Legal · v1.0

Privacy Policy

Effective date: 2026-05-26 · Last updated: 2026-05-26

This Privacy Policy explains what personal data FieldRat collects, how it is used, and the rights you have over it. Read it together with our Terms of Service and Security & Data Compliance page.

1. Who we are (Data Controller)

FieldRat is operated by TechParrot Innovations, a Salesforce ISV partner based in Chennai, Tamil Nadu, India.

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, TechParrot Innovations is the data controller for personal data processed via the FieldRat website and the FieldRat Salesforce managed package.

2. What this policy covers

This policy applies to:

  • The FieldRat marketing website at https://fieldrat.app and its subdomains.
  • The FieldRat Salesforce managed package (the "App") that subscribers install from the Salesforce AppExchange into their own Salesforce org.
  • The FieldRat Cloud Engine — a backend service operated by us on third-party cloud infrastructure (see Section 5) that the App contacts to run Deep Scan dependency analysis and to record limited usage telemetry.

This policy does not cover Salesforce itself, the customer's own Salesforce org, or any third-party tool the customer uses alongside FieldRat. Salesforce's privacy practices are governed by Salesforce's own Privacy Statement at salesforce.com/company/privacy.

3. What personal data we collect

3.1 From website visitors

When you visit https://fieldrat.app we collect:

  • Standard server logs (IP address, user agent, timestamp, requested URL) — collected by our hosting provider Cloudflare for security and abuse prevention. Logs are retained for up to 30 days.
  • Information you voluntarily submit through contact, support, or notify-on-launch forms (your name, email address, free-text message, and the intent you select). Stored to respond to your enquiry.
  • Usage analytics via Google Analytics 4 (pages visited, approximate location, device and browser type), which sets analytics cookies. We use this to understand which content is useful; retention follows the Google Analytics default of up to 14 months. You can block these cookies in your browser or with the Google Analytics opt-out add-on without affecting the site.

We do not use third-party advertising trackers. We do not sell personal data. We do not use cookies for advertising. Beyond the analytics cookies described above, strictly necessary cookies may be set by our hosting provider for security purposes.

3.2 From FieldRat App subscribers

When the FieldRat managed package is installed in your Salesforce org and an admin uses it, the App processes the following inside your Salesforce org. None of the following business record values leave your Salesforce org:

  • Names of fields, objects, metadata components, and their schema properties (data type, length, picklist values).
  • Counts of records that have a given field populated vs. empty (aggregate counts only, never record values).
  • Field dependency findings (which automations, layouts, validation rules, etc. reference a field).
  • Run records that you create (object scanned, scan mode, timestamps, status).

The following limited data is sent from your Salesforce org to the FieldRat Cloud Engine (operated by us on cloud infrastructure — see Section 5) so the service can authenticate the request, authenticate service access, and produce dependency reports:

Data sentWhenPurpose
Your Salesforce Org ID (15- or 18-character)Every requestIdentify which tenant the request belongs to
A timestamp and HMAC-SHA256 signatureEvery requestAuthenticate the request
Scan type (Quick or Deep) and aggregate counts (number of fields, number of dependencies found, duration in milliseconds)After each completed scanOperate the service and produce aggregate usage statistics
A metadata ZIP archive containing Salesforce metadata (not business record values)Deep Scan only, when the admin manually uploads itRequired input for symbolic dependency analysis across 23 metadata types

The metadata ZIP for Deep Scan is uploaded by the admin and analysed on our cloud engine. Metadata files contain schema and configuration (field definitions, automations, layouts), not customer business record values. The uploaded ZIP is deleted from our server after the Deep Scan completes.

3.3 What we do NOT collect

  • We do not collect Salesforce record values (account names, contact emails, opportunity amounts, etc.).
  • We do not collect Salesforce session IDs from production scans (v1).
  • We do not require or collect end-user credentials.
  • We do not collect special category data (health, biometrics, etc.) — there is no use case for it.
  • We do not use behavioural advertising trackers or fingerprinting.

4. Why we process this data (Lawful Basis under GDPR)

Where GDPR applies, we rely on the following lawful bases:

Processing activityLawful basis (GDPR Art. 6)
Website server logs, security monitoringLegitimate interests — operating and securing the website
Form submissions you send usPerformance of a contract (responding to your request) and consent (you voluntarily submitted the data)
FieldRat App telemetry (Org ID, scan counts, durations) sent to the Cloud EnginePerformance of a contract — necessary to provide the service and produce the dependency report you requested
Deep Scan metadata ZIP processingPerformance of a contract — necessary to produce the dependency report you requested

5. Who we share data with (Sub-processors)

We use a small number of sub-processors to operate FieldRat. Each is bound by a contract or by their own privacy commitments equivalent to ours.

