Skip to content
← Pitlane

Privacy Policy

Last updated: June 25, 2026

1. Who We Are

Pitlane ("we," "our," or "us") is a cloud platform built for independent auto repair shops. The Service is operated by Auto Shift Media LLC, an Ohio limited liability company. This policy explains what information we handle, how we use it, who we share it with, and the choices you have. You can reach us at support@usepitlane.com. This policy is incorporated into our Terms of Service.

2. Our Two Roles: Controller and Processor

Pitlane handles data in two different roles, and your rights depend on which applies:

  • As a processor / service provider. For the information a shop enters about its own customers (contacts, vehicles, service history, messages), the shop is the controller and Pitlane acts as a processor on the shop's behalf and instructions. If you are a vehicle owner and a shop has your information, your requests should go to that shop; we will assist the shop as needed. Business customers who need a data processing addendum (DPA) can request one at support@usepitlane.com.
  • As a controller. For our own account, billing, support, security, and marketing data — including information from prospective customers who use our public tools or contact us — Pitlane is the controller and this policy governs directly.

3. Information We Collect

We collect information you provide directly and information generated through use of the platform:

  • Account information: name, email address, business name, avatar, and role when you register. Login credentials and any multi-factor authentication are managed by our authentication provider, Supabase Auth; we store only an email/name mirror, not your password.
  • Business and customer data (shop-controlled): the records a shop creates, including customer contacts (name, email, phone, mailing address, notes, tags, consent flags, visit history, lifetime value), vehicles (VIN, year/make/model/trim/color, license plate and state, mileage), appointments, digital inspections, estimates, invoices, service records (customer concerns, technician notes, line items and amounts, photo/video URLs, and customer e-signature images), campaigns, and reviews.
  • Payment information: billing details for your Pitlane subscription are processed by Stripe. Your customers' card details, if you enable customer payments, are handled by Stripe Connect. We do not store full card numbers, expiration dates, or security codes anywhere. We store only amounts, payment method, and Stripe identifiers (such as PaymentIntent and customer IDs).
  • AI interactions: the prompts, tone options, or questions you submit to PitCrew; the context we attach (for example a vehicle record, an inspection, an estimate's line items, or a photo you attach for the photo-description feature); and the responses generated. We store token counts for these calls, not the prompt or response content.
  • Communications: messages you send us through support, and the SMS and email messages you send to your customers through the platform. Every inbound and outbound text message body is stored in your account.
  • Customer mobile information: phone numbers that shops enter on behalf of their customers, plus opt-in and opt-out status for SMS. See Section 6 for the specific protections that apply to mobile information.
  • SMS brand registration data: if you opt to send SMS, you submit business identity information so Twilio Trust Hub and the U.S. mobile carriers can vet your shop’s messaging brand under the A2P 10DLC framework — your legal business name, doing-business-as name, business address, website, an authorized representative’s name, title, email, and mobile phone, and a tax identifier (EIN or, for sole proprietors without an EIN, an SSN). The tax identifier is transmitted to Twilio Trust Hub over an encrypted connection and is not stored in the Pitlane database; the rest of the brand data is stored so we can show you registration status and continue the carrier-vetting flow.
  • SMS compliance attestation log: when a shop owner initiates SMS setup, we record their on-screen four-part compliance attestation along with the owner’s user ID, a timestamp, and their originating IP address, retained for the life of the account as part of our A2P 10DLC audit trail.
  • Usage and analytics data: pages visited, features used, device and browser information, external referrer, and coarse location derived from your IP address (country, region, city). Our first-party pageview measurement (Section 13) records these along with a daily-rotating, hashed visitor identifier rather than a raw IP.
  • Information from our public tools and marketing: if you use a free tool on our site (such as the website audit or reachability checks) or contact us, we collect the email address, business name, website, and city/state you provide, and we generate a report. This prospect information is held by Pitlane as controller and is used to follow up and to improve our tools.

4. How We Use Your Information

  • To provide, operate, secure, and improve the Pitlane platform.
  • To process subscription payments and manage your account.
  • To send transactional emails and notifications about your account, including optional morning briefings summarizing your shop's daily activity.
  • To deliver SMS messages, email campaigns, and review requests on your behalf to your customers.
  • To generate AI suggestions via PitCrew when you or your staff request them.
  • To respond to support requests, and to follow up with prospects who request information or use our public tools.
  • To detect, prevent, and address fraud, abuse, security incidents, and technical issues, and to comply with law.

We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use your business data, customer data, or AI prompts to train any AI model.

