Privacy Policy
Last updated 26 August 2026
Simply Plex is job, crew and billing software for trade contractors. This page explains what we collect, why we have it, who else touches it, and how to get it back or get rid of it. It describes what the software actually does today.
Who we are
Simply Plex ("we") provides field-service software to contracting businesses. If your employer uses Simply Plex, they control your data and we process it on their behalf — ask them first about access or deletion, and we will help them do it.
What we collect
Account information
- Your name, email address and role.
- A hash of your password — a one-way scramble. We never store or see the password itself, and we cannot recover it.
- The time of your most recent signed-in request, at most once an hour. This tells an account owner who is actively using their subscription.
Business information you enter
The work itself: jobs, schedules, customers and their contact details and addresses, invoices and estimates, price lists, parts, equipment, crews, timesheets, notes, checklists, forms, photographs and signatures captured on a job, and imported plan files.
Location, on photos you take
Photographs taken in the app can carry a position. When someone taps As-built photo (geotagged), or photographs a pole on a fiber job, we record where the phone was — and we save it alongside the photo, with the time it was taken and which crew member's device took it.
- Two sources, because one is unreliable. We read the coordinates your phone's camera embedded in the photo, and we also ask the phone for a reading at the moment of capture. The second exists because the first often is not there: Android strips the tag out of photos an app receives, and a camera with location switched off never writes one. If the two disagree by a wide margin — a stale tag from somewhere else — we keep the live reading and record that we did.
- This reading happens only as you take a photo. Never in the background, never while the app is closed. An as-built or pole capture will ask for location permission the first time. An ordinary before/after photo never asks — it uses a position only if you have already granted it for the captures above. (The separate, on the clock position sharing described below is a different thing, asked for separately, and you can decline it and still take geotagged photos.)
- Why we have it: it is the proof that plant was built where the claim says it was built. A contractor submits these photos to the company that hired them in order to get paid, and a coordinate is what makes that photo provable rather than merely asserted. Without it a short-paid invoice is one person's word against another's.
- You can say no, and the app keeps working. Location permission is foreground-only — the kind that applies while you are using the app — and the build has the background and “always” variants switched off entirely. Decline it, or have no signal, and the photo still saves; it simply carries no coordinate, and the app says so rather than pretending.
- Who sees it: your employer, and whoever they choose to send their evidence package to — normally the contractor that hired them. We do not send it anywhere on our own.
- How long: it stays part of the job record for as long as the account is active, exactly like the photo it belongs to, because together they are a billing record. It is removed when that record is, under "How long we keep it" below.
Location, while you are clocked in and using the app
If you are a crew member, Simply Plex can send your position to your employer's dispatch map while you are working, so an office can see where its crews are. This is the one thing in the app that is about you rather than about the work, so here is all of it.
- You are asked first, and you can say no. The first time you clock in, the app explains this in a card you have to answer before a single position is sent. Decline and nothing is collected; everything else in the app keeps working exactly as before. You can change your mind either way, any time.
- Only on the clock, and only with the app open. Both must be true at the same moment. Clock out and it stops. Switch to another app, lock the phone, or put it in your pocket and it stops — not as a policy but as a fact about how it is built: it takes single readings on a timer that cannot run while the app is in the background. Your lunch break, your commute and your evening are not collected.
- You can see it the whole time it is happening. While it is on, a bar with a live indicator sits on your jobs list, your job screen and your time clock saying so — and it carries a Stop button. It is not tucked away in a settings screen, and there is no state in which your position is being sent and nothing on screen says so.
- How often, and what it contains. About once a minute, and only when you have actually moved (roughly 50 metres) — plus once every five minutes when you are parked, so the office can tell “still on site” from “phone is off”. Each reading is a latitude and longitude, its accuracy, speed and heading, the time, and the job your shift is filed under.
- Never in the background, and the phone will not allow it. The build ships with the background and “always” location permissions switched off and the Android background-location permission blocked outright, so the operating system will not grant one even if a future version of the app asked.
