Field Connect← Back to site
Legal

Privacy Policy

Effective 31 July 2026
Applies to fieldconnect.one and the Field Connect application
Operator Sparke Data Solutions, Dubai, United Arab Emirates
Contact admin@fieldconnect.one

Field Connect is a business tool for construction logistics. It tracks containers, stillages and deliveries for a project, and prices each movement against the project's rate card. The personal information involved is almost entirely work information about the people running a package: a name, a work email address, a mobile number for sign-in, and a record of who entered what. This policy sets out what we hold, why we hold it, who else touches it, and what you can ask us to do about it.

Contents
  1. 01 · Who we are
  2. 02 · What this policy covers
  3. 03 · Our role: controller and processor
  4. 04 · Information we collect
  5. 05 · How we collect it
  6. 06 · How and why we use it
  7. 07 · Cookies and local storage
  8. 08 · Who we share information with
  9. 09 · Automated processing and AI features
  10. 10 · Where your data is held
  11. 11 · How we protect information
  12. 12 · How long we keep it
  13. 13 · Your rights and choices
  14. 14 · Invited and guest users
  15. 15 · Children
  16. 16 · Changes to this policy
  17. 17 · Contact and complaints

01Who we are

Field Connect is operated by Sparke Data Solutions ("Field Connect", "we", "us"), based in Dubai, United Arab Emirates. We provide the platform to logistics providers, builders, facade contractors and their nominated partners under a written agreement with a customer organisation.

For any question about this policy, or to make a request about your personal information, write to admin@fieldconnect.one.

02What this policy covers

This policy covers the public Field Connect website and the Field Connect application, including project workspaces, the master sheet, container and quality records, deliveries and proofs of delivery, variation and costing reports, the project contact directory, and the customs lookup.

Field Connect has no public sign-up. Accounts exist because a customer organisation asked us to create them, or because a project administrator invited a named person to view a project. There is no consumer-facing service and we do not run advertising.

03Our role: controller and processor

Two different sets of information move through the platform, and our responsibility is different for each.

  • Account and platform information. User accounts, sign-in records, invitations, support correspondence and technical logs. We decide how this is handled, so we act as the controller.
  • Project data. Everything a customer puts into a project workspace: packing lists, container and stillage records, photographs, proofs of delivery, rate cards, variation entries and the contact directory. The customer decides what goes in and who may see it. We hold and process it on their instructions, so for that data we act as a processor and the customer is the controller.

If you are an employee or contractor of a customer organisation and your question is about project data, your own organisation is the right first point of contact. Ask us and we will help, but we may need their instruction before we change or remove records inside their project.

04Information we collect

We collect what the platform needs to work and nothing gathered for its own sake. The categories below reflect what the system actually stores.

CategoryWhat it includes
Account detailsFull name, work email address (used as the username), the organisation you belong to, your role within it (administrator, writer or reader), and whether the account is active.
Sign-in credentialsA one-way hashed password, and for staff accounts a mobile telephone number in international format so we can send a one-time verification code. We never store a password in a readable form and we cannot recover one for you.
Session dataA signed session token held in a cookie, and the timestamps around your sign-in and verification.
InvitationsThe email address, name and organisation name an administrator entered for you, hashed invitation and verification codes, the number of attempts made, and when the invitation was sent, expired or accepted.
Project contact directoryNames, companies, roles, email addresses, telephone numbers and free-text notes that a customer records for the stakeholders on a project. These people may not be Field Connect users at all.
Operational project recordsShipment, container and stillage records; item IDs, levels, building numbers, weights and dimensions; movements in, out and returned, each with a date and a reason; unpack, storage and delivery dates; quality records including damage descriptions, yard locations and the reason each record was changed.
Uploaded documentsPacking lists (spreadsheets, CSV or PDF) and proofs of delivery (PDF). These come from your supply chain and may contain names, signatures, contact details or consignee information placed there by third parties.
PhotographsContainer arrival and quality photographs with optional captions. They are taken to evidence the condition of goods, but a photograph taken in a yard can incidentally include a person, a vehicle or a registration plate.
Commercial recordsProject rate cards, cost and sell amounts on each variation line, billing months, truck arrival and departure times, and export files generated from them. This is commercially sensitive business information rather than personal information, and we treat it as confidential.
Customs lookupsWhere a customer uses the customs feature, the container number searched and the declaration data returned, which can include consignee names and addresses.
Technical and log dataIP address, browser and device information, request paths, timestamps and error traces produced by our servers and infrastructure in the ordinary course of running the service.
EnquiriesIf you email us from the website about a scoping call, whatever you choose to send us: your name, email address, company and what you tell us about your package.

