Vertex Field AI

Privacy Policy

Last updated: July 21, 2026

1. Overview

Vertex Field AI LLC ("Vertex Field AI," "we," "us," or "our") is a Delaware limited liability company operating from Boston, Massachusetts. We provide an AI-assisted field-operations platform for underground utility construction — directional boring, utility installation, and restoration. Our customers include utility contractors, utility companies, municipal primes, and government-related entities.

This Privacy Policy explains what information we collect through our website and platform (together, the "Service"), how we use it, and who we share it with. The Service is offered business-to-business, in the United States only, and is not directed to consumers or to children.

At a glance. We do not sell personal information or share it for cross-context behavioral advertising. We do not use Customer Data to train, fine-tune, or improve generalized or foundation AI models, and we contractually require our AI providers not to either. We have no Social Security number field and no path for capturing one. We do not move money — no ACH origination, no payment processing, no custody of funds — and we are not a payroll-tax service. Voice input is transcribed transiently: we retain neither the audio nor the transcript. We collect no biometric identifiers, run no advertising or cross-site tracking, and use only strictly necessary cookies.

Contractual terms — warranties, disclaimers, limitations of liability, and dispute resolution — are set out in our Terms of Service, which incorporate this Policy by reference and govern it. This Policy describes our practices; it is not a warranty or a guarantee of a particular result, and it creates no rights in any third party.

2. Our Role: Customer Data vs. Account Data

Customer Data is the operational content a customer organization puts into the Service or generates through it — daily production reports, bore logs, photos, project and job records, ledgers and invoices, payroll and crew records, and onboarding documents. Some of it relates to identifiable people, such as a customer's employees, subcontractors, or job-site contacts. We process it on our customer's instructions and for the purposes described here. The customer decides what to upload, who may see it, and how long to keep it.

Account Data is what we hold in our own right to run the business — the contact details of people who administer or use accounts, billing records, support correspondence, security and audit logs, and first-party usage logs collected without advertising or cross-site tracking.

Customer responsibilities. Each customer is responsible for having a lawful basis to collect and upload information about its employees, subcontractors, and job-site contacts; for giving those individuals any notice their jurisdiction requires; for obtaining any consent required, including for photographs, location-tagged records, and recorded or transcribed speech; and for configuring roles and permissions so only the right people see sensitive records. We provide the tools and the access controls; we do not decide what a customer collects or whom it tells.

If a customer uploaded information about you and you want to access, correct, or delete it, contact that organization directly. See Section 12 (Your Rights and Choices).

3. Information We Collect

Account and contact information

Name, work email, phone number, job title, employer, role and permission level, language preference, and authentication information such as password credentials and session records. If you contact us through our website, we collect your company name, contact details, and the substance of your message.

Field-operations and safety records

Daily production reports, job hazard analyses and tailboard records, footage and restoration entries, damage reports, equipment and task records, and bore logs. Bore logs include GPS coordinates recorded at the job site to locate installed underground infrastructure. Users also upload photographs of work, sites, materials, and conditions; uploaded photos may carry embedded metadata, including location and device information, placed there by the capturing device. These records identify the crews and individuals who performed or supervised the work.

They are documentation, not verification: the Service does not inspect a job site, does not confirm that a locate was requested or is accurate, and does not substitute for one-call/811 notification, utility locating, or a customer's own safety program. Coordinates and measurements are as entered or as reported by the device.

Customer and project records

Company and project identifiers, addresses and work locations, scopes of work, rate sheets, schedules, and the names and business contact details of project contacts and of recipients of reports and invoices.

Financial and billing information

Ledgers, cost records, rates, invoices, payment status, and accounts-receivable history maintained inside the Service by our customers, plus our own billing records. We do not move money. The Service does not originate ACH transfers, process payments or payment cards, or take custody of anyone's funds. Payment happens through the bank or provider the customer already uses; the Service records that money was invoiced, owed, or paid.

Payroll information

Where a customer uses payroll features, the Service holds pay schedules, hours worked, pay rates, bonuses, deductions such as cash advances, and net amounts for that customer's workers. Pay amounts are confidential and access-restricted to the customer's designated administrators. The Service has no Social Security number field and no capture path for one.

We are not a payroll-tax service. We do not calculate, withhold, remit, or file payroll or employment taxes, and we do not issue Forms W-2 or 1099; those remain the customer's responsibility through its own payroll or tax provider. The Service has no certified-payroll or prevailing-wage functionality, and its outputs are not certified-payroll records. The customer is the employer of record for its own workers and is responsible for classification, wage-and-hour compliance, and timekeeping accuracy; the Service calculates from what administrators enter and does not determine what anyone is owed.

