Privacy Policy
Two kinds of data, treated differently on purpose.
Field Blasters is software that field-service companies use to run their business. That means we hold your data — and your customers' data, which you put in. For yours, we decide what happens; for theirs, you decide, and we only do what the software does on your behalf. We sell neither, we use neither to train anything, and we do not use your customers' data for our own purposes at all.
1. Who we are
Window Blasters LLC of St. George, Utah, operating Field Blasters. Contact: hello@fieldblasters.com.
2. What we collect, and why
From a company that subscribes
- Your business name, your account's short name, and the first administrator's email address — typed at signup, to create your account and reach you.
- Your name — typed at signup, optional, so the email we send is addressed to a person.
- The settings you enter as you set up — your town, phone number, public email, logo, timezone, the towns you cover, links to your own policies, your service prices, your staff and their pay arrangements. They are the software working.
- Sign-in records — created when you sign in, for security and support.
- The emails we send you, and what our email provider reports back about them (delivered, bounced, marked as spam) — so we know whether our messages reach you.
We do not ask for a payment card at signup. When subscription billing starts for your account, the card is collected and held by Stripe, not by us, and you will see what is charged before anything is.
About your customers, on your behalf
Whatever you put in: names, postal addresses, email addresses, phone numbers, appointments, photographs taken on a job, quotes, invoices, payment records, memberships, notes, messages sent and received, and signed forms.
We are a processor for all of it and you are the controller. We hold it, keep it separate from every other company's, and do what the software does with it when you use the software. We do not read it, mine it, resell it, or contact your customers on our own account.
3. Where it is kept
On Supabase (Postgres, authentication, file storage and server-side functions) hosted in the United States, and served through Netlify. If you are outside the United States, using the service means your data is transferred there.
Each company's records carry its own identifier, and every read and write is filtered on it in the database itself, not merely in the app.
Your staff's devices hold an offline copy. The app keeps a local copy of your working data in the browser's own storage so it opens instantly and keeps working with a poor signal. It is cleared when someone signs out on that device, but until they do it is on that device.
4. Who else sees it
We use these services and no others. Each one gets only what it needs to do its job.
- Supabase — everything above; it is where the data lives.
- Netlify — the requests that load the app.
- Stripe — your customer's name, email, amount and card details, only when you take a payment. See §5.
- Resend — the address, subject and content of any email the software sends, and what happens to it.
- Google (Maps and Places) — the address text typed into an address box, so it can be suggested and pinned.
- RentCast — a property address, only when somebody asks for a property lookup.
We use no advertising networks, no analytics or tracking pixels, and no third-party cookies. The only things stored in a browser are the ones that make the app work: your sign-in session, its offline copy of your data, and small preferences like which tab you last had open.
5. Card numbers
A card number never reaches us and we could not store one if we wanted to. Card details are entered directly into fields hosted by Stripe and go to Stripe. What we hold is what Stripe tells us afterwards: that a payment succeeded, for how much, and the last four digits and brand of the card.
When a customer of yours pays you, you are the merchant, through your own Stripe account connected to ours. Stripe holds that relationship with you directly and its own privacy notice applies to it. We never hold your customers' money.
6. How long it is kept
- A record you delete goes to a trash that keeps it for 30 days and is then removed.
- An unfinished signup — somebody who filled in the form and never followed the emailed link — expires after 24 hours. No account is created and nothing is kept.
- While your account exists, everything else is kept.
- When your account closes, your data stays readable and exportable for 90 days and is then deleted — or deleted sooner if you ask. Your account's short name is never reused, by you or anyone else.
7. What you can ask us for
You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it, at hello@fieldblasters.com. There is no self-serve export yet: a request is answered by a person, and you will have your data — as spreadsheets — within 14 days.
If you are one of our subscribers' customers and want your data changed or removed, ask that company directly — it is theirs, they control it, and we act on their instruction. If you write to us we will pass it on to them.
8. Security
Sign-in is by email and password, handled by Supabase's authentication service; we never see your password. Every request is filtered by your account's identity in the database. Server-side actions that touch money or permissions check who is asking on the server, not in the browser. Payment webhooks are accepted only with a valid cryptographic signature. The link in a signup email is stored only as a hash, so the database does not contain a working link to anyone's account.
Two things worth knowing, because they are true: when you ask us for help that requires looking inside your account, that access today is carried out directly by our own operators — a permissioned in-product support view is being built. And anyone you give an administrator login can read your company's whole settings, including your staff's pay rates — give administrator access accordingly.
9. Children
The software is for businesses. It is not for anyone under 18 and we do not knowingly collect their data.
10. Changes
If we change this policy we will say so on this page and, for a change that matters, email the administrators of every account.
Last updated: August 28, 2026.