We do not ask for and do not want special category information (health, biometric data, racial or ethnic origin, religious belief, political opinion, trade union membership or sexual orientation). We do not collect payment card details; there is no payment processing in the platform.

A note for customers uploading documents

Packing lists, proofs of delivery and yard photographs frequently carry personal information that the platform does not need: driver names, signatures, mobile numbers, people captured in the background of a photograph. Before uploading, please redact what is not required. Under our agreement you are responsible for having a lawful basis for the personal information you place in a project, and for telling the people concerned that you use a system like this.

05How we collect it

  • From your organisation. Staff accounts are created for named people at a customer organisation's request during onboarding.
  • From a project administrator. Guest access begins with an administrator entering your name, email and company to send you an invitation.
  • From you directly. What you type into the application, the documents and photographs you upload, and anything you send us by email.
  • Automatically. Session cookies, server logs and infrastructure telemetry generated as you use the service.
  • From third-party sources. Customs declaration data returned by the CargoWise service when a customer performs a lookup.

06How and why we use it

We use personal information to:

  • authenticate you, including sending one-time codes by SMS or email, and keep your session alive;
  • control what you can see, so that a guest sees the logistics view of a project they were invited to and nothing else;
  • run the features you are using: importing packing lists, recording movements, generating delivery and backload references, applying the rate card and producing variation and costing reports;
  • maintain an audit trail, including versioned quality records that keep the history of every change and the reason given for it;
  • provide support, respond to enquiries and investigate faults;
  • keep the service secure and available, detect misuse, and diagnose errors;
  • improve the product, using operational and aggregate usage information rather than reading customer project data for our own purposes;
  • meet our legal, accounting and record-keeping obligations, and resolve disputes.

Where a law such as the UAE Personal Data Protection Law or the Australian Privacy Act requires a basis for processing, we rely on the performance of our contract with the customer organisation, our legitimate interests in operating and securing a business platform, compliance with legal obligations, and consent where consent is the appropriate basis and has been given.

We do not sell personal information, we do not share it for advertising, and we do not use customer project data to build advertising or marketing profiles.

07Cookies and local storage

Field Connect uses one cookie. There are no analytics cookies, no advertising cookies and no third-party trackers on the application.

CookiePurposeLifetime
fc_sessionStrictly necessary. Holds the signed token that keeps you signed in and identifies which projects you may open. Set as HttpOnly so it cannot be read by scripts, restricted to same-site requests, and sent only over HTTPS in production.7 days, or until you sign out

Because this cookie is strictly necessary to deliver a service you have asked for, we do not present a consent banner for it. If you block it, you cannot sign in. Your browser may also hold small amounts of local data (such as your interface preferences) on your device only.

08Who we share information with

Within a project. Project data is visible to the customer organisation that owns the project and to the people it has invited. Guests see the logistics record: overview, master sheet, containers and calendar. Commercial information, including rate cards, cost and sell amounts and variation reports, is restricted to the owning organisation's staff.

Service providers. We use a small number of established providers to run the platform. Each receives only what it needs for its function, under terms that require it to protect the information and use it only to provide the service to us.

ProviderFunctionWhat it receives
Amazon Web ServicesDocument and photograph storage; outbound emailUploaded packing lists, proofs of delivery and photographs; recipient email addresses, invitation links and one-time codes
TwilioSMS verification for staff sign-inMobile telephone number and the one-time code
Google (Gemini API)Optional assistance reading packing lists and proofs of deliverySpreadsheet column headings with sample cell values, and proof-of-delivery documents submitted for date extraction. See section 09.
WiseTech Global (CargoWise)Customs declaration lookup, where the customer uses itThe container number searched
Hetzner OnlineApplication and database hostingAll data held by the application, as the hosting layer

Others. We may disclose information to our professional advisers where they are bound by confidentiality; to a regulator, court or law enforcement body where we are legally required to and after reviewing the request; and to an acquirer if the business is reorganised or sold, in which case this policy continues to apply to the information transferred until it is replaced by a policy no less protective.

09Automated processing and AI features

Two features use a third-party AI model to save manual work. Both are assistive: they propose, a person confirms, and no decision that affects a person is made automatically.

  • Packing list column mapping. When a project imports its first packing list, the column headings and a small sample of cell values are sent to Google's Gemini API so it can suggest which column is the item ID, the level, the container and so on. You confirm or correct the mapping before anything is imported, and the confirmed mapping is reused for later shipments on that project.
  • Proof of delivery date extraction. A proof-of-delivery PDF may be sent to the same service to read the delivery date off the document. Where this is unavailable, text recognition runs on our own servers instead.

We use the paid API tier and configure it so that submitted content is not used to train the provider's models. Even so, if a document is too sensitive to leave our infrastructure, tell us and we will disable these features for your project. The platform works without them, with the column mapping set by hand.