Onboarding and compliance documents

Onboarding materials uploaded by users, including IRS Form W-9 documents, certificates of insurance, signed contracts, and banking details recording where a customer directs its own payments — such as an account and routing number, which are encrypted at rest and shown masked in the interface. Uploaded documents are user content: a W-9 image may contain a Social Security number that the uploader chose to include, and we do not extract it into a structured field.

Communications, AI content, and voice

Messages you send us, email the Service sends on a customer's behalf and its delivery records, in-product notifications, prompts submitted to AI features, and the outputs those features return. Some features accept spoken input, transcribed so it can become a draft record; we retain neither the audio nor the transcript — see Section 5 (AI Features and Model Training).

Device, usage, and log data

IP address, browser and device type, operating system, features used, timestamps, referring pages, error events, and audit logs of actions taken in the account. If a user enables push notifications, we store the browser-issued push subscription needed to deliver them.

What we do not collect

We collect no biometric identifiers and no precise device location outside the job-site records described above. We do not buy personal information from data brokers, and we run no advertising or cross-site tracking. Please do not upload what the Service does not need: it has no field for, and no feature requiring, a Social Security number, a driver's-license number, a medical record, a background-check report, or a biometric identifier. Anything of that kind inside an uploaded document is user content, uploaded under the customer's responsibility; we do not extract, index, or use it.

4. How We Use Information

  • To provide and support the Service — maintain accounts, authenticate users, deliver features, generate reports, invoices, and packets, send the email and notifications a customer directs, and answer questions and investigate issues.
  • To operate AI features — process the content a user submits, or the records a feature is pointed at, to return a summary, draft, check, or answer.
  • To secure the Service — enforce permissions, maintain audit trails, and investigate abuse or unauthorized activity.
  • To maintain and improve the Service — diagnose errors, monitor reliability, and understand aggregate usage. This does not include training AI models on Customer Data.
  • To handle billing — administer subscriptions and maintain financial records.
  • To meet legal obligations — comply with applicable law, respond to lawful requests, and establish, exercise, or defend legal claims.

5. AI Features and Model Training

The Service uses AI to summarize field records, draft documents, check work for errors, transcribe voice input, and answer questions about a customer's own data.

We do not use Customer Data to train, fine-tune, or improve generalized or foundation AI models — ours or anyone else's. We contractually require our AI providers not to train on data we send them. Content submitted to AI features is processed to produce a response for the user who asked, and for no other purpose.

Our AI subprocessor. AI inference is currently performed by OpenAI under terms that prohibit training on the data we send. If we engage an additional or successor provider, we will do so only under equivalent terms, including that prohibition, and will update this Policy.

Voice. Spoken input is transcribed transiently, converted into a draft record for the user to review, and then discarded; we retain neither the audio nor the transcript. It is intended for a speaker's own dictation of their own work records. Recording laws differ by state, and some require the consent of every person whose speech is captured; users are responsible for using voice input in compliance with the laws that apply where they are. The Service does not monitor a job site and does not record continuously — it captures audio only while a user actively initiates dictation.

Human review. We do not routinely read Customer Data or AI prompts and outputs. Authorized personnel may access specific content on a limited basis when a customer asks us to investigate an issue, or where necessary for security or legal compliance, subject to internal controls.

No automated decisions. AI features produce drafts and suggestions for a person to review, and output can be incomplete or incorrect. The Service does not use AI to make decisions about individuals — it does not set pay, evaluate performance, screen workers, or determine what anyone is owed — and a person reviews and approves before an AI-assisted record, invoice, or document is finalized or sent.

6. Confidentiality and Isolation of Customer Data

Each customer's data is confidential to that customer. The Service is built so that one customer's records are not exposed to another, and access within an account follows the roles and permissions the customer's administrators configure; pay amounts, banking details, and employee records are further restricted to designated administrators. We do not use one customer's data to serve another, and we do not aggregate Customer Data across customers to build products or benchmarks that would reveal a customer's information.

7. How We Share Information

We do not sell personal information. We share it only in the circumstances below.

Service providers (subprocessors)

We rely on a small set of vendors, each bound by contract to process information only on our instructions and to protect it appropriately. If we add or replace a subprocessor, we will update this list.

