Privacy Policy

Last updated: January 17, 2025

GarageGo

Privacy Overview

GarageGo Inc. ("we", "our", "us") operates the GarageGo platform, which connects vehicle owners with automotive service providers in Quebec, Canada. This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our mobile application, web application, and related services.

We are committed to complying with applicable privacy laws, including Quebec's Act respecting the protection of personal information in the private sector and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Information We Collect

1.1 Account Information

  • Name, email address, and phone number
  • Profile picture (optional)
  • Account credentials and authentication data
  • User type (Driver or Garage owner)
  • Language preferences
  • OAuth authentication data (Google, Apple)
  • Social media profile information when using OAuth

1.2 Location Information

  • Current location (when using location-based features)
  • Garage addresses and service areas
  • Service request locations
  • Route and navigation data
  • Quebec address validation and geocoding data
  • Manual address entries and preferences

Location data is collected only when you grant permission and is essential for connecting you with nearby services. We validate addresses against Quebec postal codes and service areas.

1.3 Vehicle Information

  • Vehicle make, model, year, and VIN (Vehicle Identification Number)
  • License plate number
  • Vehicle photos and documentation
  • Service history and maintenance records
  • VIN decode data from NHTSA (National Highway Traffic Safety Administration)
  • Vehicle specifications (engine, fuel type, manufacturing details)
  • Quebec compliance status and validation notes
  • Standardized vehicle make information from Quebec market database

1.4 Service and Transaction Data

  • Service requests and descriptions
  • Quotes, pricing, and booking information
  • Payment and billing information through Stripe
  • Reviews and ratings
  • Communication records between users
  • Commission calculations and fee structures
  • Subscription plan details and usage metrics
  • Quebec tax compliance data (GST/QST)

1.5 Technical Information

  • Device information (type, operating system, version)
  • App usage data and analytics
  • IP address and network information
  • Push notification tokens
  • Crash reports and error logs
  • Real-time connection data (WebSocket/SSE)
  • Platform identification headers

1.6 Business Information (Garages)

  • Business name, address, and contact information
  • Business licenses and certifications
  • Insurance documentation
  • Services offered and specializations
  • Business hours and availability
  • Financial and tax information for billing
  • Public profile information and photos
  • SEO keywords and descriptions
  • Profile slugs for public directory listings
  • Professional certifications and credentials

1.7 Third-Party Authentication Data

  • Google OAuth: ID tokens, email, name, profile picture
  • Apple Sign-in: Identity tokens, email, full name (when provided)
  • OAuth provider IDs and account linking information
  • Access and refresh tokens (encrypted)
  • Token expiration and scope information

2. How We Use Your Information

2.1 Platform Operations

  • Create and manage user accounts
  • Facilitate service requests and bookings
  • Process payments and manage subscriptions through Stripe
  • Provide customer support
  • Verify garage credentials and qualifications
  • Decode VIN numbers using NHTSA database
  • Validate Quebec compliance for vehicles and businesses
  • Generate public garage profiles and directories

2.2 Communication

  • Send service notifications and updates
  • Facilitate messaging between drivers and garages
  • Send promotional communications (with consent)
  • Provide customer support and technical assistance
  • Send real-time notifications via WebSocket/SSE
  • Deliver push notifications based on user preferences

2.3 Platform Improvement

  • Analyze usage patterns and user behavior
  • Improve platform features and functionality
  • Develop new services and features
  • Conduct research and analytics
  • Enhance VIN decode accuracy and data quality
  • Optimize Quebec-specific validations and services

2.4 Legal and Safety

  • Comply with legal obligations
  • Prevent fraud and abuse
  • Protect user safety and security
  • Resolve disputes and enforce agreements
  • Maintain Quebec tax compliance records
  • Generate required business documentation

2.5 Billing and Financial Services

  • Process subscription payments and billing cycles
  • Calculate commissions and fees
  • Generate Quebec-compliant invoices with GST/QST
  • Track usage quotas and plan limits
  • Manage free trial periods and upgrades
  • Process lead generation fees

3. Information Sharing and Disclosure

3.1 Between Platform Users

We share necessary information between drivers and garages to facilitate services, including:

  • Contact information for service coordination
  • Vehicle information relevant to the service (including VIN-decoded details)
  • Service location and requirements
  • Reviews and ratings (anonymized when appropriate)
  • Public garage profile information

3.2 Service Providers

We may share information with trusted third-party service providers:

  • Stripe for payment processing and billing
  • NHTSA for VIN decoding and vehicle data verification
  • Google and Apple for OAuth authentication services
  • Cloud hosting providers for data storage
  • Analytics services for platform improvement
  • Push notification services (Expo)
  • Customer support tools
  • Quebec geocoding and address validation services

3.3 Legal Requirements

We may disclose information when required by law or to:

  • Comply with legal processes and government requests
  • Protect our rights and property
  • Ensure user safety and prevent harm
  • Investigate fraud or security issues
  • Meet Quebec tax reporting requirements
  • Comply with automotive industry regulations

3.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to the same privacy protections.