- Stale positions are thrown away rather than sent. If the phone loses signal, readings older than ten minutes are discarded instead of being delivered later. An hour-old position is not useful to a dispatcher and it is not fair to you.
- Who sees it: your employer — on their dispatch map and in the location history on their account. Not your coworkers. Reading the live map needs dispatch access, which is the permission an owner gives the people who schedule and assign work; a crew account does not have it, so one crew member cannot look up another's position. One narrow exception: while a job is marked en route, the customer's tracking link for that job shows the assigned technician's position, and only if it is less than fifteen minutes old. That is the “your technician is on the way” map, and it goes dark the moment the job stops being en route. We do not send your position anywhere on our own.
- How long: the position history is part of your employer's business records and is kept for as long as their account is active — we do not currently expire it automatically. It is removed when their account's data is, under “How long we keep it” below. Signing out of the app clears this phone's copy of your answer, so the next person to sign in on it is asked for themselves.
Notifications sent to your phone
If you allow notifications, the field app registers a push token — an address for your handset, issued by your phone's operating system — and we store it against your account so we can reach you. It is an identifier for a device, not for you personally, and we hold nothing else about the phone: no advertising ID, no hardware serial, no contact list.
- What we send. Two things only: a job being assigned to you, and a job of yours being cancelled. We do not notify you about status changes you made yourself, or about office edits to a job. The notification carries the job's title so you know which work it is.
- When we hold one back. If you are off the clock and it is outside your shop's business hours, a routine notification is not sent at all — you should not be woken at 9pm about tomorrow's schedule. Urgent and emergency work, and work starting within the next two hours, still comes through; so does anything sent while you are clocked in. Your employer can switch this hold off in their settings.
- Who it travels through. Expo's push service, and then Apple or Google, deliver it to your handset. They see the notification's title and text.
- Turning it off. Decline the permission, or switch notifications off for Simply Plex in your phone's settings. Everything else in the app keeps working, and the job still appears in your list. Signing out removes the token from your account, and so does the app being uninstalled — your phone tells us, and we delete the address.
Technical information
- Server logs containing IP address, request path and timing. Used to keep the service running and to investigate faults.
- An audit trail of significant actions — who changed what, and when — which exists so an account owner can answer that question.
Diagnostics when something goes wrong
When the app crashes, or cannot get your work to us, it sends a short report so we can fix it. This is our own software talking to our own servers — not an analytics company, and there is no tracker anywhere in the app.
- What a report contains. The error message and the programming stack trace that goes with it, which screen or part of the app it happened in, and exactly which build you are running. If you are signed in it also carries your account and your company's, so we know whose problem to fix.
- Plus a few numbers about the app's own plumbing. How many photographs are still waiting to upload, how many the app has given up on, how many records the server refused, and how long syncing has been failing. This is how we find out that work is stuck on a phone before somebody loses a day of it.
- What a report can never contain — and this is enforced in the software, not promised. No job titles, notes or checklists. No customer names, addresses or telephone numbers. No footage, prices or invoice amounts. No photographs or signatures. No location. A report may carry only a fixed list of counts and version numbers, and our server throws away anything else before a word of it is written down — there is no field a name or an address can be typed into.
- Only when something is wrong. There is no heartbeat and nothing on a schedule. An app that is working normally sends no diagnostics at all, and the checks ride along with a sync it was doing anyway, so they cost nothing extra on your battery.
- Where it goes, and how long. Into our server logs, alongside the other technical information described above. We use them to fix faults, and for nothing else.
What we do NOT collect
- Where you go when you are not working. There is a live crew map, and it is described in full above — but nothing runs in the background, nothing runs while the app is closed, and nothing runs when you are off the clock. The app cannot do otherwise even by accident: the background and “always” location permissions are switched off in the build itself, so the operating system will not grant them. Off shift, off screen, or after you tap Stop, there is no mechanism by which this app knows where you are. An address you type onto a job is business data you entered, not tracking.
