Privacy Policy & Data Protection
Your customer records, flat rates, and parts inventory belong strictly to your auto repair shop. We never sell, rent, or monetize your business data.
CarsKeep legal architecture: strict commercial privacy for repair shops, zero data sharing with third parties, full GDPR compliance, and 1-click data export.
Status of Parties and General Terms
When utilizing the CarsKeep cloud platform, the auto repair shop (Client) acts as the Data Controller regarding personal data of its staff and vehicle owners.
CarsKeep operates strictly as a Data Processor, processing information solely upon the Client’s instructions to deliver core software functionality.
Categories of Processed Data
We collect only the minimal data volume necessary to operate modern auto repair workflows:
Processed Data Scope
- Shop Account Information: Legal entity name, registration credentials, contact persons, branch addresses, phone numbers, email.
- Workshop Staff Details: Technician names, bay specialty, flat-rate / hourly wages, completed work order logs.
- Car Owner Records: Full name, phone number (for WhatsApp repair tracker), vehicle make, model, VIN, plate number, repair and defect history.
- Technical Media Records: Photographic and video inspection logs of body damages and hidden defects captured via Digital Vehicle Inspections (DVI).
Zero Customer Database Monetization Principle
We fundamentally reject data brokering and monetization of independent repair shop databases.
CarsKeep under no circumstances sells, leases, licenses, profiles, or discloses repair shop client lists or parts inventory data to insurance carriers, parts distributors, advertising networks, or competitors. Your clients belong exclusively to you.
Data Processing Addendum (DPA) and Security Standards
All data in transit is encrypted using TLS 1.3 cryptographic suites with strict Perfect Forward Secrecy.
Data at rest is secured via symmetric banking-grade AES-256 database partition encryption.
Support engineering access to a tenant database is restricted and requires explicit owner approval via a temporary 4-hour expiring access token.
Authorized Sub-processors
- Hetzner Online GmbH (Germany): Secure EU cluster hosting (Tier III, ISO 27001).
- Selectel / Cloud.kz (Central Asia / CIS): Localized data center clusters ensuring sovereign data compliance.
- Amazon Web Services (AWS S3): Private encrypted object storage for media and daily snapshots.
- Twilio / Meta Platforms: Official WhatsApp Business API messaging delivery gateways.
International and Regional Compliance
The architecture strictly complies with European GDPR (Regulation EU 2016/679), Kazakhstan Personal Data Law, Azerbaijan Personal Data Law, Turkish KVKK, and regional data protection statutes.
Data Freedom Charter: Zero Vendor Lock-in Guarantee
We consider locking customer data hostage unethical. Shop owners have access to a 1-click comprehensive export button in system settings.
Exports are delivered in universal, open formats: Client Directory (clients.xlsx / csv), FIFO Inventory (inventory_fifo.xlsx), Work Order History (repair_orders.json / xlsx), DVI Media Archive (ZIP).
Upon subscription cancellation, accounts retain a 30-day read-only export grace period. Following this period, customer data is cryptographically shredded upon request across all live and backup media.
Questions regarding your data privacy?
Our Data Protection Officer is ready to provide clarifications and execute tenant-specific DPA agreements.
Data Protection Officer: [email protected]