Trust and Security
Last updated 2026 · A product of RightMove Properties
This page is provided for transparency about how Fieldkeep protects data. It is a working draft and is not legal advice. Organizations evaluating Fieldkeep should review it, and the Data Processing Addendum, with their own counsel.
Fieldkeep records crew time, location, and mileage in the field and reads across your operation in a web Command Center. That means we hold sensitive data on your behalf: your workers’ location while they are on the clock, the operational and financial data we read from your property-management system, and — for customers who use in-app team chat — the messages and photos your team shares. This page explains how that data is structured, secured, retained, and shared, and points to the documents a buyer’s IT or legal team will ask for.
Who controls the data
Fieldkeep is a business-to-business tool. The organization that licenses Fieldkeep (the employer) provisions accounts, configures the product, and decides how it is used. For data about workers and operations, the employer is the controller and Fieldkeep is the processor, acting on the employer’s documented instructions. Our handling of that data is governed by our Data Processing Addendum, and our general data practices are described in the Privacy Policy and Terms.
Security
- Encryption. Data is encrypted in transit (TLS) and at rest. Hosting, databases, and file storage run on Google Cloud, which encrypts data at rest by default.
- Hosting. Fieldkeep runs on Google Cloud Platform (Cloud Run, Cloud SQL for PostgreSQL, and Cloud Storage) in United States regions. We do not run our own data centers.
- Tenant isolation. Each customer’s data is isolated by an organization identifier that is enforced on every request. The default is to fail closed: a request that cannot be resolved to a specific organization is refused rather than served another tenant’s data. Features that read across your operation, such as the briefing and Ask Fieldkeep, only ever read your own organization’s data.
- Access control. Access inside the product is role-based, from owner down to field technician, so a worker sees only their own activity, while managers and administrators see their organization’s data according to their role. Administrative access to the underlying systems is limited to the people who operate the service.
- Backups. The primary database uses automated, managed backups on Google Cloud SQL.
- Incident response. If we become aware of a security incident affecting your data, we notify affected customers without undue delay and work to contain and remediate it. The notification commitment is set out in the DPA.
Sub-processors
We use a small number of service providers to run Fieldkeep. We do not sell personal information and we do not use it for advertising.
| Sub-processor | Purpose | Region |
|---|---|---|
| Google Cloud Platform | Hosting, database, and file storage | United States |
| Google Maps Platform / Roads API | Geocoding and snapping drives to roads for mileage | United States |
| Transistor Software | Background-geolocation engine in the mobile app | United States |
| Anthropic | AI model provider for briefings and Ask Fieldkeep | United States |
| Stream (getstream.io) | Team messaging and chat delivery, for customers who use in-app chat | United States |
| QuickBooks Time | Time and location source, for customers who use it | United States |
Your property-management system (for example AppFolio) is your own system of record that you connect to Fieldkeep, not a sub-processor we share your data with. We notify customers before adding a new sub-processor, as set out in the DPA.
What we keep, and for how long
Retention is tiered, so that privacy-sensitive raw location is kept only as long as it is useful, while the records you need for payroll and compliance are kept longer.
- Raw location points are retained for a short window (currently about 45 days) and then automatically purged. This window supports mileage review and recent map history; it is enforced in code, not just stated as policy.
- Time records on Fieldkeep Time, and the location breadcrumbs that support them, are kept longer (a seven-year design) so they remain available for payroll, reimbursement, and wage-and-hour recordkeeping. The originally captured time is preserved write-once, and every later change a manager makes is recorded in an append-only, immutable audit log (who changed what, when, and why), so the record is defensible if it is ever questioned.
- Account, operational, and financial data read from your property-management system is retained for as long as you use the service and as needed for the operations and reporting you rely on.
- Team-chat messages and photos, for customers who use in-app chat, are kept as part of your operational record for as long as you use the service. Photos are currently stored by our messaging sub-processor, Stream, under their retention terms. Before a photo is uploaded, location metadata such as GPS coordinates is removed from the image file on the device.
Worker location
Location is collected only while a worker is on the clock. It starts at clock-in and stops at clock-out, never off-clock. It is used to calculate mileage, show the worker on the live dispatch map, and record where on-site work happened. Inside the product, location is visible to the worker’s own managers and administrators, not to peers.
Before the app requests location permission, it shows a prominent in-app disclosure of what is collected and why, and the worker grants the operating-system location permission themselves. A worker can turn location off in their device settings at any time, which limits or prevents location and mileage features.
Several US states require employers to give workers written notice, or obtain written acknowledgment, before tracking their location. That written acknowledgment is the employer’s responsibility as the controller of worker data; Fieldkeep’s role is to provide the in-app disclosure and the device-level permission described above. Built-in capture of a per-worker written acknowledgment is on our roadmap; today it is handled by the employer’s own onboarding.
Compliance
Fieldkeep is an early-stage product and is not SOC 2 certified today. We do not claim certifications we do not hold. Our controls are designed against the SOC 2 Security criteria, and a formal audit is on our roadmap as we grow. In the meantime, this page, the DPA, and a direct conversation with us are how we answer a security review. We are glad to complete a reasonable vendor-security questionnaire. Fieldkeep carries professional liability (errors and omissions) insurance.
Your data is yours: export and deletion
The employer owns its data. Fieldkeep can export your time and mileage records in standard formats (including CSV for common payroll providers), and on request we will assist with access, correction, or deletion of personal information consistent with the controller’s instructions and applicable law. Broader self-serve export and clean offboarding are on our roadmap; until then we handle these requests directly.
Contact
Security or privacy questions, or a vendor-security review? Contact support@fieldkeep.app. Fieldkeep is a product of RightMove Properties.