Privacy Policy

Last updated: April 2025

Overview

FieldRep is a CRM tool built for medical device sales representatives. We take data privacy seriously. Your data belongs to you. We do not sell it, share it with advertisers, or use it to train AI models. This policy explains what we collect, how we store it, and your rights.

What Data We Collect

  • Account information: Your email address and authentication credentials, used solely to log you in and identify your data.
  • CRM data: Contacts, accounts, visit notes, tasks, and calendar information that you enter into the app. This is your data.
  • Usage data: Basic app usage logs (page views, errors) to help us diagnose issues. No behavioral profiling or advertising tracking.

How Your Data Is Stored

All data is stored in a secure, encrypted database hosted by Supabase (ISO 27001 certified infrastructure on AWS). Each user's data is isolated using row-level security: no other FieldRep user can access your contacts, accounts, or notes. Data is encrypted at rest and in transit.

AI Features

FieldRep uses AI to generate prep briefs, follow-up suggestions, and daily summaries. When your data is sent to our AI provider (OpenAI), it is transmitted with store: false — meaning OpenAI does not retain or log the content of your requests, and your data is never used to train AI models. We do not use any AI provider that uses customer data for model training.

Who Can See Your Data

Only you can access your data within the app. FieldRep administrators can access the database for technical support purposes (resolving bugs, restoring data) but do not access or review your CRM content in normal operation. We do not share your data with any third parties except as required to provide the service (database hosting, email delivery).

Data Retention and Deletion

Your data is retained as long as your account is active. If you request account deletion, all of your data — contacts, accounts, visits, tasks, notes, and settings — is permanently deleted from our database. Deletion is irreversible. To request deletion, contact us at the email below.

CASL and Canadian Users

FieldRep complies with Canada's Anti-Spam Legislation (CASL). We send transactional emails only (brief summaries you have opted into, account notifications). We do not send marketing emails without your explicit consent.

Cookies

We use session cookies for authentication only. We do not use advertising or tracking cookies.

Your Rights

You have the right to:

  • Access a copy of the data we hold about you
  • Correct inaccurate data
  • Request deletion of your account and all associated data
  • Withdraw consent at any time (this will require deleting your account)

Contact

Questions about this policy or data requests can be sent to: support@fieldrep.app