we write down who opened it. The person, the file, the date and time, and whether it was an iPhone, an Android phone or a web browser. The list stops there: no IP address, location or phone number, nothing that identifies the device and nothing about how long it was open or what you did next.
Why it is kept: to answer two questions that come up later - how a drawing left the job, and whether the crew had the current revision on the day they built it.
You can always see your own record. Whatever your role, the list of job files you opened is yours to read, and nobody can hide it from you. Owners, admins and the office read it for the people at their own company. A technician never sees a coworker’s, and no other company ever sees any of it.
What the list of files shows. Every file shows its name (as it was on the computer or phone it came from, without that device’s folders), its size, who uploaded it and when. Owners, admins and the office see who opened it last and when, and how many people have opened it. Everybody else sees only when they last opened it themselves.
A safety data sheet can ask you to confirm you have read it. Opening the file is not that confirmation - you say so yourself. The confirmation is recorded once, with who said it and when. Only you can say it, and nobody can take it back.
A file in the File Vault is never handed out as a link. Other private files in FieldLink open through a temporary web address that could be forwarded. The file is drawn inside the app and never handed to the phone itself: there is no Save, no Share, no Print and no Open in, and no link to it exists that anyone could paste into a message. Your name and the time are drawn across the page while it is on screen.
Nothing here can stop somebody pointing a second phone at the screen, and no product can. The name across the page shows whose screen a photo was taken from.
How long we keep the record of who opened a file: as long as the file it belongs to. The log is not cleared on a timer, because the questions it answers usually come up long afterward. Erasing your company’s records erases it with them.
09 // Employee files
Company files, your employee file and your Social Security number
At the top of the File Vault are two folders every company has. Company files holds the company’s own documents, like the employee manual and the vehicle policy. Everybody in the company can open them, and the office adds and removes them. A removed company file is kept under Removed files until the office deletes it permanently.
Your employee file. Your company can keep documents about you in FieldLink, like a written warning, a bonus letter or a certificate. You can open every document in it. The owner and the people your company gives HR access add and remove them. Nobody else at your company can open it, and FieldLink support never can.
What is in your file is not encrypted like the number. Documents in your employee file are kept in private storage and handed only to you, the owner and people with HR access. The Social Security number field is encrypted on its own. A document in the file is not. The upload screen tells your company not to file a Social Security card. A document that shows your number or address is protected the way the file is.
Your Social Security number, if your company enters it. The owner or someone with HR access types it in. The number is encrypted before it is saved (AES-256), with a key held outside the database, which the app’s own accounts cannot read. A copy of the database does not include that key. The last four digits are kept only as a scrambled copy made with that key. Every screen shows the number as asterisks. The office can see whether one is on file. Only the owner, and people the owner grants See full Social Security numbers, can reveal it, and only after a code from an authenticator app in the last 5 minutes. A reveal is written to our audit log with who looked, whose it was, when, and a reason when one was typed. The number itself is never put in an email, a notification or the audit log. Recovery codes for the authenticator app are shown once on screen and are never emailed. FieldLink support cannot reveal a number, in support mode or otherwise.
Opening your own file. You type your account password again. We check it against your sign-in and never keep what you typed in a log. Once the file opens, it stays open for 15 minutes, on that sign-in only. Another phone or computer signed in as you stays closed. Five wrong tries in a row lock it for 15 minutes, and a third lock within a day lasts 24 hours. Your owner and HR are told about a lock in the app, without the password. We keep a note of each try, right or wrong, for 90 days, and that note never holds the password.
Who opened what. Opening a company file or a document in an employee file is recorded like a job file: who, when and what kind of device. The office sees who opened a company file last; the owner and HR see who opened the documents in an employee file. You always see when you opened one yourself. The record lasts as long as the file.
When something is added to your file, you are told in the app, never by email, and the message never names the document.
Removing a document from an employee file takes it out of your file, but your company keeps it, with who removed it and why, until the owner or someone with HR access deletes it permanently from Removed files. Then the document is gone for good, and so is the record of who opened it. The audit log records that a document was removed or deleted, by whom and from whose file, but never its name or the reason.
