⚠️ READ THIS FIRST — THIS IS A DRAFT, NOT A FINISHED LEGAL DOCUMENT
Like the accompanying Terms of Service, this Privacy Policy was drafted to accurately reflect what Auto Shop Data actually collects, stores, and shares today, based on the real codebase (not a generic template) — but it was not written or reviewed by a licensed attorney or privacy professional. Two things make this a genuinely higher-stakes document than a typical small-SaaS privacy policy, and both need real legal review before publishing:
Everywhere marked [FILL IN] needs a real value. Sections marked ⚠ ATTORNEY / PRIVACY REVIEW are the ones most likely to need judgment specific to which states your shops and their customers are in.
Last updated: [FILL IN DATE]
This Privacy Policy explains how [FILL IN LEGAL ENTITY NAME] ("Auto Shop Data," "we," "us") collects, uses, and discloses information in connection with the Auto Shop Data platform (the "Service").
1.1 Account Data (you are the business, we are the controller). If you are a collision repair shop's staff member with a login to the Service, we collect your name, email address, phone number (if provided), password (stored as a salted hash, never in plaintext), and multi-factor authentication (MFA) enrollment status directly from you. For this data, we act as the "business" or "data controller" — we decide, jointly with your employer (the Shop), how it's used to provide you access to the Service.
1.2 End Customer Data (the Shop is the controller, we are the processor/service provider). Separately, the Service stores information about the Shop's own customers and their vehicles — name, contact information, vehicle year/make/model/VIN, photos of vehicle damage, insurance company name and claim/policy numbers, repair estimates, and payment amounts ("End Customer Data") — because Shop staff enter it to run their business. We do not collect End Customer Data directly from end customers, and end customers do not have an account or relationship with us. With respect to End Customer Data, we act only as a data processor / service provider on behalf of the Shop, which is itself the controller/business responsible for that data under applicable law, including obtaining any consents its own customers must give (for example, SMS opt-in) and honoring its customers' privacy rights requests. If you are an end customer of a collision repair shop that uses Auto Shop Data and have a privacy question or request, please contact that shop directly; we will assist the shop in responding to your request as required by our agreement with them.
⚠ ATTORNEY / PRIVACY REVIEW: some state laws (e.g., CCPA/CPRA "service provider" contract requirements) require a specific data-processing addendum between us and each Shop, not just language in this consumer-facing policy — confirm whether you need a separate Data Processing Agreement (DPA) template for Shops to sign.
2.1 Provided directly:
2.2 Collected automatically:
2.3 From third parties: if and when a Shop connects a live parts-vendor API or payment gateway, we may receive quote, order-status, or transaction-status data back from that vendor/gateway as part of operating the feature the Shop enabled.
We use information described above to: (a) provide, maintain, and secure the Service; (b) authenticate logins and enforce account-lockout and MFA protections; (c) send transactional communications you or a Shop's customer trigger (e.g., a repair-status email/SMS, a password reset, an estimate PDF); (d) generate AI-assisted damage estimates by sending submitted photos/vehicle data to our AI model provider; (e) process payments once a live gateway is configured; (f) provide customer support, including the platform-admin support access described in Section 6; (g) monitor and improve the Service's reliability and security, including through error monitoring; and (h) comply with legal obligations. We do not sell personal information, and we do not use End Customer Data for our own advertising or marketing purposes.
We share information with the following categories of service providers, each of which processes data only as necessary to provide their specific function to us and is bound by contract to protect it. This list reflects current integrations as of this policy's last-updated date and may change as the Service evolves — check back periodically, or ask us for the current list.
| Provider | Purpose | Data involved |
|---|---|---|
| Resend | Transactional and reply-capable email delivery | Message content, recipient email address, Shop's per-RO reply-to address |
| Twilio | SMS sending/receiving | Message content, recipient phone number |
| GoDaddy | Domain/DNS management for branded shop email subdomains | Domain configuration data (not customer content) |
| Anthropic | AI-assisted photo damage estimating | Photos and vehicle/damage description submitted by Shop staff for estimating |
| Neon | Database hosting | All data stored by the Service (encrypted at rest and in transit per Neon's infrastructure) |
| Vercel | Application hosting | All data processed by the Service in the course of serving requests |
| Sentry | Error monitoring | Technical diagnostic data from application errors (see Section 2.2) |
| [FILL IN — payment gateway once selected] | Payment processing | Payment amount, tokenized card reference (not raw card data), transaction status |
| CollisionLink / PartsTrader / LKQ / OPSTRAX (where a Shop enables live vendor integration) | Parts quoting/ordering | Part description, vehicle data, quote/order status |
We may also disclose information: (a) to comply with a subpoena, court order, or other legal process, or to respond to a lawful government request; (b) to protect the rights, property, or safety of Auto Shop Data, our users, or the public; (c) in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections; or (d) with your (or the relevant Shop's) consent.
⚠ ATTORNEY / PRIVACY REVIEW: if any Shop or end customer is located outside the United States, cross-border transfer mechanisms (e.g., for a future EU/UK customer) are not addressed in this draft and would need separate treatment (SCCs, etc.) before marketing outside the US.
