Baird Ventures Group, LLC, a Texas limited liability company doing business as FieldSet ("FieldSet," "we," "us," or "our"), is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, share, and protect information in connection with your use of the FieldSet platform and website (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service. This Privacy Policy is incorporated into and subject to our Terms of Service.
1. Data Controller
The data controller responsible for your personal information is:
- Baird Ventures Group, LLC (d/b/a FieldSet)
- State of Formation: Texas
- Contact: support@fieldset.live
2. Information We Collect
Account Information
When you register or sign in, we collect: your name, email address, company name, industry type, and account preferences. If you sign in via Google OAuth, we receive your name and email address from Google as permitted by your Google account settings.
Business Data via Integrations
With your explicit authorization, FieldSet accesses data from the third-party services you connect. The types of data accessed depend on which Integrations you authorize:
| Integration | Data Accessed | Purpose |
|---|---|---|
| Jobber | Clients, jobs, invoices, quotes, requests, visit schedules | Dashboard KPIs, pipeline, revenue, scheduling |
| Housecall Pro / ServiceTitan | Jobs, customers, invoices, technicians | Operations dashboard and reporting |
| QuickBooks Online | Invoices, payments, AR aging, expense categories | Financial reporting and accounts receivable |
| Google Analytics | Website sessions, traffic sources, conversions | Marketing analytics dashboard |
| Google Ads | Campaigns, spend, impressions, clicks, conversions | Ad performance reporting |
| Facebook / Meta Ads | Ad campaigns, reach, spend, conversions | Social ad performance reporting |
| Apollo.io | Contacts, accounts, sequences, CRM data | CRM and lead management |
| Twilio | SMS messaging credentials (for outbound review requests) | Automated customer review requests |
Integration data is used solely to provide and display your dashboard and reports. We do not sell, share, or analyze this data for purposes beyond operating the Service.
Financial & Accounting Data โ Special Handling
What financial data we access. When you connect a financial or accounting integration, FieldSet retrieves data including invoices, payments, accounts receivable aging, revenue figures, expense categories, and billing history. This data originates entirely from the third-party service you connect โ we do not create, modify, or originate any financial records.
Read-only access. FieldSet accesses all financial data in read-only mode. We do not create, edit, delete, or submit any financial transactions, invoices, or accounting entries on your behalf in any connected service.
Not stored as permanent records. Financial data is fetched in real time when you load your dashboard and is not retained in our database as a permanent record. We do not maintain a copy of your books, general ledger, or accounting records. OAuth access tokens that enable this access are stored encrypted; raw financial record data is not persisted beyond the active request.
Third-party API terms compliance. Our access to financial data from each provider is governed by their developer API terms in addition to this Privacy Policy:
- QuickBooks Online / Intuit: Access is governed by the Intuit Developer Agreement. Intuit requires that we access only data you authorize, not use your QuickBooks data for training AI or machine learning models, not sell or transfer your data, and allow you to disconnect and request deletion at any time.
- Jobber / Housecall Pro / ServiceTitan: Invoice and billing data from field service platforms is governed by each platform's API terms. Access is limited to the scopes you authorize during the OAuth connection flow.
- Stripe: Billing and payment data processed through Stripe is governed by the Stripe Services Agreement and Stripe Privacy Policy.
Disconnecting removes access. When you disconnect a financial integration from your FieldSet account, we immediately revoke our OAuth access to that service. Any cached display data is cleared. We do not retain access to your financial accounts after disconnection.
Not a substitute for professional records. Data displayed in FieldSet is for operational visibility and should not be used as your official accounting records, tax filings, or financial statements. Maintain your books within your accounting software independently of FieldSet.
How We Secure and Revoke Integration Credentials
Connecting an integration gives FieldSet an authorization credential (an OAuth token) rather than your password. We never see, receive, or store your login password for any connected platform.
- Encrypted at rest. Access tokens and refresh tokens are encrypted before they are written to our database. The encryption key is held in a server environment variable โ it is never stored in our source code or exposed to your browser.
- Never client-side. Tokens are used only by our servers to make API calls on your behalf. They are not sent to your browser and are not written to application logs.
- Refresh-token rotation supported. Where a provider issues single-use refresh tokens, FieldSet handles rotation safely so that a token cannot be reused, and so routine token renewal cannot silently break or leak your connection.