10 // Job files
Looking at a drawing together
Someone viewing a drawing can invite a coworker to look at it with them, and anyone allowed to open that file can ask to join a drawing that is already open. The two screens then move together, on the same page and the same spot, and one side or the other person can point at something on it.
No screen is shared. The two people are already allowed to open the file, so only the page and the spot on it pass between them, about a hundred characters. No picture of anyone’s screen is sent to us or anyone else, and the drawing never leaves the File Vault.
Joining gives no one new access. Whoever joins must already be able to open that file on their own account. If they could not open it alone, they cannot open it together, and the invitation is refused before it is sent.
Nobody is joined without saying yes. Whoever is asked answers first, every time, and one person or the other can end it at any time. Closing the file ends it.
No microphone and no camera. The feature never asks one phone or the other for the microphone or the camera, and FieldLink does not carry your voice. To talk, people call each other and use speakerphone.
What we keep: who looked at which drawing with whom, and when it started and finished. Your office can read that list for its own employees, and you can always read your own. Nothing that was said or pointed at is stored.
11 // Microphone
Dictating a daily log
You can speak a daily log instead of typing it. The microphone comes on only when you tap the microphone button on that screen, and it goes off when you tap it again, press Done or leave the page.
Your phone does the listening, not FieldLink. The words come from the speech recognition built into your phone or browser. Depending on the device and its settings, it may send the audio to Apple or Google to turn it into words, under their terms rather than ours. FieldLink never receives or stores a recording of your voice. FieldLink gets only the text, which is added to what you have already written (never over it) and becomes part of your daily log as if you had typed it.
The microphone is never listening in the background. Not on another screen, not while the app is behind another app and never before you tap the button. If a device has no microphone, or you have not allowed it, the app says so and you type instead. You never need dictation to file a log.
12 // SMS
Phone numbers and text messages
Sagetech LLC does not share mobile numbers, text messaging originator opt-in data, or consent with any third parties or affiliates for marketing or promotional purposes.
Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text message services.
In plain terms: if you give us your mobile number and agree to be texted, we use that number only to text you. The number and your consent are never sold, passed to an advertiser or given to another company to market to you. The only outsiders who could see them are the carrier and the messaging service that delivers the text.
Today the FieldLink app sends no text messages, and no texting provider is connected to it. The section covers the texts we will send you about your account, such as support replies and service updates. The notice is written now so the rules are in place before we connect a texting provider. If we ever give your number to a messaging provider or an aggregator so a text can reach you, that is the one exception allowed above.
Text STOP to end the messages. Reply HELP or write to support@sagetechfieldlink.com to reach a person. The Terms of Service page has the details.
The phone number for our messaging program is +1 (864) 263-2317. The phone numbers your company keeps for its employees and customers are your company’s records, and we never use them for marketing.
13 // Money
Pay rates and job money
Pay is kept separate on purpose. Your pay rate, employee number and the name your company uses for you in its accounting software are stored apart from your profile, because anyone who can see your name could otherwise see your rate.
Who can see a rate: your office and you. Not a coworker and not a crew lead.
Job budgets and job costs. Budgets and job costs are kept separately, the same as pay rates. The job cost report shows a technician the hours with the dollars left blank, so nobody can work a rate back out of a total.
We hold no card number and no bank account number. FieldLink has no place for a card number or a bank account number and does not take payments yet. A photo of a receipt shows whatever the receipt printed, which can include the last digits of a card.
14 // Phones
The phone you work on
FieldLink remembers which phone is yours, so your company knows when someone clocks in on a phone that is not theirs.
What is kept. The first time you sign in, the app creates a random ID and keeps it on that phone. The ID is not a serial number and tells us nothing about the phone, the SIM or anything on it. Reinstalling the app makes a new one. Every time you sign in, we note which ID that sign-in is on. We keep the phone’s model name, such as "iPhone 15" or "Pixel 8", so your office can tell your phone from a new one.
What your company sees. Your name beside the phone’s model name and when you last used it, and the random ID of that phone. Nothing else on your phone.