5. How We Share Information (Sub-Processors)

We do not sell your personal information. We share data only as necessary to operate the platform, and only with vetted service providers:

  • Supabase — authentication (credentials and any MFA) and the primary database where your data is stored.
  • Vercel — hosting, serverless compute, edge delivery, bot protection, and privacy-friendly Analytics and Speed Insights.
  • Stripe — subscription billing and, if enabled, customer payments via Stripe Connect.
  • Twilio — SMS message delivery and A2P 10DLC brand and campaign registration via Twilio Trust Hub. Each shop is provisioned a dedicated Twilio subaccount and phone number; the subaccount's authentication credentials are encrypted at rest using AES-256-GCM. There is no shared sending number — messages send only from your own registered number.
  • Resend — transactional and marketing email delivery, including syncing marketing contacts to a Resend audience.
  • Anthropic — the AI provider (Claude) that powers PitCrew suggestions and our public website-audit tool. See Section 7.
  • Google — Google Analytics for website measurement (Section 13) and the Google Places API for business and competitor lookups used by some features and tools.
  • NHTSA vPIC — the U.S. government VIN decoder. When a VIN is decoded, the VIN (and no other personal data) is sent to this public API.
  • Upstash — rate limiting. Upstash receives IP addresses as short-lived rate-limit keys; it does not store your business records.

We may also disclose information if required by law, subpoena, or legal process, in connection with a merger, acquisition, or sale of assets, or to protect the rights, property, or safety of Pitlane, our users, or the public.

6. Mobile Information and SMS Data

When a Pitlane-using auto repair shop collects your phone number (provided to the shop in person at the time of service intake, after the shop has verbally asked and you have agreed) and sends you SMS messages through the platform, additional protections apply. The full opt-in and consent disclosure, sample messages, frequency, and opt-out instructions are published at usepitlane.com/sms.

  • No sharing for marketing or promotion. Mobile information (including phone numbers and SMS opt-in data) will not be shared with third parties or affiliates for marketing or promotional purposes. We do not sell, lease, trade, or rent mobile information under any circumstances. This commitment is consistent with the CTIA Messaging Principles and Best Practices.
  • Sharing with service providers is limited to delivery. To deliver your messages, your phone number is transmitted to Twilio (our SMS delivery provider — see Section 5) and the U.S. mobile carriers that route the message to your handset. Phone numbers are not transmitted to any other third party for any purpose.
  • Opt-out is honored automatically. When you reply STOP (or any of: STOPALL, UNSUBSCRIBE, CANCEL, QUIT, END) to a message, the originating shop stops sending to your number and your opt-out is recorded against your contact record at that shop. The carrier sends a one-time confirmation. Opt-out records are retained so the shop continues to honor your choice.
  • Limited-purpose use only. Phone numbers collected for SMS opt-in are used solely for the service-related communications described in our SMS Program Disclosure: repair-order-ready notifications, digital vehicle inspection links, mid-job authorization requests, payment receipts and links, appointment reminders, and post-service review-request invitations.
  • No cross-shop sharing. A phone number opted in at one Pitlane shop is never used by another Pitlane shop unless that customer separately provides their number and consent to that other shop directly.
  • Retention. Mobile information is retained as long as the originating shop's account is active. If you opt out, your opt-out is kept so the shop does not message you again. See Section 8 for deletion.
  • Carrier responsibility. Wireless carriers are not liable for delayed or undelivered messages.

7. AI Processing (PitCrew)

PitCrew uses large language models operated by Anthropic (Claude) to generate suggested text. The same provider also powers our public website-audit tool. When you trigger an AI action, the following may be transmitted to Anthropic over an encrypted connection:

  • The prompt, tone option, or question you submitted.
  • Relevant shop and customer context for the action — for example a customer's first name, a vehicle's make/model/year and mileage, an inspection's findings, an estimate's line items and amounts, a review and its author's name, technician notes, customer-stated concerns, and (for the photo-description feature) a photo of the part or condition.
  • A brief system prompt describing PitCrew's role and safety rules.

We do not deliberately send structured fields such as full customer phone numbers, mailing addresses, email addresses, or payment identifiers, and we do not send full customer contact lists or unrelated business data. Because some fields are free text (a typed concern, a note, a review), it is possible for information you type there to be included; do not enter data you would not want processed by our AI provider.

Under Anthropic's commercial terms, data submitted through its API is not used to train Anthropic's models. We do not separately store the content of your prompts or PitCrew's responses; we retain only token-count metadata for metering and abuse prevention. You can turn off the optional morning briefing in your settings, and on-demand AI suggestions are generated only when you or your staff trigger them, so if you do not use those features no data is sent for them. Our public demo returns canned responses and does not call the AI provider.

8. Data Retention & Deletion

We retain your data for as long as your account is active. Message bodies, contacts, vehicles, and service records are kept until you delete them or close your account, except where longer retention is required by law, needed to resolve disputes, or necessary to enforce our agreements.

Account owners can delete the account at any time from settings. Deletion is immediate and irreversible — it removes your organization's data from our database and your login from our authentication provider through a type-to-confirm flow, with no grace period or recovery. Two platform-level operational logs (application events and pageview records) are not tied to your organization and are purged on rolling schedules (within 60 and 180 days, respectively) rather than at the moment of deletion. Records held by our sub-processors (for example Stripe billing records and Twilio/Resend message-delivery logs) are retained under their own policies; deleting your Pitlane account does not by itself delete those, though you may request their deletion from us or the provider. Anonymized, aggregated metrics may be retained.

