Garage Invoice Vehicle Management Software logo

Privacy Policy

Table Of Contents

Garage Invoice Ltd – Privacy Policy

Last updated: 25 September 2026
Email: info@garageinvoice.co.uk
Website: www.garageinvoice.co.uk

This Policy explains how Garage Invoice Ltd collects, uses, shares, stores and protects personal data in connection with our website, workshop-management software, customer portals and related services. These may include website hosting, business email, AI assistance, messaging, vehicle data and integrations selected by our business customers.

We do not sell personal data. We do not use workshop Customer Data or connected-account content for third-party advertising, advertising profiling or data resale. Information is nevertheless shared where needed to provide an authorised service, operate our business lawfully or comply with legal duties, as explained below. Website analytics and optional third-party components have separate purposes and choices described in Section 12 and our Cookie Policy.

This Policy explains processing; it is not blanket consent to marketing, optional cookies or access to connected accounts. The contractual safeguards for personal data processed on a customer's behalf are in Section 4.4 of our Terms and Conditions, or an applicable separately agreed data-processing agreement.

1. Who We Are

Garage Invoice Ltd is registered in England and Wales under company number 15405281. Our registered office is 28/29 The Broadway No:1 Ealing Broadway, London, England, W5 2NP. Privacy enquiries can be sent to info@garageinvoice.co.uk or to our registered office.

When we are a controller

We act as a controller where we determine the purposes and means of processing, for example for our own enquiries, customer-account and subscription administration, billing records, website operation, legal obligations, complaints and protection of our legal rights.

When we are a processor

The garage or other business using Garage Invoice normally controls the personal data in its customer, vehicle, job, invoice, appointment, staff and communication records ("Customer Data"). We normally process that information on its documented instructions to supply, support, secure and integrate the selected services. Where that business is itself a processor, we may be its authorised subprocessor.

Routine processing to provide or secure the contracted service does not automatically make us a separate controller of the garage's entire database. Our role depends on the actual activity. A payment, telecommunications or other provider may have a separate controller role for its own legal or regulatory purposes.

If you are a garage's customer or member of staff, its privacy notice explains its own decisions about your information. This Policy does not replace that notice or make Garage Invoice the supplier of the garage's repairs, goods or services.

2. Personal Data We Collect

The information processed depends on your role, the services used, the permissions granted and the account settings. A provider appearing in an integrations catalogue does not mean that it receives your data.

Account and business information

This may include names, business and company details, postal and billing addresses, email addresses, telephone numbers, VAT details, user roles, authentication information, subscription details, account settings and records of permissions, instructions and notices.

Customer, vehicle and workshop records

Customer Data may include customer and supplier contact details; vehicle registrations, VINs, specifications, mileage and history; MOT and service information; estimates, invoices, payments, credit notes, expenses and purchase records; appointments, assigned jobs and inspections; notes, images, PDFs, attachments and correspondence. Vehicle information can be personal data where it relates to an identifiable person.

Connected-account and calendar information

We may process connected account identifiers, selected company or calendar identifiers, mailbox addresses, permissions, authorisation tokens, API keys, application-specific passwords and synchronisation records. Calendar information may include event identifiers, titles, descriptions, start and end times, time zones, locations, recurrence, status, availability and permitted organiser or attendee details. The actual fields depend on the selected feature and permissions.

AI information

Where an AI feature is used, we process the submitted instructions and relevant selected context, such as invoice items, job-card or inspection information, vehicle details, customer notes, images or documents, together with generated output and operational information needed for usage charging, error handling and the requested history.

Communications and verification information

Email and SMS processing may involve sender and recipient details, message content, attachments where supported, delivery status, timestamps, replies, opt-outs and complaints. Managed messaging applications may also require business or individual details, company numbers, addresses, authorised-representative details and the identity or address evidence specifically requested for the relevant number or regulatory process.

Payments, support and technical records

We may process billing and transaction references, invoice amounts, currencies, payment or subscription status, credit balances and usage history. Support requests may include correspondence, error details and relevant authorised records. Technical information may include IP address, browser and device information, operating system, access times, login activity, security events, error logs and features used. Cookie-related information is addressed in Section 12.

