Platform
Service recordsThe permanent, photo-documented logbookScheduling & bookingLive availability, contactless bookingEstimates & billingOne-tap approvals, honest invoicesCustomers & vehiclesEvery car's story, shareableReportsMoney in, money owed, at a glanceShopbook Intelligence
AI in the fabric of the platform — drafting estimates, answering questions, watching the money. Included in every plan.
Learn more ›
Effective 2026-09-11
Read alongside the Terms of Service.
This Privacy Policy explains how Shopbook, Inc. ("Shopbook", "we", "us") collects, uses, shares and protects information when a business (a "Shop") and its staff use the Shopbook websites, applications, booking pages and related services (the "Service"), and when a Shop's customers ("End Customers") interact with a Shop through the Service.
Shopbook wears two hats. For the Shops and staff who are our customers, we decide how their account information is used and this Policy describes it directly. For the information a Shop keeps about its own customers, the Shop decides; we process that information on the Shop's behalf, under its instructions and our Terms of Service, and this Policy describes what we do with it so that a Shop can answer its customers honestly. An End Customer with a question about their information should ask the shop they did business with; we will help that shop answer.
We do not sell personal information. We do not show advertising. We do not use a Shop's customers' information to market to them.
Account Data, which you give us when a Shop signs up and staff are invited: name, email address, phone number, sign-in credentials (stored only as salted hashes) and second-factor enrollment, role and privileges, the Shop's name, address, hours, time zone and settings, billing contact and subscription status. Card numbers for the subscription are entered into Stripe's fields and are held by Stripe, not us.
Shop Data, which a Shop and its staff put into the Service or the Service produces for them: customers' names, phone numbers, email addresses and addresses; vehicles and their identifiers (VIN, plate, mileage); service records, estimates, invoices, payments and receipts; appointments and booking requests; messages sent and received through the Service; photos, recordings and inspection findings; technician time entries; notes. This includes personal information about End Customers and about staff.
Information from Connected Services, only when a Shop connects one: Google calendar events the Service created and contacts the Shop chose to import; Stripe account status and payment events; QuickBooks account identifiers and export results; carrier delivery receipts for text messages.
Usage and device information collected automatically: the pages and actions used, timestamps, approximate location derived from IP address, browser and device type, and a hashed IP address recorded with a Terms acceptance. Server logs and error reports carry request metadata and, occasionally, the identifiers needed to reproduce a fault.
Communications with us: messages sent through the contact page, support conversations and feedback.
We do not knowingly collect information from anyone under 18, and the Service is not directed at children. A Shop may record that a vehicle belongs to a household; the Service does not ask for or need the ages of people in it.
We use Account Data and usage information under our own legitimate interests in operating and improving a business service, to perform our contract with the Shop, and where required with consent. We process Shop Data as the Shop's service provider.
When a Shop uses an AI Feature, the parts of Shop Data needed for that task — for example the vehicle, the complaint, the prior records and the parts catalogue for an estimate draft, or the photo for an inspection reading — are sent to Anthropic, PBC, our AI provider, over encrypted connections and processed under agreements that forbid the provider from using the content to train its models and require deletion after processing except for limited abuse-monitoring retention. Every call is recorded in the Shop's usage log with its purpose and cost. AI output is stored as part of the Shop's records only when a person on the Shop's team accepts it.
The Terms of Service contain a grant that lets the Service learn from what shops across the network actually do. Because it concerns data, we repeat it here in the same words:
You grant Shopbook a perpetual, irrevocable, worldwide, royalty-free license to use Shop Data in aggregated and de-identified form to operate, analyze, improve and develop the Service and new products and features, including the patterns the Service learns about jobs, vehicles, parts, timing and pricing across shops. Aggregated and de-identified means that no shop, customer, technician or vehicle can reasonably be identified from it; Shopbook will never publish or sell figures from which your shop can be identified, and cells too small to protect a shop's identity are suppressed, not rounded.
In practice this means: figures are computed over many shops and reported only when enough shops contribute that none can be identified; End Customers and technicians are not represented as people in any of it; a Shop's own predictions are built from its own records and from these aggregates; and nothing identifiable ever leaves a Shop's tenancy for this purpose.
If your shop connects a Google account, Shopbook accesses two things with your permission: calendar events and contacts. Calendar — when an appointment is booked, moved or cancelled in Shopbook, we create, update or delete the matching event on the calendar you connected; we read only the events Shopbook created. Contacts — when you choose to import them, we read your contacts once and store the names, phone numbers and email addresses you confirm as customers of your shop. We never modify your Google contacts. Google sign-in uses only your name, email address and profile picture to create and identify your Shopbook account.
