Privacy & cookies

Last updated: 3 August 2026

Field Manager is an Android app for core logging, geological mapping and sampling; this site is its public website and the panel where subscriptions are managed. This page explains, concretely, what data we handle, why, who we share it with and how to ask us to delete it. It is an informative text built from the actual inventory in our code, not a legal opinion.

Who is responsible

The data controller is Field Manager LLC, a limited liability company organized in the State of Texas, United States, which operates this site and the Field Manager Mining service. For anything privacy-related — access, correction, deletion, portability, or just a question — write to [email protected]. A person on the team answers, not a form.

What data we collect

Account
Name, email and password. The password is stored and verified by Firebase Authentication (Google): we never see it. Optionally company, role and country, used at sign-up and to prefill forms.
Billing
Legal name, tax ID and tax address when you need a formal invoice, plus your invoice and payment history. Card details are processed by Stripe: they never reach our servers and we don't store them.
Devices and activations
When you activate the app on a device we store a device identifier, the model, the Android version and the activation country. That's what makes a licence device-bound and what lets us detect improper reuse.
App reports
The app can send technical reports and its push notification token (Firebase Cloud Messaging) for service notices.
Support
If you write to us by email or WhatsApp we keep the conversation, so we can pick up the thread next time.
Site usage
With your consent (or implied consent outside the EEA, see below), analytics tools record page views, clicks and aggregate events. We don't build advertising profiles and we don't sell data to anyone.
Marketing attribution
We store in a first-party cookie where you came from: utm_* parameters, gclid, the domain of the site that referred you and the first page you opened. It contains nothing that identifies you.

Legal basis

  • Performance of a contract — account, licences, activations, support and billing. Without that data there is no service to provide.
  • Legal obligation — tax data on issued invoices, for as long as accounting rules require.
  • Legitimate interest — service security (rate limiting, licence reuse detection) and our own marketing attribution, aggregated and without personal identifiers.
  • Consent — third-party analytics cookies. You can withdraw it whenever you want, without giving reasons and without losing access to anything.

Consent depending on where you are

If you browse from the European Economic Area, the United Kingdom or Switzerland, analytics starts off and only turns on if you accept it in the banner. Outside those jurisdictions we don't show a screen-blocking banner and analytics starts on, because local rules don't require prior opt-in for first-party analytics. Either way you can change your mind any time with the «Cookies» button in the footer, and your explicit choice always beats the geographic rule: if you rejected, you stay rejected even if you travel.

Cookies and local storage

This is the full inventory, taken from the code. We also include «local storage» (localStorage, sessionStorage and IndexedDB): technically not cookies, but they store data in your browser and should be declared.