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and compute.
  • OpenAI — AI inference for the features described in Section 5 (AI Features and Model Training).
  • Resend — transactional and notification email delivery.
  • Google or Microsoft — only where a user authorizes a connection, to send email or write files on that user's behalf. See Section 9 (Connected Google and Microsoft Accounts).
  • Browser push services — the push infrastructure operated by the user's own browser vendor, used to deliver notifications a user has enabled.

At a customer's direction

The Service sends daily reports, production papers, invoices, and packets to recipients a customer designates, such as its general contractors and clients. Administrators control those lists and are responsible for them: for the accuracy of the addresses, for having a lawful basis to contact each recipient, and for the content sent. For these messages the customer is the sender and we are the delivery mechanism.

Legal and safety

We may disclose information where we believe in good faith that it is required by law, legal process, or an enforceable governmental request, or where necessary to investigate suspected fraud or abuse, enforce our agreements, or protect the rights, safety, or property of Vertex Field AI, our customers, or the public. Unless legally prohibited, we will make reasonable efforts to notify the affected customer before disclosing its Customer Data. Where our customer is a public agency, records it maintains in the Service may be subject to public-records laws; the agency, not Vertex Field AI, determines what it must disclose.

Corporate transactions and advisors

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction; this Policy will continue to apply to the transferred information unless and until it is replaced, and we will give notice of any material change. We may also share information with our lawyers, accountants, and other professional advisors, who are bound by professional confidentiality obligations.

8. We Do Not Sell or Share Your Information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising — as those terms are defined under the California Consumer Privacy Act and comparable U.S. state privacy laws — and we have not done so in the preceding twelve months. We run no advertising network, no ad pixels, no retargeting, and no cross-site tracking; cookies are limited to what is strictly necessary, as described in Section 14 (Cookies and Tracking; Do-Not-Track). Because we do not sell or share personal information, there is nothing to opt out of, and we honor Global Privacy Control signals.

9. Connected Google and Microsoft Accounts

A user may optionally connect a Google or Microsoft account so the Service can send email and save documents under that user's own identity. The Service works without these connections, and a user may disconnect at any time.

Google Limited Use disclosure

The Service's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request only these Google scopes:

  • gmail.send — to send email (such as invoices, daily reports, and packets) from the connected user's own Gmail account. This scope permits sending only; it does not permit reading, searching, or deleting mail.
  • drive.file — to create and manage only the files the Service itself creates in the user's Google Drive. This scope does not grant access to any other file in the user's Drive.

Data obtained through these scopes is used solely to provide the user-facing features described above. We do not transfer it to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice and consent. We do not use Google user data to train, fine-tune, or improve generalized or foundation AI models, and we do not use it for advertising. No human reads Google user data except with the user's explicit consent, for security purposes, to comply with applicable law, or on aggregated and anonymized data for internal operations.

Microsoft scopes

Where a user connects a Microsoft account, we request only:

  • Mail.Send — to send email from the connected user's own mailbox.
  • Files.ReadWrite — to create and update the documents and spreadsheets the Service produces in the user's OneDrive.

The same limits apply: this data is used only to provide the requested features, is not used for advertising, and is not used to train or improve generalized or foundation AI models.

What the Service cannot access

The Service cannot read, search, or delete a user's mailbox; cannot browse a user's Drive or OneDrive beyond the files it created; cannot access calendars or contacts; and cannot act on a connected account after the user disconnects it or revokes the authorization.

10. Data Retention and Deletion

We retain Customer Data while the customer's account is active. Customers may delete records within the Service, subject to the controls their administrators configure and to integrity rules that prevent altering finalized financial documents. On termination we delete or de-identify Customer Data within a commercially reasonable period, except where longer retention is required by law or necessary to resolve a dispute; customers should export what they need before terminating.

Account Data is retained as long as needed for the business and legal purposes it was collected for, and security and audit logs on a limited rolling basis. Data deleted from live systems persists in backups only until those backups expire on their regular cycle. Voice audio and transcripts are not retained at all.

11. Security

Traffic between users and the Service is encrypted in transit, and sensitive records — including third-party access tokens and banking details — are encrypted at rest. Access is governed by role-based permissions, with sensitive categories such as pay amounts and employee records restricted to designated administrators, and actions taken in an account are recorded in audit trails. Internal access to production systems is limited to personnel who need it, and our vendors are contractually bound to maintain appropriate safeguards. We describe our safeguards generally and do not publish implementation details, and we make no claim to hold any particular third-party certification or audit report.

