Skip to content

Privacy policy

Last updated: 3 September 2026

This policy explains what personal data is processed through the AutoGarage.pro platform, by whom, for what purpose, on what legal basis, who it is shared with, how long it is kept, and what rights you have over it. It is written for two kinds of reader: the auto repair shops that use the application, and those shops' own customers, whose data ends up in it.

WORK IN PROGRESS. This is a structured draft, prepared to be reviewed and completed by a lawyer before launch. Every field marked [COMPLETEAZĂ: …] must be filled in; until then this document has no legal effect and must not be published as a final version.

Who we are

The AutoGarage.pro platform is operated by:

Legal name:
APOLOS S.R.L.
Registration code:
52585340
Trade register:
J2025073564008
Registered office:
Sat Valea Lupului, Comuna Valea Lupului, Strada Ecaterina Teodoroiu nr. 19, etaj, cam. 3, Jud. Iași
Email:
apolossrl@gmail.com

We have not appointed a data protection officer (DPO). Whether an appointment is required in our case is a legal question still to be confirmed, not a claim we make here. For any question about personal data you can write directly to the address above. [COMPLETEAZĂ: the lawyer confirms whether a DPO or an Article 27 representative is required and, if so, adds the details here.]

Two different roles: controller and processor

For your workshop account's own data (the company name, billing details, the email addresses of the staff who sign in, the shop's settings) AutoGarage.pro is the CONTROLLER. We decide why and how that data is processed, and the basis is the contract between us.

For the workshop's customers' data (their names, phone numbers, emails, addresses, vehicles, work orders, quotes and appointments) AutoGarage.pro is a PROCESSOR. The controller of that data is the workshop that enters it. We process it only on the workshop's instructions, in order to provide the application, and never for our own purposes.

What that means in practice: if you are a workshop's customer and want to know what data is held about you, or want it erased, contact that workshop. It is the controller, and it has the export and erasure tools inside the application. You may also write to AutoGarage.pro directly and we will pass the request on, but we cannot decide on the workshop's behalf.

What data we process

Depending on your role, the following categories of data may be processed through the platform:

  • Workshop account data: email address and password (stored only as a hash by the authentication provider), the user's full name, their role in the workshop, preferred language, company details (name, registration code, address, bank account, phone) and subscription data.
  • Workshop customer data: name, phone, email, city, county, address, company name, registration code, and identity-document series/number, to the extent the workshop chooses to enter them. None of these fields except the name is mandatory.
  • Vehicle and job data: registration plate, make, model, chassis number, mileage, technical details, roadworthiness and insurance expiry dates, work orders, quotes, invoices and appointments.
  • Generated documents: quotes and invoices as PDF files, containing the customer's name and, where filled in, their billing details as they stood at the time of issue.
  • Messages sent: the recipient's email address or phone number, the channel used, when it was sent, and the message parameters (for example an appointment date or a registration plate).
  • Technical data: the visitor's IP address, used solely to rate-limit the public booking form and document scanning, and session data stored in strictly necessary cookies. Separately, inside the workshop application (once signed in) we collect diagnostic data, namely browser errors, load times and, for a small share of sessions, a recording of the screen with all text masked, on the basis of our legitimate interest in keeping the application working. None of that is collected on the public pages.

Photographs of a vehicle registration document or an ID card are NOT stored. The image is sent to the text-recognition provider, the extracted fields are shown in the form for checking, and the image is dropped from the application's memory immediately afterwards. All that remains in our database is the document type, whether the scan succeeded, and the technical cost of the operation. Never the image.

The national identity number (CNP / IDNP) has no field in the application and is never stored. When an ID scan reads one, the value is destroyed at the moment the scan result comes into existence; if the document's series and number could not be read, the value is used once as a document number, and the "ID document" field the workshop may fill in holds a document number, not a national identity number.

Vehicle photographs, if the workshop uploads them, are stored in a private space separated per workshop and reachable only by that workshop's signed-in users.

Why, and on what basis

We process the data above for the following purposes:

  • Providing the application to the workshop: performance of a contract (Art. 6(1)(b) GDPR) for account data, and processing on the controller's instructions (Art. 28 GDPR) for the workshop's customer data.
  • Public visibility of the shop: the auto repair shop’s name, city, county, logo and public description appear on its public page (/s/[code]) and, as long as the “Public page” setting stays on (on by default), in the searchable directory at /services, so customers can find you, on the basis of contract performance (Art. 6(1)(b) GDPR). Contact, billing and internal data always stay private.
  • Sending notifications and reminders about job status, appointments, and roadworthiness or insurance expiry, on the workshop's instructions, in its legitimate interest in informing its customers about the service they asked for, with the right to object at any time.
  • Billing the workshop's subscription: performance of a contract and statutory accounting and tax obligations.
  • Complying with our own legal obligations, in particular accounting and tax ones (Art. 6(1)(c) GDPR).
  • Platform security: limiting abuse of the public forms and preventing unauthorised access, on the basis of legitimate interest (Art. 6(1)(f) GDPR).

