Privacy Policy

Effective 2026-09-11

Read alongside the Terms of Service.

This Privacy Policy explains how Shopbook, Inc. ("Shopbook", "we", "us") collects, uses, shares and protects information when a business (a "Shop") and its staff use the Shopbook websites, applications, booking pages and related services (the "Service"), and when a Shop's customers ("End Customers") interact with a Shop through the Service.

Shopbook wears two hats. For the Shops and staff who are our customers, we decide how their account information is used and this Policy describes it directly. For the information a Shop keeps about its own customers, the Shop decides; we process that information on the Shop's behalf, under its instructions and our Terms of Service, and this Policy describes what we do with it so that a Shop can answer its customers honestly. An End Customer with a question about their information should ask the shop they did business with; we will help that shop answer.

We do not sell personal information. We do not show advertising. We do not use a Shop's customers' information to market to them.

1. Information we collect

Account Data, which you give us when a Shop signs up and staff are invited: name, email address, phone number, sign-in credentials (stored only as salted hashes) and second-factor enrollment, role and privileges, the Shop's name, address, hours, time zone and settings, billing contact and subscription status. Card numbers for the subscription are entered into Stripe's fields and are held by Stripe, not us.

Shop Data, which a Shop and its staff put into the Service or the Service produces for them: customers' names, phone numbers, email addresses and addresses; vehicles and their identifiers (VIN, plate, mileage); service records, estimates, invoices, payments and receipts; appointments and booking requests; messages sent and received through the Service; photos, recordings and inspection findings; technician time entries; notes. This includes personal information about End Customers and about staff.

Information from Connected Services, only when a Shop connects one: Google calendar events the Service created and contacts the Shop chose to import; Stripe account status and payment events; QuickBooks account identifiers and export results; carrier delivery receipts for text messages.

Usage and device information collected automatically: the pages and actions used, timestamps, approximate location derived from IP address, browser and device type, and a hashed IP address recorded with a Terms acceptance. Server logs and error reports carry request metadata and, occasionally, the identifiers needed to reproduce a fault.

Communications with us: messages sent through the contact page, support conversations and feedback.

We do not knowingly collect information from anyone under 18, and the Service is not directed at children. A Shop may record that a vehicle belongs to a household; the Service does not ask for or need the ages of people in it.

2. How we use information

  • To provide the Service: keep records, schedule, estimate, invoice, take and record payment, send the messages a Shop asks us to send, sync the Connected Services a Shop enabled, and show each person the surfaces their role allows.
  • To run the AI Features a Shop uses: the relevant slice of Shop Data is sent to our AI provider to draft, classify, read or anticipate, metered and capped; a person approves anything with a price or a promise on it before it takes effect.
  • To improve the Service by learning across the network, in aggregated and de-identified form only, as the Terms of Service state and Section 4 repeats.
  • To secure the Service: authenticate people, detect abuse and intrusion, isolate each Shop's data from every other Shop's, keep audit logs of administrative and money-related actions, and investigate incidents.
  • To bill and account: charge subscriptions, meter usage against plan caps, keep the financial records the law requires.
  • To communicate with account holders: transactional notices, security alerts and material changes to the Service or these documents. If we ever send product news to account owners, each message will carry an unsubscribe link. We do not send marketing to End Customers.
  • To comply with law, respond to lawful requests, enforce our Terms and protect the rights and safety of Shops, End Customers, the public and Shopbook.

We use Account Data and usage information under our own legitimate interests in operating and improving a business service, to perform our contract with the Shop, and where required with consent. We process Shop Data as the Shop's service provider.

3. AI Features

When a Shop uses an AI Feature, the parts of Shop Data needed for that task — for example the vehicle, the complaint, the prior records and the parts catalogue for an estimate draft, or the photo for an inspection reading — are sent to Anthropic, PBC, our AI provider, over encrypted connections and processed under agreements that forbid the provider from using the content to train its models and require deletion after processing except for limited abuse-monitoring retention. Every call is recorded in the Shop's usage log with its purpose and cost. AI output is stored as part of the Shop's records only when a person on the Shop's team accepts it.

4. Learning across shops

The Terms of Service contain a grant that lets the Service learn from what shops across the network actually do. Because it concerns data, we repeat it here in the same words:

You grant Shopbook a perpetual, irrevocable, worldwide, royalty-free license to use Shop Data in aggregated and de-identified form to operate, analyze, improve and develop the Service and new products and features, including the patterns the Service learns about jobs, vehicles, parts, timing and pricing across shops. Aggregated and de-identified means that no shop, customer, technician or vehicle can reasonably be identified from it; Shopbook will never publish or sell figures from which your shop can be identified, and cells too small to protect a shop's identity are suppressed, not rounded.

