Legal

Privacy Policy

Last updated: September 29, 2026

This policy explains what ProjectGarage collects, why, who it is shared with, and how to get it deleted. It covers this website (www.projectgarage.us) and the ProjectGarage application at www.shop.projectgarage.us.

1. Who we are

ProjectGarage is shop management software for independent auto repair and restoration shops. It is operated by Garage Softworks LLC, a limited liability company in the United States (“we”, “us”), at 407 Morning Mist Trl, Canton, GA 30114, USA.

You can reach us about anything in this policy at privacy@projectgarage.us. For anything else, including help with the product, write to support@projectgarage.us.

2. Two different roles, and why the distinction matters

ProjectGarage is business software sold to repair shops, so the same policy has to describe two genuinely different relationships.

  • Our own customers — the shops. For a shop’s account, its staff logins, its subscription and its billing, we decide what is collected and why. We are the controller of that information.
  • The records a shop keeps in ProjectGarage. A shop’s own customers, their vehicles, jobs, hours and invoices belong to the shop. We hold and process that data on the shop’s instructions, as its service provider. We do not use it for our own purposes, and we do not sell it.

If you are a vehicle owner and a shop has your details in ProjectGarage, the shop is the one who decides what happens to them. Ask the shop directly to see, correct or delete your information. If you contact us instead, we will pass the request to the shop and help them act on it.

3. Bank account connections

A shop on a paid plan can connect its own business bank account so that money arriving in the account can be matched against invoices the shop has issued in ProjectGarage. This section describes that feature in full, because it is the most sensitive thing the application touches.

Connecting is optional. ProjectGarage works without it. Shops that do not connect an account record payments by hand, which is the default and always available.

How the connection is made

Bank connections are provided by Stripe Financial Connections. The shop authenticates directly with its bank through Stripe. We never see, receive or store online banking usernames, passwords, security codes or any other bank login credential. What we receive back is an account identifier issued by Stripe, the name of the institution, and the last four digits of the account number.

The access is read-only. The connection cannot be used to move money, initiate a payment or change anything at the bank, and the application contains no code that could do so.

What we receive

For each transaction Stripe reports on the connected account, we receive:

  • the amount and currency
  • the date it settled
  • the description or counterparty text the bank supplies
  • a transaction identifier, used to avoid importing the same deposit twice
  • the transaction status, used to ignore anything not yet settled

We do not request or use account balances, account ownership details, or the identity of the person who holds the account.

What we do with it — and the limits built into the code

The single purpose is reconciliation: finding which incoming deposit corresponds to which unpaid invoice, so that a shop does not have to tick them off by hand. We compare the amount, the date and the description against the shop’s own open invoices and present the likely match as a suggestion. A person at the shop confirms or rejects every one. Nothing is ever applied to an invoice automatically.

Three limits are enforced in the software itself, not merely as policy:

  • Money in only. Outgoing payments — the shop’s own spending — cannot pay the shop’s own invoice, so debits are discarded during processing and are never stored.
  • Settled transactions only. Pending and voided entries are ignored.
  • Nothing from before the shop joined. Transactions dated more than fourteen days before the shop’s own ProjectGarage account was created are discarded, so connecting an account a business has held for years does not pull years of unrelated history into the product.

What we never do with it

We do not use bank transaction data for any of the following, in any form:

  • lending, credit, underwriting, insurance or eligibility decisions
  • risk, fraud or creditworthiness scoring about any person
  • marketing, advertising, or building profiles of shops or their customers
  • selling, renting or sharing it with anyone for their own purposes
  • training machine learning or AI models
  • any purpose other than reconciling that one shop's own invoices

Stopping it, and what deletion removes

A shop can disconnect its bank account at any time from Payments in the application’s settings. Disconnecting takes effect immediately: we instruct Stripe to end the subscription to that account, no further transactions are retrieved, and the stored connection record is deleted outright rather than deactivated.

Deposits that were already matched to invoices are not removed by disconnecting, and it would be wrong for them to be: once a shop has confirmed that a deposit paid an invoice, that is the shop’s accounting record of being paid. Those records are deleted when the shop’s account is deleted, as described in section 8, or sooner on request.

If we ever change the provider that supplies bank connections, we will update this policy and tell connected shops before the change takes effect.

4. What else we collect

  • Shop account information. The shop’s name, address, contact details, currency and language; the name and email address of each person who signs in, and their permissions; and, if the shop chooses to print them on invoices, its bank account details.
  • Records the shop enters. Its customers’ names and contact details, their vehicles (including registration and VIN, and odometer readings), jobs and the work done on them, hours logged by staff, parts and inventory, estimates, invoices and payments.
  • Payment and subscription data. What a shop pays us for its subscription, and — if the shop uses ProjectGarage to take card payments from its own customers — the record of those payments. Card numbers are handled entirely by the payment processor; we never receive or store them.
  • Technical data. Ordinary server logs: IP address, browser and device type, the pages and API endpoints requested, and the time. Used to keep the service running and secure, and to investigate faults.
  • This website. The marketing site at www.projectgarage.us uses Google Analytics, as described in section 5. The application itself carries no analytics or advertising trackers of any kind.

The application stores your language preference and your session in your own browser’s local storage. It does not use advertising or cross-site tracking cookies.

