Privacy Policy

Effective April 10, 2026

1. What We Collect

When you use ShopBay.Studio, we collect:

  • Account information: Name, email address, and shop details you provide during registration.
  • Customer data you enter:Names, contact information, vehicle details, and repair history for your shop's customers. You own this data.
  • Usage data: Pages visited, features used, and actions taken within the Service (for improving the product).
  • Technical data: IP address, browser type, device type, and error logs (for security and debugging).
  • Payment information: Payment processing is handled by Stripe. We store only the last 4 digits and card brand for display purposes — we never store full card numbers.

2. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Process payments and send billing communications
  • Send transactional emails and SMS (invoices, appointment reminders, service updates)
  • Respond to support requests
  • Monitor for security threats and prevent abuse
  • Comply with legal obligations

We do notsell your data or your customers' data to third parties. We do not use your data for advertising.

3. Data Sharing

We share data only with:

  • Supabase — database and authentication infrastructure
  • Stripe — payment processing (subject to Stripe's Privacy Policy)
  • Twilio— SMS communications (subject to Twilio's Privacy Policy)
  • Resend — transactional email delivery
  • Vercel — hosting and infrastructure
  • Sentry — error monitoring (error details and stack traces only; no PII)

We may disclose data if required by law, court order, or to protect the rights, property, or safety of ShopBay.Studio, our users, or the public.

4. Data Retention

We retain your account data for as long as your account is active or as needed to provide the Service. If you cancel your account, we will retain your data for 30 days (to allow recovery), then delete or anonymize it within a further 30 days. You may request earlier deletion by contacting us.

5. Your Rights

Depending on your location, you may have the right to:

  • Access — request a copy of the data we hold about you
  • Correction — request that we correct inaccurate data
  • Deletion — request deletion of your account and associated data
  • Portability — request your data in a machine-readable format
  • Objection — object to certain processing of your data

To exercise these rights, email privacy@shopbay.studio. We will respond within 30 days.

6. Security

We protect your data using industry-standard measures including encryption in transit (TLS), encryption at rest, Row-Level Security (RLS) at the database layer, multi-factor authentication options, and regular security audits. No system is 100% secure; if you discover a vulnerability, please report it to security@shopbay.studio.

7. Cookies

We use strictly necessary cookies to maintain your login session (HTTP-only, secure). We do not use advertising cookies or cross-site tracking. We use Vercel Analytics for aggregate, privacy-respecting usage statistics that do not identify individual users.

8. Children

The Service is not directed to individuals under 18. We do not knowingly collect personal information from minors. If you believe we have collected data from a minor, please contact us immediately.

9. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by email and by displaying a notice in the Service. The effective date at the top of this page will always reflect the most recent version.

10. Contact

Questions or concerns about this policy? Contact us at privacy@shopbay.studio.