Privacy Policy

Effective: July 11, 2026

DetailerOS ("we", "us", "our") provides business-management software for auto detailing businesses. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to detailflow.org, the DetailerOS web app, and related services.

1. Who this policy is about

Detailers (our customers) — people who sign up for a DetailerOS account and use the app to run their business.

End customers — the vehicle owners who book, quote, or interact with a detailer through DetailerOS. We process end-customer data on behalf of the detailer; the detailer is the controller of that data.

2. What we collect

From detailers:

  • Account info: name, email, password (hashed), business name, city.
  • Business config: services, prices, availability, payment handles (Venmo/Cash App/Zelle/etc.), branding.
  • Subscription info: your Stripe customer ID and subscription status. We never see or store your card number — Stripe handles that.
  • Usage data: pages visited, features used, errors encountered.

About end customers (entered by the detailer or submitted through a public booking/quote link):

  • Name, email, phone, address, vehicle details, and photos uploaded for quotes.
  • Booking history, membership status, quote requests, review submissions.

Automatically: IP address, browser type, device, referrer, and cookies for essential session and analytics functions.

3. What we do not collect

  • Payment card numbers, CVCs, or bank credentials.
  • Government IDs, SSNs, or driver's license numbers.
  • Location tracking beyond IP-level city inference.

4. How we use information

  • Operate, secure, and improve the Service.
  • Process your subscription (via Stripe).
  • Send transactional emails you configure (booking confirmations, reminders, receipts, review requests).
  • Send you account and product emails from DetailerOS.
  • Provide AI-assisted features (quote drafting, lead outreach) — inputs to AI models are used only to fulfill your request.
  • Detect abuse, fraud, and enforce our Terms.

We do not sell your data or your customers' data. We do not use your customer list to market anything on our own behalf.

5. Who we share with (subprocessors)

We use a small set of trusted vendors to run the Service:

  • Lovable Cloud / Supabase — database, authentication, storage, and backend hosting.
  • Cloudflare — content delivery and edge compute.
  • Stripe — subscription billing and payment processing (subscribed detailers only).
  • Email delivery provider — sending transactional and account emails.
  • Google Gemini / OpenAI (via Lovable AI Gateway) — AI photo quoting and drafting features.
  • Apify — public business-lead sourcing (Commercial Leads feature).

We share only what each vendor needs to perform its function, under a data-processing agreement. We do not share your data with advertisers.

6. Cookies and analytics

We use strictly necessary cookies for authentication and session management, and basic analytics to understand product usage. We do not use advertising cookies or cross-site tracking pixels.

7. Data retention

We keep your account data while your subscription is active and for up to 12 months after cancellation, unless you request earlier deletion. Backups may persist for up to 30 additional days. Emails and message logs are retained for up to 24 months for deliverability and abuse-prevention purposes.

8. Security

All traffic is served over HTTPS. Passwords are salted and hashed. Row-level security policies scope your data to your account. We restrict internal access on a need-to-know basis. No system is 100% secure — you are responsible for protecting your login credentials.

9. Your rights

Depending on where you live (US state laws, UK/EU GDPR, etc.), you may have the right to:

  • Access, correct, or export your personal data.
  • Delete your account and associated data.
  • Object to or restrict certain processing.
  • Opt out of marketing emails (we send very few; unsubscribe links are in every one).

To exercise any right, email jhayyat08@gmail.com. We respond within 30 days.

10. End-customer data — a note for detailers

When you enter or receive end-customer data through DetailerOS, you are the controller of that data. You are responsible for having a legal basis to contact those customers (booking confirmations, reminders, marketing) and for complying with CAN-SPAM, TCPA, GDPR, and any other applicable law. DetailerOS acts as a processor on your behalf.

11. Children

DetailerOS is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us information, email us and we will delete it.

12. International transfers

DetailerOS is operated from the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US, which may have different data-protection laws than your country.

13. Changes to this policy

We may update this policy. Material changes will be announced by email or in-app notice at least 14 days before they take effect.

14. Contact

Questions? Email jhayyat08@gmail.com.