Privacy Policy
Last updated: July 29, 2026
Carpals connects car owners with local repair shops: you post what your car needs, shops send you quotes. This policy explains exactly what we collect, what we do with it, who sees what and when, and the controls you have. The short version: we collect what it takes to get your car quoted and fixed, shops only ever see what they need to quote you, and we never sell your personal information.
1. What we collect
Everything below is something you give us directly by using Carpals:
- Your account. Name, email address, and password (stored only as a secure hash — we can’t read it), plus an optional profile photo and your notification preferences. Customers can optionally add a phone number — we use it only to text you your login email if you forget it and for SMS appointment reminders.
- Your garage. The vehicles you add: make, model, year, trim and sub-trim, mileage, and any nickname, colour, or photo you attach.
- Your requests. The description of the job, the service category and symptom tags you pick, any photos you attach or video link you add, your budget range, the location you set for the job and your chosen search radius, and any appointment times you book.
- Quotes, messages, and reviews exchanged through Carpals — they’re the record of each job for both sides.
- Shop accounts. Business name, address, phone, business licence number (used for verification), services offered, service radius, team member accounts, and subscription status.
- Device & technical data. A session cookie that keeps you signed in, push-notification tokens if you turn push on (in your browser, or in the mobile apps when they launch), your IP address for rate limiting and abuse prevention, and basic product-usage events (which features get used) tied to your account.
One more thing we collect that you don’t hand us directly — how the site gets used:
- Site analytics. We run our own, on our own servers. There is no third-party tracker, no ad network, and no data broker involved, and none of it leaves us. Across the site — including the pages you see once you’re signed in — we record which pages you view and how long you spend on each, how far down the page you scroll, which links and buttons you click, the site that referred you (plus any campaign tags on the link you followed), your device type, browser and operating system, screen and window size, browser language and time zone, page-speed measurements, and JavaScript errors so we can find broken pages. These records are not attached to your account: they carry the rotating visitor id described below and, at most, whether the visit was a customer or a shop — never your user id, name, or email. Pages whose web address is itself a secret (a team-invite or password-reset link) are not recorded at all, and neither is anything on our admin pages. Where a page address contains a record number, we store the shape of the address rather than the number.
- Approximate location. Country, region, and city only. Our hosting provider works this out at the network edge and hands it to us as three pieces of text. We don’t run an IP lookup, and we don’t store an IP address to get it.
- How we count visitors without identifying you. Instead of a tracking cookie, we make a one-way hash of your IP address, your browser details, and a random secret that we replace every night. The IP address itself is never written down, and each night’s secret is destroyed shortly after. So the id that comes out can’t be turned back into you, and today’s id can’t be matched to the one you had yesterday — which means we can count returning visits within a day, and genuinely cannot follow you across days.
2. How we use it
- Matching. Your request’s location, radius, and service category decide which nearby shops are eligible to see and quote it.
- Delivering the service. Getting quotes and messages to you, sending the notifications you’ve turned on (quote alerts, message alerts, appointment reminders), and keeping your booking history straight.
- Trust & reviews. Reviews can only come from jobs that actually happened on Carpals, and they feed each shop’s public rating.
- Safety & fraud prevention. Rate limiting, no-show tracking, dispute handling, content moderation, and suspending accounts that abuse the platform.
- Improving Carpals. Our own analytics — which pages and features get used, where people get stuck, what’s slow, what’s broken — so we know what to fix. It feeds internal dashboards our team reads and goes nowhere else: there is no outbound copy to any analytics vendor. It is never sold, never handed to an ad network or data broker, and never used to build a profile of you or to target you with anything.
Marketing email is off by default. We only send it if you opt in, and you can opt back out in Settings anytime.
3. Who sees what — and when
Your requests are never public. They’re shown only to licensed shops that could actually do the job — shops whose service area covers your request’s location and that offer the kind of work you asked for. Here’s the exact sequence:
- Before any shop quotes: eligible shops see the job description, category and symptoms, your vehicle’s details (including trim), your budget ceiling, the location you set for the job and its distance from their shop, and when it was posted. They do not see your name, email, or any contact details.
- Photos and video: the media you attach is only shown to a shop that is actually eligible to quote your request — in range while the request is open, or the single shop you sent a direct request to. Shops outside your radius never see it.
- Once a shop sends a quote: a message thread opens and the shop sees your name and profile photo. All messaging stays inside Carpals — your email address is never shown to shops, and notifications always come from us.
- When you accept and book: the shop you chose sees the appointment details and your conversation. Shops you didn’t choose see nothing more.
- Reviews: a review you leave appears publicly on the shop’s profile under your first name only.
- Direct requests: if you send a request straight to a shop you’ve used before, only that shop sees it.