Clocking in on someone else’s phone. If you leave your phone at home, you can sign in on a coworker’s phone and clock in as usual. Which phone you use never stops a punch. Your company’s owners, admins and office are then told, in the app and by email, that you clocked in or out on that person’s phone, with the job and the time. The message names only you and the person whose phone it is. Nothing on their phone changes, and your own phone stays yours.
Getting a new phone. Ask from the app, and your office can make the new one your phone. The office can clear the old one, and nothing about it is kept once it is cleared.
Not on a computer. None of this applies to the office web portal, which works in any browser.
15 // AI
What FieldLink AI reads and what it does not
FieldLink uses an AI service for two narrow jobs.
Which company. One of three: Anthropic (Claude), OpenAI (ChatGPT) or xAI (Grok). We use only one at a time, for all of FieldLink, and it is Anthropic unless this page says otherwise. Whichever it is gets exactly what is described below and nothing more.
Reading a receipt. When someone scans a printed receipt, the photo or PDF is sent to that company so the store, date, items, tax, any tip, the total, how it was paid as printed (such as a card's last four digits, never a full card number) and any printed station street, city, state and ZIP can be read from it. The request includes your company’s name and trade, so the results use your trade’s own terms. When someone photographs a pump display, that photo is sent so the sale, the gallons, the posted prices, any brand on the pump and any printed station street, city, state and ZIP can be read. When the grade prices sit in a row the phone can cut out, a second image of that grade row is cut on the phone and sent with the same request so every posted price can be read; that cut-out is not kept as its own file after the read. The person checks those numbers before the receipt is kept. If your company keeps photo details, they are still inside the photo that is sent.
Tidying up a note. When someone asks for help with a note, the text they typed is sent with your company’s name and trade and the details of the job, call or tool the note is about, such as the job name, the customer and the address. Nothing else goes with it: no photos, no pay and no coworkers’ records.
The tidied version never replaces what was written. The original note stays exactly as typed. The tidied version is saved beside it, and only after the person who asked for it reads and accepts it.
Training. We send all of this through the commercial API of whichever of the three is in use. All three say, in the terms for those APIs, that business data sent through them is not used to train their models. We do not train a model of our own on your data.
What we keep. Every time someone asks FieldLink AI for help, we note who asked, which kind of help, how many characters were sent and when. The note is how we keep each person to a daily limit. Nothing that was sent or sent back is kept in that note. You and your office can read it, and so can FieldLink administrators.
16 // Email
Email in and out
All FieldLink email - invitations, password resets, appointment reminders, the weekly payroll summary, daily log reminders, service reports and announcements - is delivered by Resend.
What we log about an email: who it went to, its subject, what kind it was and what happened to it: sent, delivered, delayed, bounced or marked as spam. Open and click tracking stay off, so we do not record whether a message was opened or which link was clicked. The log never holds the body of the email.
The email queue. Automatic emails, such as reminders, summaries and announcements, go into a queue before they are sent. Unlike the log, the queue holds the text. A sent, failed or skipped message is cleared from it 90 days after it was queued.
A blocked address. When an address bounces or someone marks a message as spam, we stop sending to it and note why. Only a FieldLink administrator can lift the block.
Replies from customers. A customer can reply to a service request by email. We keep the sender’s address, the subject and the text of the reply as part of the job record. The older messages quoted underneath are trimmed off.
Announcements can be turned off. Every announcement has an unsubscribe link. The link stops announcements only, not emails you need, like a password reset.
17 // Public pages
Visiting our website
We count page views on our public pages without knowing who you are.
No IP address is stored. Our page-view records have no place for one. Your IP address is used briefly, in memory, only to stop one machine sending thousands of views a minute, and it is forgotten a minute later. The address is not written down, logged or sent anywhere.
What is stored: the page, the site that sent you here (only its name, such as google.com, not the full address) and your device type (phone, tablet or computer). We store the country, state and city our hosting network reports, and a random ID your browser creates and keeps in its own storage. The ID is not a cookie and is not based on anything about you or your device.
Who is never counted: anyone signed in, our own staff, bots and our development machines.
The robot check. Sign-in, sign-up, password reset and the customer pages use Cloudflare Turnstile to keep bots out. When we check the result with Cloudflare, your IP address is sent with it because the check requires it, and we do not keep it. In the phone apps the check normally runs out of sight, with no box to tick.