We use industry-standard measures appropriate to the sensitivity of the data involved, including: passwords stored as salted bcrypt hashes (never in plaintext); optional/shop-required TOTP-based multi-factor authentication; automatic account lockout after repeated failed login attempts; signed, time-limited session cookies; role-based access control limiting which Shop staff can view or act on which data; and encryption in transit (HTTPS/TLS) for all traffic to the Service. Database and hosting infrastructure providers (Neon, Vercel) provide additional infrastructure-level protections per their own security documentation.
We do not claim that all data is encrypted at rest at the application layer — some configuration and profile fields (for example, a Shop's configured payment-gateway credentials, by explicit current design, and shop logo images) are stored in the underlying database without an additional application-level encryption layer beyond what the database/hosting provider provides at the infrastructure level. ⚠ ATTORNEY / PRIVACY REVIEW: if you plan to store real payment-gateway API credentials per shop, strongly consider adding application-level encryption (e.g., a KMS-backed secret store) before storing production credentials, both to reduce breach impact and because "reasonable security" standards under most state laws are read to require protecting credentials that grant financial access.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Auto Shop Data personnel with platform-administrator accounts can access a Shop's account in a logged support/impersonation mode solely to diagnose and resolve support requests or investigate suspected abuse or security incidents. This access is limited to what's needed to resolve the specific issue, is never used to independently contact a Shop's customers or move funds, and is available for the Shop to see was used (see the in-app impersonation indicator). We do not use this access to review Shop or End Customer Data for any purpose other than support, security, or as required by law.
We retain Account Data and End Customer Data for as long as the associated Shop account is active, plus the post-termination export window described in the Terms of Service, after which we will delete or anonymize it within [FILL IN — e.g. "90 days"], except where we are required to retain it longer for legal, tax, security-incident, or dispute-resolution purposes. Communications content (email/SMS logs) and payment/transaction records are retained for the same period unless a longer retention period is required by law (for example, financial recordkeeping requirements that may apply once a live payment gateway is active). ⚠ ATTORNEY / PRIVACY REVIEW: confirm actual retention periods against any state-specific insurance-record or financial-record retention statutes applicable to collision repair shops in the states where your Shops operate — this is a business-specific requirement a generic privacy policy can't answer for you.
8.1 Shop staff (Account Data). You can update your profile information in Settings, and can request account deletion by contacting [FILL IN SUPPORT EMAIL] or asking your Shop's owner to remove your account.
8.2 End customers. Because we act as a processor for End Customer Data (Section 1.2), please direct privacy requests about your own information to the collision repair shop you worked with, not to us directly; we will support that shop in fulfilling a valid request as required by our agreement with them.
8.3 State privacy law rights (e.g., CCPA/CPRA and similar laws). ⚠ ATTORNEY / PRIVACY REVIEW — this section needs real analysis before publishing: depending on your revenue, data volume, and the states your Shops and their customers are located in, you may be a "business" subject to the California Consumer Privacy Act (as amended by the CPRA) or similar laws in other states (e.g., Virginia, Colorado, Connecticut, Utah), which can grant rights to know, delete, correct, and opt out of certain processing, and may require a specific "Do Not Sell or Share My Personal Information" mechanism even though we state above that we do not sell personal information (the statutory definition of "sale"/"share" is broader than plain-English "sale"). Do not rely on the placeholder language here — have counsel confirm which thresholds apply to your actual business and add the specific rights-request mechanism required (e.g., a toll-free number or web form, response-time commitments, and an appeals process for denied requests).
8.4 Marketing communications. We do not use End Customer Data for marketing. If we ever send marketing communications to Shop staff (e.g., product update emails), we will include an unsubscribe mechanism.
The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child's information has been submitted to the Service, contact us at [FILL IN SUPPORT EMAIL] and we will investigate and delete it as appropriate.
⚠ ATTORNEY / PRIVACY REVIEW (breach-notification obligations are state-specific, and several states have short mandatory notification windows — this is not a section to leave as boilerplate). In the event of a security incident that compromises personal information in a manner that triggers notification obligations under applicable law, we will notify affected Shops (and, where we act as a controller, affected individuals) without unreasonable delay and in accordance with applicable breach-notification laws, and will support each affected Shop in meeting its own notification obligations to its customers and, where required, state regulators, for incidents involving End Customer Data.
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date, and for material changes, will provide additional notice (e.g., email to Shop owners) at least [FILL IN — e.g. "30 days"] before the change takes effect.
Questions about this Privacy Policy, or requests related to your personal information, can be sent to [FILL IN PRIVACY CONTACT EMAIL] or [FILL IN MAILING ADDRESS].
This document is a draft prepared with the help of AI tooling based on the platform's actual data flows as of the date generated. It is not legal advice and has not been reviewed by an attorney or privacy professional. Do not publish or rely on it without review by counsel, particularly for the controller/processor split in Section 1, the state-privacy-law analysis in Section 8.3, and the breach-notification analysis in Section 10.