Data received from Google is stored on Shopbook's servers, is visible only to your shop's team, is never sold, and is never shared with third parties except the infrastructure providers that host Shopbook. It is not used for advertising, and it is not used to train generalized AI or machine-learning models. The credentials Google issues us are encrypted at rest. Disconnecting Google in Settings → Apps stops all access immediately and deletes the stored credentials; closing your account removes the data we hold. Shopbook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Subscription payments and, for shops that connect a Stripe account, End Customer card payments are processed by Stripe. Card numbers are entered into fields Stripe hosts and are transmitted directly to Stripe; they never pass through or rest on Shopbook's servers. Shopbook receives from Stripe the tokens, statuses, amounts, last four digits and payout events needed to record a payment against an invoice and to show a Shop its balance. Stripe's handling of that information is governed by Stripe's privacy policy. Payments a Shop records as cash, cheque or other methods are records the Shop keeps, and Shopbook moves no money for them.
Emails and text messages the Service sends to End Customers are sent on the Shop's behalf and at its direction; the Shop is the sender and is responsible for having the consent the law requires and for honoring opt-outs. We record what was sent, to whom, when, and the delivery result, so the Shop has its record. Every lifecycle email carries an unsubscribe link, and an address that opts out is not written to again by that Shop's automated messages. Text messages are delivered through Twilio, which honors a reply of STOP at the carrier level; the Service does not read replies to text messages. We do not use End Customer contact information for any purpose of our own.
Shop Data is kept for as long as the Shop's account is open; the Shop controls its records and can export them at any time. When a Shop closes its account, its data is kept for thirty (30) days so it can be exported and the account can be reopened, then permanently deleted from the live database. Encrypted backups that contain deleted data are overwritten in the ordinary course within a further thirty (30) days.
Account Data is kept while the account is open and for the period afterwards the law requires for tax, accounting and dispute purposes. Records of Terms acceptance, security and audit logs, and billing records are kept for the periods the law requires or for as long as needed to resolve disputes. Usage logs and error reports are kept for up to ninety (90) days unless preserved for an investigation.
Aggregated and de-identified data derived under Section 4 no longer identifies any Shop or person and may be kept indefinitely. Information subject to a legal hold is kept until the hold ends.
Every Shop's data is isolated at the database layer with row-level security, so a query for one Shop cannot return another's rows even in the event of an application defect. Data is encrypted in transit (TLS) and at rest. Credentials for Connected Services are encrypted (AES-256-GCM) with a key held in the application's environment, separately from the database. Passwords are stored as salted hashes; second-factor authentication is offered to every account and required where a password alone would be the only barrier to sensitive actions. Access within the Service is governed by roles and privileges the Shop's owners assign. Administrative and money-related actions are logged. Our own access to production is limited to named engineers, protected by second factors, and used to operate and support the Service.
No system is perfectly secure. If we learn of a security incident that affects Shop Data, we will notify the affected Shop without undue delay, describe what we know, and help the Shop meet its own notification obligations to its customers and regulators.
Shops and staff can see and correct most Account Data in the Service; owners can export all Shop Data, delete records the invariants allow to be deleted, and close the account. Transactional and security notices cannot be opted out of while the account is open.
Depending on where you live, you may have the right to know what personal information we hold about you, to receive a copy, to correct it, to delete it, to restrict or object to certain processing, to withdraw consent, and not to be discriminated against for exercising these rights. Residents of California (under the CCPA/CPRA), Colorado, Connecticut, Virginia, Utah, Oregon, Texas and other states with their own privacy laws, and residents of the European Economic Area, the United Kingdom and Canada, have specific rights under those laws, and we honor them. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front; we treat a browser's Global Privacy Control signal as an opt-out in any case.
To exercise a right over Account Data, write to privacy@shopbook.io or use the contact page; we will verify your identity through your account and respond within the time the applicable law allows, normally within forty-five (45) days. An End Customer's request about information a Shop holds should go to that Shop; if it reaches us, we will forward it to the Shop and help the Shop respond. Where a Shop instructs us to delete, correct or export an End Customer's information, we do so within the Shop's tenancy, subject to the records the Shop is required by law to keep.
If you believe we have not handled your information properly, tell us first and we will try to put it right. You may also complain to your local data-protection or consumer-protection authority.
Shopbook is operated from the United States and its subprocessors process information in the United States. If you use the Service from outside the United States, your information is transferred to and processed there. Where the law requires a legal mechanism for that transfer, we rely on standard contractual clauses or the equivalent instrument with our subprocessors, and on the Terms of Service with each Shop.
The Service is a business tool for shops and their staff. It is not directed at, and may not be used by, anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
We may update this Policy as the Service changes. The effective date at the top is the version. For a material change — a new category of information, a new purpose, a new kind of recipient — we will tell account owners by email or in the Service at least thirty (30) days before it takes effect. Clarifying changes take effect on posting. Earlier versions are available on request.
Shopbook, Inc. is the business responsible for Account Data and the service provider for Shop Data. Questions, requests and complaints about privacy: through the contact page at shopbook.io/contact, or by email to privacy@shopbook.io.