Fonts and the page itself. Our website - the product page, What’s New, these two pages and "What this site counts" - is plain web pages, and their fonts come from our own address. Nothing on them is fetched from Google or anyone else. The FieldLink app, from the sign-in page on, draws its screens with an engine and fonts that come from our own address. Your browser used to fetch both from Google every time a page opened, and it no longer does. One exception, in the app: if a screen needs a character none of our fonts contain, such as an accent in a company name, another alphabet or an emoji, your browser fetches that character from Google Fonts. We send Google nothing about you or about what the screen says. The request is your browser’s own, and it carries your IP address like a request to any website.
No trackers. No advertising network, no Google Analytics, no Facebook pixel and no crash-reporting service in FieldLink.
Global Privacy Control. If your browser sends the Global Privacy Control signal, we count nothing. The page checks for it before sending anything, and our server checks for it again when a page view arrives. You do not need to do anything else.
Turning it off yourself. With or without that signal, you can turn counting off or back on from the "What this site counts" page at www.sagetechfieldlink.com/privacy-choices. Turning it off deletes the random ID from your browser, so nothing before is linked to anything after.
18 // Storage
Cookies and browser storage
We set no advertising cookies and no tracking cookies, and no one else sets one through us. The list is everything we keep in your browser.
The random page-view ID. The page-view ID is the only item here that FieldLink does not need to run. The ID is kept in your browser’s storage, not in a cookie, so it is never attached to a request and leaves only inside a page view. You can switch it off, and Global Privacy Control switches it off for you.
Your counting choice. If you turn counting off or on, your choice is kept in that browser only. The choice cannot follow you to another computer, because no account is attached to it, and clearing your site data or using a private window clears it.
Our own staff’s browsers. A browser a FieldLink staff member signs in on keeps a note that stops it being counted. The note holds nothing else and is never sent to us.
Your sign-in. Once you sign in, your browser keeps the session so you are not asked for your password on every screen. Signing out ends it. Our website’s pages only look whether it is there, to offer Open FieldLink instead of Sign in; they never read it or send it anywhere.
Your screen settings. The light or dark look you pick on the website or the office portal, and whether the calculator works sums in scientific or standard order, are kept on that device only and never sent to us. The website and the office portal share that choice in the same browser. The calculator setting is kept for each person, so a workmate on the same phone keeps their own.
Your office menu order. On the office website, a copy of the left-menu order you chose is kept in that browser so the menu does not jump while your account loads. The same order is saved to your account, as described under Signing in and staying signed in. Only you can read or change that order.
What the app keeps so it works without a signal. FieldLink keeps the jobs and cost codes it last saw, and any punch it could not send. FieldLink does this in the browser on an office computer exactly as it does on a phone. A waiting punch holds everything the punch itself would send: the GPS fix taken at the moment you punched, the job and cost code, your clock-out answers (about being hurt, whether your time is right and any questions your company added) and the clock-in photo of your face. The waiting punch stays on that device until the punch reaches us, and then it is removed.
Signing out, and deleting your account. Signing out clears the jobs and cost codes but keeps any unsent punch, because it is hours you have not been paid for, and the app tells you how many are still waiting. Deleting your account clears those, because a deleted account can never send them.
19 // Sessions
Signing in and staying signed in
Sessions. While you use the app, we keep one record per session, not one a minute. The record holds when the session started, when it was last seen and which platform it was on, and there is no list of screens on it. We use it to see whether FieldLink is being used and, if a punch is left open, to find when you last used the app. The only things FieldLink records you opening are job files, company files and documents in an employee file, as described above.
Sign-in records. Our hosting provider’s sign-in service keeps its own log of sign-ins, sign-outs and password resets, including the IP address each sign-in came from. We use it to count sign-ins and to look into an account someone is worried about. FieldLink’s own screens never show an IP address or which browser you used.
On your device. The app keeps your session and a few preferences on it, plus any punch waiting to be sent. Signing out clears the session.
Office menu order. On the office website, the order you put the left menu in is saved to your account so it follows you to another browser or computer. Only you can read or change that order. Saving an order never turns on a page your role cannot open. Reset menu order clears it. A copy is kept in the browser so the menu does not jump while the account is loading.