We take no automated decisions with legal effects on you and we do not profile. We do not sell personal data and do not use it for advertising, ours or anyone else's.

Who we share data with

To operate, the platform uses the following providers, who process personal data on our behalf. The list below is generated from the application's own code and checked automatically, in two ways: we sweep the code for calls to external hosts AND we check every library installed in the application. If a new provider appears and is not listed here, whether through an address called directly or through a package that builds its own address, the build's tests fail until somebody declares it.

ProviderWhat it is used forWhat data it receivesWhere processing happens
SupabaseThe application's database, authentication, file storage and server functions.All data entered into the application, including account data and the workshop's customer data.Outside the EEA, under an adequacy decision or standard contractual clauses
VercelHosting the web application and delivering pages to the browser.The data contained in HTTP requests, including the IP address and the contents of submitted forms.Outside the EEA, under an adequacy decision or standard contractual clauses
AnthropicAutomatic text recognition from a scanned vehicle registration document or ID card.The image of the scanned document, sent for processing. The image is not stored by us; how the provider handles it is set out in its own policy.Outside the EEA, under an adequacy decision or standard contractual clauses
ResendSending transactional email: notifications to the workshop's customers.The recipient's email address and the message content.Outside the EEA, under an adequacy decision or standard contractual clauses
Meta Platforms (WhatsApp Business Cloud API)Sending WhatsApp messages, when the workshop enables that channel.The recipient's phone number and the message parameters.Outside the EEA, under an adequacy decision or standard contractual clauses
SMSO (smso.ro)Sending SMS messages, when the workshop enables that channel.The recipient's phone number and the message text.European Union / EEA
TwilioSending SMS messages as an alternative to the primary provider.The recipient's phone number and the message text.Outside the EEA, under an adequacy decision or standard contractual clauses
StripeCollecting the workshop's subscription payment.The workshop's billing details and payment data. Card details are entered directly with the payment provider and never reach our servers. The workshop's customers do not appear in this relationship at all.Outside the EEA, under an adequacy decision or standard contractual clauses
DatadogTechnical monitoring of the application: browser errors, load times and server logs, so we can see when something breaks or slows down. It loads ONLY on screens reachable after signing in, never on the public pages, and never on the sign-in or sign-up pages.IP address, browser and device type, which application pages you opened, any errors that occurred and, for a small share of sessions, a recording of what the screen looks like. In those recordings ALL TEXT IS MASKED automatically: customer names, registration plates, phone numbers and invoice amounts are not transmitted, and only the page structure is visible. We do not link a session to your name or email address. Storage takes place on the provider's European infrastructure (the datadoghq.eu site).Outside the EEA, under an adequacy decision or standard contractual clauses

Where a provider processes data outside the European Economic Area, the transfer takes place under a European Commission adequacy decision or standard contractual clauses. [COMPLETEAZĂ: the lawyer confirms, for each provider, which of the two applies under the signed contract.]

Each provider above publishes its own privacy policy on its website. We do not include external links here, because AutoGarage.pro's public pages load nothing from third parties and send nothing to them.

How long we keep data

The periods below describe what the application actually does, not merely what was intended:

  • Account data and data entered by the workshop: kept for as long as the account exists. When the account is deleted, the data associated with it goes with it.
  • The history of sent messages: deleted automatically 90 days after it was created. The exception is messages still queued, which are kept until they are processed, precisely so that a stall stays visible.
  • Technical records used for rate limiting, which contain IP addresses: deleted after 24 hours.
  • Issued invoices: kept for the period required by the applicable accounting and tax law, with the buyer's identifying details on them, even if erasure of the person's data has been requested in the meantime. Issued quotes are NOT covered by that obligation. They are kept as job history, but the identifying details copied onto them are anonymised on erasure. Invoice retention period: 5 years.
  • Scanned images: not kept at all, as described above.

When a workshop permanently erases a customer's data at their request, the name, phone, email, address, company details and identity-document number on the customer record are replaced irreversibly, as are the name and phone copied onto appointments and onto messages already sent, and the customer is excluded from any future message. The identifying details copied onto quotes already issued are replaced too.

