Privacy & cookies
Last updated: 3 August 2026
Field Manager is an Android app for core logging, geological mapping and sampling; this site is its public website and the panel where subscriptions are managed. This page explains, concretely, what data we handle, why, who we share it with and how to ask us to delete it. It is an informative text built from the actual inventory in our code, not a legal opinion.
Who is responsible
The data controller is Field Manager LLC, a limited liability company organized in the State of Texas, United States, which operates this site and the Field Manager Mining service. For anything privacy-related — access, correction, deletion, portability, or just a question — write to [email protected]. A person on the team answers, not a form.
What data we collect
- Account
- Name, email and password. The password is stored and verified by Firebase Authentication (Google): we never see it. Optionally company, role and country, used at sign-up and to prefill forms.
- Billing
- Legal name, tax ID and tax address when you need a formal invoice, plus your invoice and payment history. Card details are processed by Stripe: they never reach our servers and we don't store them.
- Devices and activations
- When you activate the app on a device we store a device identifier, the model, the Android version and the activation country. That's what makes a licence device-bound and what lets us detect improper reuse.
- App reports
- The app can send technical reports and its push notification token (Firebase Cloud Messaging) for service notices.
- Support
- If you write to us by email or WhatsApp we keep the conversation, so we can pick up the thread next time.
- Site usage
- With your consent (or implied consent outside the EEA, see below), analytics tools record page views, clicks and aggregate events. We don't build advertising profiles and we don't sell data to anyone.
- Marketing attribution
- We store in a first-party cookie where you came from: utm_* parameters, gclid, the domain of the site that referred you and the first page you opened. It contains nothing that identifies you.
Legal basis
- Performance of a contract — account, licences, activations, support and billing. Without that data there is no service to provide.
- Legal obligation — tax data on issued invoices, for as long as accounting rules require.
- Legitimate interest — service security (rate limiting, licence reuse detection) and our own marketing attribution, aggregated and without personal identifiers.
- Consent — third-party analytics cookies. You can withdraw it whenever you want, without giving reasons and without losing access to anything.
Consent depending on where you are
If you browse from the European Economic Area, the United Kingdom or Switzerland, analytics starts off and only turns on if you accept it in the banner. Outside those jurisdictions we don't show a screen-blocking banner and analytics starts on, because local rules don't require prior opt-in for first-party analytics. Either way you can change your mind any time with the «Cookies» button in the footer, and your explicit choice always beats the geographic rule: if you rejected, you stay rejected even if you travel.
Cookies and local storage
This is the full inventory, taken from the code. We also include «local storage» (localStorage, sessionStorage and IndexedDB): technically not cookies, but they store data in your browser and should be declared.
| Name | Origin | What it does | Lifetime | Category |
|---|---|---|---|---|
| fmm_session | Field Manager | Panel session token. Without it you can't stay logged in. | 1 hour | Strictly necessary |
| refreshToken | Field Manager | Renews the session without asking for your password again. | 60 days | Strictly necessary |
| fmm_2fa_pending | Field Manager | Intermediate step of two-factor verification. | Minutes | Strictly necessary |
| fmm_consent | Field Manager | Stores your choice about analytics cookies. | 180 days | Strictly necessary |
| NEXT_LOCALE | Field Manager | The language you picked (Spanish or English). | 1 year | Functional |
| fmm_attr | Field Manager | Marketing attribution: utm_*, gclid, referring domain and first page viewed. | 180 days | Marketing |
| theme (localStorage) | Field Manager | Light or dark theme. | Until you clear browser data | Functional |
| fmm_sidebar_collapsed (localStorage) | Field Manager | Whether you left the panel menu collapsed. | Until you clear browser data | Functional |
| verificationEndTime (localStorage) | Field Manager | Countdown for the «Resend verification email» button. | 2 minutes | Functional |
| perm_me, geocoder, user, clientUsers, license (sessionStorage) | Field Manager | Short-lived panel caches, so we don't re-request the same data on every screen. | The tab | Functional |
| fmm_session_recovery_done, fmm_checkout_dismissed, fmm_conv_subscription_paid_* (sessionStorage) | Field Manager | «Already happened in this tab» markers: don't retry session recovery, don't reopen the checkout dialog, don't count the same purchase twice. | The tab | Functional |
| firebaseLocalStorageDb (IndexedDB), firebase:authUser:* | Google — Firebase Authentication | Keeps your Firebase session in the browser. Not cookies. | Until you log out | Strictly necessary |
| _ga, _ga_* | Google Analytics 4 | Distinguishes visitors and sessions for the site's aggregate metrics. | 2 years | Analytics |
| _clck, _clsk, CLID | Microsoft Clarity | Heatmaps and anonymised session replay. | _clsk 1 day; the rest 1 year | Analytics |
| MUID, ANONCHK | Microsoft | Set by Clarity on Microsoft domains, not on ours. | Up to 13 months | Analytics |
| ph_*_posthog (cookie and localStorage) | PostHog | Visitor identifier for product events. No session recording: we keep it off. | 1 year | Analytics |
| __stripe_mid, __stripe_sid | Stripe | Payment fraud prevention. Stripe sets them on its own domain when you go through checkout or the billing portal, not on fieldmanagermining.com. | __stripe_sid 30 minutes; __stripe_mid 1 year | Strictly necessary |
- Strictly necessary ones have no switch: if you reject them, the site doesn't work. The law doesn't require consent for them either.
