Strictly necessary
Required for authentication, security, sessions, forms, and storing your privacy choices.
This Privacy Policy explains how InnOneWeb OÜ, an Estonian private limited company (OÜ), registry code 16826593, with its registered office at Sakala 7-2, 10141 Tallinn, Estonia, doing business as FieldCosts (“FieldCosts,” “we,” “us,” or “our”), collects, uses, discloses, and otherwise processes personal data in connection with the FieldCosts websites, web application, mobile applications, APIs, support, and related services (collectively, the “Service”).
This Privacy Policy applies when we process personal data as a controller or business for our own purposes, including data relating to:
When a business customer submits information about its clients, employees, contractors, suppliers, jobs, receipts, invoices, or other persons to the Service (“Customer Content”), FieldCosts generally processes that information on behalf of the business customer. In that context, the customer is generally the controller or business, and FieldCosts is generally the processor or service provider. Requests relating to Customer Content should normally be directed to the customer that controls the relevant workspace.
This Policy does not apply to third-party websites, applications, or services that link to or integrate with the Service.
Controller:
InnOneWeb OÜ Registry code: 16826593 Registered address: Sakala 7-2, 10141 Tallinn, Estonia Privacy email: support@fieldcosts.com Support email: support@fieldcosts.com
Data Protection Officer: We have not appointed a Data Protection Officer because we are not currently required to do so.
The personal data we collect depends on how a person interacts with the Service.
We may collect:
We may collect:
At a customer’s direction, the Service may process:
Customers determine what Customer Content they submit. Customers are responsible for having a lawful basis and providing required notices to the people whose data they submit.
If a customer purchases a paid subscription, we and our payment providers may process:
FieldCosts does not ordinarily receive or store full payment-card numbers. Payment-card data is handled by Stripe under its own privacy and security terms.
We may automatically collect:
Depending on the features a user enables and device permissions granted, the mobile application may process:
The app requests camera or file permission when the relevant feature is used. Permissions can be managed in device settings. Authentication tokens are stored on the device for sign-in continuity and are revoked on logout, account closure, expiry, or security action.
We may collect:
We will not record calls without providing legally required notice or obtaining consent where required.
We may receive data from:
We may use personal data to:
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases:
We process account, subscription, support, and service data where necessary to provide the Service or take steps requested before entering into a contract.
We may process data where necessary for legitimate interests, including:
We consider the nature of the data, the reasonable expectations of the individuals, and the impact on their rights.
We process data where necessary to comply with tax, accounting, court, regulatory, law-enforcement, sanctions, and other legal obligations.
We rely on consent where required, including for certain cookies, marketing, device permissions, or optional processing. Consent may be withdrawn at any time, without affecting prior lawful processing.
In rare situations, we may process data to protect the vital interests of a person.
6.1. Business customers decide what Customer Content is submitted, why it is processed, and which users can access it.
6.2. When FieldCosts processes Customer Content on a customer’s behalf, we process it according to:
6.3. We may process Customer Content for our own purposes only where legally permitted, such as to secure the Service, prevent abuse, comply with law, manage billing, or create aggregated or de-identified information that does not reasonably identify a person or customer.
6.4. A person seeking access, correction, deletion, or another right concerning Customer Content should contact the relevant business customer. We will assist the customer as required by applicable law and the Data Processing Addendum.
7.1. The Service may use OCR, rules, machine learning, or other automated methods to extract or categorize information from receipts, invoices, files, and other content.
7.2. Automated output may be inaccurate and must be reviewed by an authorized user.
7.3. Unless expressly disclosed in the Service or an Order, FieldCosts does not use Customer Content to train a general-purpose artificial-intelligence model for the benefit of unrelated third parties.
7.4. The Service is not intended to make solely automated decisions that produce legal or similarly significant effects about individuals. Customers must not use automated output as the sole basis for employment, credit, insurance, eligibility, or similarly significant decisions.
We may use cookies, local storage, software-development kits, pixels, and similar technologies for:
Non-essential analytics is blocked until an affirmative analytics choice where consent is legally required.
Optional analytics is limited to public marketing pages and is loaded only after an affirmative analytics choice. FieldCosts does not run this analytics tracker inside authenticated customer workspaces or platform administration, and the first-party tracker does not capture page text, form values, full link destinations, cursor movement, or session replay.
Specific technologies, providers, purposes, and durations are listed in our Cookie Policy.
A user can control cookies through our consent tool and browser settings. Blocking essential cookies may prevent the Service from functioning.
We may disclose personal data to the following categories of recipients.
We may use providers for:
The current provider list is published on our Subprocessors page.
Workspace administrators and users with appropriate permissions may access data within the customer’s account.
When a customer enables an integration, we may disclose data to and receive data from that third party as directed by the customer.