FieldLink support mode. To help your company, a FieldLink administrator can enter your company’s account with exactly the access one of your admins has, never HR. Every entry and exit is written to an audit log, and support is never counted as one of your employees.
The control panel activity list. FieldLink’s control panel lists changes made there: companies, plans, staff and settings. What your people change inside your company stays on your company’s own record. Owners, admins and the office can read that record on the company dashboard. A technician cannot. Pay rates and job money stay off that list for anyone who cannot see them, and a Social Security number is never shown.
20 // Inside
Who sees what inside your company
Your company’s owners and admins decide, using roles, access levels they add on top of Technician, Office or Admin, named permissions for sensitive areas (HR, See full Social Security numbers, safety, live map, purchasing, billing, fleet and crew lead) and switches that turn a module off for one person, a whole role or one of those levels. A level built on Technician never sees a job’s money or a coworker’s pay rate, whatever its switches say.
Phone settings. An owner or an admin in your company’s account can open Phone settings and look at another employee’s FieldLink phone as that person sees it: their button layout, jobs, daily logs, receipts, punches, hours, service calls, customer requests, tools, rental equipment, the File Vault, crew list, shared looks and live map. The viewer stays signed in as themselves; nothing signs the viewer in as the employee. Buttons that would change data, take a photo, use this computer’s location or send a notice are blocked in the preview. Job money and rates follow what that employee is allowed to see. Whether a Social Security number is on file shows only when the viewer has HR access, and the unlock that opens that employee’s personal documents stays shut in the preview. A FieldLink administrator cannot be the person previewed.
Some things are locked, no matter who asks. Only the owner grants HR. A technician never sees a coworker’s pay rate or clock photo. A technician sees a job’s money only if an owner or admin gives them the billing permission, and never on an access level built on Technician. Only the owner and people with HR access open somebody else’s employee file. Only the owner, and people the owner grants See full Social Security numbers, can reveal a Social Security number, and only after a code from an authenticator app in the last 5 minutes. Only the owner changes their own employee file. People fix their own time by asking for a correction, and someone else in the office decides it.
Search and Export on every list. Every list in the office and in FieldLink’s own control panel has a search box and an Export menu, and so do lists on the phone such as receipts and the File Vault. Search finds matching rows among the records your role can already open. Export writes those matching rows to an Excel or CSV file on the device of the person who asked for it, including rows past the first page, so names, emails, phone numbers, addresses, job and customer details, hours, incident notes and the other columns that list already shows can leave the app that way. Job money columns stay out of the file unless that person is allowed to see job money. Pay rates are not put in any export. A Social Security number, and a full bank or tax number, are never put in an export. Every export is recorded for the company — or, for a FieldLink administrator with no company open, in platform scope — with who asked, which list, how many rows, Excel or CSV, and the search words, not the cells themselves. A File Vault drawing itself is still never handed out as a file; Export on a vault list writes only the names and details on that screen.
Your customers, when they sign in, belong to no company inside FieldLink. Customers can send a service request, see their own requests and read the report for work done for them, and nothing else. While the customer is archived, portal sign-in cannot send a request or open those pages, and a restore turns it back on.
21 // Others
The companies that help us run it
Here is every one of them and what each gets.
Supabase - the database, sign-in service and file storage. Everything in FieldLink is stored with them, in the United States. The map lookups below are sent to services in Europe, but nothing they return about a person is stored there.
Anthropic (Claude), OpenAI (ChatGPT) or xAI (Grok) - whichever one FieldLink is set to use, and only one at a time. The service gets the photo of a receipt being scanned and, for a pump display, the grade-row cut-out described above when one is sent, and the text of a note being tidied, along with the details described above. Nothing else, and the other two get nothing at all.
Resend - email out and email in: the address, the subject and the message.
Cloudflare - the robot check on our sign-in and sign-up pages, and the network our website is served through.