- fmm_attr is written without asking because it's a first-party cookie with no personal data and no third party involved. If it ever came to identify you, it would move to the category that does require consent.
- We don't currently have the Google Ads tag installed. The site's Consent Mode already reserves the advertising categories (ad_storage, ad_user_data, ad_personalization) so that, if we ever install it, it respects the choice you already made.
- On the invitation and licence redemption pages (/invite and /redeem) analytics is always off, regardless of your consent: those URLs carry a token in the address and we don't want any tool recording it.
Who we share data with
We don't sell or trade data. We work with these providers, each limited to its function:
- Google (Firebase Authentication, Firebase Cloud Messaging, Google Analytics 4)
- Login and passwords, push notifications to the app, and aggregate site metrics.
- Microsoft (Clarity)
- Heatmaps and anonymised session replay, to see which parts of the site and the manual are hardest.
- PostHog
- Event-based product analytics. Session recording disabled.
- Sentry
- Error and performance reporting for the site. It receives no user data and no form contents, and session replay is disabled.
- Stripe
- Payments, subscriptions and billing. It's who processes card details.
- Cloudflare
- Delivery network and site protection: it sees the traffic, including your IP address and the country you connect from.
- Supabase
- Only for customers who enabled cloud sync. The database project belongs to the customer; we store their configuration encrypted.
International transfers
Our server and several of these providers are outside the European Economic Area, mostly in the United States. Google, Microsoft, PostHog, Stripe and Cloudflare support those transfers with the European Commission's standard contractual clauses and, depending on the provider, with their EU-US Data Privacy Framework certification.
How long we keep it
- Account and licence data: while the account is active.
- Tax data and invoices: for as long as accounting rules require, even if you close the account.
- Analytics: per each tool's retention (14 months in Google Analytics 4).
- When you ask for deletion, we take your data out of use and erase it, except for what we are required to keep: issued invoices and their accounting entries, for the legally mandated period. Part of the billing history may therefore continue to exist, even though it is no longer used for anything else.
Your rights
If the GDPR applies to you, you have the right to:
- Access the data we hold about you and request a copy.
- Correct anything wrong or incomplete.
- Request deletion, limited by what we're required to keep (invoices).
- Restrict or object to a specific processing activity.
- Take your data to another service in a machine-readable format.
- Withdraw analytics consent at any time.
- Lodge a complaint with your country's data protection authority.
To exercise them, write to [email protected] saying what you want. We answer within 30 days. We may ask you to confirm your identity before touching anything: that's so we don't hand your data to someone else.
How to withdraw consent
At the bottom of any page, in the footer, there's a «Cookies» button. It opens the same panel as the banner and you can reject analytics there, in one click. The choice applies immediately: the tools stop recording new events. Events already sent can't be withdrawn from the browser; if you want us to request their deletion from the providers, write to us.
You can also delete cookies from your browser settings. If you delete fmm_consent, we'll ask you again.
Contact
[email protected] — for privacy, support or anything else. We're a small team and we do answer.