BC PIPA disclosures

Privacy policy

This page describes how FieldChamp BC collects and handles personal information under British Columbia's Personal Information Protection Act. It covers both audiences — customers whose contact and contract records are held, and representatives whose location and activity are recorded during scheduled visits. Where a question is not yet settled we say so; we do not invent numbers.

Who this covers

Customers. We hold your contact details, the address of the demonstration, records of the products discussed, any estimate or contract you receive, and the evidence trail that shows how the transaction was formed.

Representatives and staff. We hold your account information and — during scheduled customer visits — your device location. Location is what BC PIPA calls employee personal information; you must be told what is collected and why, and consent must be recorded rather than assumed.

Employee location — the plain-language notice

The wording below is the notice representatives see and consent to before they can be scheduled to an appointment. It exists to be short enough to actually read.

Loading current notice…

A record is stored per representative with the notice version and a timestamp, so a future change to the notice does not silently inherit an old record. A representative can withdraw at any time; without a current record, appointments cannot be scheduled to them because separation evidence cannot be recorded.

What we collect and why

  • Customer contact and address. To schedule the demonstration and later, if you order, to deliver the product.
  • Demonstration and order records. Estimates, contracts, credit agreements, and the nine-event ledger that proves the transaction was formed the way the BPCPA requires.
  • Representative device location. Captured only during a scheduled visit and the short exit window. Used to prove that the representative had left before you placed an order — never for productivity tracking, canvassing, or route optimisation.
  • Account activity. Sign-ins, actions taken in the app, and the identity that took them, so the ledger can attribute each event correctly.

Who we disclose it to

Personal information stays within the organisation that collected it — a distributor can see their own customer and representative data, not another distributor's. FieldChamp operates the platform on their behalf.

We do not currently use third-party processors for personal information beyond the hosting infrastructure that runs the database and application. counsel_pendingA full subprocessor list, breach-notification timeline, and cross-border-transfer disclosures require legal review before we publish specifics.

Retention schedule

Evidence ledger. The ledger is append-only and cannot be purged row by row. That is a deliberate design choice — its entire purpose is to be un-revisable after the fact — and it is in tension with data minimisation. Our approach: organisation-level deletion when an organisation leaves the platform, and, where a specific customer or employee's payload must be removed, cryptographic erasure of the payload (destroying the key that decrypts it) while leaving the hash chain intact. The exact retention period before organisation-level deletion has not been set.counsel_pending

Customer records. Contact and contract records are kept for as long as your organisation of record uses the platform. Contracts, credit agreements and delivery records are subject to statutory retention requirements that vary by product and by lender. counsel_pendingSpecific durations require counsel review.

Representative location. Location points recorded during a visit are stored with the transaction they belong to and share that transaction's retention. They are not aggregated into a movement history and are not captured outside the visit + exit window.

Consent records. Location-notice consents are append-only and are retained for the life of the account so we can prove what each representative saw and agreed to.

Security posture

Access is controlled at the database layer with Row-Level Security scoped to the organisation. The compliance ledger is protected by an event trigger that refuses any attempt to disable or drop the append-only guards. A ledger-wide anchor chain lets a reader detect whole-transaction deletions after the fact.

We do not currently make specific claims about encryption at rest, penetration testing, SOC/ISO certifications, or breach-notification timelines.counsel_pendingAnything we cannot verify today, we do not put on this page.

Access and deletion requests

Under PIPA you can ask what personal information we hold about you and — subject to the retention exceptions above — ask that it be deleted. Requests are recorded, assigned to the relevant organisation's compliance staff, and tracked until answered. They are not lost, and they are not fulfilled automatically.

Deletion requests are subject to the retention exceptions above; you will get a written response either way.

Contact

For privacy questions that are not a formal request, email our privacy contact. For a formal access or deletion request, use the form above so it enters the tracked queue.