1. Who we are
GarageFlow is shop management software for auto repair businesses. This policy is issued by GarageFlow Systems OÜ, a Osaühing (private limited company) registered in Estonia in the Estonian Business Register (Äriregister) under registry code 17601459, with its registered office at Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia.
For any question about this policy or about how we handle personal data, write to [email protected]. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR.
2. Two roles: please read this first
GarageFlow handles personal data in two distinct capacities, and which one applies changes who is responsible for what. This is the most important section of this policy.
| Capacity | Whose data | Who decides how it is used |
|---|---|---|
| Controller | Repair shops that subscribe to GarageFlow, and the staff members they invite — account, billing, and usage data. | We do. This policy governs it. |
| Processor | The shop's own customers, vehicles, orders, invoices, messages, and inspections — everything a shop enters into the product. | The shop does. We act only on their documented instructions. |
If you are a vehicle owner who received a booking link, an estimate to approve, an invoice, or a message from a repair shop using GarageFlow: the shop is the controller of your data, not us. We host and process it on their behalf. Direct requests about your data to the shop you dealt with. If you cannot reach them, contact us at [email protected] and we will help you identify and reach the right controller.
3. Data we collect as a controller
| Category | Examples | Lawful basis |
|---|---|---|
| Account data | Name, email address, password (stored only as a hash), role, language preference | Performance of a contract — Art. 6(1)(b) |
| Shop data | Business name, address, VAT number, currency, branding, subscription plan | Performance of a contract — Art. 6(1)(b) |
| Billing data | Subscription status, plan, invoices, payment-provider customer identifier. We never see or store full card numbers. | Contract and legal obligation — Art. 6(1)(b), (c) |
| Authentication data | Sessions, API tokens, single-use sign-in-link tokens (stored hashed) | Performance of a contract — Art. 6(1)(b) |
| Security and audit logs | Administrative actions taken on the platform, sign-in events | Legitimate interests — Art. 6(1)(f): securing the service |
| Technical error records | Diagnostic information when something fails, retained 30 days | Legitimate interests — Art. 6(1)(f): keeping the service working |
| Enquiries | Anything you send us through the contact form or by email | Legitimate interests / pre-contractual steps — Art. 6(1)(f), (b) |
We do not run advertising, we do not profile you, and we make no decisions about you by automated means that produce legal or similarly significant effects.
4. Data we process on behalf of repair shops
When a shop uses GarageFlow, it enters data about its own business and customers. We process it solely to provide the service, under the shop's instructions and our Data Processing Agreement. This typically includes:
- Customer records — name, phone, email, company, address, notes, tags, contact and language preferences
- Vehicle records — make, model, VIN, registration plate, mileage history, photographs
- Work records — estimates, repair orders, inspections and their findings, parts and labour
- Financial records — invoices, payments, and payment terms
- Correspondence — messages exchanged between the shop and its customers through the product
- Approvals — electronic signatures captured when a customer authorises work
- Staff time records — clock-in and clock-out entries for the shop’s own employees
- Marketing records — whether a customer has opted out of marketing, which campaigns and service reminders they were sent, and whether each was delivered, opened, or clicked
- Review records — review invitations sent, and reviews the shop has received on its connected Google Business Profile
Shops are responsible for having a lawful basis for this data, for telling their own customers how it is used, and for not entering special categories of personal data (such as health data) into free-text fields. We do not use this data for our own purposes, we do not sell it, and we do not use it to train artificial-intelligence models.
6. Marketing emails and service reminders
If you are a customer of a repair shop:that shop may use GarageFlow to send you service reminders — that your oil change is due, that work you deferred is still outstanding — and occasional offers, along with invitations to review the work. The shop decides who receives these and what they say. It is the controller for them, and it is responsible for having a lawful basis to send them. We provide the tool and send on the shop's instructions.
Every one of these messages carries an unsubscribe link, and mail clients that support one-click unsubscribe will show a button of their own. Unsubscribing takes effect immediately and applies to all marketing from that shop. It never stops the messages you need — the confirmation of your appointment, a reminder that it is tomorrow, your invoice, a receipt — which are sent to carry out the work you asked for, not to market to you, and which you can control separately by telling the shop.
Where a booking form we host collects your address, it offers this choice at that point, so you can decline before anything is ever sent.
So that shops can see whether their messages work, we record whether each one was delivered, whether it was opened, and whether a link in it was clicked, and — via the gfc cookie described above — whether a click led to a booking. This is measurement for the shop that sent the message. It is not combined across shops, not used to build a profile of you, and not shared with advertisers.