The pricing engine is deterministic, not AI. Storage weeks, delivery units, demurrage and backload charges are calculated by applying the rate card your organisation entered.

10Where your data is held

We operate from the United Arab Emirates. Our application servers and database are hosted in the European Union, uploaded documents and photographs are stored in an Amazon Web Services region selected for the deployment, by default Asia Pacific (Sydney), and our service providers may process limited data in other countries where they operate, including the United States.

This means personal information may be transferred outside the country you are in, including outside Australia and outside the UAE. Where we transfer personal information across borders we rely on the recipient being subject to comparable protection, on contractual protections such as standard data protection clauses in our agreements with providers, and on the technical measures in section 11. If you would like detail on the arrangements for a specific provider, ask us.

11How we protect information

  • Passwords are stored only as one-way bcrypt hashes; invitation tokens and one-time codes are stored hashed, expire, and are limited in the number of attempts allowed.
  • Staff sign-in requires a second factor: a one-time code sent by SMS to the registered mobile number.
  • Sessions use a signed token in an HttpOnly, same-site cookie, delivered over HTTPS with certificates renewed automatically.
  • Access is scoped by organisation, role and project membership. A project you have no access to is not merely hidden from the interface; the server does not acknowledge that it exists.
  • Documents and photographs are not publicly addressable. They are served through short-lived links that expire approximately one hour after they are issued.
  • Uploads are restricted by file type and size, and deleting a shipment or delivery removes its stored files.
  • Quality records are versioned rather than overwritten, so the history of a change and the reason for it remain available.

No system is perfectly secure. If we become aware of a breach of personal information that is likely to cause serious harm, we will notify the affected customer organisations and the relevant regulator as required by law, and act promptly to contain it.

12How long we keep it

  • Project data is kept for as long as the customer's agreement with us is in force, because a logistics and costing record has to remain auditable for the life of the package and beyond. After termination we retain it for the period set out in that agreement to allow export, then delete or irreversibly anonymise it.
  • Account details are kept while the account is active. Deactivated accounts are retained where a name must remain attached to a historical record for the audit trail to make sense.
  • Invitations expire automatically. Unaccepted invitations and their hashed codes are cleared once they lapse.
  • Technical logs are kept for a short period for security and troubleshooting, typically no more than twelve months.
  • Enquiries are kept while there is an active conversation and for a reasonable period afterwards.

We may keep information for longer where a law requires it or where it is needed for an actual or anticipated legal claim.

13Your rights and choices

Depending on where you are, you may have the right to:

  • ask what personal information we hold about you and get a copy of it;
  • have inaccurate information corrected;
  • ask us to delete information we no longer have a reason to keep;
  • ask us to restrict or object to a particular use, including any use based on our legitimate interests;
  • receive information you gave us in a portable, machine-readable form;
  • withdraw consent where we relied on consent, without affecting what was done before;
  • complain to a data protection authority.

To exercise any of these, email admin@fieldconnect.one. We will verify who you are before we act, and respond within thirty days or the shorter period a law requires. We do not charge for a reasonable request.

Where the request concerns project data that a customer organisation controls, we will forward it to that organisation and support them in responding, rather than altering their records on our own initiative.

Australian users. Nothing in this policy limits your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, including the right to access and correct your personal information and to complain to the Office of the Australian Information Commissioner.

14Invited and guest users

If you were invited to view a project, your account was created from the details a project administrator entered. Guest accounts hold no password and no mobile number: you are verified by a code sent to the email address on the invitation, and only to that address. Guest access is read-only, limited to the projects you were invited to, and can be revoked by the administrator at any time. It does not extend to variation reports, costing, project contacts, project settings or the customs lookup.

15Children

Field Connect is a workplace tool for adults acting in a professional capacity. It is not directed at children and we do not knowingly collect information about anyone under 18. If you believe a child's information has reached us, tell us and we will remove it.

16Changes to this policy

We will update this policy as the platform changes. The effective date at the top always reflects the current version. If a change materially affects how we handle personal information, we will notify customer organisations by email or in the application before it takes effect.

17Contact and complaints

Sparke Data Solutions, operator of Field Connect
Dubai, United Arab Emirates
admin@fieldconnect.one

Please put "Privacy" in the subject line so your message reaches the right person quickly.

If you are not satisfied with our response, you may complain to the UAE Data Office or, if you are in Australia, to the Office of the Australian Information Commissioner. We would rather hear from you first and put it right.

Field ConnectFrom ship to site
ProductHow it worksScoping callLogin
LegalPrivacy policyTerms & conditionsadmin@fieldconnect.one

Field Connect · Sparke Global Technologies, Dubai
In partnership with One Global Logistics Pty Ltd
© 2026 Sparke Global Technologies. All rights reserved.