Payment card or bank information is handled through the relevant secure payment flow. Garage Invoice does not store full payment-card details as part of its payment functionality. Please do not put card numbers, security codes or banking credentials into ordinary notes, uploads, messages or AI requests.

Where information comes from

Information may come directly from you; the business which gives you access or records your transaction; its authorised users and customers; an account or device connected with authority; payment, email or telecommunications providers; and government or commercial data services used for an authorised lookup. Public company records, address information and vehicle or MOT datasets may be obtained where the relevant lookup is enabled. We do not obtain every category for every person.

Where information is needed to create an account, fulfil an order, authenticate access or meet a verification requirement, not providing it may prevent that particular service. Optional integrations and AI features are not required merely to hold a core software subscription.

3. How We Use Personal Data

We use relevant information to administer accounts and subscriptions; supply workshop records and customer-portal functions; process payments and Credits; deliver requested messages and reminders; perform authorised lookups and integrations; provide support; maintain security and reliability; investigate errors, fraud and misuse; handle complaints and rights requests; and meet legal, accounting and regulatory duties.

Where we act as a processor, those activities are limited by the customer's documented instructions and the applicable processing terms. A reference to improving reliability or investigating a problem is not permission to use the content of customer records for unrelated product development, advertising or general-purpose AI training.

AI assistance and provider routing

AI features may be provided through managed Garage Invoice AI or a provider account connected by the customer. Supported options may include OpenAI, Google Gemini, Mistral AI, Anthropic Claude, GroqCloud and OpenRouter. A routing service may pass a request to an underlying model provider, depending on the selected route and settings.

We submit the information needed for the requested function and seek to avoid unnecessary personal data. AI output may be stored as a draft, history or business record where the feature and your instructions require it. Users must check output before applying or relying on it.

We do not use Customer Data to train our own general-purpose AI models. Provider retention, security monitoring and data-use arrangements depend on the selected service and route; an AI request must not be assumed to have zero retention. For managed AI, the applicable providers and processing arrangements are made available before use. For a customer-owned provider account, the customer must also review its agreement and settings. Any processor appointed by us remains subject to the safeguards in Section 7, and Google API information remains subject to Section 5.

Connecting an email, calendar or accounting account does not automatically authorise submission of its contents to AI. Any such use must be a separately selected or enabled, clearly described function, within the granted permissions and applicable provider restrictions.

Automation and communications

The Service can carry out configured actions such as reminders, synchronisation and usage charging. AI tools assist users; the Terms do not authorise relying on them as the sole basis for a decision with legal or similarly significant effects on an individual. Automated security checks may restrict access, and payment or verification providers may make their own decisions. You may contact us to query an action affecting your account and request an appropriate review. Any separately introduced significant automated decision-making requires the applicable explanation and safeguards; this Policy is not advance authorisation for it.

Necessary billing, security, renewal and service notices are distinct from promotional messages. Where we send our own promotional communications, we use a permitted basis and provide an effective opt-out. Garages remain responsible for the purpose and lawfulness of communications they send to their own contacts.

4. Legal Basis for Processing Personal Data

For processing where we are a controller, we rely on a lawful basis appropriate to the particular purpose. This is not an unrestricted choice to use any basis for any activity.

Contract

Where you are personally a party to a contract with us, for example as a sole trader, we process information necessary to take requested steps before that contract and to perform it, including account administration, supplying the service, billing and support.

Legitimate interests

We rely on legitimate interests where appropriate to manage relationships with business customers and their staff, respond to enquiries, operate and protect our business, prevent fraud, maintain proportionate security and diagnostic records, and establish or defend legal claims. For a contact employed by a company customer, business-relationship administration is normally based on these interests rather than a contract with that employee personally. We assess necessity and the effect on individuals and do not rely on this basis where their interests or rights override ours.