Sub-processorPurposeWhere data is processed
Cloudflare, Inc.Hosts the marketing website and provides DDoS protection, caching, and CDN.Global CDN edge; primary processing in the United States.
Railway CorporationHosts the FieldRat Cloud Engine backend (compute and storage).United States.
GitHub, Inc. (a Microsoft company)Stores the source code of the FieldRat App and website. Stores anonymous build artefacts and issue-tracker entries. We do not push customer data to GitHub.United States.
Salesforce, Inc.Operates the AppExchange and Partner Community where FieldRat is published.Varies by Salesforce instance.

We do not sell, rent, or trade personal data to third parties. We do not use the data we receive to train AI models or for any purpose other than operating FieldRat.

6. International data transfers

FieldRat is operated from India. Our hosting providers process data primarily in the United States. If you are located in the EU/EEA, the UK, or another jurisdiction with data-export rules, your data may be transferred to India and the United States to operate the service.

For transfers covered by GDPR/UK GDPR, we rely on:

  • The EU Standard Contractual Clauses (SCCs) with our US-based sub-processors (Cloudflare, Railway, GitHub) where the sub-processor has incorporated SCCs into its terms.
  • Sub-processors' own adequacy mechanisms where available (e.g., participation in the EU-US Data Privacy Framework).

The amount of personal data transferred is intentionally minimal (an Org ID, timestamps, aggregate counts, and metadata file names — see Section 3 for the full list).

7. How long we keep data

DataRetention
Marketing website server logsUp to 30 days (Cloudflare default).
Form submissions (contact, support, launch notify)Up to 24 months from your last interaction, then deleted unless retention is required to resolve an active issue.
FieldRat Cloud Engine tenant registry (Org ID + service status + aggregate usage telemetry)Retained for the life of the tenant. Deleted on uninstall request — see Section 8.
Deep Scan uploaded metadata ZIPsDeleted from the server immediately when the scan finishes (success or failure). Any upload that never reaches the scan step is purged by an automatic sweeper within 1 hour.
Aggregate usage telemetry (counts only, no Org ID)Retained indefinitely as aggregate statistics for product analytics. Once aggregated, the data is no longer personal data.
BackupsDisaster-recovery backups may retain data for up to 30 days beyond the deletion date.

8. Your rights

If you are in the EU/EEA, UK, California, or another jurisdiction that provides data-subject rights, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your personal data ("right to be forgotten") in the circumstances permitted by law.
  • Restrict or object to certain processing.
  • Portability — request a copy of your data in a structured format.
  • Withdraw consent at any time where we rely on consent.
  • Complain to a supervisory authority (in the EU, your local Data Protection Authority; in the UK, the Information Commissioner's Office at ico.org.uk).

To exercise any of these rights, email contact@fieldrat.app with the words "Data Request" in the subject line. We will respond within 30 days. We may ask you to verify your identity before acting on the request.

How to delete your data

  • Website form data: email contact@fieldrat.app and we will delete your submission record.
  • FieldRat App tenant data: uninstall the FieldRat managed package from your Salesforce org. To also delete the server-side tenant registry entry, email contact@fieldrat.app with your Salesforce Org ID. We will purge the registry entry within 7 days.
  • Deep Scan uploaded files: already deleted immediately when each scan finishes; no action needed.

9. Children's data

FieldRat is a tool for Salesforce administrators and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has provided data to us, email contact@fieldrat.app and we will delete it.

10. Security

We protect personal data with technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit (HTTPS / TLS 1.2+), HMAC-signed authentication for all FieldRat App ↔ Cloud Engine traffic, and access controls on our hosting infrastructure. See our Security & Data Compliance page for more detail.

We cannot guarantee absolute security. No internet system is completely secure. If we become aware of a personal data breach affecting your data, we will notify the relevant supervisory authority within 72 hours where required, and notify affected users without undue delay.

11. Changes to this Privacy Policy

We may update this policy from time to time. Material changes will be announced by:

  • Updating the Last updated date at the top of this page.
  • Publishing the previous version in our public git archive so prior versions remain inspectable.
  • For substantial changes affecting how we use existing data, providing reasonable advance notice via email (where we have your address) before the change takes effect.

12. Contact

For any privacy-related question:

This Privacy Policy is provided in plain English for clarity. If there is any conflict between this document and applicable law, the law prevails. The data controller named in Section 1 is responsible for the processing described here.