Privacy Policy
Last updated · May 18, 2026|Effective · May 18, 2026
On this page
- Who We Are
- Scope
- Information We Collect
- How We Use Information
- Legal Basis for Processing (GDPR)
- Sub-Processors
- International Data Transfers
- Data Retention
- Your Rights
- Cookies and Tracking
- Children's Privacy
- Security
- Data Breach Notification
- Third-Party Services and Links
- Do Not Track
- Changes to This Policy
- Contact Us
This Privacy Policy explains how Novex Solutions LLC (“Novex,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the Get Repair platform — our web-based repair shop management software, marketing website, and related services (collectively, the “Service”).
We act in two distinct capacities:
- As a data controller for information about our direct customers (the repair businesses that subscribe to Get Repair) and visitors to our marketing website.
- As a data processor for the end-customer information that subscribing businesses (“Organizations”) upload to, store in, or generate within the Service.
Who We Are
Novex Solutions LLC is a Delaware-registered limited liability company.
- Legal Entity: Novex Solutions LLC
- Mailing Address: 1111B S Governors Ave STE 26220, Dover, DE 19904
- Privacy Contact: privacy@getrepair.co
- General Contact: legal@getrepair.co
If you are located in the European Economic Area (EEA) or United Kingdom, you may contact us at the address above regarding any GDPR-related matter.
Scope
This Privacy Policy applies to:
- Visitors to our marketing website
- Account holders and authorized users of Get Repair (Organization owners, managers, technicians, front-desk staff, and other invited team members)
- End customers of subscribing Organizations whose information is uploaded to or generated within the Service
It does not apply to third-party websites, applications, or services that integrate with Get Repair. Those services are governed by their own privacy policies.
Information We Collect
Information You Provide Directly
Account and Organization Information
- Name, email address, phone number
- Business name, address, tax IDs, business type
- Payment method details (processed and stored by Square — we do not store full card numbers; see “Payment Information” below)
- Login credentials (passwords are hashed and salted; we never see plaintext)
- Profile photos, signatures, branding assets
Communications
- Support requests, feedback, and any correspondence you send us
- Survey responses and product research participation
Information Uploaded or Generated Within the Service (Customer Data)
When subscribing Organizations use Get Repair, they upload or create data about their own end customers and operations. This may include:
- End-customer names, email addresses, phone numbers, postal addresses
- Device information: make, model, serial numbers, IMEI, condition notes, photos
- Repair tickets, estimates, invoices, work history
- Inventory and purchase order records
- Point-of-sale transaction history
- Internal notes, attachments, and uploaded files
- Custom intake form submissions
The subscribing Organization is the controller of this Customer Data. Novex processes it on their behalf in accordance with our agreement with the Organization and this Privacy Policy.
Information Collected Automatically
- Usage data: pages viewed, features used, clicks, session duration, referring URLs
- Device and connection data: IP address, browser type and version, operating system, device identifiers, language preferences
- Log data: API requests, error logs, timestamps, performance metrics
- Cookies and similar technologies: see “Cookies and Tracking” below
Payment Information
Payments are processed by our payment partner, Square. When you enter payment card details, they are transmitted directly to Square and tokenized. Novex stores only non-sensitive references (tokens, last four digits, card brand, expiration). We never store full payment card numbers or CVV codes. Square is PCI-DSS Level 1 certified.
How We Use Information
We use information for the following purposes:
- Provide the Service — authenticate users, deliver features, sync data across devices, render reports, generate invoices, process payments
- Account management — onboarding, billing, subscription renewals, support
- Communication — transactional emails (receipts, password resets, system notifications) and, where permitted, product updates
- Improve the Service — analyze usage patterns, debug issues, develop new features, conduct internal research
- Security and fraud prevention — detect abuse, prevent unauthorized access, investigate suspicious activity, enforce our Terms of Service
- Legal compliance — comply with laws, respond to lawful requests, exercise or defend legal claims
We do not sell personal information, and we do not use Customer Data to train artificial intelligence or machine learning models that benefit other customers or third parties. Vector embeddings generated via OpenAI for in-app semantic search are scoped to the originating Organization and are not used to train OpenAI’s foundation models (per our agreement with OpenAI’s API terms).
Legal Basis for Processing (GDPR)
For users in the EEA or UK, we rely on the following legal bases under Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)) — to deliver the Service you have subscribed to, manage your account, and process payments
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud, improve our product, and conduct limited direct marketing to existing customers (you may object at any time)
- Consent (Art. 6(1)(a)) — for optional cookies, marketing emails to non-customers, and any processing where consent is the appropriate basis (you may withdraw consent at any time)
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, and other legal requirements
Where Novex processes Customer Data on behalf of an Organization, the Organization is responsible for establishing the legal basis for that processing under its own privacy practices.
