Privacy Policy
Last updated: March 2026
1. Data Collection
Rabis1 collects the following data to provide our service:
- Personal information: Name, email, phone of workshop owners and staff
- Customer information: Name, phone, email of workshop customers
- Vehicle information: License plates, VIN, make/model, year
- Photos and videos: Before/During/After vehicle condition media
- Operational data: Work orders, quotes, repair history, payments
- HR data: Attendance, GPS/WiFi check-in location, payroll information
- Subscription data: Plan tier, payment status, transaction history
2. Purpose of Use
- Provide and operate the Rabis1 service
- Store Before/After evidence for workshops
- Manage work orders, inventory, quotes, and payments
- Calculate payroll, commissions, and attendance
- Send customer notifications about vehicle status
- Process subscriptions and recurring payments
- Improve service quality
3. Data Security
- All data encrypted in transit (TLS/SSL)
- Multi-tenant architecture ensures complete data isolation between workshops
- Role-based access control (Admin, Manager, Receptionist, Technician) + custom roles
- All important actions recorded in audit log
- Submitted media cannot be edited or deleted by regular staff
- API keys are encrypted, time-limited, and auto-disabled on expiry
4. Multi-shop Data Isolation
- Each shop has completely separate data, not shared between shops
- Users can be members of multiple shops, but each shop's data is isolated
- Admin of Shop A cannot access Shop B data (unless explicitly invited)
5. Data Ownership
- All data generated within Rabis1 belongs to the workshop
- Rabis1 does not claim ownership of customer data
- Workshops can export data at any time (CSV/Excel)
- Data retained for 90 days after service termination before deletion
6. Data Storage
- Media stored on Cloudflare R2 (Asia data centers)
- Database hosted on Supabase (PostgreSQL)
- Retention period depends on subscription plan
- Metadata (customers, vehicles, work orders) is not deleted when subscription expires
7. Third-party Sharing
Rabis1 does not sell or share data with third parties, except:
- Infrastructure providers (Cloudflare, Supabase, Fly.io)
- Payment processing (SePay — transaction codes only, no personal data)
- Error monitoring (Sentry — technical info only, no user data)
- When required by law enforcement
8. Contact
For privacy-related questions, contact us at: info@rabis1.com or call 0969 190 701.