Information we process
- Account data: name, email, authentication provider, role, shop membership, and session information.
- Shop data: business name, contact details, country/region defaults, tax identifiers, invoice settings, logos, and staff settings.
- Customer and repair data: customer contact details, device details, issue descriptions, repair status, notes intended for staff use, estimates, invoices, labels, and receipts.
- Inventory and sales data: suppliers, stock items, purchase orders, POS sales, device purchases, device sales, pricing, and transaction records.
- Support data: messages or requests you send to RepairFlow support.
- Web usage data, when approved and enabled: account ID, organization ID, shop ID, role, and the latest UTC date and time that an operational signed-in Web page was observed.
Signed-in Web usage measurement
RepairFlow includes a disabled-by-default, first-party activity measure for signed-in operational Web pages. If approved and enabled, the server records at most one normal update per account per UTC day. The record contains the current organization, shop, role, and latest observed time. It does not contain page URLs, searches, clicks, customer records, device identifiers, or browsing history.
Access is restricted to trusted server operations. Internal administrators can view aggregate active-user and active-shop counts only; underlying account records are not sent to the reporting screen. Counts can understate use when recording fails, JavaScript is blocked, or tracking is disabled, and a user's shop attribution reflects only their latest recorded tenant.
How we use information
- Provide shop management workflows, including intake, repair tracking, documents, inventory, POS, and settings.
- Authenticate users, enforce roles, secure sessions, and protect shop data from unauthorized access.
- Generate operational documents such as estimates, invoices, receipts, labels, and customer-facing repair summaries.
- Support beta users, diagnose issues, prevent abuse, and improve product reliability.
- Comply with applicable legal, security, fraud-prevention, and data-rights obligations.
Service providers
RepairFlow Web uses trusted providers to operate the service:
- Firebase Authentication for account identity and secure login.
- Firestore for shop, staff, repair, customer, inventory, settings, and transaction data.
- Firebase App Check and reCAPTCHA Enterprise for abuse prevention on selected public or signup-related requests.
- Cloudinary for selected uploaded media such as shop logos and business images used by documents.
- Vercel for hosting the RepairFlow Web application.
The public marketing website may describe mobile app permissions or mobile billing tools. This web policy describes the web beta surface specifically.
Cookies and local storage
RepairFlow Web uses an essential HTTP-only session cookie to keep signed-in users authenticated and a small number of local browser storage keys for UI preferences. If signed-in usage measurement is enabled after review, one account-and-shop-scoped local marker remembers the last successfully recorded UTC day and reduces duplicate requests. See the Cookie Notice for details.
Customer-facing documents
Customer-facing documents should only include public repair and transaction information. Internal staff notes are not intended for customer receipts, labels, invoices, estimates, or printable customer documents.
Data rights and requests
During web beta, data export, account deletion, correction, and privacy requests are handled manually. Contact support@repairflow.app from the account email or with enough shop-identifying information for us to verify the request.
Retention and security
Data is retained while accounts and shops are active or as needed for business, security, support, legal, or backup purposes. Access is controlled through Firebase Authentication, shop membership, custom claims, server checks, and Firestore security rules. The latest Web activity record is overwritten as use is observed and is included in verified manual account or shop deletion handling. This does not claim that deletion is automatic.
Contact
For privacy, security, deletion, export, or support questions, email support@repairflow.app.