Cookies and local storage
NameOriginWhat it doesLifetimeCategory
fmm_sessionField ManagerPanel session token. Without it you can't stay logged in.1 hourStrictly necessary
refreshTokenField ManagerRenews the session without asking for your password again.60 daysStrictly necessary
fmm_2fa_pendingField ManagerIntermediate step of two-factor verification.MinutesStrictly necessary
fmm_consentField ManagerStores your choice about analytics cookies.180 daysStrictly necessary
NEXT_LOCALEField ManagerThe language you picked (Spanish or English).1 yearFunctional
fmm_attrField ManagerMarketing attribution: utm_*, gclid, referring domain and first page viewed.180 daysMarketing
theme (localStorage)Field ManagerLight or dark theme.Until you clear browser dataFunctional
fmm_sidebar_collapsed (localStorage)Field ManagerWhether you left the panel menu collapsed.Until you clear browser dataFunctional
verificationEndTime (localStorage)Field ManagerCountdown for the «Resend verification email» button.2 minutesFunctional
perm_me, geocoder, user, clientUsers, license (sessionStorage)Field ManagerShort-lived panel caches, so we don't re-request the same data on every screen.The tabFunctional
fmm_session_recovery_done, fmm_checkout_dismissed, fmm_conv_subscription_paid_* (sessionStorage)Field Manager«Already happened in this tab» markers: don't retry session recovery, don't reopen the checkout dialog, don't count the same purchase twice.The tabFunctional
firebaseLocalStorageDb (IndexedDB), firebase:authUser:*Google — Firebase AuthenticationKeeps your Firebase session in the browser. Not cookies.Until you log outStrictly necessary
_ga, _ga_*Google Analytics 4Distinguishes visitors and sessions for the site's aggregate metrics.2 yearsAnalytics
_clck, _clsk, CLIDMicrosoft ClarityHeatmaps and anonymised session replay._clsk 1 day; the rest 1 yearAnalytics
MUID, ANONCHKMicrosoftSet by Clarity on Microsoft domains, not on ours.Up to 13 monthsAnalytics
ph_*_posthog (cookie and localStorage)PostHogVisitor identifier for product events. No session recording: we keep it off.1 yearAnalytics
__stripe_mid, __stripe_sidStripePayment fraud prevention. Stripe sets them on its own domain when you go through checkout or the billing portal, not on fieldmanagermining.com.__stripe_sid 30 minutes; __stripe_mid 1 yearStrictly necessary
  • Strictly necessary ones have no switch: if you reject them, the site doesn't work. The law doesn't require consent for them either.
  • fmm_attr is written without asking because it's a first-party cookie with no personal data and no third party involved. If it ever came to identify you, it would move to the category that does require consent.
  • We don't currently have the Google Ads tag installed. The site's Consent Mode already reserves the advertising categories (ad_storage, ad_user_data, ad_personalization) so that, if we ever install it, it respects the choice you already made.
  • On the invitation and licence redemption pages (/invite and /redeem) analytics is always off, regardless of your consent: those URLs carry a token in the address and we don't want any tool recording it.

Who we share data with

We don't sell or trade data. We work with these providers, each limited to its function:

Google (Firebase Authentication, Firebase Cloud Messaging, Google Analytics 4)
Login and passwords, push notifications to the app, and aggregate site metrics.
Microsoft (Clarity)
Heatmaps and anonymised session replay, to see which parts of the site and the manual are hardest.
PostHog
Event-based product analytics. Session recording disabled.
Sentry
Error and performance reporting for the site. It receives no user data and no form contents, and session replay is disabled.
Stripe
Payments, subscriptions and billing. It's who processes card details.
Cloudflare
Delivery network and site protection: it sees the traffic, including your IP address and the country you connect from.
Supabase
Only for customers who enabled cloud sync. The database project belongs to the customer; we store their configuration encrypted.

International transfers

Our server and several of these providers are outside the European Economic Area, mostly in the United States. Google, Microsoft, PostHog, Stripe and Cloudflare support those transfers with the European Commission's standard contractual clauses and, depending on the provider, with their EU-US Data Privacy Framework certification.

How long we keep it

  • Account and licence data: while the account is active.
  • Tax data and invoices: for as long as accounting rules require, even if you close the account.
  • Analytics: per each tool's retention (14 months in Google Analytics 4).
  • When you ask for deletion, we take your data out of use and erase it, except for what we are required to keep: issued invoices and their accounting entries, for the legally mandated period. Part of the billing history may therefore continue to exist, even though it is no longer used for anything else.

Your rights

If the GDPR applies to you, you have the right to:

  • Access the data we hold about you and request a copy.
  • Correct anything wrong or incomplete.
  • Request deletion, limited by what we're required to keep (invoices).
  • Restrict or object to a specific processing activity.
  • Take your data to another service in a machine-readable format.
  • Withdraw analytics consent at any time.
  • Lodge a complaint with your country's data protection authority.

To exercise them, write to [email protected] saying what you want. We answer within 30 days. We may ask you to confirm your identity before touching anything: that's so we don't hand your data to someone else.

How to withdraw consent

At the bottom of any page, in the footer, there's a «Cookies» button. It opens the same panel as the banner and you can reject analytics there, in one click. The choice applies immediately: the tools stop recording new events. Events already sent can't be withdrawn from the browser; if you want us to request their deletion from the providers, write to us.

You can also delete cookies from your browser settings. If you delete fmm_consent, we'll ask you again.

Contact

[email protected] — for privacy, support or anything else. We're a small team and we do answer.