Privacy Policy
Mendly Field Service — technician mobile application and field service system. Last updated 22 August 2026.
Who this covers
This policy describes how Mendly handles information in the Mendly Field Service Android application, used by Mendly's own field technicians, and in the field service system it connects to. The application is issued to employees and contracted technicians for work use. It is not a consumer product and is not intended for general public use.
What the application handles
When a technician signs in with their own work account, the application holds:
- Work account identity — the technician's name, login and work email address, so the system can show them their own jobs and record who did what.
- Job records assigned to that technician — job reference, description, scheduled time, current stage, and the service site's name, street, landmark, city, contact telephone number and map coordinates.
- Work the technician records — photographs taken of the work, a customer signature captured on screen where a job requires one, parts used, resolution notes, and arrival and departure times.
- A device identifier — a random value generated on first use, held only to diagnose synchronisation problems. It is not derived from the handset, not an advertising identifier, and is not used to identify a person.
What the application does not do
- It does not track the device's location. The coordinates it displays belong to the service site and are sent by the server; the application requests no location permission from Android.
- It contains no advertising, no analytics and no third-party tracking software.
- It does not read contacts, messages, call logs or files belonging to other applications.
- It does not sell or share information with third parties for advertising or any other purpose.
- The camera and photo permissions are used solely to attach photographs to a job, at the technician's initiative.
Where the information is held
The application is built to work without a network connection, so job records are stored on the handset itself in storage private to the application, and photographs awaiting upload are held in the application's own document directory. When a connection is available the application sends this work over an encrypted HTTPS connection to Mendly's own field service server. A queued photograph is deleted from the handset once the server confirms it has been received.
Mendly's server is operated by Mendly on hosting it controls. Information is not passed to any other service.
How the information is protected
These are the measures in place for personal and sensitive user data:
- The technician's password is never stored on the handset. It is used once to sign in and is not written to disk. Only the resulting session token is kept, and it is held in the operating system's hardware-backed secure storage — the Android Keystore, or the Keychain on iOS — never in application files or in the job database. Signing out erases it.
- All transmission is encrypted. Every exchange between the application and Mendly's server uses HTTPS with TLS. The server accepts no unencrypted connection; plain HTTP is redirected and certificates are renewed automatically.
- Data on the handset is confined to the application. Job records and photographs awaiting upload are written to storage that the operating system makes private to this application, so no other installed application can read them.
- The server is access controlled. It is administered only over authenticated encrypted connections, is not shared with other companies, and is not exposed to any third-party service or analytics provider.
- Every request is authenticated as a named person. The application never uses a shared key or service account, so access rules and the audit trail apply to the individual technician on every read and every write.
- Backups. Copies of the server database are taken regularly so that customer and job records can be restored, and are held under the same access restrictions as the server itself.
Who can see what
Each technician signs in with their own credentials rather than a shared key, and the system's access rules restrict a technician to the jobs assigned to them. Supervisory staff can see the full schedule. Every change carries the identity of the person who made it.
How long it is kept
Job records, photographs and signatures are business records of work performed and are retained on the server for as long as Mendly needs them for operational, contractual, accounting and legal purposes. Data held on a handset is removed when the technician signs out of the application or the application is uninstalled.
Access and correction
A technician who wants to see, correct or have removed the personal information Mendly holds about them should contact Mendly using the details below. Requests concerning a customer's information should be made to Mendly directly.
Changes
If this policy changes, the revised version is published on this page with a new date at the top.
Contact
Mendly
Addis Ababa, Ethiopia
info@mendly.solutions