FieldQuo

Privacy Policy

Effective September 29, 2026

FieldQuo is software a contracting company runs its business on: quotes, invoices, scheduling, and — for companies that turn it on — an AI phone receptionist and AI drafting tools. This page explains what personal information passes through it, who else sees it, and what say you have over it. It applies to FieldQuo staff, to the contractors ("companies") who subscribe to FieldQuo, and to the clients and callers of those companies (their "homeowners" or "clients") whose information reaches us because a company they hired uses FieldQuo.

1. Who this policy covers, and a word about who controls what

FieldQuo is multi-tenant software: each subscribing company (a painter, a cabinet maker, a plumber, and so on) has its own account, its own clients, and its own data. For most of the personal information described here — a homeowner's name, address, phone number, quote and invoice history, photos of their property, and any recorded phone calls — the company is the data controller and FieldQuo is its processor. We hold this information because a company we serve put it into the product to run its business; we do not decide to collect it, and we do not use it for our own purposes beyond running and improving the product itself. If you are a homeowner or client with a question about your own information, the fastest route is usually the company you hired — see Section 6.

Separately, FieldQuo is the data controller for information about the companies and staff who subscribe to FieldQuo itself — account details, billing contacts, and how staff use the product.

2. What we collect

From a subscribing company and its staff

  • Account and contact details: name, email, phone, company name and address.
  • If you start the signup form and do not finish it, what you had typed so far (your name, email, phone, company name, trades and language) is kept so that we can follow up with you about the signup — by email, or by a call from our sales team if you gave a phone number. You can ask us to delete it at any time (see Section 6).
  • Billing information, handled by Stripe (see Section 4) — FieldQuo does not store card numbers.
  • Everything the company enters to run its business: clients, quotes, invoices, jobs, pricing, photos, and staff activity within the product.

From a client, homeowner, or caller

  • Name, address, phone number and email, when a company adds them as a client, or when they submit a self-quote form, a booking request, or call a company's AI receptionist.
  • Photos of their property, when they or a company's staff attach them to a quote or job.
  • On a company’s instant-estimate page or lead funnel: how far the visit got and which link or ad it arrived from (counted without a cookie), and — under a notice beside the fields saying so — the name, email and phone typed into the contact step even if the request is never sent, kept for that company to follow up and hidden after 30 days. If the company has added its own advertising pixel (Meta, Google or TikTok), that platform receives page views and a “lead” event from the visitor’s browser, with no name, email, phone or address; a company can require the visitor’s consent before any pixel loads.
  • Payment details, when they pay an invoice or a booking fee online — handled by Stripe; FieldQuo does not store card numbers.
  • The content of quotes, invoices, and messages sent to them.
  • If a company uses the AI phone receptionist: the audio, recording, and transcript of calls to that company's number.
  • If a company offers automatically-recurring payments (a "service plan"): their saved payment method, and the IP address and browser user agent present when they authorised it — recorded because Stripe's rules for charging a saved payment method later require us to be able to show that authorisation happened.
  • When they approve a quote by signing it online: the drawn signature itself, the name they typed, the time, and the IP address and browser user agent the signature came from. That last part is what makes the signature worth anything — a signature nobody can place at a time and a connection is a picture, not evidence, and if the approval is later disputed it is the contractor who needs to be able to show it happened.

Page views

FieldQuo measures which of its own pages are viewed — the marketing site, the help centre, the back office and the pages a company's clients open — itself, without any third-party analytics service, tracking cookie or advertising pixel. What is recorded is the page's route (never the specific quote, booking or client it showed), the interface language, a screen-size bucket, the referring site's domain and any campaign tags in the link, plus a random identifier kept in the browser's own storage so that one reader is counted once. No IP address is stored. Raw entries are kept for 30 days and then reduced to daily totals.

Separately, back-office page loads (never a page a company's clients see) report performance timings to Vercel Speed Insights so we can find slow pages: the page path without its query string, the device and browser type, and how long the page took to load. It is listed in Section 4.