Legal obligation

We process information where necessary to comply with obligations which apply to us, such as accounting and tax record-keeping, lawful regulatory requirements and responses required by law. A supplier's commercial rule is not automatically a legal obligation imposed on Garage Invoice.

Consent

We rely on consent where required, including the optional cookie purposes described in our Cookie Policy and promotional communications where applicable law requires consent. Consent can be withdrawn without affecting the lawfulness of earlier processing based on it. Refusing optional consent does not, by itself, prevent use of unrelated core services.

Customer instructions and connection permissions

For Customer Data processed on a business customer's behalf, that business determines and explains the lawful basis for its processing. Accepting our Terms, connecting an account or approving an OAuth permission is an instruction or access authorisation; it is not necessarily data-protection consent from every person whose information is involved.

For verification administration where we determine the purpose, we use contract where necessary for an individual customer's requested service, or legitimate interests in verifying authority and preventing misuse, and legal obligation only to the extent an obligation actually applies to us. Additional safeguards are required if a permitted activity involves special-category or criminal-offence information.

5. Google User Data and Calendar Integrations

Google Gmail and Google Workspace

Where you connect a supported Google email account, the sending function uses the authorised account to send emails you request or configure, including invoices, estimates, statements, job cards and appointment or MOT reminders. It processes the account identity, recipients, message content, attachments and sending information needed for that purpose.

An outgoing-email connection does not authorise us to read, search, monitor, download or delete your Gmail inbox. Any separate mailbox-access feature must first be clearly described and separately authorised. We request permissions for the selected function, not unrelated future functions.

Google Calendar, Microsoft Calendar, iCloud and CalDAV

Supported calendar connections may synchronise events, appointments, assigned job cards and availability with the calendars selected by an authorised user. Depending on the enabled direction and settings, information may be read from the provider, stored in Garage Invoice, or used to create or update linked events in the provider calendar. Deletions are applied only where the supported functionality and the customer's instructions authorise them.

Calendar information can include the fields described in Section 2 and customer, vehicle or job details included in an event. Recurrence, notifications and invitations may also be processed where supported and enabled. Synchronisation may continue in the background until the connection is disabled or access is revoked.

Information exported to a calendar is subject to its sharing, administrator, delegate and device-notification settings. A business should check who can see the destination calendar before including names, registrations, contact details or confidential job information. Imported information is made available according to the application's access and sharing settings, which should also be reviewed.

These principles apply to supported Google Calendar, Microsoft Outlook or Microsoft 365 Calendar, Apple iCloud Calendar and compatible CalDAV connections. Authorisation may use provider tokens or another supported method, such as an application-specific password. Connecting Google Calendar does not also authorise Gmail access, and connecting email does not itself authorise calendar access.

Additional Google data restrictions

Garage Invoice's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy and the applicable Google Workspace user data and developer policy, including the Limited Use requirements.

Google data is used for the disclosed, authorised user-facing functionality. It is not sold, used for advertising or used to train or improve general-purpose AI models. Transfers are limited to those permitted by the applicable policies, including necessary authorised functionality, security, legal requirements and a qualifying business transfer only with the required prior consent.

Human access is restricted by those policies: a general support clause is not specific permission to read connected data. Where required, we obtain affirmative permission for the particular data; other permitted cases concern security, law or appropriately aggregated and anonymised internal operations. Corresponding restrictions apply to derived data. A calendar or email connection is not blanket permission to transfer Google data to an AI provider.

Disconnecting and deleting

You can disconnect through available Garage Invoice controls, revoke access with the provider, or contact info@garageinvoice.co.uk for assistance. For Google accounts, access can also be reviewed through Google Account connections. We stop further authorised access when disconnection takes effect and handle credentials and retained records under Sections 10 and 16. Disconnection does not automatically erase copies already transferred or cancel an instruction already accepted by the provider.

6. Email Sending, SMS and Verification

Email services

Outgoing email may use Garage Invoice's built-in service, a customer-controlled SMTP server or a supported provider. Options may include Microsoft 365, Outlook or Hotmail, Gmail or Google Workspace, Yahoo or AOL, Zoho, iCloud Mail, Mail.com and transactional email providers such as SendLayer, SMTP.com, Brevo, Amazon SES, Elastic Email, Mailgun, Mailjet, MailerSend, Mandrill, Postmark, Resend, SendGrid or SMTP2GO.

