Privacy Policy

Last updated: March 2026

1. Data Collection

Rabis1 collects the following data to provide our service:

  • Personal information: Name, email, phone of workshop owners and staff
  • Customer information: Name, phone, email of workshop customers
  • Vehicle information: License plates, VIN, make/model, year
  • Photos and videos: Before/During/After vehicle condition media
  • Operational data: Work orders, quotes, repair history, payments
  • HR data: Attendance, GPS/WiFi check-in location, payroll information
  • Subscription data: Plan tier, payment status, transaction history

2. Purpose of Use

  • Provide and operate the Rabis1 service
  • Store Before/After evidence for workshops
  • Manage work orders, inventory, quotes, and payments
  • Calculate payroll, commissions, and attendance
  • Send customer notifications about vehicle status
  • Process subscriptions and recurring payments
  • Improve service quality

3. Data Security

  • All data encrypted in transit (TLS/SSL)
  • Multi-tenant architecture ensures complete data isolation between workshops
  • Role-based access control (Admin, Manager, Receptionist, Technician) + custom roles
  • All important actions recorded in audit log
  • Submitted media cannot be edited or deleted by regular staff
  • API keys are encrypted, time-limited, and auto-disabled on expiry

4. Multi-shop Data Isolation

  • Each shop has completely separate data, not shared between shops
  • Users can be members of multiple shops, but each shop's data is isolated
  • Admin of Shop A cannot access Shop B data (unless explicitly invited)

5. Data Ownership

  • All data generated within Rabis1 belongs to the workshop
  • Rabis1 does not claim ownership of customer data
  • Workshops can export data at any time (CSV/Excel)
  • Data retained for 90 days after service termination before deletion

6. Data Storage

  • Media stored on Cloudflare R2 (Asia data centers)
  • Database hosted on Supabase (PostgreSQL)
  • Retention period depends on subscription plan
  • Metadata (customers, vehicles, work orders) is not deleted when subscription expires

7. Third-party Sharing

Rabis1 does not sell or share data with third parties, except:

  • Infrastructure providers (Cloudflare, Supabase, Fly.io)
  • Payment processing (SePay — transaction codes only, no personal data)
  • Error monitoring (Sentry — technical info only, no user data)
  • When required by law enforcement

8. Contact

For privacy-related questions, contact us at: info@rabis1.com or call 0969 190 701.