9. Security

We use a range of security measures, including TLS/HTTPS encryption in transit (enforced via HSTS and edge termination), a strict nonce-based Content Security Policy, rate limiting on sensitive endpoints, webhook signature verification on third-party callbacks (Stripe and Twilio), and AES-256-GCM encryption at rest for sensitive credentials such as per-shop SMS authentication tokens. Tenant isolation is enforced at the application layer, which automatically scopes every data query to your organization, backed by deny-all database policies against anonymous access as defense in depth. Authentication, session cookies, and password handling are provided by Supabase Auth. Tax identifiers submitted for SMS brand registration are transmitted to Twilio Trust Hub but are not stored in our database. Pitlane runs on SOC 2-compliant infrastructure and follows SOC 2-aligned practices; we are not ourselves SOC 2 certified. No system is completely secure, but we take reasonable precautions and review our posture regularly.

10. Your Privacy Rights

Self-service. Account owners can export their organization's data as a downloadable archive from account settings, edit or correct records directly in the platform, and delete the account (Section 8) at any time.

By request. You may also request access to, correction of, portability of, or deletion of your personal data by emailing support@usepitlane.com. We will verify and respond within 30 days (extendable where the law allows). If you are a vehicle owner whose information a shop holds in Pitlane, that shop is the controller of your data — contact the shop, and we will support the shop in fulfilling your request.

11. U.S. State Privacy Rights

Depending on your state of residence (including California under the CCPA/CPRA, and Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws), you may have the right to:

  • Know and access the personal information we hold about you and how we use and share it.
  • Request correction of inaccurate personal information.
  • Request deletion of your personal information.
  • Obtain a portable copy of your personal information.
  • Opt out of the sale of personal information and of sharing or processing for targeted/cross-context behavioral advertising.

We do not sell or share personal information, and we do not use it for targeted advertising, so there is no sale or sharing to opt out of. We honor browser Global Privacy Control (GPC) signals for analytics as described in Section 13. We do not use personal information to make decisions producing legal or similarly significant effects, and we do not offer financial incentives for your data. To exercise any right, email support@usepitlane.com; you may use an authorized agent. We will not discriminate against you for exercising your rights, and we verify requests before responding. If we deny a request, you may appeal by replying to our decision. Where Pitlane acts as a processor/service provider for a shop, we will route your request to the shop or assist the shop in fulfilling it.

12. Children's Privacy

Pitlane is a business-to-business service and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

13. Cookies & Analytics

Essential cookies. We set cookies to maintain your login session (managed by Supabase Auth) and to remember your active shop, and to protect against cross-site request forgery. These are required for the platform to function.

Analytics. We use Vercel Analytics and Speed Insights for aggregate web-vitals reporting (cookieless), and a first-party pageview measurement that records the page path, external referrer, coarse IP-derived location (country, region, city), device type, and a daily-rotating hashed visitor identifier — not a raw IP. When configured, we also load Google Analytics across the site to understand traffic and pageviews; Google Analytics sets first-party cookies. We do not use any advertising, retargeting, or cross-site tracking, and we opt out of Google's interest-cohort tracking.

Global Privacy Control. If your browser sends a Sec-GPC: 1 signal — automatic in Brave and DuckDuckGo, available as an extension elsewhere — we do not load Google Analytics for your visit. The signal is honored server-side, not just disclaimed here. (Our cookieless first-party measurement still runs.)

Other ways to opt out of GA. Use the official Google Analytics opt-out browser add-on, or block analytics domains in your browser’s tracking-protection settings. We do not display a cookie consent popup because Pitlane targets U.S.-based shops and does not use any tracking that triggers EU/UK consent requirements; if that ever changes, this policy and the platform will be updated together.

14. Data Location & International Users

Pitlane is operated from the United States and stores and processes data on infrastructure located in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data-protection laws may differ from those in your jurisdiction, and you consent to that processing.

15. Data Breach Notification

If we become aware of a security breach that compromises your personal information, we will investigate promptly and notify affected users and, where required, the relevant authorities, in accordance with applicable law and without undue delay. Where Pitlane acts as a processor for a shop, we will notify the shop so it can meet its own notification obligations to its customers.

16. Demo Account

Our public demo account uses shared credentials and is intended for evaluation only. Any data you enter into the demo may be visible to other demo visitors and may be reset or deleted at any time. Outbound actions (messages, AI calls, payments) are stubbed in the demo and do not reach real customers. Do not enter real customer information, payment details, or confidential data into the demo.

17. Changes to This Policy

We may update this policy from time to time. We will post the updated policy with a new "Last updated" date and, for significant changes, notify you by email or by a notice in the platform. Continued use of Pitlane after changes take effect constitutes acceptance of the updated policy.

18. Contact

Questions about this policy, or want to exercise a privacy right? Email Auto Shift Media LLC at support@usepitlane.com.

Terms of Service · Back to Pitlane