Privacy Policy
Last Updated: October 3, 2025
Introduction
WorkshopBase ("we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our workshop management platform.
This policy applies to all users of WorkshopBase, including workshop owners, managers, technicians, and customers.
Information We Collect
Information You Provide Directly
Workshop Account Information:
- Business name, address, and contact details
- Owner and employee information
- Business registration details
- Payment and billing information
Customer Information:
- Names, addresses, phone numbers, and email addresses
- Vehicle information (make, model, year, VIN, registration)
- Service history and maintenance records
- Communication preferences
- Photos and documentation related to vehicle services
Service and Job Information:
- Appointment bookings and scheduling details
- Service requests and work performed
- Parts orders and inventory transactions
- Time tracking and timesheet data
- Invoices and payment records
Information Collected Automatically
Usage Information:
- Log data (IP addresses, browser type, device information)
- Pages visited and features used
- Date and time of access
- Performance metrics and error logs
Communications Data:
- Email messages and attachments processed through our system
- Social media messages via connected platforms (Facebook Messenger)
- SMS notifications and responses
- Communication history and threading
Information from Third-Party Integrations
When you connect third-party services to WorkshopBase, we may collect:
Email Providers (Gmail, Outlook):
- Email content for booking extraction and customer communication
- Contact information from email signatures
- OAuth authentication tokens
EzyParts Integration:
- Parts quotes and pricing information
- Order history and tracking data
- Inventory availability information
Xero Accounting:
- Invoice and financial transaction data
- Payment reconciliation information
- Tax calculation details
Facebook Messenger:
- Customer messages and conversations
- Profile information of customers who message your business
- Media files shared in conversations
How We Use Your Information
We use the collected information for the following purposes:
Service Delivery
- Providing and maintaining the WorkshopBase platform
- Processing appointments, bookings, and service requests
- Managing customer relationships and communications
- Tracking inventory and parts orders
- Generating invoices and processing payments
- Creating reports and analytics
Communication
- Sending service reminders and appointment confirmations
- Responding to customer inquiries
- Providing customer support
- Sending important service updates and notifications
Business Operations
- Improving our platform functionality and user experience
- Analysing usage patterns and performance metrics
- Troubleshooting technical issues
- Conducting internal research and development
Legal and Security
- Complying with legal obligations
- Protecting against fraud and unauthorised access
- Enforcing our terms of service
- Maintaining data security and system integrity
Data Storage and Security
Storage Infrastructure
WorkshopBase uses Supabase and industry-standard cloud infrastructure to store your data securely. All data is:
- Encrypted in transit using TLS/SSL protocols
- Encrypted at rest using industry-standard encryption
- Stored in secure data centers with redundant backups
- Subject to daily automated backups with point-in-time recovery
Access Controls
- Role-based access control (RBAC) limiting data access to authorized users only
- Multi-factor authentication support for enhanced account security
- Secure session management with appropriate timeouts
- Audit logs tracking access to sensitive information
Security Measures
We implement comprehensive security measures including:
- Regular security assessments and vulnerability scanning
- Penetration testing and security audits
- Staff training on data protection practices
- Incident response procedures for security events
Data Sharing and Disclosure
Service Providers
We may share your information with trusted third-party service providers who assist us in operating our platform:
- Cloud infrastructure providers (Supabase)
- Email service providers
- Payment processors
- Analytics services
These providers are contractually obligated to protect your information and use it only for the specific services they provide to us.
Third-Party Integrations
When you connect third-party services (EzyParts, Xero, email providers, Facebook), we share relevant data necessary for those integrations to function. You control these connections and can disconnect them at any time.
Legal Requirements
We may disclose your information when required by law or in response to:
- Valid legal processes (court orders, subpoenas)
- Government or regulatory requests
- Protection of our rights, property, or safety
- Emergency situations involving safety or security
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control.
Your Rights and Choices
Access and Control
You have the right to:
- Access your personal information stored in WorkshopBase
- Correct inaccurate or incomplete information
- Request deletion of your information (subject to legal retention requirements)
- Export your data in a standard format
- Object to certain processing activities
Communication Preferences
You can control:
- Email notification settings
- SMS message preferences
- Marketing communication opt-ins/opt-outs
- Automated reminder configurations
Account Management
Workshop owners and administrators can:
- Manage user access and permissions
- Configure data retention policies
- Control third-party integrations
- Review audit logs and access history
Data Portability
You can export your data from WorkshopBase at any time, including:
- Customer records and vehicle information
- Service history and job records
- Financial data and invoicing information
- Communication history
Data Retention
We retain your information for as long as necessary to:
- Provide our services to you
- Comply with legal obligations (e.g., tax records, financial reporting)
- Resolve disputes and enforce agreements
- Support business operations and analytics
Specific Retention Periods:
- Active customer records: Retained while account is active
- Service history: 7 years (or as required by local regulations)
- Financial records: 7 years (or as required by tax authorities)
- Communication logs: 3 years
- System logs: 90 days
You can request earlier deletion of data, subject to legal and contractual obligations.
Cookies and Tracking Technologies
WorkshopBase uses cookies and similar technologies to:
- Maintain user sessions and authentication
- Remember user preferences and settings
- Analyse platform usage and performance
- Provide enhanced functionality
You can control cookie preferences through your browser settings. Note that disabling cookies may limit platform functionality.
Children's Privacy
WorkshopBase is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable data protection laws.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by:
- Posting the updated policy with a new "Last Updated" date
- Sending email notifications to registered users
- Displaying prominent notices in the platform
Continued use of WorkshopBase after changes constitutes acceptance of the updated policy.
Your Privacy Rights by Region
Australian Privacy Principles (APPs)
If you are in Australia, you have rights under the Privacy Act 1988, including the right to access and correct your personal information and to make complaints about privacy breaches.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@workshopbase.com.au
Mail: WorkshopBase Privacy Team, 9 Burgay Court, Osborne Park WA 6017
Phone: (08) 9309 2998
For data protection inquiries, please include:
- Your name and workshop account details
- Description of your inquiry or request
- Any relevant reference numbers or documentation
We aim to respond to all privacy inquiries within 30 days.
Consent
By using WorkshopBase, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.