No selling. No sharing. No surprises. Here's exactly how your shop's data is stored, protected, and returned to you if you ever leave.
Every byte of your shop data - customers, vehicles, work orders, invoices - is encrypted at rest in our database using AES-256, the same standard used by financial institutions and the US government.
AES-256 - Neon PostgreSQLAll communication between your browser and our servers travels over HTTPS with TLS. Data is never transmitted in plain text, whether you're on your shop's network or a mobile connection.
HTTPS - TLS 1.2 / 1.3Passwords are hashed with bcrypt before storage - they are never saved in readable form and cannot be reversed. Session cookies are HttpOnly and Secure, meaning browser scripts can never access your credentials.
bcrypt - HttpOnly CookiesEvery shop's data is logically isolated at the application level. It is architecturally impossible for one account to query or read data belonging to another - this is enforced by design, not policy.
Shop-scoped access controlWe never see, store, or touch your card data. All payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified provider. The most sensitive data in the transaction never reaches our servers.
Stripe - PCI DSS Level 1All data is stored and processed on servers located in the United States (AWS us-east-1). We do not route your business data through foreign jurisdictions or transfer it internationally without explicit notice.
AWS us-east-1 - Vercel EdgeYour shop records belong to you - not us. Here's exactly what happens from the day you sign up to the day you decide to leave.
Your data is stored securely and accessible only to your account and the users you authorize. We process it solely to provide the software - no analytics profiling, no third-party sharing, no advertising use.
Your subscription remains active through the end of the current billing period. Your data stays fully accessible during that window - use it to export everything you need before it closes.
Once your billing period ends, your data is no longer accessible through the platform. Retained data is purged from active systems within 90 days. Backups are rotated on a standard schedule and purged accordingly.
Basic, Pro, and Elite subscribers can export customers, vehicles, work orders, invoices, and history at any time from within the platform. Standalone Mobile customers keep local records on their own device.
We believe you deserve to know exactly which third-party providers touch your data and in what capacity.
Serverless PostgreSQL. All shop and account data is stored here. SOC 2 Type 2 certified. AES-256 encryption at rest. Hosted on AWS us-east-1 with automated backups and point-in-time recovery.
Neon Security Policy ?The website and API run on Vercel's serverless platform. Vercel handles TLS termination, DDoS protection, and global edge routing. Your data passes through Vercel in transit only - it is not stored there.
Vercel Privacy Policy ?Handles all subscription billing. Payment card data never reaches our servers. Stripe is PCI DSS Level 1 certified - the highest level of payment security certification available.
Stripe Privacy Policy ?The AI chat assistant on our public website is powered by Anthropic's Claude. It is not connected to the software or your shop's data. Messages are processed by Anthropic per their API terms. Anthropic does not use API messages to train models by default.
Anthropic Privacy Policy ?Outbound emails - invoices, estimates, account notifications - are delivered through Resend. Message content may transit their infrastructure briefly for delivery. Email logs are retained for a limited window for debugging.
Resend Privacy Policy ?We do not use Google Analytics, ad pixels, behavioral tracking, or any data monetization services. Your shop data is used to run your shop - nothing else.
In the event of a security incident affecting your data, we will notify affected account holders within 72 hours of confirmed discovery - in line with GDPR Article 33 requirements and consistent with reasonable breach notification practices under US state laws.
Notification will include: the nature of the incident, the categories of data involved, the likely consequences, and the steps we are taking to address it. We will also notify relevant authorities as required by applicable law.
Questions about our security practices info@bkgaragepro.com — we respond within 2 business days.
Our database infrastructure (Neon PostgreSQL on AWS us-east-1) performs continuous automated backups with point-in-time recovery. Backups are retained for a minimum of 7 days on standard plans. In the event of a data loss incident, we target a recovery point objective (RPO) of under 1 hour and a recovery time objective (RTO) of under 4 hours for full service restoration.
Backups are stored in geographically redundant locations within the United States. We conduct periodic recovery tests to verify backup integrity. This infrastructure is managed by Neon, which maintains SOC 2 Type 2 certification.
Enterprise customers requiring custom backup retention, dedicated recovery SLAs, or written business continuity documentation should contact us at info@bkgaragepro.com.
We take security seriously and welcome reports from security researchers. If you believe you have discovered a vulnerability in BK Garage Pro, please report it to us privately before disclosing it publicly.
To report: Email security@bkgaragepro.com with a description of the issue, steps to reproduce, and your assessment of impact. We will acknowledge within 48 hours and aim to resolve confirmed issues within 30 days depending on severity.
Safe harbor: We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, provided they do not access or modify data beyond what is necessary to demonstrate the issue, do not disrupt service for other users, and do not publicly disclose before we have had reasonable time to respond.
A security.txt file is available at /.well-known/security.txt for security tooling.