Last updated: 14 April 2026
1. Who we are
FieldPlan is a service operated by Constructor Labs Ltd, a company registered in England and Wales (company number 08389656) with its registered office at Flat 4, 60 The Drive, Hove, BN3 3PD.
In this policy, "FieldPlan", "we", "us", and "our" all refer to Constructor Labs Ltd trading as FieldPlan. "You" means the person using the service, whether as an individual sole trader or on behalf of a business.
For the purposes of the UK GDPR and the Data Protection Act 2018, Constructor Labs Ltd is the data controller for the personal data we collect through FieldPlan.
If you have any questions about this policy or how we handle your data, email us at support@fieldplan.app.
2. Summary
We collect the minimum personal data we need to provide FieldPlan to you and to keep it running reliably. We don't sell your data. We don't run profiling or automated decisions that affect you legally. We use well-known third-party providers (listed in section 6) for hosting, payments, email, error tracking, and AI processing — we only share what they need to do their job.
3. Personal data we collect
3.1 Data you give us directly
- Account data: the email address you use to sign in. If you choose to add a display name or a business name, we store that too.
- Billing information: we do not see or store your full card number. Stripe processes your payment and passes us only what we need for our records — last four digits of the card, expiry month/year, the Stripe customer and subscription identifiers, and the payment status.
- Site content: the text, images, links, files, and brand assets you upload to or generate through FieldPlan. This may include names, phone numbers, addresses, or email addresses that belong to you or to your business contacts.
- Support correspondence: anything you send us by email, including the content of your message, your email address, and any attachments.
3.2 Data we collect automatically
- Usage data: logs of the pages you visit inside FieldPlan, the actions you take, and the chat messages you send to the AI assistant. These are used to operate the service, diagnose bugs, and improve FieldPlan.
- Technical data: your IP address, browser type and version, operating system, device identifiers, and the timestamps of your requests.
- Error diagnostics: when something goes wrong, we capture a stack trace and the surrounding context. We use Sentry for this (see section 6). We strip cookies and auth headers before sending, but if you happen to have pasted a password into a chat message immediately before the error, it may appear in the captured context.
- Cookies (strictly necessary only): see section 12.
3.3 Data from third parties
- If you import content from your social accounts (for example, photos from an Instagram Business account), we temporarily receive that content from the relevant platform via our scraping provider (BrightData) and store it against your site.
- We do not buy personal data from data brokers.
4. Purposes and legal bases
We process your personal data on the following legal bases under Article 6 of the UK GDPR:
| Purpose | Data involved | Legal basis |
|---|---|---|
| Provide FieldPlan to you (account, site editing, publishing, support) | Account data, site content, usage data, support correspondence | Contract — processing is necessary to perform our contract with you. |
| Take payment and keep billing records | Billing information | Contract and legal obligation (tax and accounting law). |
| Keep FieldPlan secure and diagnose problems | Technical data, error diagnostics, logs | Legitimate interests — ensuring the service is reliable and not abused. You can object; see section 9. |
| Understand how FieldPlan is used and improve it | Aggregated, non-identifying server-side logs only | Legitimate interests — we do not use analytics cookies. |
| Comply with legal requests | Whatever data is requested | Legal obligation. |
| Send service announcements (billing, security, policy changes) | Email address | Contract / legitimate interests. |
| Send marketing emails (if you opt in) | Email address | Consent. You can withdraw at any time. |
5. How long we keep your data
| Category | Retention |
|---|---|
| Account data | While your account is active, plus 30 days after closure. |
| Site content (files, uploads, chat history) | While your account is active. You can clear your chat history at any time from Settings → Conversation. If you delete your account, site content is removed within 30 days. |
| Billing records (invoices, receipts) | 6 years after the end of the tax year in which they were issued, as required by HMRC. |
| Support correspondence | Up to 3 years after the last interaction. |
| Server logs and error diagnostics | Up to 90 days. |
| Analytics (aggregated, non-identifying) | Up to 26 months. |
6. Who we share data with
We use the following third-party processors. Each is contractually bound to process your data only on our instructions and to maintain appropriate security.