The selected route processes sender and recipient addresses, message content, attachments and delivery information. Sending and failure records may be retained to provide communication history, investigate delivery problems and operate suppression controls. Outgoing sending does not, by itself, bring incoming replies into Garage Invoice or authorise general inbox access.

Recipients and their mail providers receive and may retain their own copies. A sent email cannot be erased from every recipient's system merely by deleting it in Garage Invoice.

Managed, customer-connected and device-based SMS

SMS may use the managed Garage Invoice service, a customer's connected provider account or the supported Garage Invoice SMS (FREE) Android-device option. Providers may include Twilio, Clickatell, MSG91, Mobivate, Voodoo SMS, QuickSMS, The SMS Works, BulkSMS and Dexatel, depending on the selected route.

Message content, phone numbers, sender details, delivery information and, where supported, replies pass through the relevant service, device and telecommunications networks. We may store history, replies, delivery outcomes, opt-outs and associated usage records for the selected functionality. The device-based option requires the permissions needed for its supported operation; selecting it does not give us blanket permission to collect an unrelated address book or every personal message on the device.

Telecommunications providers may process traffic and subscriber information for their own legal, network-security and billing obligations. A customer's independently connected provider account has its own privacy arrangements in addition to our responsibilities for the connection.

Dedicated-number and regulatory verification

When you request managed regulated messaging or a dedicated number, we may collect the details and evidence required for that application and transmit them to Twilio or the identified communications provider. Relevant information may pass to its verification providers, affiliates, carriers and competent regulators for review, approval, allocation and continued eligibility.

Application references, status, reasons supplied for rejection or requests for further information, and relevant evidence may be processed to administer the application and inform the account's authorised users. Only submit documents requested for the relevant application through the designated process. Do not place identity evidence in an AI request or an unrelated support message.

Different recipients may have independent retention obligations. Section 10 explains our retention approach. Twilio's own processing is further described in its privacy information. Authorising submission does not guarantee approval or override an individual's data-protection rights.

Marketing and opt-outs

The business sending a message is responsible for appropriate notices, any necessary consent, provider requirements and an effective opt-out. We process suppression information where needed to respect those choices and prevent repeat unwanted contact. A one-way sender name cannot receive a reply; the sender must provide an effective supported alternative. You can contact the named business about its communications, or contact us about suspected misuse of our platform.

7. Sharing of Personal Data

We share information only for an identified authorised or lawful purpose and limit it to what is appropriate for that purpose. Relevant recipients may include:

  • Infrastructure and support suppliers: providers of hosting, storage, backup, technical support, security and communications used to operate the selected service.
  • Selected integration providers: the AI, calendar, email, SMS, accounting, payment and data services required for the features enabled by the customer.
  • Intended recipients and authorised users: people receiving a requested email, SMS, calendar invitation, document or payment link, and people given access under the customer's settings.
  • Professional advisers and competent authorities: where necessary for advice, legal obligations, proportionate fraud prevention or the establishment, exercise or defence of legal claims.

Accounting and data services

Supported QuickBooks, Xero, Sage and FreeAgent integrations may exchange customer or supplier information, invoices, payments, credit notes, expenses, account mappings and other supported records with the selected accounting company. The data and direction depend on the enabled functionality; a connection is not permission to transfer every record.

Authorised vehicle, MOT, valuation, history, address or company lookups transmit the search information needed by the relevant source, such as a registration, VIN, postcode or company query. Results may be stored with the associated record or as a dated report where permitted by the source licence. Availability of a dataset does not mean that every lookup includes personal information about owners or keepers.

Website and domain services

Where we supply hosting, domains or business email, relevant account, technical, mailbox and registrant information may be processed by the hosting infrastructure, mail services, registrars or registries needed for that service. The customer's published content and its own privacy obligations remain separate from our processing on its behalf.

