← Back to FieldStay

Privacy Policy

Effective: June 9, 2026

For Data Processing Agreement (enterprise / GDPR Article 28): View DPA

1. Who We Are (Controller Identity)

FieldStay, Inc.(“FieldStay,” “we,” “our,” or “us”) is the data controller for personal information processed through the FieldStay platform (“Service”) — a field operations and property management system for short-term rental managers.

Contact: privacy@fieldstay.app

FieldStay has not appointed a Data Protection Officer (DPO) because it does not engage in large-scale systematic processing of special categories of personal data as described in GDPR Article 37. If you are in the EU/EEA and wish to contact us about data protection matters, please use the email above.

2. Personal Data We Collect

We collect the following categories of personal information:

Identity and Contact Data
Name, email address, and profile photo (optional) when you create an account. Phone numbers you voluntarily add to your profile or enter for crew and vendor contacts.
Credentials
Password (stored as a bcrypt hash — we never see the plaintext). OAuth tokens for connected integrations (OwnerRez, Uplisting) stored encrypted in Supabase Vault.
Business and Operational Data
Property details, booking records, crew schedules, vendor contacts, work orders, inventory data, and financial transactions you enter into the Service. This data is attributable to your organization and may include personal data about third parties (crew members, vendors, property owners) that you provide to us.
Financial Data
Billing information is collected and processed directly by Stripe. We store only your Stripe customer ID and subscription status — we never see or store full card numbers.
Usage and Technical Data
Pages visited, features used, error logs, browser type, IP address, and device identifiers collected via server logs and our hosting infrastructure (Vercel). This data is used to operate, debug, and improve the Service.
Communication Data
Records of messages sent via the in-app messaging system between property managers, crew members, and vendors. Push notification tokens if you enable browser notifications.
Audit and Security Logs
Records of security-relevant actions taken in the Service (logins, permission changes, data exports, deletions) associated with your user account ID and timestamp.

Sources

  • Directly from you when you create an account, configure your organization, or use the Service.
  • From connected third-party platforms (OwnerRez, Uplisting) when you authorize an integration.
  • Automatically from your device and browser as you interact with the Service.
  • From Stripe, for subscription and billing events.

Sensitive Personal Information

We do not intentionally collect sensitive personal information as defined under CPRA (California Privacy Rights Act) — such as Social Security numbers, racial or ethnic origin, health data, or precise geolocation — as part of normal Service operation. Property addresses and zip codes are collected for operational purposes (geocoding for crew dispatch) and are not used for consumer profiling.

SMS Communications

FieldStay collects mobile phone numbers solely for the purpose of delivering stay-related SMS communications to guests who have explicitly opted in. Phone numbers are not sold, shared, or transferred to third parties for marketing purposes. SMS consent is not a condition of any purchase or service. Message and data rates may apply. You may opt out at any time by replying STOP to any message.

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:

Contract Performance (Article 6(1)(b))
Processing necessary to provide the Service you have subscribed to — account creation, property management operations, sending work order notifications to crew and vendors, billing via Stripe, and delivering transactional emails.
Legitimate Interests (Article 6(1)(f))
Security and fraud prevention (maintaining audit logs, detecting unauthorized access); service improvement (aggregated usage analytics, error monitoring); and product communications (feature announcements to existing customers). Our legitimate interests do not override your fundamental rights and freedoms — we conducted a balancing test for each purpose and would share that assessment on request.
Legal Obligation (Article 6(1)(c))
Retention of financial transaction records for 7 years to comply with tax and accounting regulations (U.S. IRS requirements; equivalent EU member state fiscal law).
Consent (Article 6(1)(a))
Push notifications to your browser — only when you explicitly grant permission. You may withdraw this consent at any time through your browser settings or in Settings → Account.

4. Purposes of Processing

  • To create and manage your account and organization.
  • To operate the property management, crew scheduling, and work order workflows.
  • To send transactional communications: invitation emails, work order assignments, billing receipts, and expiry alerts.
  • To sync reservation data from connected third-party platforms when you authorize them.
  • To process payments and manage your subscription through Stripe.
  • To generate AI-assisted review responses (RepuGuard feature) using review text you submit.
  • To maintain security logs and an audit trail for your organization.
  • To detect, investigate, and prevent unauthorized access or abuse.
  • To comply with applicable law and enforce our Terms of Service.
  • To improve and develop the Service using aggregated, de-identified usage data.

We do not sell, rent, or share your personal data with third parties for their own marketing or advertising purposes. We do not use your data for cross-context behavioral advertising.

