A
Auto Shop Data

Privacy Policy

⚠️ READ THIS FIRST — THIS IS A DRAFT, NOT A FINISHED LEGAL DOCUMENT

Like the accompanying Terms of Service, this Privacy Policy was drafted to accurately reflect what Auto Shop Data actually collects, stores, and shares today, based on the real codebase (not a generic template) — but it was not written or reviewed by a licensed attorney or privacy professional. Two things make this a genuinely higher-stakes document than a typical small-SaaS privacy policy, and both need real legal review before publishing:

  1. Two very different "data subjects." Shop staff (who create accounts and log in) are one population; the shop's own customers, whose names, contact info, vehicle/VIN data, and sometimes insurance-claim details are entered by shop staff into the system, are a completely different population who never sign up, never see this policy unless a shop chooses to link it, and never directly consent to Auto Shop Data processing their information. Privacy law (especially CCPA/CPRA and similar state laws) treats these differently, and getting the controller/processor distinction wrong is the most common way a B2B SaaS privacy policy fails.
  2. Insurance-claim and financial data. VIN numbers, insurance claim numbers, and (once a real payment gateway is live) payment data carry their own state-specific handling and breach-notification obligations beyond generic "personal information."

Everywhere marked [FILL IN] needs a real value. Sections marked ⚠ ATTORNEY / PRIVACY REVIEW are the ones most likely to need judgment specific to which states your shops and their customers are in.

Privacy Policy for Auto Shop Data

Last updated: [FILL IN DATE]

This Privacy Policy explains how [FILL IN LEGAL ENTITY NAME] ("Auto Shop Data," "we," "us") collects, uses, and discloses information in connection with the Auto Shop Data platform (the "Service").

1. Two Kinds of Data We Handle — Please Read This Section

1.1 Account Data (you are the business, we are the controller). If you are a collision repair shop's staff member with a login to the Service, we collect your name, email address, phone number (if provided), password (stored as a salted hash, never in plaintext), and multi-factor authentication (MFA) enrollment status directly from you. For this data, we act as the "business" or "data controller" — we decide, jointly with your employer (the Shop), how it's used to provide you access to the Service.

1.2 End Customer Data (the Shop is the controller, we are the processor/service provider). Separately, the Service stores information about the Shop's own customers and their vehicles — name, contact information, vehicle year/make/model/VIN, photos of vehicle damage, insurance company name and claim/policy numbers, repair estimates, and payment amounts ("End Customer Data") — because Shop staff enter it to run their business. We do not collect End Customer Data directly from end customers, and end customers do not have an account or relationship with us. With respect to End Customer Data, we act only as a data processor / service provider on behalf of the Shop, which is itself the controller/business responsible for that data under applicable law, including obtaining any consents its own customers must give (for example, SMS opt-in) and honoring its customers' privacy rights requests. If you are an end customer of a collision repair shop that uses Auto Shop Data and have a privacy question or request, please contact that shop directly; we will assist the shop in responding to your request as required by our agreement with them.

⚠ ATTORNEY / PRIVACY REVIEW: some state laws (e.g., CCPA/CPRA "service provider" contract requirements) require a specific data-processing addendum between us and each Shop, not just language in this consumer-facing policy — confirm whether you need a separate Data Processing Agreement (DPA) template for Shops to sign.

2. Information We Collect

2.1 Provided directly:

  • Account Data: name, email, phone, password hash, role, MFA status.
  • Shop profile data: business name, address, phone, fax, contact email, logo image, branding/theme preferences.
  • End Customer Data: as described in Section 1.2, including photos submitted for AI damage estimating.
  • Communications content: email and SMS messages sent and received through the Service, and their delivery status.
  • Payment-related data: amounts, surcharge calculations, and payment status. We do not store full card numbers, expiration dates, or CVV codes on our own servers once a live, tokenizing payment gateway is configured; while the Service operates in simulated payment mode (no live gateway configured), no real card data is transmitted or stored by anyone, because no real charge occurs.