Provider roles and safeguards

A supplier appointed by us to process Customer Data on the customer's behalf is a subprocessor. We require appropriate written processing, confidentiality and security commitments and remain responsible for the obligations we undertake for those subprocessors. Their identity, role and processing location are made available to the customer, with the advance-change and objection process in Section 4.4 of the Terms.

A provider contracted directly by the customer, or acting for its own payment, telecommunications or regulatory purposes, may instead be a separate processor or controller. Its privacy information explains those activities. Listing a possible integration is not a statement that every listed organisation is an active Garage Invoice subprocessor or that all providers have identical data-use terms.

In a proposed restructuring or sale, we may disclose information necessary for lawful due diligence under confidentiality safeguards and transfer relevant information as part of the transaction where lawful. Google API data and other restricted information remain subject to the additional permissions and transfer restrictions that apply to them.

8. Payment Providers

There are two different payment situations: payments for Garage Invoice's own subscriptions and services, and payments a garage receives from its customers using an enabled payment gateway.

For our own fees, we and the relevant payment provider process the information required for billing, subscriptions, authorisations or mandates, receipts, refunds, reconciliation, fraud prevention and disputes. This may include billing contact details, payment references, status and limited payment-method information returned by the provider.

For garage customer payments, the selected gateway may receive invoice and customer information, amounts, currencies and payment instructions and return references and status. Supported options may include Stripe, Square, Klarna, Mollie, SumUp, Teya, Revolut Pay, GoCardless, PayPal, Braintree, 2Checkout, Authorize.net, Instamojo and PayU, depending on the account and supported product.

The garage remains responsible for its transaction with its customer. A payment provider may process information as an independent controller for its own fraud, verification, legal, credit or payment purposes. These uses are described in that provider's notice, not authorised without limit by this Policy. Removing a gateway does not erase its transaction records or cancel its separate agreement.

Our Refund Policy concerns payments to Garage Invoice, not a garage's refund obligations to its repair or retail customers.

9. Data Storage and Security

We apply appropriate technical and organisational measures proportionate to the processing risks. These address access permissions, confidentiality, secure transmission and storage where appropriate, protection of connection credentials, backup and recovery, incident handling, monitoring and assessment of security measures.

Access by our personnel is limited to authorised purposes and those who need it. Support access to a customer's records is limited to what is reasonably required and remains subject to instructions and any stricter provider rules, including the Google restrictions in Section 5.

Available account controls may include password policies, login restrictions and two-factor authentication. Their availability depends on the service and settings. Security or authentication services such as reCAPTCHA, where enabled, may process IP address, browser or device information and authentication results. Relevant storage or access on a user's device is addressed in our Cookie Policy and the feature notice.

Customers should maintain appropriate user permissions, remove access when staff leave and review connected accounts. Those responsibilities do not remove our own security obligations. No online service can guarantee that every incident or data loss will be prevented.

Where a personal data breach affects information we process on a customer's behalf, we notify that customer without undue delay after becoming aware of it and provide relevant assistance under the processing terms. Any separate notification to individuals or a regulator is made where the applicable law requires.

10. Data Retention

We keep identifiable information only for an appropriate period for the relevant purpose. Retention is assessed by category, not by assuming that every item in an account must be kept for as long as a billing record.

  • Account and billing records: during the relationship and afterwards to the extent necessary for applicable accounting, tax, payment reconciliation, complaints or legal-claim requirements.
  • Customer Data: for the customer's instructed service and retention needs, followed by the agreed return or deletion process when processing ends.
  • Connection credentials: while needed for an authorised connection. After disconnection, we stop using them for access and remove or securely disable them as appropriate; residual protected backup copies follow the deletion cycle.
  • Communication, calendar, AI and integration records: for the selected history, synchronisation and business-record functions, and any proportionate, separately justified operational retention. Copies incorporated into a customer's records follow its instructions.
  • Verification information: for the application, number allocation and continued eligibility, followed only by retention justified for applicable legal, audit, fraud-prevention or dispute requirements. We do not automatically retain every identity document for as long as the account exists.
  • Support, diagnostic and security information: for the time proportionate to investigating and resolving the issue, protecting the service and dealing with relevant claims or obligations. Unrelated customer content is not retained indefinitely in diagnostic records.
  • Consent and suppression records: for the period needed to demonstrate and respect choices and prevent further unwanted contact, using only the information necessary for that purpose.

