What we hold, who it reaches, and what we cannot delete. Last updated 4 September 2026.
Almost everything below depends on this distinction, so it comes first.
The shop is our customer. We decide how we handle a shop's own account information — who works there, what they are paid, what the shop pays us.
The shop's customers are the shop's. When a vehicle owner's name, phone number and repair history sit in this system, they are there because a shop put them there. That shop decides what is collected, what it is used for and how long it is kept. We hold it on the shop's behalf and act on the shop's instructions. If you are a vehicle owner with a question about your own record, the shop that served you is the right place to start, and we will help them answer it.
Shop name, shop code, address and time zone. Each person's name, sign-in name and role. PINs, stored only as a one-way hash — we cannot read them and cannot tell you what yours is. Optionally an hourly wage, and an email address or phone number if that person wants the weekly report.
Whatever the shop enters to do the work: name, phone, email, their vehicles and VINs, mileage, what they said was wrong, what was done, photographs, what they were charged and what they paid, and their signature approving the work.
Who moved a job, who took a payment, who sealed a record, and when. That trail is the point of the product — a repair record that cannot say who did the work is worth much less — so it is not optional and it is not editable.
One cookie, scarab_session. It is HTTP-only, secure, same-site, and expires after twelve hours. It exists to keep you signed in and does nothing else. There are no advertising cookies and nothing follows anybody between websites.
We do count page views, across the marketing pages and the application alike, using Vercel's analytics. It sets no cookie. It records the shape of a route — /workorders/[id] — and never the address actually visited, so no job, customer or vehicle identifier ever reaches it.
The complete list. Each one receives only what it needs to do its job, and three of them only exist if the shop switches them on.
| Who | What they get | When |
|---|---|---|
| Vercel | Hosting, photograph storage, and counting page views. The application runs here. | Always |
| Neon | The database itself — every customer, vehicle, repair and invoice above is stored on it. | Always |
| Resend | An email address and the message sent to it — a weekly report to an owner, or a document sent to a customer. | Only when the software sends email |
| The NHTSA | A VIN on its own, to decode the year, make, model and engine. A United States government service. Nothing about the customer is sent with it. | When a vehicle is decoded from its VIN |
| Twilio | The phone number, the message and its content — the same as any text message has to reach a carrier. | Only if the shop uses texting or call handling |
| Intuit (QuickBooks) | The invoice: customer name, line items and totals. Pushed one job at a time, by hand. Nothing syncs on its own. | Only if the shop connects QuickBooks |
| CarKnown | The vehicle's permanent record — see below. Never prices, costs, vendors, or anything identifying the customer. | Only once the shop is verified and has accepted the terms |
| OpenTimestamps | One hash. Nothing else, ever. No names, no records, no numbers — a single fingerprint that cannot be turned back into anything. | Only when a shop publishes its chain head |
We do not sell anything, to anyone, ever. There is no advertising business here and no data broker on that list. We are paid by shops for software.
We do measure how many people visit the public pages, using page patterns rather than addresses — we can see that /workorders/[id] was visited, never which job. Shop and customer identifiers do not leave the application.
When a repair is sealed and the shop is publishing, this is exactly what crosses to CarKnown, and it is checked by an automated test so it cannot drift:
The VIN. The work that was done and the parts fitted. The date. The mileage. The shop's name. A score for how well documented the repair is.
Nothing about the customer — not their name, phone, email or address. And no money at all: not what was charged, not what the parts cost the shop, not which vendor supplied them.
Any customer can refuse. Tell the shop, or use the link to your own records, and nothing further about your vehicles is published. Ask before the work is sealed and nothing about that repair is published at all.
Messages come from the shop's own number, about that customer's own repair. Consent is given on the authorisation the customer signs, which says plainly that it covers their repair and not marketing.
Reply STOP at any time and the shop cannot text you again through this system until you reply START. That is handled automatically — nobody has to remember to do it. Reply HELP and you get told who the shop is and how to reach a person.
Most software promises to delete anything on request. We cannot, and it would be dishonest to say otherwise, so here is exactly where the limit is and why it exists.
Not by the shop's staff, not by the shop's owner, and not by us. That is the entire value of the record: a history that could be quietly edited later would prove nothing to a future owner, another garage, or a court. If something in it is wrong, a correction is sealed as its own record and the original stays.
Their fingerprints are locked inside the sealed record, which is what proves the pictures are the ones taken at the time. Deleting the file would break the proof, so sealed photographs stay. Photographs on a job that has not been sealed can still be removed.
When a shop timestamps its records, one fingerprint is written into a public blockchain. It is a hash and nothing else — no names, no numbers, nothing that can be turned back into a person. But it is permanent, and neither we nor the shop can remove it.
Customer contact details, unsealed jobs, appointments, messages, photographs on open work, and a shop's whole account: all of it can be corrected or removed. The limit above is narrow and specific, and it is the only one.
A shop can hand any customer a private link to their own records — their vehicles, the work done, warranties and what is coming up. No password and no account.
From that same link a customer can fix their own name, phone, email and preferences, and what they enter is what the shop's counter sees.
Ask the shop. Everything except sealed repairs can be removed, and a shop can clear its records itself. Where a sealed repair has to stay, we will say so plainly rather than pretend it is gone.
Refuse at the counter or from your own link, and no further work on your vehicles goes onto the permanent record.
Depending on where you live you may also have the right to a copy of your data in a portable form, to object to certain processing, or to complain to a regulator. Ask the shop, or write to us and we will help them.
PINs are hashed, never stored in a form anybody can read. Sign-in is rate-limited and a name locks after repeated wrong guesses. A shop's data is reachable only by people signed in to that shop, and what each role can see is enforced on the server rather than hidden in the interface — technicians never see costs or margins, and customers never see either.
Links to a customer's own records are private, revocable, excluded from search engines, and stop working the moment a shop revokes them.
This is software for businesses. It is not directed at children and we do not knowingly collect anything from them.
If this policy changes in a way that affects what happens to your information, shops are told before it takes effect rather than after. The date at the top moves when the substance moves, not when the wording is tidied.
Scarab OS is operated by BellaMadison Co LLC. Questions about this policy, or a request about your own information: privacy@scarab-os.tech.