5. Analytics and cookies

The marketing site at www.projectgarage.us (in English and Czech) uses Google Analytics, a service of Google LLC, to count visits and see which pages are read. The application at www.shop.projectgarage.us does not use it.

Nothing is stored in your browser until you accept. A bar at the bottom of the site asks. Until you choose, and if you decline, Google Analytics runs without cookies and can only send Google a cookieless signal that a page was viewed.

If you accept, Google Analytics collects:

  • the pages you view, when, and the page you came from
  • your browser, operating system, device type and screen size
  • your approximate location (country and city), which Google derives from your IP address; Google Analytics does not store the IP address itself
  • two first-party cookies: _ga, which tells one visitor from another, and _ga_ followed by our property id, which keeps the current visit together. Each is kept for up to 13 months.

Advertising features are never turned on: Google’s ad-storage and ad-personalisation signals stay denied whatever you choose, and the data is not used to advertise to you.

Changing your mind. “Cookie settings” at the bottom of every page of this site reopens the choice. Declining there removes the _ga cookies and stops them being set again. Your answer is kept in your own browser’s local storage, not in a cookie, and is not sent to us. Clearing your browser’s site data resets it, and the bar asks again.

6. How we use information

  • To provide the application: storing and showing a shop its own records, producing estimates and invoices, sending the emails a shop asks us to send on its behalf, and matching payments as described above.
  • To keep accounts secure: authentication, permissions, and detecting abuse.
  • To bill for subscriptions and answer support requests.
  • To fix problems and improve the product, using aggregate usage and error information.
  • To meet legal and tax obligations.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done so.

We do not use shop or customer data to train machine learning models. One feature — an optional “look up with AI” button that identifies a part from a scanned barcode — sends the barcode and product description to Anthropic’s API. It is used only when a person presses that button, and it sends no customer, vehicle or financial information.

7. Who we share information with

We use a small number of service providers to run ProjectGarage. Each receives only what it needs for its own function, and none of them is permitted to use it for their own purposes.

ProviderWhat it is used for
RailwayHosting for the application and its database, in the United States.
StripeBank account connections, card payments, and subscription billing.
SquareCard payments, for shops that choose it instead of Stripe.
ResendSending email: account activation, password resets, and the estimates, invoices and reminders a shop sends its own customers.
Google AnalyticsVisitor statistics for the marketing website only, as described in section 5. Not present in the application.
AnthropicThe optional barcode part lookup described above. Receives no personal data.
DHL, FedEx, UPS, USPSTracking parts shipments, where a shop has entered a tracking number.
NHTSA, DecodeThis, UPCitemdb, RockAutoLooking up vehicle details from a VIN and part details from a part number. These receive a VIN or a part number, not the owner's identity.

We will also disclose information where the law requires it, and to protect our rights or someone’s safety. If ProjectGarage is ever sold or merged, information may transfer with the business; we will say so here before that happens.

8. How long we keep it

  • While the shop uses the service. A shop’s records are kept for as long as its account is open, because they are the shop’s working history. A shop can delete individual records at any time.
  • Bank connections. Deleted immediately on disconnection, as described in section 3.
  • After an account is closed. We delete a closed shop’s data within 90 days, except for records we are required to keep for tax and accounting purposes.
  • Logs. Server logs are kept for a short operational period and then discarded.

9. Security

  • All traffic between your browser and ProjectGarage is encrypted with TLS.
  • Stored bank account numbers are encrypted with AES-256-GCM, so they are unreadable in a database backup and cannot be silently altered.
  • Bank account numbers are shown only as the last four digits, and revealing them in the application requires the account password again.
  • Each shop's data is isolated from every other shop's, enforced on the server rather than in the browser. Within a shop, what each member of staff can see and do is controlled by the owner.
  • Sign-in supports passkeys as well as passwords.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your information, we will tell you and any authority we are required to notify.

10. Your rights

If you are in California, you have the right to know what personal information we have collected about you and where it came from, to receive a copy of it, to have it corrected, and to have it deleted. You may not be discriminated against for exercising any of these. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to exercise. You may use an authorised agent to make a request; we will ask for proof of their authority.

If you are in the European Union, the European Economic Area or the United Kingdom, you have the right to access, correct, delete, restrict and object to the processing of your personal data, and to receive it in a portable form. Where a shop holds your data, the shop is the controller and we act on its instructions; send your request to the shop, or to us and we will route it. You may complain to your national data protection authority.

To make any request, write to privacy@projectgarage.us. We will respond within the time the applicable law allows, and we will verify who you are before acting on a request about someone’s data.

11. Where data is held

ProjectGarage is operated from the United States and its data is stored there. If you use it from the European Economic Area, the United Kingdom or elsewhere, your information is transferred to the United States. Where that transfer requires a legal safeguard, we rely on the European Commission’s standard contractual clauses with the providers listed in section 7.

12. Children

ProjectGarage is business software and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child’s information has reached us, write to us and we will delete it.

13. Changes to this policy

When this policy changes we will update the date at the top of the page. If a change materially affects how we handle bank or payment data, we will notify affected shops directly rather than relying on this page alone.

14. Contact

Garage Softworks LLC
407 Morning Mist Trl
Canton, GA 30114
United States
privacy@projectgarage.us

Privacy requests may be sent by post to the address above or by email to privacy@projectgarage.us. Email reaches us faster.