2.2 Collected automatically:

  • Standard web server/application logs (IP address, browser/user-agent, timestamps, pages/requests accessed), used for security, debugging, and abuse prevention.
  • Error and performance data collected by our error-monitoring tool (Sentry) when the application encounters an unexpected error — this is limited to technical diagnostic information (stack traces, request metadata) and is configured not to record session replays, screen video, or general page content, given the sensitive customer/insurance data shown on many screens.
  • Session cookies used to keep you logged in and to remember basic preferences (e.g., light/dark theme).

2.3 From third parties: if and when a Shop connects a live parts-vendor API or payment gateway, we may receive quote, order-status, or transaction-status data back from that vendor/gateway as part of operating the feature the Shop enabled.

3. How We Use Information

We use information described above to: (a) provide, maintain, and secure the Service; (b) authenticate logins and enforce account-lockout and MFA protections; (c) send transactional communications you or a Shop's customer trigger (e.g., a repair-status email/SMS, a password reset, an estimate PDF); (d) generate AI-assisted damage estimates by sending submitted photos/vehicle data to our AI model provider; (e) process payments once a live gateway is configured; (f) provide customer support, including the platform-admin support access described in Section 6; (g) monitor and improve the Service's reliability and security, including through error monitoring; and (h) comply with legal obligations. We do not sell personal information, and we do not use End Customer Data for our own advertising or marketing purposes.

4. Sub-Processors and Third Parties We Share Data With

We share information with the following categories of service providers, each of which processes data only as necessary to provide their specific function to us and is bound by contract to protect it. This list reflects current integrations as of this policy's last-updated date and may change as the Service evolves — check back periodically, or ask us for the current list.

ProviderPurposeData involved
ResendTransactional and reply-capable email deliveryMessage content, recipient email address, Shop's per-RO reply-to address
TwilioSMS sending/receivingMessage content, recipient phone number
GoDaddyDomain/DNS management for branded shop email subdomainsDomain configuration data (not customer content)
AnthropicAI-assisted photo damage estimatingPhotos and vehicle/damage description submitted by Shop staff for estimating
NeonDatabase hostingAll data stored by the Service (encrypted at rest and in transit per Neon's infrastructure)
VercelApplication hostingAll data processed by the Service in the course of serving requests
SentryError monitoringTechnical diagnostic data from application errors (see Section 2.2)
[FILL IN — payment gateway once selected]Payment processingPayment amount, tokenized card reference (not raw card data), transaction status
CollisionLink / PartsTrader / LKQ / OPSTRAX (where a Shop enables live vendor integration)Parts quoting/orderingPart description, vehicle data, quote/order status

We may also disclose information: (a) to comply with a subpoena, court order, or other legal process, or to respond to a lawful government request; (b) to protect the rights, property, or safety of Auto Shop Data, our users, or the public; (c) in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections; or (d) with your (or the relevant Shop's) consent.

⚠ ATTORNEY / PRIVACY REVIEW: if any Shop or end customer is located outside the United States, cross-border transfer mechanisms (e.g., for a future EU/UK customer) are not addressed in this draft and would need separate treatment (SCCs, etc.) before marketing outside the US.

5. Data Security

We use industry-standard measures appropriate to the sensitivity of the data involved, including: passwords stored as salted bcrypt hashes (never in plaintext); optional/shop-required TOTP-based multi-factor authentication; automatic account lockout after repeated failed login attempts; signed, time-limited session cookies; role-based access control limiting which Shop staff can view or act on which data; and encryption in transit (HTTPS/TLS) for all traffic to the Service. Database and hosting infrastructure providers (Neon, Vercel) provide additional infrastructure-level protections per their own security documentation.

We do not claim that all data is encrypted at rest at the application layer — some configuration and profile fields (for example, a Shop's configured payment-gateway credentials, by explicit current design, and shop logo images) are stored in the underlying database without an additional application-level encryption layer beyond what the database/hosting provider provides at the infrastructure level. ⚠ ATTORNEY / PRIVACY REVIEW: if you plan to store real payment-gateway API credentials per shop, strongly consider adding application-level encryption (e.g., a KMS-backed secret store) before storing production credentials, both to reduce breach impact and because "reasonable security" standards under most state laws are read to require protecting credentials that grant financial access.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

6. Platform-Admin Support Access

Auto Shop Data personnel with platform-administrator accounts can access a Shop's account in a logged support/impersonation mode solely to diagnose and resolve support requests or investigate suspected abuse or security incidents. This access is limited to what's needed to resolve the specific issue, is never used to independently contact a Shop's customers or move funds, and is available for the Shop to see was used (see the in-app impersonation indicator). We do not use this access to review Shop or End Customer Data for any purpose other than support, security, or as required by law.

