Privacy policy
What we collect when we act as a controller, why, and the rights you have over it.
Autograff, Inc. · Version 1.3 · Last updated September 7, 2026
This Privacy Policy explains how Autograff, Inc. (“Autograff,” “we,” “us,” “our”) collects, uses, and shares personal information when we act as a controller of that information — for example, in relation to our website, our business customers and prospects, and the individuals who use our products on their behalf.
Important — who controls your data. When a repair shop, fleet operator, or other business customer uses Autograff to process information about their own customers (for example vehicle owners), or connects a business system of their own (for example an accounting system such as QuickBooks Online), that business is the controller of that information and Autograff acts as a processor on their behalf. This Policy does not govern that processing — it is governed by our Data Processing Addendum and by the privacy notice of the business you dealt with. If you are a vehicle owner or other end customer asking how your data is used, please contact the repair shop or fleet operator you dealt with.
1. Who This Policy Covers
This Policy applies to personal information we handle as a controller, including information about:
- Visitors and prospects: people who visit our website, contact us, or express interest in our products.
- Business customers and their users: our customers’ personnel and authorised users who set up or use the Platform, and the account, billing, and support information associated with them.
Where we process information on behalf of a business customer — including end-customer or vehicle-owner data submitted into the Platform, and data we retrieve from a business system the customer connects to the Platform — we do so as a processor under our Data Processing Addendum, not under this Policy. Section 5 describes how connected-system data is handled, because customers and their accountants regularly ask.
2. Information We Collect
| Category | Examples | Source |
|---|---|---|
| Contact and identity | Name, business email, phone, company, role. | You; your employer; our customers. |
| Account and authentication | Login credentials, account settings, roles and permissions. | You; the Platform. |
| Billing | Billing contact, transaction history, and payment status (payment-card details are handled by our payment processor). | You; our payment processor. |
| Usage and device | Log data, IP address, device and browser type, pages and features used, and similar analytics data. | Automatically, via the Platform and our website. |
| Connected business-system data | Accounting and financial-record data retrieved from a system a customer connects, such as QuickBooks Online — for example customer and vendor records, contact details, chart of accounts, items and services, estimates, invoices, bills, credit memos, payments and payment status, tax codes, class or location tracking, and account names and identifiers. May include the names and contact details of the customer’s own personnel, customers, and suppliers. | The connected system, retrieved with the customer’s authorisation. |
| Connection credentials | OAuth access and refresh tokens, connection identifiers such as an Intuit company ID (realm ID), and connection status and error logs. We never receive or store the username or password for a connected system. | The connected system’s authorisation flow. |
| Website visitor identification | Business and professional identifiers — such as name, company, professional email, and LinkedIn profile — that a third-party identity provider matches to your visit when you browse our website. In the United States this may identify you individually; outside the United States it is limited to the associated company. | RB2B (a Retention.com service). |
| Communications | Messages, support requests, and feedback you send us. | You. |
| Marketing | Preferences and engagement with our communications and events. | You; analytics providers. |
We do not seek to collect special categories of personal data through our website or in our controller capacity. Please do not send us sensitive information except where specifically requested.
We do not request or store full payment-card numbers. Where the Platform handles payments, card data is captured by our payment processor’s secure components.
3. How We Use Information
We use personal information to:
- provide, operate, secure, and support our website and the Platform, and administer accounts;
- process billing and manage our business relationship with customers;
- communicate with you, including service messages and, where permitted, marketing;
- identify the businesses that visit our website — and, in the United States, the business contacts behind those visits — so we can follow up with relevant business-to-business communications;
- understand and improve our products, including capacity planning, product analytics, and feature development, using aggregated and de-identified data wherever practical, and subject to the limits in Sections 4 and 5;
- detect, prevent, and investigate security incidents, fraud, and misuse;
- comply with law and enforce our agreements; and
- with your consent where required, for other purposes we describe to you.
