Last updated: September 1, 2026
Foreman (“we”, “us”, “our”) is a field service management platform. We can be reached at hello@foremandesk.com.
We collect information you provide directly: your name, email address, phone number, and any data you enter into the platform (customer records, job notes, quotes, invoices, etc.). We also collect usage data automatically through cookies and similar technologies.
We use your data to provide and improve the Foreman service, send you product updates and support messages, and process payments through our payment processor (Stripe). We do not sell your data to third parties.
As a contractor using Foreman, you are the data controller for your customers' information. We act as a data processor on your behalf. You are responsible for ensuring you have appropriate consent from your customers to store their data in Foreman.
We use industry-standard security practices including encryption in transit and at rest. Our infrastructure runs on Supabase (PostgreSQL) with row-level security to ensure data isolation between accounts.
Authorised Foreman staff on our onboarding and support team can open your account from our back end to help you — for example, to work out why a job will not invoice or why your booking page is blank. Only people we have explicitly given staff access can do this, and withdrawing someone's staff access cuts them off immediately, even mid-session. We do not ask your permission before each session and we do not notify you at the time one happens. Instead, what staff can see is deliberately limited, every session is time-limited and reason-bound, and the whole history is available to you on request. This is what that access covers.
What our staff can see:
What our staff cannot see:
What our staff can change. Support staff are read only: the server refuses their changes, not just the screen. Onboarding and admin staff can change only your business name, phone, address, timezone and working hours while helping you, and every change is recorded. No staff role of any kind can move money, issue refunds, change your subscription or Stripe connection, send texts or emails as your business, buy or release phone numbers, or delete your jobs, customers, quotes, invoices or expenses.
Every session is time-limited and requires a stated reason. A staff member must type a reason of at least ten characters before a session can begin, and that reason is stored alongside the record of the session. Sessions end automatically after 30 minutes and cannot be extended — looking further means starting a fresh session with a new reason, recorded separately.
Access is logged. We record the start of every session with the staff member, your account, the reason given and the time, and its end when a staff member closes it (a session left open simply stops working after 30 minutes, without a separate entry); every change made and which fields it touched; every attempt that was refused; every customer lookup that returned a result (the number of matches only, never the text searched for and never a customer's name); and each time a staff member opens your account page in our console. What is recorded is the session rather than the screen: the log shows that a named staff member had access to your account for a period and why, not each individual page they opened during it. Once written, an entry cannot be edited or deleted — our database refuses the change, so this holds for our own staff and systems too, not only for you. Entries are kept after a staff member leaves and after an account is closed. Our staff also keep a written log of their contact with you (for example, “called Tuesday, waiting on documents”), which is protected the same way.
How to get your record. Email hello@foremandesk.com from the address on your account and ask for a record of staff access. We will send you the logged entries for your account, including the staff contact log described above. You do not need to give a reason and there is no charge.
We retain your data as long as your account is active. You may request deletion of your account and all associated data at any time by emailing hello@foremandesk.com.
We use the following third-party services: Stripe (payment processing), Resend (email delivery), Supabase (database and authentication), and Vercel (hosting). Each has their own privacy policy.
If you or your customers provide a mobile phone number, it is used to send the service-related text messages described in our SMS Terms (appointment scheduling, quotes, invoices, payment links, and follow-ups). No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties. Mobile numbers are shared only with our telecommunications provider (Twilio) as necessary to deliver the messages themselves. You can opt out of text messages at any time by replying STOP.
Questions about this policy? Email us at hello@foremandesk.com.