For data we process on a customer's behalf, we return or securely delete the personal data at that customer's choice when the relevant processing ends, and delete existing copies unless applicable law requires storage. We cooperate on a documented export and deletion process. A general reference to fraud, disputes or business purposes does not override those processor duties.

Backups that cannot immediately be selectively erased are protected, put beyond ordinary use and deleted as soon as reasonably possible within the normal deletion cycle. They are not retained indefinitely. Relevant deletions are reapplied if a backup must be restored.

We can explain the retention and backup-deletion periods applicable to a particular service or request at info@garageinvoice.co.uk. Where we retain information separately as a controller, retention is limited to the records and period justified for that purpose. Information which is genuinely anonymised so that individuals are no longer identifiable is treated differently from merely pseudonymised records.

External providers and recipients may keep their own copies under their agreements or legal duties. Their retention does not entitle Garage Invoice to keep an additional copy indefinitely.

11. User-Controlled Data

Business customers must have authority and a lawful basis for the Customer Data and instructions they provide, give appropriate notices to their customers and staff, and use suitable access and retention settings. This includes the authority to connect an employee mailbox, shared calendar, merchant account or provider account.

Customers should minimise unnecessary personal information in event titles, attachments, notes and AI input and check the audience before sharing. Do not use ordinary fields or uploads to submit passwords, payment credentials or identity evidence that a feature has not requested.

The Service is not intended for systematic processing of special-category or criminal-offence data unless expressly agreed with appropriate safeguards. Incidental inclusion does not remove our applicable responsibilities, but the customer should avoid it where it is not necessary and authorised.

We assist customers with applicable individual-rights, security and deletion obligations as described in the processing terms. Customer responsibilities do not excuse our own breach or remove an individual's rights.

12. Cookies and Similar Technologies

Our website and software use cookies or similar technologies for functions such as sessions, security and remembering requested actions. Optional technologies may support preferences, website analytics or third-party content. The categories, providers, purposes, durations and available choices are explained through our Cookie Policy and the relevant consent information.

Under the approach described in that Policy, optional analytics and optional tracking components are enabled only after the relevant choice. Necessary technologies are distinguished from optional ones. You can revisit the website's Manage consent control to change your choices; browser controls are an additional option, not a substitute for consent where it is required.

Website analytics and embedded social or other external content may involve technical information about a visit being sent to the identified provider. Depending on the component and permissions, that provider may associate the interaction with its own account or use information for purposes explained before activation. This is distinct from sharing workshop records, AI input or connected-calendar content for advertising, which this Policy does not authorise.

Accepting the Terms, connecting an integration or continuing to browse does not, by itself, consent to optional tracking. Our Cookie Policy does not authorise a garage to place unrelated tracking on its own website or customer portal without appropriate information and choices.

13. Children's Privacy

Garage Invoice is intended for business use and is not directed at children as a consumer service. We do not seek children's information for that purpose. A business may nevertheless lawfully hold information about a young customer, employee or apprentice; this remains subject to its instructions and applicable safeguards rather than an assumption that all such information can be disregarded.

Please contact us if you believe a child has provided information inappropriately. We will assess the circumstances and take appropriate steps, including deletion where required.

14. International Data Transfers

Information may be processed in the United Kingdom, the European Economic Area or elsewhere, depending on the selected providers, support arrangements and intended recipients. UK hosting of a core application does not mean that every email, calendar, AI, payment or messaging provider processes information only in the UK. Access from another country can also require a transfer assessment.

Where we are responsible for a restricted international transfer, we use the applicable lawful mechanism and required assessment and safeguards. Depending on the destination and arrangement, this may involve an applicable adequacy decision or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum, and EU Standard Contractual Clauses where EU requirements apply.

