Privacy Policy
Operfield (“Operfield”, “we”, “us”) is a field-operations platform for construction and trades businesses. This policy explains what information we collect, how we use it, who can see it, and the choices you have. It applies to the Operfield web application, the installable app, and related pages (together, the “Service”).
The short version:your company’s data belongs to your company. We collect only what the Service needs to work, we don’t sell personal information, and location is captured only at the moment of clocking in or out - never tracked continuously.
01Who is responsible for your data
Operfield is used by companies (“Customers”) to run their field operations. If you use Operfield as an employee, supervisor, or subcontractor of a Customer, that company decides what data is entered and who in the company can see it - Operfield processes the data on the company’s behalf. Questions about your employer’s practices (for example, why hours or location are recorded) should go to your employer first; questions about the platform itself can come to us.
02Information we collect
- Account information - name, email address or username, phone number, role, department, and profile photo if one is uploaded.
- Work records - timesheets (clock-in/out times, breaks, notes), schedules, work orders, site reports, safety reports, material requests, and related photos and documents your company creates in the Service.
- Location at clock-in/out - if you allow location access, your device’s GPS position is captured only at the moment you clock in or clock out, along with an approximate street address. Operfield does not track your location continuously or in the background. Clocking via a notification button records no location at all.
- Financial records - invoices, expenses, budgets, payroll figures derived from timesheets, and subcontractor bid information entered by your company or its subcontractors.
- Device and technical data - push-notification subscription tokens (if you enable notifications), browser type, and basic logs needed to run and secure the Service.
03How we use it
- To provide the Service: timekeeping, scheduling, work orders, reports, invoicing, and payroll summaries.
- To send notifications you or your company set up - clock-in reminders, invoice and approval alerts, schedule changes.
- To send transactional email (for example, invites, signature requests, or “your check is ready” notices).
- To secure the Service, prevent abuse, and debug problems.
We do notsell personal information, and we do not use your company’s data for advertising.
04Who can see your information
- Your company - managers and office roles in your company see work records according to the role permissions your company sets (for example, supervisors see their own site; wage figures are restricted to owner/accounting roles).
- Service providers - we use a small number of processors to run the Service: Supabase (database, authentication, and file storage), Vercel (hosting), Resend (transactional email), and your device platform’s push service (Google, Apple, or Mozilla) for notifications. Each receives only what it needs to perform its function.
- People you share with - links your company generates intentionally (subcontractor portals, signature requests, client portals) expose only the specific records those links are for.
- Legal requirements - we may disclose information if required by law or to protect the rights, safety, or property of Operfield, our Customers, or others.
05Location data, in plain words
Location exists in Operfield for one reason: proving a clock-in/out happened at the job site. It is requested from your browser only when you tap clock in or clock out, is stored with that single timesheet entry, and is visible to your company’s office roles. You can decline the browser’s location permission and still clock in - the entry is simply saved without a position. Your employer may have its own policy requiring location; that policy is theirs, not ours.
06Cookies and similar technologies
We use cookies strictly to keep you signed in (authentication session cookies) and to remember basic preferences on your device (for example, sidebar layout or completed tours, stored in your browser’s local storage). We do not use advertising or cross-site tracking cookies.
07Retention and deletion
We keep your company’s data for as long as the company’s account is active, because work records (timesheets, invoices, safety reports) are business records the company relies on. When a company account is closed, its data is deleted or anonymized within a reasonable period, except where we must keep records to meet legal obligations. Individual employees who leave a company are deactivated by their employer; their historical work records remain part of the company’s books.
08Security
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access inside the Service is controlled by role-based permissions and row-level security so each company sees only its own data. No system is perfectly secure - if we learn of a breach affecting your personal information, we will notify affected Customers without undue delay.
09Your rights
Depending on where you live (including under Canada’s PIPEDA and similar provincial laws), you may have the right to access, correct, or delete personal information we hold about you. Because your employer controls most records in the Service, start with them; for anything about the platform itself, contact us at support@operfield.com and we will respond within 30 days.
10Children
The Service is a workplace tool and is not directed to anyone under 16.
11Changes to this policy
If we make material changes, we will update the date at the top of this page and notify Customers through the Service. Continued use after a change means you accept the updated policy.
12Contact
Operfield · support@operfield.com