If we become aware of a security incident affecting personal information we hold, we will notify the affected customer's administrators without undue delay and as required by applicable law, and will provide the information reasonably available to us so the customer can meet its own notification obligations. Because our customers control the records in their accounts and know the individuals in them, notice to those individuals is the customer's responsibility.

No system is perfectly secure, and part of account security rests with our customers: administrators control who has access and at what level, safeguard their own credentials, and should revoke access when a person leaves. If you believe your account has been compromised, contact info@vertexfield.ai.

12. Your Rights and Choices

Depending on where you live, you may have the right to know what personal information we hold about you, to receive a copy, to correct inaccuracies, to request deletion, and to be free from discrimination for exercising those rights.

How to exercise. Email info@vertexfield.ai with enough detail for us to understand the request; you may use an authorized agent, in which case we will ask for proof of authority. We verify identity proportionately to the sensitivity of the request, ordinarily by confirming control of the associated email address, and collect no additional information solely for verification. We respond within the period applicable law requires, generally forty-five days.

Customer Data requests. If your information is in the Service because one of our customers put it there, that customer controls it, and you should send your request to that organization. If you send it to us, we will route it to the relevant customer and support their response. We do not alter or release a customer's records on our own initiative, apart from the security and legal-compliance access described in Section 5 (AI Features and Model Training) and Section 7 (How We Share Information).

Communications. You can opt out of non-essential email using the unsubscribe link, and push notifications can be disabled at any time. Service, security, and billing messages are part of the account and cannot be turned off while it is active.

13. U.S. State Privacy Rights

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have the rights described in Section 12 (Your Rights and Choices), and in some states the right to appeal a refusal. To appeal, reply to our response or write to info@vertexfield.ai with "Privacy Appeal" in the subject line.

Several of these laws also provide rights to opt out of the sale of personal information, of targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects. None of those activities occur here: we do not sell personal information, conduct targeted advertising, or use personal information to make automated decisions about any individual.

For purposes of the California Consumer Privacy Act, as amended: the categories of personal information we collect, the purposes for which we use them, and the categories of recipients are described in Section 3 (Information We Collect), Section 4 (How We Use Information), and Section 7 (How We Share Information). The sensitive personal information we hold is limited to account log-in credentials and, where a customer records them, financial account details, used solely to provide and secure the Service — a use that does not give rise to a right to limit. Where we process Customer Data on a customer's behalf, we act as that customer's service provider. We certify that we understand and will comply with the restrictions applicable to a service provider: we will not sell or share the personal information we receive, will not retain, use, or disclose it for any purpose other than performing the services specified in our agreement with the customer or as otherwise permitted by law, and will not combine it with personal information from other sources except as permitted.

14. Cookies and Tracking; Do-Not-Track

We use only strictly necessary cookies and equivalent browser storage — those needed to keep you signed in, maintain your session, remember your language preference, and protect against fraud and abuse. We use no advertising cookies, no analytics cookies that build cross-site profiles, no retargeting pixels, and no third-party trackers, and blocking our cookies will prevent the Service from working properly.

Do-Not-Track and Global Privacy Control. There is no consistent industry standard for responding to Do-Not-Track signals, and we do not track users across third-party sites, so there is nothing for such a signal to change. We honor the Global Privacy Control by default: we neither sell nor share personal information for any user, signal or no signal.

15. International Data Transfers

The Service is offered in the United States only, for U.S. business users, and our infrastructure and subprocessors store and process information here. We do not offer the Service in the European Economic Area, the United Kingdom, or elsewhere outside the United States, and we do not target users there. If you access the Service from abroad, your information will be processed in the United States, where privacy laws may differ from those of your location.

16. Children's Privacy

The Service is a business tool intended for adults in the course of their employment. It is not directed to children, and we do not knowingly collect personal information from children; accounts are created by our business customers for their own workforce. If we learn that we have directly collected information from a child, we will delete it. Information a customer uploads about its own workers is Customer Data under that customer's control.

17. Changes to This Policy

We may update this Privacy Policy to reflect changes in the Service, our practices, or applicable law, and will revise the "Last updated" date at the top of this page when we do. If a change materially affects how we handle personal information, we will give notice — by email to account administrators, in the Service, or both — before it takes effect. Continued use after a change takes effect constitutes acceptance of the updated Policy.

18. Contact Us

Questions, requests, and privacy concerns can be sent to us at:

Vertex Field AI LLC
1 Beacon Street, 15th Floor
Boston, MA 02108
United States
info@vertexfield.ai

For the contractual terms that govern use of the Service, see our Terms of Service.

Privacy · Terms · © 2026 Vertex Field AI LLC