These mechanisms are applied to the actual recipient and processing; the fact that a provider is well known or has an overseas office is not sufficient. Transfers of Customer Data also remain subject to the customer's documented instructions and our processing terms.

You may contact info@garageinvoice.co.uk for information about relevant recipients, processing locations and the safeguards applying to a particular service, and to request a copy of the relevant safeguards, subject to proportionate protection of confidential information.

15. Your Data Protection Rights

Depending on the processing and applicable law, you may have rights to access your personal data, correct inaccuracies, request erasure, restrict processing and receive or transfer certain information in a portable form. These rights have conditions and exceptions; for example, portability generally concerns information you provided that is processed automatically on the basis of consent or a contract with you.

Your right to object: you may object to processing based on legitimate interests on grounds relating to your circumstances. We will consider whether the law requires us to stop. You may object to direct marketing at any time, and we will stop processing your information for that marketing.

Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Use the relevant consent or unsubscribe control, or contact info@garageinvoice.co.uk.

You can exercise rights by contacting us without using a particular form or legal phrase. We may request proportionate information to verify identity or clarify a request where permitted, without asking for unnecessary evidence.

We respond without undue delay and normally within one month, subject to the rules that apply to the particular request. Where a permitted extension is needed, for example because of complexity or the number of requests, we explain it within the applicable period. We do not impose a general fee for exercising rights.

For Customer Data controlled by a garage, we will direct or pass the relevant request to that business and assist it as appropriate. A billing disagreement with the business does not, by itself, remove data-protection rights.

Privacy complaints

You may complain about our handling of personal data at info@garageinvoice.co.uk or by writing to our registered office. We acknowledge a data-protection complaint within thirty (30) days, make appropriate enquiries, keep you informed and communicate the outcome without undue delay. This complaints process is separate from ordinary software-support response arrangements.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK data-protection regulator. Where EU GDPR applies, you may also complain to the relevant supervisory authority, including in the country where you live, work or consider an infringement occurred. Contacting us does not remove that right.

16. Account Deletion and Data Removal

Contact info@garageinvoice.co.uk to request account closure or assistance with returning or deleting data. We verify the authority of someone asking to close a business account or erase its records. Individual rights requests do not require account ownership and are handled under Section 15.

Subscription cancellation, account deletion, integration disconnection and withdrawal of optional consent are different actions. We will clarify the requested scope where necessary. Stopping a future subscription renewal does not, by itself, instruct immediate deletion while the paid service continues; removing a connection does not automatically cancel a subscription or delete the external account.

Before access ends, the business should arrange any necessary export. Personal data processed on its behalf is returned or deleted under the processing terms, with the limited retention and backup treatment described in Section 10. Unpaid fees do not override our processor return and deletion duties.

Records already sent to recipients or accepted by external calendars, accounting platforms, mail services or payment providers may remain there. We assist with requests within our responsibility, but deleting our copy does not automatically remove those independent records. Provider-side disconnection or deletion may need to be requested separately.

17. Changes to This Privacy Policy

We may update this Policy to reflect changes in services, processing or legal requirements. The current version and its update date are published on our website. We will provide additional notice of material changes where appropriate, including through email, the service or the relevant feature.

A new or materially different use requires the relevant lawful basis, information and permissions before it begins. Updating this page or continuing to use the Service does not create consent where fresh consent is required, override customer instructions or reduce contractual processing safeguards.

18. Contact Us

Garage Invoice Ltd
Company number: 15405281
Registered office: 28/29 The Broadway No:1 Ealing Broadway, London, England, W5 2NP
Email: info@garageinvoice.co.uk
Website: www.garageinvoice.co.uk

Please identify the relevant account or service where helpful, but do not send passwords, full payment-card details or unnecessary sensitive documents with a privacy enquiry.

Garage Invoice Vehicle Management Software logo in the footer section
Professional, affordable, and feature-rich Invoicing software for Workshops and Car Garages - making management simple and efficient.