Version 1.1 · Last updated 2026-09-06

Privacy

FieldScroll is a managed field-workflow platform operated by Thirtysix Solutions, LLC. This page covers what we collect from website visitors, prospective customers, and the people who use FieldScroll for their organization, how we use it, who we share it with, and how long we keep it.

Who this covers

FieldScroll is a business-to-business service. Most people using it day to day are field staff whose organization signed up for the service. That organization is the controller of the records its team collects — it decides which forms run, who has access, and what happens to the data. FieldScroll is the processor that stores and transmits those records on the organization’s behalf under the Data Processing Addendum. This policy covers three audiences:

  • Website visitors — anyone browsing fieldscroll.com.
  • Prospective customers — operators and businesses evaluating FieldScroll, typically through a discovery call or a pilot.
  • People using FieldScroll for their organization — field crews, reviewers, and administrators of an organization that runs on FieldScroll, including white-labeled apps built on it. Their organization’s own notices also apply.

What we collect

Website

We collect standard request data — IP address, user agent, referrer, pages visited — to keep the site online and improve it. Product analytics on this site run only after you accept them in the cookie banner, and they do not build cross-site advertising profiles. The contact form uses a bot check that sees your IP address.

Discovery, pilots, and Early Access

When you book a call, start a pilot, or join Early Access, we collect the information you provide: name, work email, company, and notes about your workflow. We store this in our CRM and use it only to coordinate the conversation and follow up.

Accounts

When someone creates an account we store their email address, a hashed password, the organization they belong to, and the roles assigned to them. Our authentication provider logs sign-in events. Administrative actions — creating organizations, adding or removing members, changing roles, publishing forms — and every request made with an API key are recorded in an audit log with the requester’s IP address and user agent.

Records your team captures

Forms can capture text, numbers, dates, choices, photos, files, signatures, and — only where a form includes a location field and the person taps to capture it — GPS coordinates with accuracy, altitude, heading, and speed. The app never records location in the background. Every submission from the mobile app also carries the device model, operating system and version, and app version; that device information is part of the record and is delivered with it to any integration the organization configures. Record content belongs to the organization. We store and transmit it on the organization’s behalf and do not use it to train models or for any purpose other than running the service.

Device permissions (mobile app)

  • Camera — to take photos for a record and scan barcodes and QR codes. Never used in the background.
  • Photo library — to attach an existing photo to a record.
  • Location — only when a form has a location field and you choose to capture it.

The app does not read your contacts, calendar, call log, SMS, or any other app’s data, and does not send push notifications. Drafts and queued records are stored on the device while offline and rely on your device’s own storage encryption and passcode.

Product analytics and diagnostics

In production, the web dashboard and mobile app send anonymous usage events — screen views, feature usage, error events — with user, organization, form, and record identifiers but never record contents, photos, or form values. Session recording is off on every surface. Errors and crashes are logged with the detail needed to reproduce the problem (route, device type, stack trace); an error message can incidentally include a fragment of the request that caused it.

AI assistant

The optional AI assistant for building forms, reports, and integrations sends what you type, the relevant form or report definition, and any image you attach to Anthropic to generate proposals. Anthropic does not train on that content and deletes it within 30 days. The assistant is off unless your organization’s agreement enables it. Do not paste record data or personal information into it.

How we use information

  • To operate, secure, and improve FieldScroll.
  • To respond to inquiries, schedule calls, and coordinate onboarding and pilots.
  • To monitor platform health — error rates, uptime, sync behavior — so we can fix issues before they affect customers.
  • To meet legal, security, and contractual obligations.

We do not sell personal information. We do not use customer data to train models or for advertising.

Who we share it with

We share information only with the vendors that help us run the platform — cloud hosting, authentication and storage, document rendering, email, error monitoring, logging, analytics, and maps — under contract, and only what each vendor needs to do its job. The current list, with what each one receives, is published at Subprocessors. We will disclose information if required by law or to protect the safety of users, narrowing the disclosure to what is necessary and notifying the affected organization where we can.

Google Drive

If your organization connects a Google Drive destination for reports, FieldScroll uses the Google Drive API to list the folders you choose and to upload the reports you configure into them. It reads folder names and ids to show you the picker and to build the folder path you set; it does not read the contents of other files in your Drive. FieldScroll's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect a Google Drive destination at any time from the report's page, which revokes the platform's access and deletes the stored tokens.

Where data lives

FieldScroll runs on cloud infrastructure in the United States: database, authentication, and file storage in the US East region; document rendering in Virginia; web hosting in the United States. The shared FieldScroll environment isolates each organization by database row-level security; Launch and Partner plans run on a dedicated environment. We can discuss regional residency requirements as part of a Partner conversation.

Retention

Inquiry and discovery records are retained while the relationship is active and for a reasonable period after, typically up to two years. Records, media, forms, and reports are retained for the term written into the organization’s order form and are not deleted automatically; at the end of the term the organization elects export, extension, or deletion, and deletion is carried out under the Data Processing Addendum (30 days after the export window, including our media backup copies; database backups expire on a seven-day cycle). Audit logs are retained for 365 days, upload diagnostics for 90 days, integration delivery history for 90 days after delivery or failure, and operational metrics for 30 to 90 days.

Your choices

  • You can request access to, correction of, or deletion of personal information we hold about you by emailing privacy@fieldscroll.com. See Account deletion for account requests. Records that belong to your organization are handled through your organization, which is the controller of that data.
  • You can unsubscribe from any non-transactional email at any time using the link in the message.
  • You can change your analytics choice for this website at any time from the cookie preferences link in the footer.

Security

We protect FieldScroll with encryption in transit, provider-managed encryption at rest for the database, storage, and backups, role-based access, row-level isolation between organizations, and automated error and uptime monitoring with alerting. Multi-factor authentication is not currently offered. We do not claim certifications we do not hold; the full list of controls is Attachment 3 to the Data Processing Addendum.

Security incidents

If we confirm unauthorized access to customer data in our possession, we notify the affected organization without unreasonable delay — where feasible within 72 hours of confirming it — with what we know, what was affected, and what we are doing about it. The organization is responsible for notices to its own users and customers unless the law or its agreement says otherwise. Report a security concern to security@fieldscroll.com.

Children

FieldScroll is for business use and is not directed at children. An organization may not give access to a person under 18 without our written approval.

Changes

We will update this page when our practices change. The version and date at the top reflect the most recent revision, and prior versions are available on request. Material changes are sent to each customer’s designated contract contact; we do not ask every user to re-accept.

Contact

Privacy questions: privacy@fieldscroll.com. Account deletion: account-deletion@fieldscroll.com. Thirtysix Solutions, LLC, 43450 Interval St., Chantilly, VA 20152.