Skip to main content

Privacy policy

Privacy, explained without hidden promises.

This policy describes how the current VehicleDesk website and managed workspace handle information today. It separates implemented behavior from future integrations and does not turn planned controls into production claims.

Last updatedAugust 26, 2026
Applies toCurrent production
Plaid statusNot deployed

At a glance

The shortest accurate version.

VehicleDesk processes shop operating data for enabled workflows. The public site does not intentionally use behavioral advertising trackers. Plaid Link and Plaid consumer data are not part of the current production application.

Public website

No behavioral ad network

Infrastructure sees ordinary request metadata. Public forms create a local email draft and submit nothing automatically.

Managed workspace

Shop data stays tenant-scoped

Roles and capabilities limit access to customer, vehicle, service, payment, consent, and operational records.

Consent

Communication choices are explicit

VehicleDesk stores consent and suppression evidence. Those controls do not create universal consent for every CRM record.

Plaid

No Plaid data today

Plaid Link, access-token storage, synchronization, and Plaid financial records are not deployed in production.

01

Scope and current status

This policy covers the live VehicleDesk marketing website and authenticated VehicleDesk workspace. VehicleDesk is a managed operating layer for independent repair shops; enabled workflows, support expectations, data roles, and integrations depend on the shop's approved implementation or commercial arrangement.

This page describes current production behavior. It does not claim that draft legal documents, repository-only checks, future integrations, or planned workflows are already operating.

02

Information VehicleDesk handles

The authenticated workspace can process information needed for enabled shop workflows, including:

  • Shop and staffBusiness profiles, settings, staff accounts, roles, authentication state, sessions, security notices, and access history.
  • Customers and communicationNames, contact details, communication preferences, consent, suppression, and do-not-contact status.
  • Vehicles and serviceVehicle identifiers, mileage, service context, repair orders, estimates, invoices, parts, appointments, reminders, and operational notes.
  • Operations and securityRecorded payments, weekly-close records, portal activity, worker status, synchronization evidence, data-quality findings, audit records, and bounded diagnostic metadata.

Shopmonkey remains authoritative for supported source repair and financial records imported through configured integration paths. VehicleDesk separately stores locally managed workflow, audit, consent, suppression, and operational records required for its own features.

03

How information is used

  • Provide authenticated CRM, daily operations, customer and vehicle context, parts and weekly-close workflows, appointments, reports, reminders, tasks, compliance visibility, and customer portal views.
  • Import or synchronize supported information from configured source systems and show connection, freshness, mapping, conflict, and data-quality evidence.
  • Authenticate users and enforce role, capability, tenant, origin, CSRF, rate-limit, consent, suppression, and incident-control boundaries.
  • Operate audit, security, backup, troubleshooting, support, and incident-response processes.
  • Prepare drafts or recommendations in guarded workflows where enabled. AI-assisted output does not itself send communications, change consent, or update Shopmonkey.
05

Service providers and sharing

VehicleDesk shares information only as needed to operate an enabled feature, follow an authorized shop instruction, protect the service, or meet an applicable legal obligation.

  • Production infrastructure providers process application traffic, stored records, operational logs, and security metadata needed to provide the service.
  • Configured Shopmonkey integration paths may process customer, vehicle, invoice, service, and payment information for authorized import or synchronization.
  • Communication, Google, or AI-assisted provider paths receive information only when the corresponding feature and production configuration are enabled.

The public website does not intentionally use a behavioral advertising network. VehicleDesk does not currently represent personal information as sold for behavioral advertising.

06

Security and access controls

Protected transportThe public site, authenticated frontend, and API support TLS 1.2.
Account controlsServer-managed sessions, tenant-scoped roles, mutation protections, rate limits, and TOTP MFA protect authenticated access.
Scoped portalsCustomer portal links are designed to be expiring, revocable, token-hash based, and read-only for the permitted customer view.
Bounded supportSupport diagnostics require a shop-approved, time-bounded, scoped grant and a case-specific audited reason.

VehicleDesk does not claim that every database field is individually encrypted, that every hosted security workflow is currently executing, or that the service is SOC 2 certified.

07

Retention, export, deletion, and offboarding

VehicleDesk does not currently publish a universal time-based retention schedule covering every application table, provider log, backup, export, and subprocessor. Records follow their implemented product lifecycle, shop operations, source-system behavior, and provider configuration.

  • Specific records can be revoked, archived, or deleted through guarded product workflows where those actions exist.
  • General customer deletion across all related CRM, audit, provider, and backup records is not currently available as an automated privacy workflow.
  • A shop-wide export and offboarding process is planned but is not represented here as fully automated or exercised.
  • Suppression and opt-out evidence may be retained to avoid reactivating contact contrary to the recorded preference.
08

Current Plaid status

Before Plaid is enabled, VehicleDesk requires a separately approved pre-Link notice and consent flow, product and account minimization, encrypted token custody, authorization history, retention, disconnection, export, deletion, backup, and operational evidence.

09

Privacy requests and contact limitation

A monitored public privacy-request mailbox or public privacy-request form is not configured in the current production environment. Outside privacy requests are not accepted through the public website today.

Existing workspace users should use the approved implementation or commercial support channel supplied to their shop. A shop remains responsible for requests concerning customer data it controls.

10

Children, policy updates, and legal status

VehicleDesk is a business application for repair shops and staff and is not directed to children.

This policy will be reverified when the production release, hosting architecture, public contact configuration, provider activation, retention or deletion behavior, shop agreement, or privacy practices materially change.

This is a current operational policy, not legal advice or a compliance certification. It has not been represented as reviewed by external privacy counsel.