This is a template, not legal advice. It lists the categories of data this specific application actually collects, but data-protection law (GDPR, CCPA, etc.) depends on where your users are and what you do with their data — have a lawyer review this before you rely on it, and fill in every bracketed [placeholder].

Last updated: [date]

1. Who we are

[Company legal name] ("we", "us") operates this repair-shop marketplace. This policy describes what personal data the platform collects and why.

2. What we collect

  • Repair requests: name, email, phone number, device details, a description of the issue, and an optional photo of the damage.
  • Accounts: for Customers and Owners — name, email, phone, and a hashed password (we never store your password in plain text).
  • Payments: when you pay by card, your card details go directly to Square or Clover — we only store the payment status and a reference id, never your card number.
  • Reviews: your name and whatever you write in a review, shown publicly once approved.
  • Two-factor authentication: if you enable it, an encrypted TOTP secret and recovery codes.
  • Technical: standard server logs (IP address, request timestamps) used for security and rate-limiting abusive requests.

3. Why we collect it

To connect you with a repair shop and let them (and only them) see your request; to let you track your repair by tracking code or account; to process payments; to send you email/SMS updates about your repair's status (SMS only if a phone provider is configured); and to secure accounts (2FA, rate limiting).

4. Who we share it with

The repair shop assigned to your request sees your contact details and repair description — that's the point of the platform. Payment processors (Square/Clover) receive what they need to process a card payment. [Twilio, if SMS notifications are enabled, receives your phone number to send the SMS.] We don't sell personal data to third parties.

5. How long we keep it

[Add your actual retention policy — e.g., "Repair records are kept for N years for warranty/dispute purposes; you can request deletion of your account data by contacting us, subject to records we're legally required to keep."]

6. Your choices

You can track a repair anonymously without creating an account. If you do create an account, you can request password resets yourself; for data access/deletion requests, contact [support email].

7. Security

Passwords are hashed, two-factor authentication is available, and card numbers never touch our servers. No system is perfectly secure, though — [add your incident notification commitment here].

8. Changes to this policy

[Describe how you'll notify users of material changes to this policy.]

9. Contact

Questions about this policy or your data: [support email / contact page link].