In practice this means: figures are computed over many shops and reported only when enough shops contribute that none can be identified; End Customers and technicians are not represented as people in any of it; a Shop's own predictions are built from its own records and from these aggregates; and nothing identifiable ever leaves a Shop's tenancy for this purpose.

5. Who we share information with

We share information only as needed to provide the Service and as described here. We do not sell personal information, and we do not share it with data brokers or advertisers.

Subprocessors — the companies that process information on our behalf, each bound by contract to protect it and use it only for us:

  • Vercel, Inc. — Application hosting, edge network and serverless compute (United States).
  • Neon, Inc. — Primary database (PostgreSQL) and backups (United States).
  • Vercel Blob — File and photo storage (inspection photos, recordings, exports) (United States).
  • Stripe, Inc. — Subscription billing; payment processing for shops that connect a Stripe account (United States).
  • Anthropic, PBC — AI Features — drafting, classification, image reading; no training on Shop Data (United States).
  • Resend, Inc. — Transactional email delivery on the shop's behalf (United States).
  • Twilio Inc. — Text-message delivery on the shop's behalf (United States).
  • Google LLC — Sign-in, calendar and contacts, only for shops that connect a Google account (United States).
  • Intuit Inc. — QuickBooks Online export, only for shops that connect QuickBooks (United States).
  • PartsTech, Inc. — Parts ordering — receives the vehicle (VIN or year, make and model) when a shop opens a parts search (United States).
  • U.S. National Highway Traffic Safety Administration (vPIC) — VIN decoding — receives the VIN only; a public government service (United States).

Connected Services a Shop chooses, under that provider's own terms: when a Shop connects Stripe, Google, QuickBooks or an SMS number, the information needed for the feature flows to that provider, and the Shop can disconnect it at any time in Settings → Apps.

End Customers, as a Shop directs: the estimates, invoices, receipts, appointment details, inspection reports and messages a Shop sends to its customers through the Service are, by design, shared with those customers. Internal notes are never included.

Professional advisers and successors: our lawyers, accountants and auditors under confidentiality; and, if Shopbook is involved in a merger, acquisition, financing or sale of assets, the counterparty — with notice to account owners and this Policy continuing to apply to the information transferred.

Legal requirements: when the law, a court order or a lawful request requires it, or when necessary to protect the rights, safety or property of Shops, End Customers, the public or Shopbook. Where the law permits, we will tell the affected Shop before disclosing its data and will disclose only what is required.

We will update the subprocessor list on this page before adding a provider that will process Shop Data, and account owners may object in writing; if we cannot address the objection, the Shop may close its account and export its data.

6. Google account data

If your shop connects a Google account, Shopbook accesses two things with your permission: calendar events and contacts. Calendar — when an appointment is booked, moved or cancelled in Shopbook, we create, update or delete the matching event on the calendar you connected; we read only the events Shopbook created. Contacts — when you choose to import them, we read your contacts once and store the names, phone numbers and email addresses you confirm as customers of your shop. We never modify your Google contacts. Google sign-in uses only your name, email address and profile picture to create and identify your Shopbook account.

Data received from Google is stored on Shopbook's servers, is visible only to your shop's team, is never sold, and is never shared with third parties except the infrastructure providers that host Shopbook. It is not used for advertising, and it is not used to train generalized AI or machine-learning models. The credentials Google issues us are encrypted at rest. Disconnecting Google in Settings → Apps stops all access immediately and deletes the stored credentials; closing your account removes the data we hold. Shopbook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Payments

Subscription payments and, for shops that connect a Stripe account, End Customer card payments are processed by Stripe. Card numbers are entered into fields Stripe hosts and are transmitted directly to Stripe; they never pass through or rest on Shopbook's servers. Shopbook receives from Stripe the tokens, statuses, amounts, last four digits and payout events needed to record a payment against an invoice and to show a Shop its balance. Stripe's handling of that information is governed by Stripe's privacy policy. Payments a Shop records as cash, cheque or other methods are records the Shop keeps, and Shopbook moves no money for them.

8. Messages to End Customers

Emails and text messages the Service sends to End Customers are sent on the Shop's behalf and at its direction; the Shop is the sender and is responsible for having the consent the law requires and for honoring opt-outs. We record what was sent, to whom, when, and the delivery result, so the Shop has its record. Every lifecycle email carries an unsubscribe link, and an address that opts out is not written to again by that Shop's automated messages. Text messages are delivered through Twilio, which honors a reply of STOP at the carrier level; the Service does not read replies to text messages. We do not use End Customer contact information for any purpose of our own.