Where the EU or UK GDPR applies, we rely on the following legal bases: performance of a contract; our legitimate interests (such as operating, securing, and improving our business and products) balanced against your rights; your consent (which you may withdraw); and compliance with legal obligations.
Where the EU or UK GDPR applies to the website visitor-identification described in Section 6, we rely on your consent for the storing of and access to information on your device, and on our legitimate interest in identifying the organisations interested in our products.
4. AI Features and Product Improvement
Our products include AI features. Where we improve our AI and other models, we use aggregated and de-identified information, consistent with our agreements and applicable law, in a way that does not identify you, any individual driver, vehicle, end customer, or repair shop. We do not use the content a business customer processes through the Platform to train models in a way that would identify that customer’s data, except as permitted under our Data Processing Addendum.
Connected accounting and financial data is excluded. We do not use data retrieved from a connected accounting or financial system — including QuickBooks Online — to train, fine-tune, or improve any machine-learning model, and we do not include it in benchmarking, market-intelligence, or other analytics products, even in aggregated or de-identified form. We use it only to provide the connected feature to the customer whose system it came from, as described in Section 5. The only exception is where that customer has separately and expressly authorised a different use in writing, and any authorisation required from the provider of the connected system has been obtained.
5. Data From Systems You Connect (Including QuickBooks Online)
The Platform can connect to business systems our customers already use, so that records do not have to be entered twice. This section explains how we handle data from those connections. Our accounting integration with QuickBooks Online is the primary example, and the commitments below apply to it in full.
Who controls it. The customer who authorises the connection is the controller of the data in the connected system. Autograff acts as that customer’s processor, under our Data Processing Addendum and the customer’s instructions.
We do not act on the provider’s behalf. We do not process data from a connected system on behalf of the provider of that system, and the provider does not process it on our behalf. Where the provider also processes the same data, it does so as an independent controller for its own purposes, under its own privacy statement and its own agreement with the customer — not under this Policy and not on our instructions. For QuickBooks Online, Intuit’s Global Privacy Statement governs Intuit’s own handling of your data. Our access is as your agent, on your authorisation, for the purposes you have enabled.
Authorisation. A connection is only created when a person with authority at the customer authorises it through the connected system’s own authorisation flow — for QuickBooks Online, Intuit’s OAuth 2.0 flow. We never ask for, receive, or store the username or password for a connected system. Access tokens are stored encrypted, with access restricted to the systems and personnel that need them. We keep a record of who authorised each connection and when, so that the authorisation can be evidenced, and we do not modify or bypass the provider’s own consent screens.
What we access. We request the narrowest set of permissions (scopes) needed for the features the customer has enabled, and we retrieve only the record types those features require. The categories we may retrieve from an accounting system are listed in the table in Section 2.
Where it is held. Connected-system data is processed and stored in the United States, on the infrastructure described in Section 8, and is transferred only to the subprocessors described in Section 7.
What we use it for. We use connected-system data only to provide the connected feature to the customer who authorised the connection — for example to match a repair invoice to an accounting record, sync estimates and invoices, reflect payment status, or reconcile fleet billing. We use it to provide support and to investigate errors in the connection when asked or where necessary. We do not use it for any other purpose.
What we will not do. We do not sell, rent, license, trade, or otherwise transfer connected-system data, or make it available to any third party for a purpose that does not directly support the customer’s own use of the connected feature. We do not use it for advertising or marketing, our own or anyone else’s. We do not combine it with other customers’ data to create benchmarks, indices, market intelligence, pricing intelligence, or datasets offered to third parties. We do not use it to train or improve AI or prediction models (see Section 4). We do not use it to assess creditworthiness or to make or inform any credit, lending, financing, insurance, tenancy, or employment decision, and we do not supply it to anyone who does. We do not disclose it to any third party except a subprocessor engaged to help us deliver the connected feature, and then only under written obligations at least as protective as those in this section, or where we are legally required to disclose it.
