Before this can become a published notice
Replace every bracketed item below, make the corresponding product behavior real, and have counsel confirm the final language. A policy cannot make an unbuilt data practice safe or compliant.
- Identify the legal business name, physical mailing address, privacy contact, and effective date.
- Create a data map for each customer, mechanic applicant, assigned mechanic, support, payment, analytics, and location-data flow.
- Name each production vendor and its role: hosting, authentication, payments, mapping, notifications, analytics, document storage, support, and screening.
- Implement a verified privacy-request workflow and a retention/deletion schedule before accepting personal information.
- Confirm the final notice against California privacy rules and any other laws that apply to the actual business model.
Information a live service may need
A final notice should list only information the released service actually collects. The categories below are a design checklist, not a statement that Torque Mend Mobile Mechanics currently collects them.
- Customer account and contact information
- Name, phone number, email address, communication preferences, and account-security records. The final notice must state the actual production purposes, retention, and providers.
- Vehicle and service-request details
- Vehicle year, make, model, trim, mileage, reported condition, requested work, photos or messages supplied by the customer, and the service address. If a customer explicitly requests a VIN-verified written quote, the final notice must separately disclose the VIN, the verification/pricing providers that receive it, the purpose, access limits, and retention period.
- Service transaction records
- Itemized estimates, authorizations, revised-scope approvals, work orders, invoices, communications, customer support records, and repair history when a live transaction system is implemented.
- Mechanic applicant and partner information
- Business, insurance, licensing or registration, training, tax, payout, availability, service-area, and verification information only after the onboarding process, legal basis, retention plan, and protections are implemented.
- Device and service diagnostics
- Security, fraud-prevention, crash, and performance records. The final notice must name any analytics or advertising technologies actually used.
Precise location must be a separate, informed choice
Before a live location feature ships, Torque Mend Mobile Mechanics must obtain contextual consent before requesting device permission and explain the purpose in plain language. Browsing, estimating, and entering a service address should remain possible without precise device location.
- Request precise location only for a clear, customer-selected purpose such as locating a service address, enabling an assigned mechanic to navigate to an active visit, or showing an active-visit ETA.
- Show who can see the location, how long it is available, whether it updates in the background, and how the customer can stop sharing it.
- Offer a manual address or map-pin alternative when practical; do not use background location by default.
- Keep exact live-location data restricted to the people and systems needed for the active visit. Do not expose a customer's or mechanic's location publicly.
Release gate: do not describe location sharing as live, safe, or consent-based until the backend, permissions, access controls, retention schedule, and user controls have been tested.
California privacy rights and requests
California’s CCPA, as amended, may give eligible California residents rights to know, delete, correct, opt out of certain sale or sharing, limit certain uses of sensitive personal information, and avoid discrimination for exercising privacy rights. Whether and how those rules apply depends on the final business, data, and vendor model; counsel must make that determination.
Before launch, publish a working request method, identity-verification process, response workflow, authorized-agent process, and Global Privacy Control handling where required. Do not publish a dead email address, form, or toll-free number.
Required before publication: privacy contact: [privacy request method]; legal entity: [legal entity]; postal address: [mailing address]; effective date: [effective date].
Retention and security are implementation work
Set a documented schedule for each category of information and retain data no longer than needed for the documented purpose, legal obligations, dispute resolution, security, or recordkeeping. Service records may have separate automotive-repair recordkeeping requirements; privacy deletion workflows must account for those obligations.
Before live collection, implement HTTPS, authenticated and role-limited access, encrypted storage where appropriate, secret management, vendor due diligence, audit logging for sensitive actions, incident response, backups, deletion verification, and tested recovery. Describe safeguards truthfully; do not claim that any system is perfectly secure.
Children and sensitive information
Decide and document the service’s age policy before launch. If the service is not intended for children, build age-appropriate handling and a process for information submitted in error. Treat precise geolocation, government identifiers, financial information, and mechanic-verification documents as sensitive; collect only what is necessary and restrict access.
Publication contacts and official resources
Replace the placeholders before publication. Until then, this page is a planning document, not a public support channel.
- Privacy questions: [privacy email or web form]
- Privacy requests: [verified request method]
- Mailing address: [legal entity and mailing address]
Useful starting points: California Attorney General CCPA overview and CCPA regulations. These links are resources, not legal advice.