Intuit (QuickBooks Online) - only if your company connects it. FieldLink reads your QuickBooks employee list (names, email addresses and whether each is active) so your office can match it to the crew, and sends what the sync moves: approved hours, and approved receipts with their photos, for the employees and customers matched between the two. An owner or an admin can add someone who is in FieldLink and not in QuickBooks as a QuickBooks employee. FieldLink sends that person’s name, email and phone, and does not send a home address, a hire date, a pay rate, a tax form, direct deposit or a Social Security number. Payroll setup stays in QuickBooks. The connection’s keys are stored where nothing in the app can read them, and disconnecting revokes them.
The National Weather Service - a job site’s coordinates, to put the day’s weather on a daily report. The National Weather Service is a US government service and needs no account or key. Nothing about a person goes with the request, only a point on the map. The request is made by your phone or browser, so it carries its IP address, as any web request does.
Photon (Komoot) - the addresses suggested under an address box while you type one. FieldLink’s own server sends Photon the words typed and, on a job that already has a pin on the map, that pin rounded to within about half a mile, so nearby addresses come first. A pin put where your phone or computer is, with "Use my current location", is never sent. Photon is not told who is asking or which company they work for. Nothing it sends back is kept, except an address somebody picks, which is saved like one typed by hand. On a job, the point it gives for that address becomes the job’s pin on the map. Photon is a free search of OpenStreetMap data, run by Komoot in Germany. No account and no key.
OpenStreetMap - the street map behind the live map and the job site map, and "Find on map" on the job site page, which sends them the address typed there to put the job’s pin on it. A fuel receipt built from a pump photo sends the photo’s location, through FieldLink’s own server, to free public Overpass mirrors to name the nearest fuel station. The mirrors are overpass-api.de (run by FOSSGIS e.V. in Germany), overpass.kumi.systems and overpass.private.coffee. One mirror is asked at a time, starting with overpass-api.de. A timeout or an error does not ask another mirror; the other mirrors stay listed for a network where the first is blocked. When no station comes back, Nominatim reads the street, city, state and ZIP at the photo's point. Only the point is sent to those mirrors, not who is asking or which company. If the station’s address is incomplete, Nominatim fills in the missing street, city, state or ZIP from that station’s point. When the station still has a US ZIP and no city, FieldLink’s own server sends the five-digit ZIP to Nominatim’s postal search so the city can be named. The ZIP search is not told who is asking or which company. A job site with a pin and a blank city or state sends that pin to Nominatim, through FieldLink’s own server, to fill the blank. A city or a state somebody typed is kept. Nominatim is not told who is asking or which company. Loading the map from a browser tells their servers the device’s IP address and which part of the map is on screen, as any web map does. No account and no key.
The U.S. Geological Survey (The National Map) - the Terrain and Satellite views of the live map and the job site map, only when someone picks one of them. Loading those views tells their servers the device’s IP address and which part of the map is on screen, the same as the street map. The National Map is a US government service run by the U.S. Geological Survey and needs no account or key.
Apple and Google (the dictation built into your phone) - only when you tap the microphone to dictate a daily log, and only what your own device sends them to turn speech into words, under their terms. FieldLink never receives the audio, and nothing else about you goes with it.
Apple and Google (the barcode reader built into your phone) - when you scan an equipment label, the phone reads it itself. The picture never leaves the device, though Google’s reader on Android may report its own usage to Google under their terms.
No one else. We do not give your records to data brokers, advertisers or "partners", and nobody can buy access to them.
22 // Keeping
How long we keep it
We do not delete your work records on a timer. Hours, punch history, injuries and job records are what a contractor needs years later, when someone asks about an old job. Nothing your company puts into FieldLink (a punch, a receipt, a daily log, a photo, a service call, a customer, a tool or a piece of equipment) is ever removed on a schedule.
What is removed on a schedule is FieldLink’s own housekeeping: its messages, queues and logs. The roster is the complete list.
A notification you have already read, 180 days after it was made. One you have not read yet stays until you read it, however old it gets.
A queued email we are done with, 90 days after it was queued. "Done with" means it was sent, it failed or it was skipped because there was no point sending it. An email still waiting its turn is never touched.
The email log, 400 days after the email was logged. The window is a year and a month, so this month can still be compared with the same month last year. The recipient, subject, outcome and delivery history are removed together. A blocked address stays blocked.