We do not knowingly collect information from anyone we know to be a minor, and FieldQuo is built for business-to-business and business-to-homeowner transactions, not for use by children.

3. How we use AI

FieldQuo uses AI in specific, narrow places — never to build a general profile of a person, and never to compare one company's data against another's. What follows is what each AI feature is for; it does not describe how any figure is calculated, because that is not a privacy question.

  • Reviewing a quote before it's sent. The photos attached to a quote are read by an AI model to surface things worth double-checking on site, and to help write plain-language descriptions of the work. A company can also pay for a deeper photo review of the same photos.
  • Recovering and drafting from phone calls. For companies using the AI phone receptionist, call transcripts are used to reconstruct a lead from a call that wasn't captured any other way, to draft a quote from what a caller described, and to build a monthly digest summarising a company's call activity.
  • The FieldQuo AI assistant. Built into the product for a company's own staff to ask questions about their own business — cash flow, quotes, invoices, jobs. It answers only from that company's own data, refuses requests unrelated to running the business, and never sees another company's information. Where it needs to reference a client to answer a question, it is given that client's name only — never their address, phone number, email, or financial history — enforced in code, not left to the model's judgement.
  • Generating marketing images. A company can generate or edit marketing images (for ads and its website) using AI, from a reference photo it supplies.
  • Drafting and translation. AI drafts website copy and translates text a company writes, working from that company's own data — it does not invent services, prices, or layouts.

AI processing for these features is performed by OpenAI, and — for phone calls — by Retell; see the table in Section 4.

4. Who else sees this information

We use the following third-party services to run FieldQuo. Each receives only the categories of information its role requires.