9. How long we keep information

Shop Data is kept for as long as the Shop's account is open; the Shop controls its records and can export them at any time. When a Shop closes its account, its data is kept for thirty (30) days so it can be exported and the account can be reopened, then permanently deleted from the live database. Encrypted backups that contain deleted data are overwritten in the ordinary course within a further thirty (30) days.

Account Data is kept while the account is open and for the period afterwards the law requires for tax, accounting and dispute purposes. Records of Terms acceptance, security and audit logs, and billing records are kept for the periods the law requires or for as long as needed to resolve disputes. Usage logs and error reports are kept for up to ninety (90) days unless preserved for an investigation.

Aggregated and de-identified data derived under Section 4 no longer identifies any Shop or person and may be kept indefinitely. Information subject to a legal hold is kept until the hold ends.

10. How we protect information

Every Shop's data is isolated at the database layer with row-level security, so a query for one Shop cannot return another's rows even in the event of an application defect. Data is encrypted in transit (TLS) and at rest. Credentials for Connected Services are encrypted (AES-256-GCM) with a key held in the application's environment, separately from the database. Passwords are stored as salted hashes; second-factor authentication is offered to every account and required where a password alone would be the only barrier to sensitive actions. Access within the Service is governed by roles and privileges the Shop's owners assign. Administrative and money-related actions are logged. Our own access to production is limited to named engineers, protected by second factors, and used to operate and support the Service.

No system is perfectly secure. If we learn of a security incident that affects Shop Data, we will notify the affected Shop without undue delay, describe what we know, and help the Shop meet its own notification obligations to its customers and regulators.

11. Your choices and rights

Shops and staff can see and correct most Account Data in the Service; owners can export all Shop Data, delete records the invariants allow to be deleted, and close the account. Transactional and security notices cannot be opted out of while the account is open.

Depending on where you live, you may have the right to know what personal information we hold about you, to receive a copy, to correct it, to delete it, to restrict or object to certain processing, to withdraw consent, and not to be discriminated against for exercising these rights. Residents of California (under the CCPA/CPRA), Colorado, Connecticut, Virginia, Utah, Oregon, Texas and other states with their own privacy laws, and residents of the European Economic Area, the United Kingdom and Canada, have specific rights under those laws, and we honor them. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front; we treat a browser's Global Privacy Control signal as an opt-out in any case.

To exercise a right over Account Data, write to privacy@shopbook.io or use the contact page; we will verify your identity through your account and respond within the time the applicable law allows, normally within forty-five (45) days. An End Customer's request about information a Shop holds should go to that Shop; if it reaches us, we will forward it to the Shop and help the Shop respond. Where a Shop instructs us to delete, correct or export an End Customer's information, we do so within the Shop's tenancy, subject to the records the Shop is required by law to keep.

If you believe we have not handled your information properly, tell us first and we will try to put it right. You may also complain to your local data-protection or consumer-protection authority.

12. Cookies and similar technologies

The Service uses cookies and local storage that are strictly necessary to operate: a session cookie that keeps you signed in, a request-forgery protection token, short-lived cookies that carry a confirmation from one page to the next, and storage the installed app uses to work when the connection drops. We do not use advertising cookies or third-party tracking pixels. Our hosting provider records anonymized performance and error telemetry to keep the Service fast. You can clear or block cookies in your browser; the Service will not stay signed in without the session cookie.

13. Where information is processed

Shopbook is operated from the United States and its subprocessors process information in the United States. If you use the Service from outside the United States, your information is transferred to and processed there. Where the law requires a legal mechanism for that transfer, we rely on standard contractual clauses or the equivalent instrument with our subprocessors, and on the Terms of Service with each Shop.

14. Children

The Service is a business tool for shops and their staff. It is not directed at, and may not be used by, anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

15. Changes to this Policy

We may update this Policy as the Service changes. The effective date at the top is the version. For a material change — a new category of information, a new purpose, a new kind of recipient — we will tell account owners by email or in the Service at least thirty (30) days before it takes effect. Clarifying changes take effect on posting. Earlier versions are available on request.

16. Contact

Shopbook, Inc. is the business responsible for Account Data and the service provider for Shop Data. Questions, requests and complaints about privacy: through the contact page at shopbook.io/contact, or by email to privacy@shopbook.io.