- Least privilege. We request only read scopes needed to display your dashboard. Write permissions are not requested for field-service or accounting platforms.
Disconnection works in both directions, and deletes credentials either way:
- If you disconnect inside FieldSet, we notify the connected platform that the connection has ended, then delete the stored credentials for that integration from our database.
- If you disconnect from the platform's own app marketplace or settings, that platform notifies FieldSet, and we delete the stored credentials for that integration. We verify the authenticity of these notifications cryptographically before acting on them.
In both cases the result is the same: FieldSet retains no ability to access that account. We also store a provider-side account identifier solely so that an incoming disconnection notice can be matched to the correct FieldSet account; it contains no personal or financial information.
Use of Artificial Intelligence
FieldSet uses an AI service to write a short plain-English daily briefing about your business. We want to be precise about what that does and does not involve.
What is sent. Only a small set of already-calculated summary totals โ figures such as revenue this month, revenue last month, number of open quotes, total value of overdue invoices, and average days to payment. This list is a fixed allow-list built into our code.
What is never sent. No customer names, addresses, email addresses, phone numbers, invoice numbers, job descriptions or any other individual record ever leaves our servers for this purpose. The AI service receives numbers, not people. Data retrieved from accounting platforms, including QuickBooks, is not included at all.
The AI does not calculate anything. Every figure in your briefing is computed by FieldSet from your own data. The AI service is used only to put those figures into readable sentences and to judge which of them matters most. Before a briefing is shown to you, we automatically check every number in it against the figures we supplied; if the text contains any number we did not provide, the briefing is discarded rather than shown.
How often it happens. Your briefing is written once per day as part of the morning digest, and the result is stored and reused. Viewing a page in FieldSet does not send anything to the AI service. The only other time it runs is when you personally press "Refresh" on the briefing card. This means the amount of information leaving our servers is bounded and predictable rather than growing with how often you use the product.
Subprocessor and training. The AI provider we use for this feature is Anthropic, PBC (the Claude API), acting as our subprocessor. Your data is not used to train any AI model, whether ours or a third party's, and is not used to build products for anyone other than you. If we change AI providers or expand what is sent, we will update this Policy and tell you before the change takes effect.
Accounting data is excluded. Intuit prohibits the use of QuickBooks data to train artificial-intelligence or machine-learning models. We do not train models on any of your data, and we go further for accounting data specifically: figures obtained from QuickBooks are not sent to the AI service at all, for training or for anything else. The summary totals used in your briefing come from your field-service platform, not your accounting platform.
Turning it off. The daily briefing is a convenience feature. If you would prefer that no data about your business be sent to an AI service at all, contact us and we will disable it for your account; every other part of FieldSet, including all insights calculated directly from your figures, continues to work without it.
Payment Information
Billing is handled entirely by Stripe, Inc. We do not store your credit or debit card number, CVV, or full banking details. What we do store: your Stripe Customer ID, subscription status, plan type, and billing history (plan name, amounts, dates). Stripe's handling of your payment information is governed by the Stripe Privacy Policy.
Usage Data
We automatically collect technical information about how you interact with the Service, including: pages visited, features used, session duration, browser type, operating system, IP address (used for security and fraud detection), and error logs. This data is used to maintain and improve the Service.
Support Communications
If you contact us for support, we collect your name, email, and the content of your communication to respond to your inquiry and improve our service quality.
Information We Do Not Collect
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, operate, maintain, and improve the FieldSet platform and all of its features;
- Authentication: To verify your identity, manage your session, and secure your account;
- Billing: To process payments, manage your subscription, send receipts, and handle billing disputes;
- Communications: To send you account notifications, billing updates, security alerts, and product announcements (you may opt out of marketing emails at any time);
- Support: To respond to your requests, troubleshoot issues, and improve customer service;
- Analytics & Improvement: To understand how customers use the Service, identify issues, and develop new features (using aggregated, anonymized data);
- Security & Fraud Prevention: To detect, investigate, and prevent fraudulent transactions, abuse, and security threats; and
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
We do not use your data to train AI models, and we do not use it for purposes beyond operating and improving the Service. We do use an AI service to write your daily briefing from summary totals โ see Use of Artificial Intelligence above for exactly what is and is not sent.