- Analytics and advertising. No analytics SDK, no advertising network, no third-party tracker, no cross-site profile. We do not sell or share personal information for advertising, and we never have. We do not study how you use the app — nothing records which screens you open, what you tap or how long you spend. The crash diagnostics described above are a different thing: they are ours, they go nowhere else, they carry none of your work, and an app that is working normally sends none.
- Payment card numbers. If card payments are enabled, card details go directly to Stripe and never reach our servers.
- Contacts, photos library, microphone or calendar. The app opens the camera or picker only when you attach a photo to a job, and receives only that photo — plus, on an as-built capture, the coordinates the camera embedded in it.
Why we have it
To provide the service, keep it secure, bill for it, and give account owners the records their business runs on. We do not use your business data to train machine-learning models.
Who else touches it
We use other companies to run the service. They may only process data to provide their service to us.
| Company | What for | Status |
|---|---|---|
| Supabase | Database hosting (United States) | Always |
| Railway | Application server hosting | Always |
| Vercel | Website hosting | Always |
| Cloudflare (R2) | Storage for photos and files you upload | Always |
| Resend | Sending email such as invoices and invitations | Always |
| Mapbox | Maps and turning an address into coordinates | Always |
| Expo (plus Apple or Google) | Delivering job notifications to your phone | Only if you allow notifications |
| Twilio | Text messages to your customers | Only if your shop enables it |
| Stripe | Card payments | Only if your shop enables it |
| An AI provider | Reading a plan file or work order so its details can be filled in for you — one you upload, or the text of a work-order email sent to an intake address or mailbox your shop connected | Only if your shop enables it |
Twilio, Stripe and the AI provider are switched off unless a shop turns them on, and no notification reaches Expo unless you allow notifications on your own phone.
AI document reading is off until an owner switches it on in Settings, and it is off for a new account. While it is off, nothing you upload or forward is sent to an AI provider at all — every screen that offers it says so, and the work can still be done by hand. While it is on, what goes is the document itself: the plan file or work order you opened, or the body text of a work-order email that reached an intake address or a connected mailbox. It is sent to have that document read and returned as fields — not to train a model.
What is stored on your phone
The field app is built to work with no signal, so it keeps a copy of your assigned work on the device and syncs when service returns. Your sign-in tokens are held in the operating system's secure keychain. Signing out erases the local copy, and so does signing in as a different person — a phone that changes hands does not keep the previous account's work.
How long we keep it
- Business records are kept for as long as the account is active, because they are the account's books.
- Deleted records are marked deleted and hidden rather than erased immediately, so a mistake can be undone and so field devices learn to remove their copy.
- Backups are retained on a rolling basis and overwritten in turn, so deleted data can persist in a backup for a short period after removal.
- Close an account and we will delete or return its data within 30 days of being asked.
Security
Traffic is encrypted in transit. Passwords are stored only as bcrypt hashes. Each business's data is separated and every request is scoped to the account it came from. Sign-in tokens are short-lived and deactivating a user ends their sessions. Backups are encrypted, and we test restoring them rather than assuming they work.
No system is perfectly secure. If a breach affects your data we will tell the affected account owners without undue delay.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal information, and to object to certain processing. If your employer uses Simply Plex, start with them — the data is theirs to control. Otherwise write to hello@simplyplex.com and we will respond within 30 days.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Children
Simply Plex is software for businesses and is not directed at anyone under 16. We do not knowingly collect information from children.
Where data lives
Our infrastructure is hosted in the United States. If you use the service from elsewhere, your information is transferred to and processed there.
Changes
If we change what we collect or who we share it with, we will update this page and change the date at the top. Material changes will be emailed to account owners.
Contact
hello@simplyplex.com — questions, requests, or anything on this page that does not match what you see in the product.