Privacy Policy
Last updated 30 July 2026
This policy explains what personal data Auto Advance collects, why, where it is stored, and what rights you have over it. It covers both this website and the audit platform.
1.Who we are
Auto Advance is an automotive audit and operational-excellence platform operated by [registered company name], registered at [registered address], company number [number].
For data your organisation enters into the platform, your organisation is the data controller and we act as a data processor on its instructions. For this website and for account administration, we are the controller.
Data protection contact: [responsible person, email].
2.What we collect
Account data. Name, work email address, job title, the organisation you belong to, and the roles and branches you are assigned to. Passwords are never stored in readable form — authentication is handled by Supabase Auth, which stores a cryptographic hash.
Audit content. The records your organisation creates: checklists, audit answers and comments, scores, findings, corrective actions, review decisions, and any files attached as evidence. Evidence photographs may incidentally contain people, vehicles or registration plates — what gets captured is controlled by your organisation, not by us.
Activity records. An append-only log of significant actions — who published an audit, who amended an answer, who closed an action, and when. This is a core feature of an audit product rather than analytics, and it cannot be switched off without destroying the integrity of the record.
Technical data. Session cookies, IP address and browser information in server logs, and error reports when something breaks.
Contact data. If you write to us through the demo form, whatever you choose to include. That form composes a message in your own email client — nothing is stored on our side before you press send.
3.Why we process it
To provide the service you or your employer signed up for (performance of a contract); to keep the platform secure, available and free of abuse (legitimate interests); to meet legal obligations; and, where consent is required, on the basis of consent you can withdraw at any time.
We do not sell personal data, we do not use your audit content to train machine-learning models, and we do not use it for advertising.
4.Where it is stored
Application data and evidence files are stored in the European Union, in Amazon Web Services' eu-central-1 region (Frankfurt, Germany), managed through Supabase. Evidence files sit in a private bucket and are never publicly readable: each view is granted by a short-lived signed link issued only after a permission check.
The application is served from Vercel's global edge network, which may handle requests outside the EU in transit. Where personal data leaves the EEA, transfers rely on the European Commission's Standard Contractual Clauses.
5.Who else processes it
We use a small number of sub-processors, each for a defined purpose:
- Supabase — database, authentication and file storage (EU, Frankfurt).
- Vercel — application hosting and content delivery.
- Resend — transactional email such as invitations and escalation notices.
- Inngest — scheduled background work, including overdue-action escalation.
- Upstash — rate limiting, to protect the service from abuse.
- Sentry — error monitoring, so faults can be diagnosed.
Each is bound by a data processing agreement. We will give reasonable notice before adding a sub-processor that handles customer content.
6.Keeping organisations separate
Every organisation on the platform is a separate tenant. All access to tenant-owned data goes through a scoped database client that attaches the tenant identity to every query, and a request that would cross a tenant boundary is rejected by the data layer rather than merely hidden by the interface. Within an organisation, what each person sees is further limited by their role and the branches, regions or groups they are assigned to.
7.How long we keep it
Audit records are retained while your organisation's account is active, because their value is precisely that they form a history. Your organisation controls its own retention within the platform.
Default retention after an account closes: [e.g. 90 days, then permanent deletion]. Backups are retained for [period] and then overwritten on a rolling basis.
When an organisation is permanently deleted, its records and evidence files are removed. The platform-level administrative entry recording that deletion is kept, since removing it would defeat its purpose.
8.Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to processing, and to receive it in a portable format. You may also complain to your local supervisory authority.
If your data was entered by your employer, the fastest route is usually to ask them, since they control the record. If you contact us directly we will help, and where we act only as processor we will pass the request to the controlling organisation. We aim to respond within 30 days.
9.Cookies
We use strictly necessary cookies only: a session cookie that keeps you signed in, and a preference cookie that remembers the region filter you last selected. There are no advertising or third-party tracking cookies, which is why there is no consent banner to dismiss.
10.Security
Data is encrypted in transit and at rest. Access to production systems is limited to named administrators. Passwords are hashed by our authentication provider, optional two-factor authentication is available, and evidence files are reachable only through expiring signed links issued after an authorisation check.
No system is perfect. If we become aware of a breach affecting personal data we will notify the affected organisations and, where required, the relevant supervisory authority within 72 hours.
11.Children
The platform is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16.
12.Changes
We will update this policy as the platform changes. Material changes will be notified to account administrators by email before they take effect, and the date at the top of this page always shows the current version.
Questions about this document? [email protected]