7. Data Retention and Deletion

We retain Account Data and End Customer Data for as long as the associated Shop account is active, plus the post-termination export window described in the Terms of Service, after which we will delete or anonymize it within [FILL IN — e.g. "90 days"], except where we are required to retain it longer for legal, tax, security-incident, or dispute-resolution purposes. Communications content (email/SMS logs) and payment/transaction records are retained for the same period unless a longer retention period is required by law (for example, financial recordkeeping requirements that may apply once a live payment gateway is active). ⚠ ATTORNEY / PRIVACY REVIEW: confirm actual retention periods against any state-specific insurance-record or financial-record retention statutes applicable to collision repair shops in the states where your Shops operate — this is a business-specific requirement a generic privacy policy can't answer for you.

8. Your Choices and Rights

8.1 Shop staff (Account Data). You can update your profile information in Settings, and can request account deletion by contacting [FILL IN SUPPORT EMAIL] or asking your Shop's owner to remove your account.

8.2 End customers. Because we act as a processor for End Customer Data (Section 1.2), please direct privacy requests about your own information to the collision repair shop you worked with, not to us directly; we will support that shop in fulfilling a valid request as required by our agreement with them.

8.3 State privacy law rights (e.g., CCPA/CPRA and similar laws). ⚠ ATTORNEY / PRIVACY REVIEW — this section needs real analysis before publishing: depending on your revenue, data volume, and the states your Shops and their customers are located in, you may be a "business" subject to the California Consumer Privacy Act (as amended by the CPRA) or similar laws in other states (e.g., Virginia, Colorado, Connecticut, Utah), which can grant rights to know, delete, correct, and opt out of certain processing, and may require a specific "Do Not Sell or Share My Personal Information" mechanism even though we state above that we do not sell personal information (the statutory definition of "sale"/"share" is broader than plain-English "sale"). Do not rely on the placeholder language here — have counsel confirm which thresholds apply to your actual business and add the specific rights-request mechanism required (e.g., a toll-free number or web form, response-time commitments, and an appeals process for denied requests).

8.4 Marketing communications. We do not use End Customer Data for marketing. If we ever send marketing communications to Shop staff (e.g., product update emails), we will include an unsubscribe mechanism.

9. Children's Privacy

The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child's information has been submitted to the Service, contact us at [FILL IN SUPPORT EMAIL] and we will investigate and delete it as appropriate.

10. Data Breach Notification

⚠ ATTORNEY / PRIVACY REVIEW (breach-notification obligations are state-specific, and several states have short mandatory notification windows — this is not a section to leave as boilerplate). In the event of a security incident that compromises personal information in a manner that triggers notification obligations under applicable law, we will notify affected Shops (and, where we act as a controller, affected individuals) without unreasonable delay and in accordance with applicable breach-notification laws, and will support each affected Shop in meeting its own notification obligations to its customers and, where required, state regulators, for incidents involving End Customer Data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date, and for material changes, will provide additional notice (e.g., email to Shop owners) at least [FILL IN — e.g. "30 days"] before the change takes effect.

12. Contact Us

Questions about this Privacy Policy, or requests related to your personal information, can be sent to [FILL IN PRIVACY CONTACT EMAIL] or [FILL IN MAILING ADDRESS].


This document is a draft prepared with the help of AI tooling based on the platform's actual data flows as of the date generated. It is not legal advice and has not been reviewed by an attorney or privacy professional. Do not publish or rely on it without review by counsel, particularly for the controller/processor split in Section 1, the state-privacy-law analysis in Section 8.3, and the breach-notification analysis in Section 10.

Terms of Service · Sign in