Disconnecting. A customer can disconnect at any time from the integrations screen in the Platform. For QuickBooks Online, a customer can also disconnect from the Apps area of their QuickBooks Online company. On disconnection we stop retrieving data immediately and revoke the stored tokens without undue delay, and in any event within 24 hours.
Deletion. We securely delete connected-system data from our production systems within 30 days of disconnection, of the customer’s deletion request, or of termination of the customer’s subscription, whichever comes first. Deletion is permanent, not de-identification and not a reversible soft delete. The only records we keep beyond that are those the law requires us to keep, such as transaction and tax records.
Backups. Copies contained in backup and disaster-recovery images can’t be deleted individually without compromising the integrity of the backup. Those images are encrypted, access-controlled, held only for disaster recovery, and expire on a fixed 180-day rolling cycle, after which the data in them is unrecoverable. If we ever restore an image after a disaster-recovery event, we re-apply any deletion that had already taken effect. So a deletion is complete in the systems that serve you within 30 days, and complete everywhere within 180 days.
Data a customer chose to store in the Platform itself — for example an invoice created in ShopOS — remains the customer’s Platform data and is governed by Section 9 and by our Terms.
Availability. Connections depend on the third-party provider’s service and API. Providers can change, deprecate, or withdraw their APIs, and we may have to change or discontinue a connection as a result. The provider of a connected system is not a party to our agreement with the customer and gives no warranty in respect of the Platform.
6. Cookies and Analytics
Our website uses cookies and similar technologies for functionality, analytics, and marketing. How we handle non-essential technologies depends on your location. In the EEA, the UK, and other regions where consent is required, we ask first, and nothing non-essential runs until you agree. In the United States, non-essential technologies may operate by default, and you can opt out at any time using the “Your Privacy Choices” link in our website footer or the options below. Wherever you are, if your browser sends a Global Privacy Control (GPC) signal we treat it as an opt-out of the website visitor-identification described below, which then does not run. For more detail, see our Cookie Notice at autograff.ai/cookies.
Everything in this section applies to our public website only. It does not apply to the Platform, to Customer Data, or to data from connected business systems described in Section 5. We do not run advertising, marketing, or identity-resolution technologies inside the Platform.
We use a third-party identity-resolution provider to recognise the businesses that visit our website so we can follow up with relevant business-to-business communications. In the United States, this identification may include information that identifies you as an individual. Outside the United States, it is limited to company-level information — identifying the organisation associated with a visit — and does not identify you as an individual. It never operates on our confidential deck pages (autograff.ai/d/…).
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout.
You also have the option to opt out of the collection of your personal data in compliance with GDPR by visiting https://www.rb2b.com/rb2b-gdpr-opt-out.
7. How We Share Information
We share personal information with:
- Service providers and subprocessors: vendors who process data on our behalf to provide the Platform and run our business (for example cloud-infrastructure, AI and model, telephony and messaging, payment, analytics, and support providers), under appropriate contractual obligations. Our current subprocessor list is available as described in our Data Processing Addendum, and identifies which subprocessors may process data from connected business systems.
- Business customers: where you are an authorised user, with the customer that operates your account.
- Professional advisors and authorities: where reasonably necessary, or to comply with law, legal process, or a lawful government request, or to protect rights, safety, and the integrity of our services.
- Corporate transactions: in connection with a merger, financing, acquisition, or sale of assets, subject to appropriate protections. Data from a connected business system is transferred only where the recipient is bound by obligations at least as protective as Section 5, and only where the provider of that connected system permits it — a connection may instead need to be re-authorised by the acquiring entity.
We do not sell personal information for money. The website visitor-identification described in Section 6, and certain advertising or analytics cookies, may qualify as a “sale” or “share” under US state privacy laws, which define those terms broadly. We treat them as such, and honour opt-out rights as described in Section 10, including recognised browser opt-out signals such as Global Privacy Control. This applies only to information collected through our public website. We never sell or share Customer Data or data from connected business systems, under any definition of those terms.