4. Data Security and Protection

4.1 Security Measures

  • End-to-end encryption for sensitive data
  • Secure HTTPS connections for all communications
  • Regular security audits and vulnerability assessments
  • Access controls and authentication requirements
  • Secure cloud infrastructure with industry-standard protections
  • OAuth token encryption and secure storage
  • VIN data masking in logs for privacy protection
  • Rate limiting and fraud prevention systems

4.2 Data Storage

Your data is stored on secure servers located in Canada, ensuring compliance with Canadian data residency requirements. We use industry-leading cloud providers with robust security measures. VIN decode data is cached securely with automatic expiration policies.

4.3 Data Retention

We retain personal information only as long as necessary for the purposes outlined in this policy or as required by law. Account data is typically retained for 7 years after account closure for legal and tax compliance purposes. VIN decode cache data is retained for 24 hours, while vehicle information is retained as part of your account profile.

5. External Services and APIs

5.1 VIN Decode Service (NHTSA)

We use the National Highway Traffic Safety Administration (NHTSA) API to decode Vehicle Identification Numbers and provide vehicle specifications. This service helps auto-populate vehicle details and verify Quebec compliance. VIN data shared with NHTSA includes only the VIN number and model year.

5.2 OAuth Authentication

We offer authentication through Google and Apple Sign-in services. These services are governed by their respective privacy policies. We only collect basic profile information (name, email, profile picture) that you choose to share during the authentication process.

5.3 Payment Processing (Stripe)

We use Stripe for payment processing and subscription management. Stripe's privacy policy governs how they handle your payment information. We do not store complete credit card numbers on our servers. Billing data includes subscription details, usage metrics, and Quebec tax calculations.

5.4 Location and Mapping Services

Location and mapping features may use third-party geocoding services for Quebec address validation. Your location data shared with these services is subject to their respective privacy policies.

6. Push Notifications and Communications

6.1 Notification Types

We send push notifications for:

  • New service quotes and booking confirmations
  • Messages from other users
  • Appointment reminders
  • System updates and maintenance notices
  • Payment confirmations and billing alerts
  • VIN decode completion notifications
  • Subscription usage and limit notifications
  • Real-time platform updates via WebSocket/SSE

6.2 Notification Controls

You can control notification preferences through your device settings or within the app. We store push notification tokens securely and delete them when you uninstall the app or revoke permissions. Notification preferences include quiet hours, delivery settings, and category-specific controls.

7. Your Privacy Rights

7.1 Access and Correction

You have the right to access your personal information and request corrections to inaccurate data. Most information can be updated directly through your account settings, including vehicle information, public profile settings, and notification preferences.

7.2 Data Portability

You can request a copy of your personal data in a structured, machine-readable format. This includes your account information, vehicle data, service history, and billing records. Contact our support team to request your data export.

7.3 Account Deletion

You can delete your account at any time through the app settings or by contacting support. Upon deletion, we will remove your personal information, though some data may be retained for legal compliance, including billing records and tax documentation required by Quebec law.

7.4 Consent Withdrawal

You can withdraw consent for data processing at any time, though this may limit platform functionality. Location permissions, OAuth connections, and marketing communications can be disabled in your settings. VIN decode can be disabled while still allowing manual vehicle entry.

8. Quebec Privacy Law Compliance

8.1 Applicable Laws

We comply with Quebec's Act respecting the protection of personal information in the private sector and Bill 64 (Law 25), which strengthens privacy protections for Quebec residents.

8.2 Privacy Officer

We have designated a privacy officer responsible for ensuring compliance with Quebec privacy laws and handling privacy-related inquiries and complaints.

8.3 Breach Notification

In the event of a privacy breach that poses a risk of serious harm, we will notify affected individuals and relevant authorities as required by Quebec law.

9. Cookies and Tracking Technologies

9.1 Web Cookies

Our web application uses cookies to maintain login sessions, remember preferences, and analyze usage. You can control cookie settings through your browser.

9.2 Mobile Analytics

Our mobile app collects anonymized usage analytics to improve performance and user experience. This data cannot be used to identify individual users.

10. Third-Party Services

10.1 Payment Processing

We use Stripe for payment processing. Stripe's privacy policy governs how they handle your payment information. We do not store complete credit card numbers on our servers.

10.2 Map Services

Location and mapping features may use third-party services. Your location data shared with these services is subject to their respective privacy policies.

11. Children's Privacy

GarageGo is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it immediately.

12. Policy Updates

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify users of material changes through the app or by email. The "Last Updated" date indicates when the policy was last revised.

13. Contact Us

If you have questions about this Privacy Policy or how we handle your personal information, please contact us:

Privacy Officer: [email protected]

General Support: [email protected]

Mailing Address: GarageGo Inc., Quebec, Canada

You also have the right to file a complaint with Quebec's Commission d'accès à l'information if you believe we have not properly handled your personal information.

This Privacy Policy is effective as of the date listed above and applies to all information collected by GarageGo.