Privacy Policy

How we collect, use, and protect your data. Last updated: April 2026.

1. Data Controller

GarageSync Ltd ("we", "us", "our") is the data controller responsible for your personal data. We are registered in England & Wales and operate the platform at garagesync.co.uk.

Contact: privacy@garagesync.co.uk

2. Data We Collect

Account Information

When you register, we collect your name, email address, phone number, business name, and address. For tenant administrators, we also store role and permission settings.

Customer Data

Garage operators ("tenants") may store their customers' data within GarageSync, including names, contact details, vehicle information, repair history, and payment records. Tenants are the data controllers for their customer data; GarageSync acts as a data processor.

Payment Information

Payment card details are processed directly by our payment partners (Stripe, PayPal, GoCardless) and are never stored on our servers. We store transaction references, amounts, and billing history.

Usage Data

We collect information about how you use the platform, including pages visited, features used, browser type, IP address, and device information.

Communication Data

When notifications are sent via SMS (Twilio), email, or WhatsApp, we retain delivery status and metadata. Message content is stored temporarily for delivery purposes.

3. How We Use Your Data

  • To provide and maintain the GarageSync platform
  • To process payments and manage subscriptions
  • To send service notifications (repair updates, payment confirmations)
  • To provide customer support
  • To improve our platform and develop new features
  • To comply with legal obligations

4. Third-Party Services

We share data with the following third parties, only as necessary to provide our services:

  • Stripe — payment processing
  • PayPal — payment processing
  • GoCardless — Direct Debit / SEPA payment processing
  • Twilio — SMS and WhatsApp notifications
  • SMTP providers — email delivery

Each third party processes data under their own privacy policy and in compliance with applicable data protection laws.

5. Data Retention

We retain your account data for as long as your account is active. After account deletion or subscription cancellation, we retain data for up to 90 days before permanent deletion. Financial records are retained for 7 years as required by UK law.

6. Your Rights (UK GDPR)

Under the UK General Data Protection Regulation, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your data
  • Restrict processing — limit how we use your data
  • Data portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent

To exercise any of these rights, contact us at privacy@garagesync.co.uk. We will respond within 30 days.

7. Cookies

We use cookies to maintain your session and improve your experience. For full details, see our Cookie Policy.

8. Security

We implement industry-standard security measures including encrypted connections (TLS), secure password hashing, prepared database statements to prevent injection attacks, and regular backups. Each tenant's data is stored in an isolated database.

9. Changes to This Policy

We may update this policy from time to time. We will notify registered users of significant changes via email. Continued use of the platform after changes constitutes acceptance.

10. Contact

For privacy-related enquiries:

Email: privacy@garagesync.co.uk
GarageSync Ltd, United Kingdom