5. Data Sharing and Sub-Processors

We share personal data only with the following categories of recipients, each acting as a data processor on our behalf under contractual data protection obligations:

Supabase, Inc. (United States)
Database and authentication infrastructure. Your data is stored in the United States (us-east-1 region). Supabase participates in the EU-US Data Privacy Framework. Supabase Privacy Policy
Vercel, Inc. (United States)
Application hosting, edge network, and server-side rendering. Vercel processes request logs including IP addresses. Vercel Privacy Policy
Stripe, Inc. (United States)
Payment processing. Stripe is the data controller for payment card data. Stripe is PCI DSS compliant and certified under the EU-US Data Privacy Framework. Stripe Privacy Policy
Resend, Inc. (United States)
Transactional email delivery (work order notifications, invitations, billing receipts). Email addresses and message content are transmitted for delivery purposes only.
Inngest, Inc. (United States)
Background job orchestration for asynchronous workflows. Receives event payloads containing property and booking identifiers.
Anthropic, PBC (United States)
AI-powered review response generation (RepuGuard feature only). Guest review text is transmitted to Anthropic's API to generate a draft response. Anthropic does not retain this data beyond the API call per their enterprise data agreements. Anthropic Privacy Policy
Mapbox, Inc. (United States)
Geocoding service. Property addresses and ZIP codes are transmitted to resolve latitude/longitude coordinates for crew dispatch distance calculations.
Kroger Co. (United States)
Grocery and supply fulfillment (optional). If you connect your Kroger account via OAuth, your Kroger access token is stored encrypted. Property addresses may be transmitted to identify the nearest store.

We may also disclose personal data: (a) to comply with a court order, subpoena, or applicable law; (b) to enforce our Terms of Service; (c) to protect the rights, property, or safety of FieldStay, our users, or the public; or (d) in connection with a merger, acquisition, or sale of all or substantially all of our assets, in which case the acquirer would be bound by this Privacy Policy.

6. International Data Transfers

FieldStay is headquartered in the United States. If you access the Service from the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data is transferred to and processed in the United States.

We rely on the following transfer mechanisms to ensure an adequate level of protection:

  • EU-US Data Privacy Framework (DPF): Our primary sub-processors (Supabase, Vercel, Stripe) are certified under the EU-US DPF, which was deemed adequate by the European Commission in Decision 2023/1795. Their DPF certifications are listed on the DPF website maintained by the U.S. Department of Commerce.
  • Standard Contractual Clauses (SCCs):Where sub-processors are not DPF-certified, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914) incorporated into our data processing agreements with those processors.

You may request a copy of the applicable transfer mechanisms by contacting us at privacy@fieldstay.app.

7. Cookies and Local Storage

We use only strictly necessary cookies for session management (keeping you logged in) and a localStorage entry to remember your theme preference. No advertising, tracking, or analytics cookies are set.

Because we use only technically necessary cookies, consent is not required under the GDPR ePrivacy Directive or CPRA for these cookies. You may delete all cookies via your browser settings, which will log you out of the Service.

8. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this policy, or as required by law. The specific retention periods are:

Account and Profile Data
Retained for the life of your account. Deleted within 30 days of account deletion.
Business Operational Data
(Properties, bookings, work orders, crew records.) Retained for the life of your account. Deleted within 30 days of account deletion, subject to legal holds.
Financial Transaction Records
Billing receipts and owner transaction audit entries are retained for 7 years from the date of the transaction to comply with IRS record-keeping requirements (Rev. Proc. 98-25) and GAAP. These records may be retained even after account deletion.
Security and Access Logs (Audit Events)
Operational audit events (logins, permission changes, data exports) are retained for 3 yearsfrom the date of the event, consistent with SOC 2 Type II audit requirements and GDPR's reasonable retention standard for security logs.
Communication Logs
In-app messages are retained per the retention period configured by your organization (default: 365 days), after which they are soft-deleted and permanently purged 30 days later.
Push Notification Tokens
Deleted immediately when you revoke notification permissions or delete your account.

9. Your Rights Under GDPR

If you are located in the EEA, United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and equivalent national law:

Right of Access (Article 15)
You may request confirmation of whether we process your personal data, and a copy of that data together with information about how it is processed. Use the “Export My Data” function in Settings → Audit Log, or email us.
Right to Rectification (Article 16)
You may correct inaccurate personal data by editing your profile in Settings → Account. For data you cannot self-edit, contact us.
Right to Erasure (Article 17)
You may request deletion of your personal data where: (a) the data is no longer necessary for the purpose it was collected; (b) you withdraw consent and no other legal basis applies; (c) you object and we have no overriding legitimate interests; or (d) we have processed your data unlawfully. Note: legal retention obligations (e.g., 7-year financial records) may prevent immediate full deletion.
Right to Restriction (Article 18)
You may request that we restrict processing of your personal data in limited circumstances (e.g., while we verify a rectification request or pending resolution of an objection).
Right to Data Portability (Article 20)
For data you provided to us based on contract or consent, you may receive a structured, machine-readable copy of your personal data. Use the “Export My Data” function (JSON format) in Settings → Audit Log.
Right to Object (Article 21)
You may object to processing based on our legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for legal claims.
Right to Withdraw Consent (Article 7(3))
Where processing is based on consent (e.g., push notifications), you may withdraw consent at any time without affecting the lawfulness of prior processing. Withdraw via Settings → Account or your browser's notification permissions.
Rights Related to Automated Decision-Making (Article 22)
FieldStay uses automated crew assignment suggestions based on location, availability, and historical performance scores. This automation produces recommendations that a human property manager reviews and approves or overrides — it does not produce decisions with legal or similarly significant effects on individuals. Crew members are not excluded from consideration based solely on algorithmic output.
Right to Lodge a Complaint (Article 77)
You have the right to lodge a complaint with your local supervisory authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the ICO at ico.org.uk. We encourage you to contact us first — most concerns can be resolved directly.