ServiceWhat it doesWhat reaches it
NeonDatabase hostingEvery table FieldQuo writes to — companies, staff accounts, clients, quotes, invoices, jobs, call and message logs, everything. This is the single database behind the whole product.
Stripe (Connect)Payment processing — a homeowner paying a contractorA homeowner's card details, when they pay an invoice or a booking fee. The charge is created on FieldQuo's platform Stripe account and the funds are transferred to the contracting company's own connected Stripe account — FieldQuo's servers never store the card number itself; Stripe does.
Stripe (Billing)Payment processing — a contractor paying FieldQuoA contracting company's own card details and billing contact, for their FieldQuo subscription. Separate from Stripe Connect above — this is FieldQuo getting paid, not a homeowner.
Stripe (saved payment methods)Payment processing — automatic recurring payments a homeowner authorisesA homeowner's saved payment method, for a recurring service plan they've agreed to (e.g. a seasonal maintenance contract billed automatically). We also record the IP address and browser user agent present when they authorise it, because Stripe's rules for charging a saved payment method without the cardholder present require us to be able to show that authorisation happened.
ResendOutbound email deliveryEvery email FieldQuo sends on a company's behalf passes through Resend to be delivered — the recipient's address and the full content of whatever was sent: a quote, an invoice, a booking confirmation, a marketing message.
TwilioSMS deliveryA homeowner's phone number and the content of text messages sent to or received from them — appointment reminders, booking confirmations, and STOP/START opt-out replies.
CloudinaryImage and video storage and deliveryPhotos uploaded into the product — job-site photos, photos a homeowner attaches to a quote request, and images used on a company's generated website — and the video clips a company uploads to post to its own social accounts, which Cloudinary also converts to the vertical format those platforms take.
OpenAIAI featuresProperty photos (when a quote is reviewed, and on the paid deep photo review), call transcripts (to recover a lead from a missed call, draft a quote from a call, and build the monthly activity digest), and — for the FieldQuo AI assistant built into the product — a client's NAME ONLY, never their contact details, address, or financial history. See "How we use AI" below for what each of these is for.
RetellAI phone answeringFor companies using the AI phone receptionist: the live call audio, the recording, and the transcript of every call it takes.
VercelHostingFieldQuo runs on Vercel's infrastructure — all traffic to the product passes through it.
Vercel Speed InsightsPerformance measurement of the FieldQuo back officeFor a sample of page loads inside the contractor back office only: the page path with the query string removed, the device and browser type, and performance timings (how long the page took to load and respond). No names, contact details, or customer records are sent. It is never loaded on anything a homeowner sees — quotes, invoices, booking pages, client portals, or a contractor's website.
Meta (Facebook/Instagram Ads) — spend importAd-spend import — a contracting company's own Meta ad account, read onlyFor companies who connect their own Meta ad account (Settings → Meta Ads, an owner/admin-only action): an OAuth access token scoped to ads_read, and which ad account id is connected. In return FieldQuo receives that company's own ad spend, campaign names, and performance figures — impressions, clicks, and Meta's own reported conversions. This never includes a homeowner's information: no client name, contact detail, or quote/job data is sent to Meta, and FieldQuo does not use Meta's Conversions API. See docs/META-ADS-BUILD.md.
Google MapsAddress autocomplete and mappingAn address as a homeowner or contractor types it, for autocomplete, and the address on a job for map display.
UnsplashStock photography, loaded from Unsplash's own serversNo personal information is SENT to Unsplash by us. But a new company website starts with stock photos in its decorative slots, and those are hotlinked rather than copied — so a homeowner visiting a contractor's site makes a request to Unsplash's image servers, which sees their IP address and browser. The same applies to stock photos placed in the Marketing Designer. Uploading real photos replaces them.
YouTube (Google)Video embedded on FieldQuo's own marketing pagesA visitor's IP address and browser, when a FieldQuo marketing page with a video on it loads. We use YouTube's no-cookie embed domain, which does not set a tracking cookie before the visitor presses play — but the request to Google still happens. This is FieldQuo's own website, not a contractor's.
Google CalendarA staff member's own calendar, connected by that member from Settings → My calendarOnly when a staff member connects their own Google account. FieldQuo writes its own events to that member's calendar — the visits assigned to them, with the site address and a link back — and reads back only whether the member is busy at a given time, never the titles or details of their own events. The connection is revoked and every FieldQuo-created event removed when the member disconnects. Nothing from Google Calendar is used for advertising, sold, or shown to anyone but that member as busy time.
Google SolarRoof measurementA property's address, sent to estimate roof area and shape for a self-serve roofing quote.
Meta (Facebook & Instagram) — publishingSocial media publishing — posting a company's own ad to its own Page or Instagram accountOnly when a company chooses to publish a Marketing Designer ad or video: the rendered image or the video clip (fetched by Meta from a public, unlisted Cloudinary URL — see lib/social/metaSpecs.js and lib/marketing/videoPost.js), the caption text, and the company's own connected Page/Instagram account id and access token. No homeowner data is involved — the asset published is the company's own advertisement, not a client record. Separate from the ad-spend import below, which reads FROM Meta rather than posting TO it.
TikTok — publishingSocial media publishing — posting a company's own ad to its own TikTok accountOnly when a company connects its TikTok account and chooses to post a Marketing Designer ad or video: the rendered image or the video clip (which TikTok downloads from a short-lived, unguessable FieldQuo link), the caption, and the visibility, comment and commercial-content settings the person chose. To connect, TikTok returns the account's id, display name, picture and access tokens, which FieldQuo stores encrypted and deletes on disconnect. No homeowner data is involved — the post is the company's own advertisement, not a client record.

We do not sell personal information, and we do not share a company's client data with any other company on FieldQuo. The one exception is described in Section 7: the pooled industry benchmark, on by default and switchable off in Settings, which takes only a company's own anonymised, aggregate figures (never its client-level data).

Where data is hosted:FieldQuo's database and application servers are in the United States, in the northern Virginia / Washington, D.C. area (Neon on AWS us-east-1 and Vercel's iad1 region). The other services listed above run on their own infrastructure and may process the information they receive in other countries, under their own terms.

Requests from public authorities

If a government agency, regulator, or law-enforcement authority asks FieldQuo for personal information, we:

  • review every request to confirm it is lawful and properly made before we respond;
  • challenge a request we consider unlawful, overly broad, or not properly made, and do not disclose anything while that challenge is open unless the law requires us to;
  • disclose only the minimum information the request legally requires; and
  • keep a record of each request, our response, the legal basis for it, and who handled it.

