Privacy Policy
Last updated 31 July 2026
This policy describes what Tarek Elghatit, trading as FieldProof Safety, collects when your company uses the service, why we hold it, who it is shared with, and how long it stays.
It is written to describe what the system actually does rather than to cover every theoretical possibility. Where we do not do something, we say so.
1. Who the data belongs to
Almost everything in FieldProof is entered by a company about its own operations and its own employees. That company controls the data and decides who in it has access. We hold and process that data on their behalf in order to run the service.
If you are a worker whose name or signature appears in FieldProof and you want something corrected or removed, the right place to start is your employer, because they decide what their safety records contain. We will help them action it.
2. What we collect
Account information, so people can sign in and be identified on records:
- Name and work email address
- Company name, and the role assigned to the person within that company
- A password, which is hashed by our authentication provider and never visible to us
- The time zone selected at signup, so dates on records display correctly
3. What your records contain
The substance of the service. Entered by your company, about your company:
- Job Safety Analysis content: job description, customer, location, date and time, steps, hazards, controls, risk levels, and PPE requirements
- Photographs of completed paper JSA forms, where your crews upload them
- Signatures drawn on a screen, with the signer name and the time they signed
- A record of who created, submitted, reviewed, approved, declined, or deleted each JSA, and when
4. What we deliberately do not collect
The application does not record the IP address of the person taking an action. We considered it and decided against it: the signature, the signer name, and the timestamp are the record, and logging where a person was sitting adds retention about people without improving the document.
We should be precise rather than flattering here. Our hosting and database providers keep their own infrastructure logs, and those logs do contain IP addresses for a limited period, in the ordinary way that any website operates. What we mean is that the application itself does not store an IP address against your safety records.
We do not use advertising cookies, we do not run third-party analytics or tracking pixels, and we do not sell data to anyone. The cookies the service sets exist to keep you signed in.
We do not use your content to train machine learning models.
5. Payment information
Subscription payments are processed by Stripe. Card numbers are entered on Stripe systems and are never sent to us or stored by us. What we keep is the identifier Stripe gives us for your subscription, its status, and when the current period ends, which is what tells the service whether your account is active.
6. Who else processes it
We use a small number of providers to run the service. Each of them only receives what they need for their part of it:
- Supabase, for the database, sign-in, and file storage
- Vercel, for hosting the application
- Stripe, for subscription payments
- Resend, for transactional email such as invitations and password resets
7. How access is restricted
Separation between companies is enforced in the database itself, not only in the application. Every query runs under rules that scope it to the requesting company, so a request that tried to read another company records would return nothing even if the application asked for it.
Traffic to the service is encrypted in transit, and our infrastructure providers encrypt stored data at rest.
Within your own company, the people you invite can see your company records. That is intentional: crews reading each other hazard analyses is how awareness spreads, and the boundary that matters is between companies.
We do not make claims about formal certifications we do not hold.
8. How long we keep it
While your subscription is active, your records are kept so they are available when an auditor, operator, or investigation asks for them, which can be years after the work was done.
When a subscription ends, access to the application ends with it. For 30 days afterwards you can write to us and request a full export of your company records, and we will provide it.
After that period we may delete your company data. We do not guarantee retention beyond it, and we would rather say so plainly than imply an archive we do not commit to keeping.
Deactivating a team member does not delete the JSAs they created or signed. Those stay, because they are part of the company compliance history rather than personal data we are free to remove on request.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal information we hold about you, and to object to or restrict certain processing.
To exercise any of them, write to support@fieldproofsafety.com. If the request concerns data your employer put into the service, we will work with them, because it is their record.
10. Children
The service is a business tool and is not directed to anyone under 18. We do not knowingly collect information about children.
11. Changes to this policy
If we change what we collect or how we use it, we will update this page and change the date at the top. Where a change is material we will tell account owners directly rather than relying on you noticing.
12. Contact
Questions, requests, or concerns about privacy: support@fieldproofsafety.com.
Tarek Elghatit d/b/a FieldProof Safety.