Response timeframe: We will respond to your request within 30 days. If the request is complex or numerous, we may extend by up to 2 additional months with prior notice. Requests are free of charge unless manifestly unfounded or excessive. Submit requests to privacy@fieldstay.app.

Provision requirement: Providing your name and email address is contractually required to create an account and use the Service. Without this data we cannot provide the Service. All other data fields are voluntary.

10. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you the following rights:

Categories of Personal Information Collected

  • Identifiers (name, email address, IP address, user ID)
  • Commercial information (subscription plan, billing history via Stripe)
  • Internet or other electronic network activity (usage logs, feature interaction data)
  • Professional or employment-related information (crew role, reliability scores)
  • Inferences drawn from the above (crew assignment recommendations)

We Do Not Sell or Share Your Personal Information

FieldStay does not sell your personal information within the meaning of CCPA § 1798.100 or share it for cross-context behavioral advertising within the meaning of CPRA § 1798.140(ah). No opt-out is required because we do not engage in these activities.

Your CCPA / CPRA Rights

Right to Know (§ 1798.100)
You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom it is shared.
Right to Delete (§ 1798.105)
You may request deletion of your personal information, subject to exceptions (e.g., completing transactions, legal obligations, security purposes).
Right to Correct (§ 1798.106 — CPRA)
You may request correction of inaccurate personal information we maintain about you. Edit your profile in Settings → Account or submit a correction request.
Right to Opt-Out of Sale/Sharing (§ 1798.120)
As noted above, we do not sell or share personal information. No opt-out mechanism is required, but you may contact us to confirm.
Right to Limit Use of Sensitive Personal Information (§ 1798.121 — CPRA)
We do not use sensitive personal information for purposes beyond those necessary to perform the Service. No limitation request is needed.
Right to Non-Discrimination (§ 1798.125)
We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you the Service, charge different prices, or provide a different level of service based on your exercise of these rights.

Response timeframe: We will respond to verifiable California consumer requests within 45 days. We may extend by an additional 45 days where reasonably necessary with prior notice. Submit requests to privacy@fieldstay.app or use the account deletion feature in Settings → Account. We will verify your identity before fulfilling deletion or access requests.

Authorized agents: California residents may designate an authorized agent to submit requests on their behalf. We may require written authorization and identity verification.

11. Do Not Track

California's Online Privacy Protection Act (CalOPPA) requires disclosure of how we respond to Do Not Track (DNT) signals. FieldStay does not respond to DNT signals because we do not engage in cross-site tracking of any kind. We do not track your activities across third-party websites or services.

12. Security

We implement technical and organizational measures appropriate to the risk, including:

  • TLS 1.2+ encryption for all data in transit.
  • AES-256 encryption at rest for sensitive credentials and tokens in Supabase Vault.
  • Row-Level Security (RLS) policies on every database table enforcing tenant isolation.
  • Role-based access controls (admin, manager, crew, viewer, owner).
  • Append-only audit log for all security-relevant actions.
  • Stripe-side storage of payment card data (we never receive or store card numbers).

No method of transmission over the Internet or electronic storage is 100% secure. If you discover a security vulnerability, please report it to privacy@fieldstay.app.

13. Children

The Service is directed to and intended for use only by individuals who are 18 years of age or older. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA). If you believe we have inadvertently collected personal information from a minor, contact us immediately at privacy@fieldstay.app and we will delete it promptly.

14. Changes to This Policy

We may update this policy to reflect changes in our practices, technology, or applicable law. Material changes will be communicated by email to registered account holders at least 30 days before taking effect. The revised effective date will be updated at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

15. Contact Us

For any privacy questions, requests, or concerns, contact our privacy team at:

FieldStay, Inc.

Email: privacy@fieldstay.app

EEA/UK residents with unresolved complaints may also contact your local data protection supervisory authority. EU authority directory: edpb.europa.eu. UK: ICO at ico.org.uk.