Privacy Policy
Version 1 · Last updated 16 April 2026
1. Who we are
Garaz ("we", "us") is a software service that helps mechanic shops track vehicles through repair workflows. For questions about this policy, contact privacy@garaz.io.
2. Data we collect
We collect the following categories of data:
- Account & authentication. Your name, email address, and a hashed password when you create or use a Garaz account.
- Demo requests. The name, email, phone, and company name you submit via the demo form on our landing page.
- Customer & vehicle data. When a mechanic shop enters data about its customers and vehicles into our service (vehicle details, owner contact, inspection results), the shop is the data controller. Garaz acts as a data processor on their behalf.
- Analytics (with consent). When you accept the Analytics cookie category, we collect anonymized page views, CTA clicks, scroll depth, and demo form submissions on our public landing page. We do not use analytics on signed-in pages.
3. Why we collect it
Under Article 6 of the EU General Data Protection Regulation (GDPR), we rely on the following legal bases:
- Contract (Art. 6(1)(b)) — to provide the service you signed up for.
- Legitimate interest (Art. 6(1)(f)) — to secure the service against abuse.
- Consent (Art. 6(1)(a)) — for analytics cookies, when you opt in.
4. Sub-processors
We use the following third-party services to run Garaz:
- Resend — transactional email delivery.
- Twilio — SMS delivery to shop customers.
- Viber Business — messaging delivery to shop customers.
- A Postgres database provider for primary storage.
Each sub-processor has its own data-protection agreement with us and processes data only on our instructions.
5. How long we keep data
- Account data: as long as the account is active, plus 30 days after deletion request.
- Customer/vehicle data: controlled by the shop; we delete on their instruction.
- Demo request data: up to 24 months for follow-up, then deleted.
- Analytics data: 13 months, then anonymized aggregates only.
6. Your rights
You have the right to access, correct, delete, or port your data, and to withdraw consent at any time. To exercise these rights, email privacy@garaz.io. You also have the right to lodge a complaint with your local data protection authority.
7. Cookies
We use the following cookie categories:
- Essential. The
tokencookie keeps you signed in. Always set. Expires after 7 days. - Analytics (opt-in). Loaded only if you accept via the cookie banner. You can change your choice anytime via the "Cookie settings" link in the footer.
8. Changes to this policy
We may update this policy. The version + last-updated date are shown at the top of this page. Material changes (new cookie categories, new sub-processors) will force a re-prompt of the cookie banner for existing visitors.
Related: Terms of Service.