1. Who we are and when this policy applies
WrenchOps Inc ("WrenchOps," "we," "us," or "our") provides business software for auto repair shops. This policy applies to our websites, applications, support communications, and related services (collectively, the "Service").
WrenchOps is intended for businesses and their authorized workers. A shop or other organization that creates a workspace controls the operational records entered into that workspace. For those records, WrenchOps Inc acts as a service provider and processes information on the organization's instructions. We act directly as the accountable organization for website, account, billing, security, and support information that we collect for our own business purposes.
2. Information we collect
Account and workspace information
We collect account identifiers and profile details such as name, email address, profile image, authentication identifiers, current workspace, membership, permissions, staff roles, invitations, and workspace business details. If you contact us, we collect the contents of your request and the information needed to respond.
Shop and work-order information
Authorized users may enter customer names and contact details; vehicle information such as year, make, model, licence plate, VIN, and images; work orders, assignments, statuses, inspections, tracked time, comments, estimates or operational notes; and photos, videos, documents, or other uploaded media. Some records may contain information about employees, contractors, customers, or other individuals supplied by the workspace organization.
Sharing, notifications, and communications
We process workspace invitations, client-share recipient emails, secure share links, access-code records, operational email delivery information, in-app notifications, and browser-push tokens. Notification permissions can be changed in the Service or in your browser settings.
Billing information
We collect subscription status, billing interval, workspace and seat allocations, Stripe customer and subscription references, invoice status, and related billing events. Stripe processes payment-card and payment-method details; WrenchOps does not store complete payment-card numbers.
Device, usage, cookie, and local-storage information
We and our providers may collect IP address, browser and device type, operating system, pages viewed, referring pages, approximate location derived from IP, timestamps, diagnostic events, and interaction data. We use essential session cookies to keep users signed in, preference cookies for interface settings, and browser local storage to complete email-link sign-in. Our landing pages use Firebase Analytics, which may use cookies or similar identifiers to measure visits and usage. You can limit non-essential cookies through your browser settings, although blocking essential storage may prevent parts of the Service from working.
3. How we use information
We use information to:
- provide, authenticate, secure, maintain, and improve the Service;
- create and administer workspaces, roles, subscriptions, and support requests;
- process work orders, assignments, tracked time, uploads, client shares, and notifications as directed by workspace organizations;
- process payments, prevent fraud and abuse, enforce our agreements, and comply with law;
- understand website and product performance and diagnose technical problems; and
- send transactional messages and, where permitted by law and consented to where required, commercial communications.
We collect, use, and disclose personal information with consent or as otherwise permitted by applicable law. Consent may be express or implied depending on the sensitivity of the information and the context. You may withdraw consent subject to legal or contractual restrictions, but doing so may affect our ability to provide the Service.
4. How we disclose information
We may disclose information:
- to authorized members of the relevant workspace according to their roles and settings;
- to a client or other recipient when an authorized user creates and sends a secure share;
- to Google, Firebase, and Google Cloud for authentication, hosting, databases, storage, messaging, and analytics;
- to Stripe for subscriptions, payment processing, invoices, and billing management;
- to Resend and related delivery infrastructure for authentication, invitations, shares, and operational email;
- to professional advisers, auditors, insurers, or prospective transaction parties under appropriate confidentiality obligations; and
- when required by law, to protect rights or safety, investigate misuse, or complete a corporate transaction.
We do not sell personal information.
5. International processing and safeguards
Our service providers may process or store information in Canada, the United States, or other countries where they operate. Information in another country may be available to courts, law enforcement, or regulators under that country's laws. We use contractual, administrative, technical, and organizational safeguards appropriate to the sensitivity of the information, including access controls, workspace authorization, encrypted network transmission, restricted service credentials, and logging. No service can guarantee absolute security.
6. Retention and deletion
We retain personal information only as long as reasonably necessary for the purposes described in this policy, to provide the Service, maintain security and business records, resolve disputes, or meet legal obligations. Retention varies by record type and workspace instructions. Workspace owners can delete operational records and can permanently delete a workspace through the Service. Deletion may remove members, invitations, customers, vehicles, work orders, comments, time entries, notifications, and uploaded media. Limited information may remain temporarily in backups or where retention is required for legal, fraud-prevention, accounting, or security purposes.
7. Your choices and privacy rights
Subject to applicable law, you may request access to or correction of personal information, ask about our processing and service providers, withdraw consent, or make a complaint. You may also manage browser notifications, analytics storage, and cookies through the Service or your browser.
If your information was entered by a repair shop or another WrenchOps customer, contact that organization first because it controls the workspace record. We will assist the organization as appropriate. We may need to verify identity and authority before fulfilling a request.
8. Business use and third-party links
The Service is not directed to children and is intended for business use by adults authorized by their organization. Our websites and Service may link to third-party services. Their privacy practices are governed by their own policies.
9. Changes to this policy
We may update this policy as our practices, providers, or legal obligations change. We will post the revised policy on this page and change the effective date. We encourage you to review it periodically.
10. Contact us
Direct privacy questions, requests, or complaints to the Privacy Officer, WrenchOps Inc, at contact@wrenchops.ca.