Legal information

Privacy policy

How the customer portal is designed to collect, use and protect personal information.

Draft information for review

This page is a practical Phase One draft, not legal advice. The final wording must be reviewed and approved before production use.

Who is responsible for your information

Motor Menders Ltd, company number 15050770, is the data controller for information collected through this website and customer portal. Its registered office is 64 Castle Boulevard, Nottingham, England, NG7 1FN. Privacy requests can be sent through the contact page or by writing to the registered office.

Information we collect

Depending on how you use the service, this can include account and contact details, vehicle details, appointment requests, messages, consent records, authentication events and limited email-delivery metadata.

Passwords, reset tokens and refresh tokens are managed by Supabase Auth and are not stored in public application tables.

Signing in with Google or Apple

If you choose social sign-in, Google or Apple authenticates you and supplies Supabase Auth with an account identifier, email address, email-verification status and any basic name information the provider makes available. Apple may supply a private relay address instead of your usual email. Motor Menders does not receive your Google or Apple password.

First-time social-sign-in customers must still provide a UK mobile number and separately accept the Terms and Privacy Policy before the portal is enabled. Using these options also tells the chosen provider that you signed in to this service.

Why we use it

Information is used to provide secure accounts, manage vehicles and appointments, respond to enquiries, send transactional updates, protect the service and meet garage record-keeping obligations. The final policy must identify the appropriate UK GDPR lawful basis for each purpose.

Service providers and transfers

Vercel hosts the application, Supabase provides database and authentication services, and Resend delivers authentication and transactional emails. Google or Apple also processes authentication data when a customer chooses the corresponding sign-in option. The business must review each provider’s data-processing terms, locations and safeguards before production launch.

Retention and security

Role-based access, Row Level Security, encryption in transit, protected server credentials and minimal email logs reduce exposure. Formal retention periods for customer records, appointments, contact requests and email events must be approved and inserted before launch.

Your UK data-protection rights

Subject to applicable law, people may have rights to access, correct, erase, restrict or object to processing, and to data portability. A verified process for handling these requests and complaints to the ICO must be established before production use.

Questions about these terms can be sent through the contact page.