WHAT STILL EXISTS AFTER AN ERASURE. We would rather tell you exactly, so that you can check: (1) invoices already issued, carrying the name, company name, registration code and address frozen at the moment of issue (see the next paragraph); (2) the vehicle record, INCLUDING ITS REGISTRATION NUMBER, chassis number, make, model and any photographs uploaded; (3) the job history, meaning the work orders and quotes with their date, mileage and status, which stay linked to the anonymised customer record; (4) appointments, which lose the name and the phone but keep the vehicle's registration number and whatever free text was typed into them; (5) free text typed by hand by workshop staff into work orders and appointments (notes, faults, requests, customer-supplied parts): if somebody wrote a name or a phone number there, the erasure does not change it automatically. In short: after an erasure you can no longer be identified from the customer record, but the registration number, the invoices issued and any hand-written notes remain in the workshop's records.

EXACTLY ONE CATEGORY IS EXEMPT: INVOICES. An invoice is an accounting document, and the law requires it to be kept intact with the buyer's identifying details on it. An invoice with the buyer removed is no longer a valid invoice. The basis is Art. 17(3)(b) GDPR: the right to erasure yields to a legal obligation. Concretely: after an erasure request, the person's name, company name, registration code and address remain on invoices already issued for 5 years. Beyond the invoices, the customer record no longer holds identifying details, but that does not mean nothing about the person remains: what does remain is listed, point by point, in the paragraph above. Quotes are not covered by that obligation, because they are offers rather than accounting documents, which is why they are anonymised, including those an invoice was later raised from.

Your rights

Under the GDPR you have the following rights:

  • The right of access: to find out whether your data is processed and to receive a copy of it.
  • The right to rectification: to have inaccurate data corrected and incomplete data completed.
  • The right to erasure, within the limits of statutory retention obligations.
  • The right to restriction of processing, in the cases the law provides for.
  • The right to portability: to receive your data in a structured, commonly used, machine-readable format.
  • The right to object to processing based on legitimate interest, including reminders.
  • The right to withdraw consent where processing is based on it, without affecting the lawfulness of processing before withdrawal.

If you are a workshop's customer, contact the workshop directly: it is the controller of your data. The application gives it a button that exports everything it holds about you as a machine-readable file, and a button that erases it permanently.

The export file contains your customer record, your vehicles, the work orders, the quote headers, the INVOICES issued in your name, the appointments and the messages sent to you. It covers the right of ACCESS (Art. 15) in full. The right to PORTABILITY (Art. 20) is narrower: it reaches only data processed on the basis of a contract or of consent, so it does not cover the invoices, which are kept under a legal obligation, or the message history, which is sent in the workshop's legitimate interest. The file itself states, in a section of its own, which tables fall under each of the two rights.

If you hold a workshop account, write to the address in the contact section. We answer within one month of receiving the request; that period may be extended in the cases the GDPR allows, and we will tell you if it is.

Every reminder email carries an unsubscribe link that stops future messages to that person immediately, with no written request needed.

Data security

The technical measures we apply:

  • Isolation between workshops is enforced in the database itself, through row-level access policies, not only in application code: a user of one workshop cannot read another's data even if the request is tampered with.
  • All traffic between the browser and the platform, and between the platform and its providers, is encrypted.
  • Access to sensitive operations, such as permanently erasing a customer's data, is restricted to the account owner and checked in the database, not only in the interface.
  • Credentials a workshop entrusts to us for external integrations are stored encrypted and cannot be read back through the application by anyone, including the account owner.

In the event of a data breach that poses a risk to people's rights, we notify the competent supervisory authority within 72 hours of becoming aware of it and inform the people affected where the law requires it.

We hold no security certification (for example ISO 27001 or SOC 2) and do not claim to. We would rather say so plainly than leave room for interpretation.

Cookies

AutoGarage.pro's public pages use no analytics or marketing cookies and load no third-party script, font or visual element. Only strictly necessary cookies are used. Inside the workshop application, once you are signed in, a session cookie belonging to our technical monitoring tool (Datadog) is added. All of them are described in full in the cookie policy.

Read the cookie policy

Minors

The application is addressed exclusively to companies and professionals. We do not address minors and do not knowingly collect their data. If a workshop enters a minor customer's data, responsibility for the basis of that processing lies with the workshop, as controller.

Changes to this policy

We may update this policy when the platform changes or when new legal requirements appear. The date of the last update is shown at the top of the document. If a change is substantial, we tell account holders by email before it takes effect.

Contact and complaints

For any question about this policy, or to exercise your rights, write to us at apolossrl@gmail.com.

If you are in Romania and believe your rights have been infringed, you may lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), Bucharest.

If you are in the Republic of Moldova, the competent authority is the National Centre for Personal Data Protection (CNPDCP), Chișinău.

See also the terms of service