The record of an accounting sync run, after 180 days. The row is the note of when the QuickBooks sync ran and how it went. The record of what was sent to QuickBooks is kept, and so is the list of sync problems waiting for your office.
The record of one app session, after 200 days. The row is a line saying someone had FieldLink open, on what kind of device and for how long. Our internal dashboard counts are built from it, and they never look back more than 90 days.
The record of a punch that was sent in late, after 90 days. When a phone takes a punch with no signal, FieldLink keeps a small record of it so the punch cannot be saved twice if it is sent again. A punch older than 30 days is not accepted, so by 90 days that record has no work left to do. The punch itself is never removed, only this record.
The note that your office has already been told something, after 180 days. The row is how FieldLink avoids telling your office the same thing twice, such as someone still clocked in late at night, a camera that would not open or a punch on someone else’s phone. A note about a punch that is still open is never removed, however old it gets.
The record that a customer’s reply reached us, after 400 days. The row is the line saying an email came in and what we did with it, kept as long as the email log. The reply itself stays on its service request.
Which phone a sign-in was on. The record is removed 30 days after it was last seen. What your office was told about a punch on someone else’s phone stays with its other notifications and email.
The daily count of address suggestions, after 400 days. The row is one number a day, how many address, station and ZIP-city lookups were made, and how many of them were from people not signed in. The ZIP search the server runs inside a station lookup counts as that one station lookup. The city lookup the phone runs on its own afterward counts as its own lookup. What was typed, the point, the ZIP, and who asked are never written down with the count. The lookup server remembers a point, a ZIP, or the words typed for up to a day, in memory only, so it does not ask the map service twice, and then forgets them.
A try at opening an employee file, after 90 days. We keep who tried, when and whether the try was right, never the password typed. Only the last 15 minutes decide whether a file is open or locked.
A try at a recovery code, after 90 days. We keep who tried, when and whether the try was right, never the code typed. Wrong tries in the last 15 minutes decide whether recovery codes are locked.
The day’s trail of live positions, at your company’s own midnight, as described above. Only the current day is ever kept.
Anonymous page views. A page view on our public website is removed 180 days after it was counted. Our internal dashboard never looks back more than 90 days, so there is no reason to keep them longer.
The audit log is never trimmed. The same is true of the record of what has already gone to QuickBooks, because losing it would send the same hours and receipts again, nor the record of who opened a job file, a company file or a document in an employee file, which lasts as long as the file, nor the note of each time someone used FieldLink AI, which holds no words.
A daily log or daily report your office deletes goes to an archive first. The item leaves every list, and a log leaves the day’s report. Its words, photos, signature and PDFs stay in the archive until an owner, an admin or the office restores it or deletes it permanently. Nothing empties the archive on a timer. Deleting permanently erases it and every file that is only its own, for good. A daily report that was already approved keeps its own copy of that day until it is reopened or deleted. The audit log keeps a short note of what it was: the job, the day, who wrote or signed it, where it was sent and who deleted it, but never its words or photos.
A customer your office deletes moves to Archived customers. The customer, its people, jobs, service calls and receipts stay on file. An owner, an admin or a manager can archive or restore, when Customer Portal is on. While archived, portal sign-in cannot send a request or open those pages, and a restore turns it back on. Nothing erases a single customer from Customers; only removing or erasing the whole company can take that company’s customers off FieldLink. The audit log records every archive and restore.
A draft receipt, or one the office sent back, can be deleted for good. The person who made it, or anyone who can already review receipts, can delete it while it is still a draft, including one saved for later, or while it is sent back. A receipt waiting for approval, approved or in the books cannot be deleted. The receipt and its photo are removed for good, with no archive and no audit-log note of the delete. The office’s note and review stamp are part of that receipt and go with it. A receipt that named it as a duplicate stays, with the link cleared. A QuickBooks send record for it stays with the receipt cleared off, and an open QuickBooks problem for it is removed with the receipt.
A document removed from Company files or an employee file waits under Removed files. Nothing deletes it on a timer. The office can delete a removed company file permanently, and the owner or someone with HR access a removed document in an employee file. Deleting permanently erases the document, its file and the record of who opened it, for good. The audit log keeps a short note of it: for a company file, its name, who added it, who removed it and why, and who deleted it; for an employee file, only whose file it was and who deleted it, never the document’s name or the reason.