8. International Transfers
We operate globally and may transfer personal information to, and process it in, the United States and other countries that may have different data-protection laws than your own. Where we transfer personal information subject to the EU or UK GDPR to a country without an adequacy decision, we use an approved transfer mechanism, such as the European Commission’s Standard Contractual Clauses and the UK Addendum. You may contact us for more information about these safeguards.
The Platform is hosted in the United States, and data from connected business systems is processed and stored in the United States.
9. Retention and Security
We keep personal information for as long as needed for the purposes described in this Policy, to provide our products, to comply with legal obligations, to resolve disputes, and to enforce our agreements, after which we delete or de-identify it. Retention and deletion of data from connected business systems is governed by Section 5.
We maintain administrative, technical, and organisational safeguards designed to protect personal information, including:
- encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest using industry-standard methods;
- encrypted storage of integration credentials, including OAuth access and refresh tokens, with access limited to the systems and personnel that require it;
- no collection or storage of usernames or passwords for connected third-party systems;
- role-based, least-privilege access control, with multi-factor authentication required for administrative access;
- logical separation so that one customer’s data is not accessible to another customer;
- logging and monitoring of access to production systems;
- vulnerability management and timely, risk-based patching; and
- a documented security incident-response process, including notification of affected customers without undue delay and notification of any affected third-party provider as required.
No method of transmission or storage is completely secure, and we do not represent that our safeguards are impenetrable.
Information obtained through the website visitor-identification described in Section 6 is deleted or de-identified when you ask us to, and in any event no later than 24 months after your last interaction with us.
10. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information; to object to or restrict certain processing; to withdraw consent; and to opt out of certain uses. We will respond consistent with applicable law and may need to verify your identity.
If your personal information was provided to us by, or is processed by us on behalf of, a business customer (for example as an end customer of a repair shop or fleet, or as a contact in a connected accounting system), please direct your request to that business; we will assist them as a processor under our Data Processing Addendum.
To opt out of the website visitor-identification described in Section 6, use the “Your Privacy Choices” link in our website footer. Doing so stops further identification of you on this website and removes the identifiers previously set on your device. We treat a recognised Global Privacy Control signal from your browser the same way, wherever you are, so if your browser sends one you do not need to do anything else.
You can also opt out directly with the provider at https://app.retention.com/optout, and — in the EEA or UK — under the GDPR at https://www.rb2b.com/rb2b-gdpr-opt-out. These stop the provider identifying you; they operate separately from the controls on our own website.
None of these options delete information we have already collected. To request deletion, contact us as described below.
To exercise rights regarding information we control, contact us at contact@autograff.ai. You also have the right to complain to a supervisory authority, and — in the EEA or UK — to lodge a complaint with your local data-protection authority.
11. Children
Our products are for business use and are not directed to children, and we do not knowingly collect personal information from children.
12. Text Messages
The repair shop is the controller of the messages described below; Autograff sends them through the Platform on the shop’s behalf. We set the terms out here so they are easy to find.
Where a repair shop uses our platform’s phone assistant, customers who book an appointment by phone may receive a single text message confirming their appointment, sent through our platform on the shop’s behalf.
Consent is collected verbally during the booking call, and every message includes opt-out instructions; replying STOP stops all further messages.
We send one message per confirmed booking; we do not send marketing or recurring texts.
Phone numbers and opt-in information collected for text messaging are used solely to deliver these messages.
No mobile opt-in data or phone numbers are shared with third parties or affiliates for marketing or promotional purposes.
Message and data rates may apply.
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated version and revise the “Last updated” date, and where required by law we will provide additional notice.
14. How to Contact Us
Autograff, Inc., 131 Continental Dr, Suite 305, Newark, New Castle County, Delaware 19713, USA. Privacy contact: contact@autograff.ai.
End of Privacy Policy
Questions about your data: contact@autograff.ai