DAEDALUS

Privacy Policy

Effective June 15, 2026  ·  Version 1.1

Short version: We collect only what's needed to run your shop. We don't sell your data, track you across the web, or use advertising cookies. Your shop data is yours — export it any time, take it with you if you leave.

What We Collect

Your account: email address, password (stored as a one-way hash — we cannot read it), and your name.

Your shop: business name, address, contact details, and the settings you configure (labor rates, tax rates, etc.).

Your customers' data: names, vehicles, repair history, communications — everything you enter on their behalf. You are responsible for this data; we store and process it only to run the service for you.

Security logs: login timestamps and IP addresses, kept for 90 days for fraud prevention and then deleted.

How We Use It

We use your information to run Daedalus — to authenticate you, deliver the features you pay for, send the notifications you ask us to send, and keep the service secure. That's it.

We do not sell your data. We do not use it for advertising. We do not share it with anyone except the services we need to operate the platform (hosting, transactional email, SMS for reminders). Those services process data on our behalf and are bound to handle it appropriately.

Cookies

We set two cookies when you log in — a short-lived access token and a longer-lived refresh token. Both are HttpOnly and Secure, which means JavaScript can't read them. We use no tracking, advertising, or analytics cookies. No third-party scripts set cookies on our pages.

Data Retention

  • Account and shop data: kept for the life of your account
  • Invoices and repair records: kept for 7 years to satisfy standard tax-retention requirements, even if a customer requests deletion
  • Security logs (login IPs): 90 days, then deleted
  • Inactive accounts: accounts with no activity for 3 years may be closed after 90 days' notice

Your Rights

Depending on where you're located (GDPR, CCPA, and similar laws), you may have the right to access, correct, delete, or export the personal data we hold about you. To make a request, email [email protected] with "Privacy Request" in the subject line. We respond within 30 days.

Shop owners can handle customer-level requests (GDPR / CCPA export or deletion) directly from Settings → Privacy & Data.

California residents: we do not sell or share personal information for advertising purposes. Do Not Sell or Share My Personal Information →

Security

All connections are encrypted with TLS. Passwords are bcrypt-hashed. Authentication cookies are HttpOnly, Secure, and SameSite=Strict. Access tokens expire after one hour. In the event of a breach affecting your data, we will notify you by email within 72 hours of confirming it.

Changes

We'll notify you of material changes by email and in-app notice before they take effect. The effective date above reflects the most recent update.

Contact

Daedalus Automotive
[email protected]

Terms of Service Data Processing Agreement Do Not Sell or Share Privacy settings (shop)