- Carpals staff: our team can access account data when it’s needed to run the platform — support, verification, dispute resolution, moderation. Administrative access is limited and admin actions are logged.
4. What we never do
- We never sell or rent your personal information. To anyone. Ever.
- We never give shops your email or contact details — messaging happens inside Carpals.
- We don’t run ads and don’t share your data with ad networks or data brokers.
- Our analytics never read what you type. Form fields, text boxes, search inputs, and passwords are excluded outright, and we never capture your screen, your keystrokes, or your clipboard. Where we do save the wording of a link or button you clicked, we take only the control’s own short label — not the contents of the card or row around it — and cut it to 40 characters, and anything resembling an email address, a phone number, a postal code, or a long number is stripped out first. Links whose label is somebody’s name or contact details are marked as off-limits and record no wording at all. It is possible for a short label to be more specific than we intended; tell us and we’ll exclude it.
- We never charge customers and never store customer payment details — you pay your shop directly, and Carpals is not part of that transaction.
- We don’t send marketing unless you opted in.
5. Payments and Stripe
The only people who pay Carpals are shops, through their monthly subscription. Shop billing is processed by Stripe: card details go directly to Stripe and we never see or store full card numbers — we only keep the subscription status (trial, active, canceled).
Customers never pay anything through Carpals. Payment for repair work is arranged directly between you and the shop, by whatever method you two agree on.
6. How long we keep things
While your account is open, we keep your account, garage, requests, quotes, messages, and reviews so both you and the shops you’ve worked with have an accurate history. Technical data used for security (like rate-limit counters) is kept only as long as it’s needed for that purpose. When you delete your account, the section below applies immediately.
Analytics records of site visits are kept for a limited window — 400 days by default — and a job runs every night deleting anything older. The nightly secret used to count visitors is destroyed after two days, so one visit stops being linkable to another long before the records themselves age out.
7. Deleting your account
You can delete your account yourself, any time, from Settings → Delete account. It’s confirmed with your password and it’s irreversible. Here is precisely what happens:
- Your profile is anonymized on the spot: name, email, phone, profile photo, and push tokens are removed, and the account can never sign in again.
- Your notifications, saved shops, and push subscriptions are deleted outright.
- Any analytics records still linked to your account — visits, pageviews, clicks, speed samples and error reports — are deleted immediately rather than waiting for the retention window to age them out. Conversion counts (that a signup or a quote happened) are kept, with your identity removed.
- Photos you uploaded are scrubbed from your vehicles and requests.
- The text of every message you sent is redacted.
- Any open requests are closed, pending quotes on them are declined, and upcoming bookings are cancelled so no shop is left waiting on a car that won’t arrive.
- Records tied to completed interactions — reviews of jobs that really happened, finished bookings, message threads — are kept in de-identified form, so the shops and customers you worked with keep an accurate history without your identity attached.
If you own a shop, deleting your account also takes the shop off the marketplace: its public identity is scrubbed, open quotes are withdrawn, and the subscription is cancelled.
8. Cookies, browser storage, and tracking signals
Carpals uses one essential cookie: the session cookie that keeps you signed in. We don’t use analytics cookies, third-party advertising cookies, or cross-site tracking cookies of any kind. That’s the whole list, which is why you never see a cookie banner here.
Our analytics do keep one short-lived id in your browser’s sessionStorage — not a cookie. It exists so the pages you view in one sitting can be grouped into a single visit, and your browser throws it away the moment you close the tab.
If your browser sends a Do Not Track or Global Privacy Control signal, we honour it automatically: the analytics script never starts, nothing is sent, and our server refuses the data even if something else sends it. There is nothing for you to click.
Want the analytics records from your visits deleted sooner than the window in section 6? Email contact@carpals.ca. Because the visitor id is deliberately impossible to reverse, we can’t look you up by name — telling us roughly when you visited and from where helps us find the right records.
9. Service providers
A small set of providers help us run Carpals: infrastructure that hosts the app and database, Stripe for shop subscription billing, and an email delivery provider for transactional email like quote alerts and password resets. They process data only on our instructions to provide their service to us — none of them may use your data for their own purposes.
10. Your choices and rights
You can edit your profile, change your photo, and switch every notification type on or off in Settings. Canadian privacy law gives you the right to access and correct the personal information we hold about you — email us and we’ll help. And deletion isn’t a request form: it’s a button in your own Settings, described above.
11. Changes to this policy
If we change this policy, we’ll update the date at the top. For material changes — anything that affects what we collect or who sees it — we’ll notify you in the app or by email before it takes effect.
12. Contact
Privacy questions, access requests, or anything unclear? Email contact@carpals.ca and a human will get back to you.