We may disclose data to lawyers, accountants, auditors, insurers, banks, and professional advisers where reasonably necessary and subject to confidentiality obligations.
We may disclose data where we reasonably believe disclosure is necessary to:
Where legally permitted, we may notify the affected customer before disclosure.
Data may be disclosed in connection with financing, due diligence, merger, acquisition, reorganization, insolvency, or sale of all or part of our business or assets. The recipient may continue to process data subject to this Policy or a replacement policy provided as required by law.
We may disclose data where the individual or customer consents or directs us to do so.
FieldCosts does not sell personal information for money.
FieldCosts does not sell personal information or share it for cross-context behavioral advertising. We do not use authenticated workspace content for advertising.
We do not knowingly sell or share personal information of persons under 16.
FieldCosts is established in Estonia, and service providers or customers may be located in other countries.
Personal data may be transferred to and processed in countries whose laws may differ from those of the person’s country.
Where required, we use an approved transfer mechanism, such as:
Information about applicable safeguards may be requested through support@fieldcosts.com.
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining security, complying with law, resolving disputes, and enforcing agreements.
Our operational retention schedule is:
A documented workspace legal hold pauses scheduled record cleanup and final workspace deletion. Retained data remains access-restricted and is not used for unrelated purposes. The scope and continuing need for the hold must be reviewed, and normal retention resumes when the hold is released.
We may retain aggregated or de-identified information that no longer reasonably identifies a person.
We use technical and organizational measures designed to protect personal data, which may include:
No method of transmission, storage, or processing is completely secure, and we cannot guarantee absolute security.
Customers are responsible for secure credentials, devices, user permissions, endpoint security, and lawful configuration of their workspace.
We maintain procedures to assess and respond to personal-data incidents.
Where FieldCosts acts as processor, we will notify the affected customer without undue delay after becoming aware of a personal-data breach affecting Customer Content, as required by the applicable Data Processing Addendum and law.
Where FieldCosts acts as controller, we will notify the competent authority and affected individuals where required by law.
Depending on location and applicable law, a person may have rights to:
Rights may be subject to legal exceptions and verification.
To exercise a right concerning data that FieldCosts controls, contact support@fieldcosts.com.
To exercise a right concerning Customer Content, contact the business customer that controls the relevant workspace.
We may request information reasonably necessary to verify identity and authority. An authorized agent may submit a request where permitted by law, subject to verification.
We will not discriminate against a person for exercising applicable privacy rights.
Individuals in the EEA, UK, or Switzerland may have the rights described above and may lodge a complaint with their local data-protection authority.
Because the controller is established in Estonia, the lead supervisory authority may be:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) Tatari 39, 10134 Tallinn, Estonia Website: https://www.aki.ee/
Individuals are encouraged to contact us first so that we can attempt to resolve the concern.
Residents of certain U.S. states may have rights under state privacy laws, subject to legal thresholds and exceptions.
Where applicable, this section serves as a supplemental notice.
In the preceding 12 months, we may have collected the following categories:
We use these categories for the business and commercial purposes described in Section 4.
We disclose categories of personal information to the recipients described in Section 9.
Where applicable, residents may request access, correction, deletion, portability, or information about collection and disclosure, and may opt out of sale, sharing, targeted advertising, or certain profiling.
Submit requests to support@fieldcosts.com or the support page at fieldcosts.com/support.
If we deny an appealable request, instructions for appeal will be included in the response.
If FieldCosts becomes subject to the California Consumer Privacy Act, the Policy must be reviewed at least annually and updated to include all required disclosures, request methods, and applicable metrics or notices.
We may send marketing emails to business contacts where permitted by law.
A recipient may unsubscribe using the link in the message or by contacting us. We may still send non-marketing communications relating to accounts, security, billing, support, legal notices, and the Service.
Customers are responsible for ensuring that communications they send through or using data from the Service comply with applicable marketing, privacy, and telecommunications laws.
The Service is intended for businesses and is not directed to children.
No person under 18 may create an account.
We do not knowingly collect personal data directly from children. If we learn that a child has submitted personal data without appropriate authorization, we will take reasonable steps to delete it.
Customers must not submit children’s personal data unless necessary for a lawful business purpose and permitted under applicable law and these Terms.
The Service may contain links to or integrations with third-party services. Their privacy practices are governed by their own policies.
We are not responsible for a third party’s collection, use, security, or disclosure of personal data.
We may update this Policy to reflect changes in law, technology, providers, or the Service.
We will post the updated version and revise the “Last updated” date. If a change materially affects personal data or legal rights, we will provide additional notice where required.
Questions, requests, or complaints may be sent to:
InnOneWeb OÜ Sakala 7-2, 10141 Tallinn, Estonia Privacy email: support@fieldcosts.com Support email: support@fieldcosts.com