To stop marketing from a shop, use the unsubscribe link in any of its messages or ask the shop directly. If you cannot reach them, contact us at [email protected] and we will pass it on.
7. Artificial intelligence
GarageFlow includes two optional AI features, both of which draft text for a person to review. Neither makes a decision about anyone, and neither produces anything that reaches a customer without a human choosing to send it.
- Suggested replies — a shop employee can ask for a draft answer to a customer message. The recent messages in that conversation, with the customer name, vehicle, and shop context, are sent to our AI provider, Anthropic, to generate it.
- Suggested review responses — a shop can ask for a draft reply to a review on its Google Business Profile. The review text, the reviewer name as it appears publicly on Google, the star rating, and the shop context are sent to Anthropic to generate it.
In both cases the draft appears on screen for a human to read, edit, and decide whether to use. Nothing is published or sent automatically — a review reply in particular is never posted to Google without someone approving it. Data sent for these purposes is not used to train the provider's models. Both features are off unless a shop enables them, and a shop that prefers not to use AI at all can simply not use the buttons.
8. Service providers and sub-processors
We use a small number of vetted providers to run the service. Each is bound by a data processing agreement and may use personal data only to provide their service to us.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting, primary database, and file storage | Germany (EU) |
| Stripe | Subscription billing and card payments | EU / United States |
| MailerSend | Sending and receiving email | United States |
| Pusher | Real-time updates in the app | EU / United States |
| Anthropic | AI suggested replies to customer messages and to reviews (optional) | United States |
| Customer sign-in to the portal, and Business Profile reviews (optional) | United States | |
| Meta | WhatsApp messaging (optional) | EU / United States |
| Intuit QuickBooks | Accounting sync (optional) | United States |
| Xero | Accounting sync (optional) | New Zealand |
| Teya | Card payment processing (optional) | Iceland (EEA) |
Providers marked optional are used only if a shop chooses to connect that integration. We maintain this list as our providers change, and we notify subscribing shops in advance of adding a new sub-processor so they have the opportunity to object. The same list, with the transfer safeguard relied on for each, is Annex III of our Data Processing Agreement.
We also use a third-party vehicle catalogue to populate makes, models, and trim levels. That service receives no personal data — we download a reference list of vehicle specifications and store it on our own servers — so it is not a sub-processor.
9. Where your data is held
Our application servers, primary database, and file storage are all hosted by Hetzner in Nuremberg, Germany. Your data — accounts, customers, vehicles, orders, invoices, messages, and every document and photograph you upload — is stored in the European Union and stays there.
Some of the providers listed above are established outside the EEA. Where personal data is transferred to them, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies to that country. You may request a copy of the safeguards in place by writing to [email protected].
10. How long we keep data
| Data | Retention period |
|---|---|
| Shop and account data | For the life of the subscription, then 90 days before deletion |
| Customer and work records entered by a shop | Until the shop deletes them, or 90 days after the subscription ends |
| Invoices and accounting records | Seven years, where required by tax and accounting law |
| Technical error records | 30 days |
| Security and audit logs | 12 months |
| Backups | Rolling, overwritten within 30 days |
| Contact-form enquiries | 24 months |
A shop can delete an individual customer record at any time from within the product, which removes that record from the live service.
11. Your rights
Where we are the controller of your data, you have the right to:
- Access the personal data we hold about you, and receive a copy
- Have inaccurate data corrected
- Have your data erased, where no legal obligation requires us to keep it
- Restrict or object to processing based on our legitimate interests
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time, where we relied on consent
- Lodge a complaint with a data protection authority
Write to [email protected] to exercise any of these. We respond within one month. We do not charge for this, and we will not treat you differently for asking.
If you are a vehicle owner whose data was entered by a repair shop, please direct these requests to that shop — they are the controller. If they do not respond, we will assist you in reaching them.
Our supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — https://www.aki.ee/en. You may also complain to the data protection authority in your own country of residence.
12. How we protect data
Data is encrypted in transit. Passwords are stored only as salted hashes and are never recoverable. Each shop's data is isolated so that one shop cannot reach another's records. Access to production systems is restricted to those who need it, and administrative actions are logged.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform affected users without undue delay. Security concerns can be reported to [email protected].
13. Children
GarageFlow is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
14. Changes to this policy
We will update this policy as the service changes. The version number and effective date at the top of this page always reflect the current text. If a change materially affects your rights, we will notify subscribing shops by email before it takes effect.