4. Legal Basis for Processing (Where Applicable)
If you are located in a jurisdiction that requires a legal basis for processing personal data (such as under GDPR principles), we process your information under the following bases:
- Contract Performance: Processing necessary to provide the Service under our Terms of Service (e.g., account management, billing, integration data);
- Legitimate Interests: Processing for security, fraud prevention, service improvement, and analytics โ where our interests do not override your privacy rights;
- Legal Obligation: Processing required to comply with applicable laws; and
- Consent: Where you have explicitly consented, such as connecting a third-party Integration or subscribing to marketing communications.
5. Data Sharing & Disclosure
Service Providers. We share data with trusted vendors who process data on our behalf and are contractually bound to keep it confidential:
- Supabase โ cloud database and authentication (your account data, integration tokens, and session data are stored here);
- Vercel โ hosting and serverless infrastructure for the FieldSet platform;
- Stripe โ payment processing and subscription management; and
- Other operational service providers as needed (e.g., email delivery for transactional notifications).
Third-Party Integrations. When you authorize a third-party Integration, we exchange only the data necessary to display your dashboard. We act as a conduit โ we do not transfer your data to third parties on your behalf beyond what is required to display your authorized data.
Legal Requirements. We may disclose your information if required by law, regulation, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers. If FieldSet is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email or in-app notice of any such change and any choices you may have.
Aggregated / Anonymized Data. We may share aggregated, de-identified data that does not identify you (e.g., industry benchmark statistics) for research, marketing, or business purposes.
6. Third-Party Services & Their Policies
FieldSet integrates with third-party services, each with its own privacy practices. We encourage you to review their privacy policies:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Stripe | Payment processing | stripe.com/privacy |
| Supabase | Database & auth | supabase.com/privacy |
| Vercel | Hosting | vercel.com/legal/privacy-policy |
| Analytics & Ads data | policies.google.com/privacy | |
| Meta / Facebook | Ads data | facebook.com/privacy/policy |
| Apollo.io | CRM data | apollo.io/privacy-policy |
| Jobber | Field service data | getjobber.com/privacy-policy |
| Twilio | SMS messaging | twilio.com/legal/privacy |
7. Cookies & Authentication Tokens
Session Cookie. FieldSet uses a single HttpOnly, Secure session cookie named fieldset_uid to maintain your authenticated session. This cookie:
- Cannot be accessed by JavaScript (HttpOnly flag prevents cross-site scripting attacks);
- Is transmitted only over HTTPS (Secure flag);
- Expires when you sign out or after a period of inactivity; and
- Contains only your unique user identifier โ not personal information.
Authentication Tokens. Integration OAuth tokens (e.g., your Jobber access token) are encrypted and stored in our database. They are used solely to make authorized API calls on your behalf when you view your dashboard.
No Ad or Tracking Cookies. We do not use advertising cookies, cross-site tracking pixels, third-party analytics cookies, or any technology that tracks your behavior across other websites.
Local Storage. We use browser localStorage to store your UI preferences (such as your selected light/dark mode theme). This data stays in your browser and is not transmitted to our servers.
8. Data Security
We implement technical and organizational measures designed to protect your information from unauthorized access, disclosure, alteration, or destruction:
- HTTPS / TLS Encryption: All data transmitted between your browser and our servers is encrypted using TLS;
- Row-Level Security (RLS): Our database enforces at the database level that each user can only access their own data โ not that of other customers;
- Encrypted OAuth Tokens: Integration access tokens are encrypted at rest in our database;
- Scoped API Keys: Server-side API keys are stored as environment variables and never exposed to client-side code;
- HttpOnly Cookies: Session authentication uses HttpOnly cookies to prevent JavaScript-based session theft;
- CORS Restrictions: API endpoints enforce origin restrictions to prevent unauthorized cross-site requests; and
- PCI Compliance via Stripe: Payment card data is handled by Stripe, which maintains PCI DSS compliance. We are not in scope for PCI DSS as we do not store, process, or transmit raw card data.
