Privacy policy
How information is handled in PDRHailHQ, in plain language. Last updated 8 August 2026.
Who this covers
This policy describes how PDRHailHQ handles information for the shops that use it and for the customers whose vehicles those shops repair.
A shop is the controller of its own customer records. PDRHailHQ processes that information on the shop's behalf and does not sell it, share it between shops, or use it to train models.
What a shop stores here
Repair orders and estimates, including vehicle details, damage assessments, pricing and photographs.
Customer contact details entered by the shop — name, phone, email and, where the shop records it, address.
Insurance claim details where the work is an insurance job: carrier, claim number, deductible and adjuster contact.
Staff records for the shop's own team, including access role and compensation arrangements.
Messages sent to customers through the platform, where the shop has connected messaging.
What we collect to run the service
Account credentials, handled by our authentication provider. Passwords are never stored in readable form and are never visible to us.
Standard operational logs needed to keep the service running and secure.
We do not run advertising trackers or sell usage data.
Isolation between shops
Every record is scoped to the organization that owns it, and that scoping is enforced inside the database rather than only in the application. One shop cannot read another shop's repair orders, pricing, payroll or customers.
Access within a shop is further restricted by role: compensation, pricing and organization settings are limited to owners and admins.
Shared estimate links
A shop can generate a read-only link to show a customer their estimate. The link carries a high-entropy token, is excluded from search engines, and can be revoked by the shop at any time.
Such a page shows only what a customer should see — the shop's identity, the vehicle, the repair lines and the totals. It never exposes cost, commission, technician assignment or internal notes.
Service providers
Hosting and application delivery, database and file storage, transactional email, and SMS and voice messaging where a shop enables it.
Providers process information only to deliver those functions. A shop's messaging credentials are stored per shop and are never exposed to the browser.
Retention and export
Records are retained for as long as the shop's account is active, because estimates and payroll are financial records the shop may need to produce years later.
A shop can export its estimates and documents as PDF and its payroll and reports as CSV at any time, at no charge.
On request we will delete a shop's data. Where a shop is legally required to retain records, deletion is the shop's decision to make, not ours.
Photographs
Damage photographs uploaded by a shop are stored in that shop's own storage area and are subject to the same isolation as every other record. They are visible to that shop, and to anyone the shop deliberately sends a document or link to.
Changes and contact
If this policy changes materially we will tell account owners rather than quietly updating the page.
Questions about privacy, access or deletion can be sent to the contact address on our contact page.