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare (Workers, R2, Durable Objects, AI Gateway) | Hosting, storage, request routing, AI traffic gateway | UK / EU (with global edge) |
| Supabase | Account authentication and database | EU |
| Stripe | Payment processing, customer billing portal | US (with UK / EU redundancy) |
| Resend | Transactional email (sign-in links, invoices, service notices) | US |
| Google (Gemini via Cloudflare AI Gateway) | AI processing of your chat prompts and generated site content | US |
| Sentry | Error and performance monitoring | US |
| Firecrawl (only when you request a website import) | Scraping the URL you asked us to import | US |
| BrightData (only when you request an Instagram import) | Fetching your social content | US |
We may also share data:
- With professional advisers (lawyers, accountants, auditors) under confidentiality.
- If required by law, court order, or a valid regulatory request.
- If we sell, restructure, or transfer the business — in which case we will inform you first and ensure the new owner is bound by equivalent protections.
We do not sell your personal data.
7. International transfers
Some of the processors listed above are based outside the UK. When we transfer your personal data to a country that the UK has not recognised as providing adequate protection, we rely on one of the following safeguards:
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, signed with the processor.
- The UK government's adequacy decisions for specific jurisdictions (such as the UK extension to the EU–US Data Privacy Framework for certified US companies, where applicable).
You can request a copy of the transfer safeguards we have in place for any specific processor by emailing support@fieldplan.app.
8. Security
We protect your data with measures appropriate to the risks involved. These include:
- Encryption in transit (TLS) for all connections to FieldPlan.
- Encryption at rest for files, database records, and backups stored with our processors.
- Access controls: only authorised personnel can access production data, and only when necessary to operate or support the service.
- Secure authentication via short-lived magic-link emails; we do not store reusable passwords.
- Monitoring, patching, and ongoing security review.
No service can guarantee perfect security. If we ever become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours as required and inform affected users without undue delay.
9. Your rights
Under the UK GDPR, you have the following rights in relation to the personal data we hold about you:
- Access — ask for a copy of your personal data.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — ask us to delete your data, subject to legal and contractual retention obligations.
- Restriction — ask us to stop processing your data in certain circumstances.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Objection — object to processing based on our legitimate interests, or to direct marketing.
- Withdraw consent — where we rely on consent, you can withdraw it at any time.
- Automated decision-making — we do not make automated decisions that produce legal or similarly significant effects on you. The AI that generates site content is a tool you direct, not a decision-making system in the sense of Article 22.
To exercise any of these rights, email support@fieldplan.app. We will respond within one month. We may need to verify your identity before releasing personal data.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk — though we would always prefer a chance to resolve any concerns directly first.
10. Automated decisions and AI
FieldPlan uses AI (currently Google Gemini, accessed through Cloudflare's AI Gateway) to help you build and edit websites. The AI generates text, suggests layouts, and edits files based on prompts you provide. This is a tool you direct, not a process that makes legal or similarly significant decisions about you or anyone else under Article 22 of the UK GDPR.
Your prompts and the content you edit are sent to the AI provider for the sole purpose of generating a response. We have contractual arrangements with our AI gateway and upstream provider that prohibit them from using your prompts to train their models.
11. Children
FieldPlan is not directed at children under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email support@fieldplan.app and we will delete it.
12. Cookies and similar technologies
FieldPlan uses only strictly necessary cookies — the ones needed to keep you signed in, maintain your session while you edit, and complete payment flows. These are exempt from the consent requirement in the Privacy and Electronic Communications Regulations (PECR) because they are essential to deliver a service you have explicitly requested.
We do not set any analytics, advertising, tracking, or marketing cookies. We do not use third-party tracking pixels, session replay, or cross-site fingerprinting.
The cookies we do use fall into these families:
- Authentication cookies (from Supabase) — keep you signed in to your FieldPlan account.
- Payment session cookies (from Stripe) — used during checkout and when you open the billing portal. Set only when you interact with those flows.
You can clear cookies in your browser settings at any time. Doing so will sign you out of FieldPlan and you will need to sign in again.
If we ever decide to introduce analytics or other non-essential cookies, we will update this policy and deploy a proper consent mechanism before any such cookie is set.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will tell you by email and by a prominent notice inside FieldPlan at least 14 days before they take effect. The "last updated" date at the top of this page always reflects the most recent version.
Previous versions are available on request.
14. Contact
For any question about your data or this policy:
Constructor Labs Ltd Flat 4, 60 The Drive Hove, BN3 3PD United Kingdom
Email: support@fieldplan.app