9. Data Retention
We retain your data for as long as your account remains active and as necessary to provide the Service and comply with legal obligations:
- Active Account: We retain all account and integration data for the duration of your subscription;
- After Cancellation: We retain your data for 90 days following account closure or subscription cancellation to allow you to reactivate or export. After this period, your data is permanently deleted from production systems;
- Integration Tokens: OAuth access tokens are deleted from our database immediately upon disconnection of the Integration;
- Billing Records: We retain billing transaction records for the period required by applicable law (typically 7 years) for tax and accounting purposes; and
- Support Communications: Retained for up to 2 years to ensure quality and continuity of support.
10. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, email support@fieldset.live. We will respond within 30 days of receipt of a verified request.
- Right to Access: Request a copy of the personal data we hold about you;
- Right to Correction: Request correction of inaccurate or incomplete information;
- Right to Deletion: Request deletion of your personal data (subject to legal retention requirements);
- Right to Portability: Request your data in a structured, machine-readable format;
- Right to Restrict Processing: Request that we limit how we process your data in certain circumstances;
- Right to Object: Object to processing based on legitimate interests or for direct marketing; and
- Right to Opt Out of Marketing: Unsubscribe from promotional emails at any time using the unsubscribe link in the email or by contacting us.
We will not discriminate against you for exercising any of these rights. We may need to verify your identity before fulfilling certain requests.
11. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information.
Categories of Personal Information Collected. In the past 12 months, we have collected the following categories of personal information: identifiers (name, email, IP address), commercial information (subscription details, payment history), internet activity (usage logs, features accessed), and professional/employment information (company name, industry).
Selling or Sharing Personal Information. We do not sell your personal information for monetary consideration. We do not share your personal information with third parties for cross-context behavioral advertising. You have the right to opt out of the sale or sharing of personal information; however, we have no such activity to opt out of.
Your CCPA Rights. As a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and sell;
- Delete personal information we have collected from you (subject to exceptions);
- Correct inaccurate personal information;
- Opt out of the sale or sharing of personal information (not applicable here, as we do not sell data);
- Limit the use and disclosure of sensitive personal information; and
- Non-discrimination for exercising your privacy rights.
To submit a CCPA rights request, email support@fieldset.live with "CCPA Request" in the subject line. We will respond within 45 days. We may extend this period once by an additional 45 days with notice.
Authorized Agent. You may designate an authorized agent to make a CCPA request on your behalf. We may require verification of the agent's authority and your identity.
12. Children's Privacy
The Service is intended for business use by adults and is not directed to individuals under the age of 18 ("children"). We do not knowingly collect, solicit, or use personal information from children. If we discover that we have inadvertently collected personal information from a child without verified parental consent, we will delete that information promptly. If you believe we may have collected information from a child, please contact us immediately at support@fieldset.live.
13. International Data Transfers
FieldSet is operated from the United States and our data is stored and processed in the United States. If you are accessing the Service from outside the United States, your information will be transferred to and processed in the U.S. By using the Service, you consent to the transfer of your information to the U.S., which may have different data protection laws than your country of residence.
We rely on our service providers' standard contractual mechanisms for international data transfers where required.
14. Security Incidents & Breach Notification
In the event of a security incident involving your personal data, we will:
- Investigate and contain the incident promptly;
- Notify affected users within 72 hours of becoming aware of a breach (or within the timeframe required by applicable law) if the breach is likely to result in a risk to your rights and freedoms;
- Provide information about the nature of the breach, the types of data affected, and steps we are taking; and
- Notify relevant regulatory authorities as required by applicable law.
To report a suspected security vulnerability, email support@fieldset.live with "Security Report" in the subject line.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. For material changes, we will provide at least 14 days' advance notice via email to your registered email address or through a prominent in-app notice before the change takes effect. The "Last updated" date at the top of this page indicates the most recent revision.
Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. If you do not agree, you should stop using the Service and may request deletion of your account.
16. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: support@fieldset.live
- Subject Line: "Privacy Request" or "Privacy Question"
- Company: Baird Ventures Group, LLC (d/b/a FieldSet)
- State: Texas
We are committed to working with you to resolve any privacy concerns. If you feel your request has not been adequately addressed, you may have the right to lodge a complaint with the applicable data protection authority in your jurisdiction.
This Privacy Policy was last updated on July 18, 2026. It should be reviewed in conjunction with our Terms of Service. This document is for informational purposes; consult a qualified attorney for specific legal advice.