Legal

Privacy Policy

Last updated 21 July 2026

This notice explains how The Garage App Ltd (company number 16985727, trading as The Garage) collects and uses personal information when you visit thegarage.to, use app.thegarage.to, contact us, or pay for Premium. The Garage App Ltd is the controller for this processing.

Contact: hello@thegarage.to.

Information we collect

  • Account data: name, email address, authentication identifiers, email-verification status and preferences. Firebase Authentication handles passwords; we do not see them.
  • Vehicle records: registration, VIN where supplied, make, model, mileage, MOT data, ownership dates, service and maintenance history, costs, notes, activities, reminders and sharing choices.
  • Files: vehicle photos, receipts, invoices, service documents and V5C images that you choose to upload.
  • Subscription data: Stripe customer and subscription identifiers, plan, status, renewal date and payment-event records. Stripe receives card and billing details directly; The Garage does not store full card numbers.
  • Communications: support requests and transactional email delivery information.
  • Technical and security data: IP address, browser and device information, request logs, errors, upload-volume counters, file hashes, automated moderation decisions and diagnostic context. Sentry session replay runs only after cookie consent.
  • Optional analytics: page, feature, navigation and engagement events collected by Google Analytics only after affirmative cookie consent.

Where information comes from

Most information comes directly from you. If you use Google Sign-In, Google supplies your name, email address and account identifier. When you request a vehicle or MOT lookup, we obtain vehicle information from UK Vehicle Data and the Driver and Vehicle Standards Agency MOT History service. A person transferring a vehicle record to you also supplies your email address for that transfer.

Why we use information

Purpose Information UK GDPR lawful basis
Create and secure your account Account, authentication and security data Contract; legitimate interests in preventing abuse
Store, organise, share and transfer vehicle history Vehicle records and files Contract; your instructions when you publish or transfer data
Provide vehicle, MOT and AI-assisted document features Registration, vehicle details, uploaded document content and extracted results Contract, when you request the feature
Take payment and manage Premium Subscription, billing and transaction data Contract; legal obligations for accounting and tax
Send verification, reminder, billing and service emails Name, email, vehicle reminder and subscription status Contract; legitimate interests in operating the service
Diagnose faults, protect the service and respond to support Technical, security, moderation and communication data Legitimate interests in a reliable and secure service
Measure use of the website and app Optional analytics and session replay Consent, which you may withdraw at any time
Meet legal claims and regulatory duties Relevant account, transaction and communication data Legal obligation; legitimate interests in establishing or defending claims

AI-assisted features

When you ask The Garage to scan a receipt, service document or V5C, or to generate a maintenance schedule, the relevant image, text or vehicle details are sent to the paid Google Gemini API. Google processes that content to return structured results. Paid Gemini API inputs and outputs are not used by Google to train its models, although Google may retain them for a limited period for abuse monitoring. Check extracted information before relying on it. Do not upload documents you are not entitled to use.

Upload safety checks

Files are checked before storage to enforce file, account and storage limits, confirm that their actual format matches the declared type, detect unsafe or prohibited content, and identify vehicle-gallery uploads that are clearly unrelated to automotive use. Ambiguous images are accepted. Accepted images are re-encoded, which normally removes embedded metadata such as GPS coordinates. Rejected files are not placed in your file storage. We retain a cryptographic file hash, the moderation result, reason codes and limited request-security data so that we can investigate abuse, prevent repeated attempts and respond to reports. Public viewers can report a shared history; reports are reviewed and may lead to removal or suspension. Automated checks can be wrong. Contact us if you believe a file was rejected incorrectly.

Providers and data locations

Provider Purpose and data Location and retention
Google Cloud and Firebase Hosting, Firestore database, file storage, Cloud Functions and authentication Production Firestore is in Google's eur3 European multi-region, Cloud Functions run in London (europe-west2), and the production file bucket is in US-EAST1. Firebase Authentication is processed in the United States. Google may use global support infrastructure. Account and vehicle data remain while the account is active and are removed through the deletion process described below.
Google Sign-In Optional account authentication Google processes sign-in data on global infrastructure under its own privacy notice. The linked identifier remains while the account is active.
Google Cloud Vision Pre-storage image safety screening and broad vehicle relevance labels Google Cloud infrastructure. We retain the resulting labels and safety likelihoods with the moderation audit; rejected image bytes are not stored by The Garage.
Google Gemini API Document extraction, maintenance-schedule generation and PDF upload safety/relevance screening Global Google infrastructure. Inputs and outputs may be logged for a limited abuse-monitoring period under the paid API terms; extracted results remain in your account until deleted.
Google Analytics Consented website and product analytics Google may process data globally. User-level event retention is limited by the standard GA4 setting to no more than 14 months; aggregated reports may remain longer. Analytics cookies normally last up to two years.
Stripe Checkout, subscriptions, invoices, fraud prevention and payment support Stripe entities and providers process data in the UK, EEA, United States and other service locations. Invoice and transaction records are retained for six years after the relevant financial year where required for UK tax and accounting.
Resend (Plus Five Five, Inc.) Delivery of verification, reminder and billing emails United States and its subprocessors' locations. Recipient and delivery data are retained only as needed to deliver, troubleshoot and evidence service emails, subject to Resend's service retention.
Sentry (Functional Software, Inc.) Error monitoring, diagnostics and consented session replay Germany (Sentry's DE/EU data-storage region). Sentry may use approved subprocessors in other locations under its transfer safeguards. Events expire after 90 days.
UK Vehicle Data and DVSA Registration and MOT lookups United Kingdom. Lookup responses may be cached to provide the service and control supplier usage; account-linked copies remain with the vehicle record.

Where a provider processes personal information outside the United Kingdom, we rely on an applicable UK adequacy regulation (including the UK Extension to the EU–US Data Privacy Framework where available) or contractual transfer safeguards such as the UK International Data Transfer Addendum. Contact us for more information about the safeguard used for a particular provider.

Sharing and public links

We do not sell personal information. We disclose it to the providers above only as needed to operate The Garage, or where law requires it. If you create a public vehicle link, anyone with that unguessable link can view the sanitised history you chose to publish. Private records, VIN, owner identity, uploaded files and costs are excluded unless the sharing control explicitly says otherwise. You can rotate or disable the link.

How long we keep information

  • Account, vehicle and uploaded content remains while your account is active, unless you delete an individual vehicle or record first.
  • Public projections remain only while sharing is enabled and are removed when sharing is disabled, the link is rotated, or the vehicle is deleted.
  • Support correspondence and security logs remain only while reasonably needed to answer the request, investigate abuse, meet legal duties or defend a claim.
  • Sentry events expire after 90 days. Google Analytics user-level events are retained for no more than 14 months.
  • Stripe invoices, payment records and the minimum related audit trail may be kept for six years for tax, accounting, fraud and legal obligations even after account deletion.

Account deletion

Self-service account deletion is not currently available in Settings. Email hello@thegarage.to from the address registered to your account. We will verify control of the account and respond without undue delay, normally within one month. Active subscriptions are cancelled before account data, vehicle records, files, public links and login credentials are deleted. We retain only information that law requires or permits us to keep, such as invoice records.

Your rights

UK data protection law may give you rights to access, correct, erase, restrict or receive a copy of your information, and to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. Contact hello@thegarage.to. We may ask for information needed to verify your identity.

You may complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address the concern first.

Security and changes

We use access controls, encrypted transport, provider security controls and separate staging and production environments. No internet service can be guaranteed completely secure. We may update this notice when the service or law changes; material changes will be highlighted through the service where appropriate.