Your Social Security number, until your company takes it off file. Nothing removes it on a timer. The owner or someone with HR access can take it off file at any time, and erasing your company’s records erases it. The number stays, still encrypted, after you leave the company, as the next line says. A number taken off file can remain, still encrypted, in our host’s daily backups until those backups are replaced. Those backups do not hold the key that unlocks a number.
When a person leaves a company, their sign-in is deleted and their profile stays behind as a marker. The name is kept so their hours still carry it, and their email, phone number and picture are wiped. Their employee file stays with the company’s records. Their Social Security number, if the company entered one, stays with those records, still encrypted. Their email address stays in three places: our audit log’s note that the account was deleted, the email log until it is removed after 400 days, and our list of blocked addresses if mail to it bounced.
A sign-up nobody verified. The name, company and business address typed on the sign-up page stay until the same address signs up again.
Closing a company takes thirty days. The owners are emailed, and any owner or admin can cancel the closing in that time. At the end, everyone in the company is locked out, their sessions end and every owner’s sign-in is deleted. The records are kept, and nothing reopens a closed company.
When we remove a company from FieldLink, everyone in it is locked out, its customer portal stops taking requests, nothing more is emailed and the accounting sync stops. Every record stays, and the removal can be undone. Erasing everything, files included, is a separate step. A FieldLink administrator must type the company’s name to confirm it, and it is written to an audit log.
If your company wants its records erased, write to us and we will erase them.
23 // Your rights
Getting a copy of your data, or deleting it
Owners and customers delete their own accounts in the app. Open Account settings and choose Delete account, then type DELETE and your password again. Account deletion deletes your account and no one else’s. A company’s only owner must first hand the company over on the Employees page, or close the company.
Employees ask from the same place. Your account holds your employer’s record of your hours, so Account settings offers Request account deletion instead. An owner or admin at your company approves or declines it, and you can withdraw the request until they answer. If it is approved, your sign-in is deleted, and the work you logged stays with your employer under your name.
Turning off page-view counting, without asking us. The "What this site counts" page, at www.sagetechfieldlink.com/privacy-choices, turns it off and back on for the browser you are using, and Global Privacy Control turns it off automatically. None of that needs an account, and every page still works the same.
What else you can ask us for: a copy of what we hold about you, a correction, a deletion or a plain answer about anything on this page.
Where to write: legal@sagetechfieldlink.com for accounts and data requests, and support@sagetechfieldlink.com for anything else. A person answers, not a form, and we aim to reply within a few business days.
If you work for a contractor, your employer owns the records of your work, so a request to erase your hours is theirs to decide. We will pass it on and tell you who has it.
24 // Security
Keeping it safe
The rules live in the database. Hiding a button is a courtesy; the database is what refuses. Every record is kept separate by company, every change made in a module is checked again on the server and sensitive actions are audited.
Keys never ship in the app. FieldLink AI, email and accounting keys exist only on our servers. Nothing on a phone holds a secret that could reach another company’s data.
Files are private by default. A file is served only after the server checks who is asking and which area the file belongs to.
Social Security numbers are encrypted. The key that unlocks them is held outside the database, which the app’s own accounts cannot read. A copy of the database does not include that key. Only the owner, and people the owner allows to see full Social Security numbers, can reveal one, and a reveal needs an authenticator code from the last 5 minutes. No screen shows a number unless that person reveals it, and a reveal is recorded.
No system is perfect. If something puts your records at risk, we will tell the affected companies what we know, what we are doing and what they should do, as soon as we have something worth saying.
25 // Changes
Children and changes to this page
FieldLink is a tool for people at work. FieldLink is not meant for children, and we do not knowingly collect anything about anyone under 18. If you believe a child’s details are in FieldLink, write to us and we will remove them.
When the product changes, this page changes with it. A feature that collects something new does not ship until this page says so. The date at the top shows when the page last changed.
For a major change, such as sharing something with anyone not named above, we will tell you in the app and by email rather than quietly editing a line.