Where the law allows, we tell the affected company before disclosing its information, so it can respond itself.

5. How long we keep information

We want to state this plainly rather than promise a retention schedule the product doesn't implement: FieldQuo does not currently delete data on a schedule, and there is no way for a company to delete its FieldQuo account today. If a company's subscription lapses, its account becomes inaccessible — nobody can sign in and use it — but the underlying records are not erased.

  • A client record can only be deleted by a company's own staff, and only if that client has no quotes and no invoices on file. A client with any billing history cannot be deleted through the product.
  • Call recordings and transcripts have no automatic expiry — they are kept until a company's staff removes what they can, subject to the limits above.
  • Email unsubscribe and SMS opt-out records are kept permanently, by design — an opt-out is a standing instruction, and honouring it later depends on still having the record that it was given.

We are telling you this directly because we think a retention policy that describes a deletion schedule the product doesn't have would be worse than one that says plainly what happens today. We intend to build account and data deletion; this policy will be updated, with a new effective date, when that ships.

In the meantime, deletion is a request handled by a person. Data Deletion sets out exactly what to send, where, and what we can and cannot erase.

6. Your rights, and how to reach us

Depending on where you are, you may have rights to access, correct, export, or request deletion of your personal information. We want to be direct about where the product stands today: there is currently no self-service way for a homeowner or client to see, correct, export, or delete their own information through FieldQuo. The client account area a company's client can reach shows their own quotes and invoices with that company and lets them pay a balance — it is not a data-access tool.

If you want to exercise a privacy right, the most direct route is the company you dealt with — they hold your primary relationship and can act on your request. If you'd rather contact FieldQuo directly, email hello@fieldquo.com and tell us which company's records your request concerns; we will act on it directly where we are able to, and otherwise route it to that company on your behalf. For a deletion request specifically, Data Deletion lists what to include so we can act without a round trip.

7. Aggregate industry benchmarking (on by default, switch off in Settings)

A company's anonymised pricing and conversion figures are pooled into a benchmark that shows companies like them how their numbers compare — for example, a median win rate across similar trades. This ison by defaultunder the Terms of Service (Section 7) a company accepts when its account is created, is never shown broken out by individual company, is only published where enough companies contribute that no single company's figures can be worked out, and can be switched off at any time in Settings › Company. No client-level data — no client name, address, or contact information — is included in this pool, only aggregate figures about the company's own business.

Information about a business, as opposed to an identifiable individual, is generally not "personal information" under Canadian privacy law (PIPEDA) — which is part of why this is offered as a product setting rather than treated as a personal-data consent flow. The one case that doesn't fit that reasoning is a sole proprietor, whose business figures can be inseparable from them as an individual. If that describes your business, treat this setting as covering your own personal information too, and decide accordingly.

8. Marketing email and text messages

Commercial emails from a company using FieldQuo — marketing campaigns, review requests, and similar outreach — carry a working, one-click unsubscribe link, and unsubscribing takes effect immediately. Transactional messages (a quote, an invoice, a payment receipt, a password reset) do not carry an unsubscribe link, because they are not marketing and CASL does not require one on them.

For text messages, replying STOP to a message from a company's own dedicated number opts that number out of future texts from that company; replying START opts back in. One current gap, stated plainly: a company that hasn't been assigned its own dedicated texting number and is using FieldQuo's shared fallback number does not yet have a working STOP reply on that shared number — see the Security page for more detail.

9. Quebec — Law 25

Emilio Boves, Chief Executive Officer, and Person in Charge of the Protection of Personal Information, is responsible for the protection of personal information at FieldQuo and can be reached at 819-238-7263.

10. Changes to this policy

If we change this policy in a way that matters, we'll update the effective date at the top and, where the change is material, tell subscribing companies directly.

11. Contact

Questions about this policy: hello@fieldquo.com.