Sub-Processors
We engage trusted third parties to help us operate the Service. Each sub-processor is bound by contractual obligations consistent with this Privacy Policy and applicable law (including, where relevant, Standard Contractual Clauses).
| Sub-Processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, and file/image storage | US / EU |
| Vercel | Application hosting and edge delivery | Global (US primary) |
| Square | Payment processing | US |
| Resend | Transactional email delivery | US |
| OpenAI | Vector embeddings for in-app semantic search | US |
An up-to-date list of sub-processors is maintained at /privacy#sub-processors. We will provide reasonable advance notice of new sub-processors to Organizations who have subscribed to such notifications.
International Data Transfers
Novex is based in the United States. If you access the Service from outside the US, your information may be transferred to, stored in, and processed in the US or other countries where our sub-processors operate.
For transfers of personal data from the EEA, UK, or Switzerland to the US or other non-adequate jurisdictions, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Addendum where applicable
- Supplementary safeguards such as encryption in transit and at rest, access controls, and contractual restrictions on sub-processors
EU and UK-based Organizations may request a copy of the relevant transfer mechanisms by contacting privacy@getrepair.co.
Data Retention
We retain personal data only as long as needed for the purposes described in this Policy:
- Account data: for the duration of your subscription, plus up to 12 months after termination for accounting, dispute resolution, and legal compliance
- Customer Data uploaded by Organizations: for the duration of the Organization’s subscription. After termination, Organizations have 30 days to export data, after which it is deleted from active systems within 30 days and from backups within 90 days
- Billing and tax records: retained for the period required by applicable law (typically 7 years in the US)
- Logs and security data: typically retained for 12 months
- Marketing data: retained until you unsubscribe or object
You or your Organization may request earlier deletion by contacting privacy@getrepair.co, subject to legal retention obligations.
Your Rights
Rights Under GDPR (EEA / UK Users)
Under Articles 12–22 of the GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure (“right to be forgotten”) — request deletion, subject to legal retention obligations
- Restriction — request that we limit how we process your data
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests or direct marketing
- Withdraw consent — where processing is based on consent
- Not be subject to automated decision-making that produces legal or similarly significant effects (we do not currently conduct such processing)
- Lodge a complaint with your local supervisory authority
If you are an end customer of a subscribing Organization, please direct your request to that Organization first, as they are the controller of your data. We will assist them in responding.
Rights Under CCPA / CPRA (California Residents)
If you are a California resident, you have the right to:
- Know what categories and specific pieces of personal information we have collected, used, disclosed, or sold about you in the prior 12 months
- Delete personal information we have collected from you, subject to exceptions
- Correct inaccurate personal information
- Opt out of the “sale” or “sharing” of personal information (Novex does not sell or share personal information as those terms are defined under California law)
- Limit use of sensitive personal information (we do not use sensitive personal information for purposes that trigger this right)
- Non-discrimination for exercising any of these rights
To exercise your rights, email privacy@getrepair.co. We will verify your identity before fulfilling requests. You may designate an authorized agent to make requests on your behalf, subject to verification.
Notice of Financial Incentives: We do not offer financial incentives in exchange for personal information.
Shine the Light: California Civil Code Section 1798.83 does not apply because we do not disclose personal information to third parties for their direct marketing purposes.
How to Exercise Your Rights
Email privacy@getrepair.co with the subject line “Privacy Rights Request.” Include:
- Your full name and the email associated with your account (or the Organization name if you are an end customer)
- A description of the right you wish to exercise
- Sufficient detail to verify your identity
We will respond within 30 days (GDPR) or 45 days (CCPA), with extensions where permitted.
Children's Privacy
The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from anyone under the age of 16 (or under 13 in jurisdictions where that lower threshold applies). If you believe we have collected information from a minor, contact privacy@getrepair.co and we will delete it.
Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control with least-privilege defaults
- Row-Level Security in our database
- Multi-factor authentication for administrative access
- Continuous monitoring, logging, and intrusion detection
- Regular security reviews, dependency scanning, and patching
- Background checks and security training for personnel with access to production systems
No system is perfectly secure. You are responsible for maintaining the confidentiality of your account credentials and notifying us promptly of any suspected unauthorized access.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will:
- Notify affected Organizations without undue delay and, where feasible, within 72 hours of becoming aware of the breach (consistent with GDPR Art. 33)
- Provide information sufficient for Organizations to meet their own notification obligations
- Notify affected individuals directly where Novex is the controller and notification is required by law
- Cooperate with regulators and law enforcement as required
Third-Party Services and Links
The Service may contain links to third-party websites or integrate with third-party services (for example, payment processors, accounting tools, or shipping providers chosen by the Organization). We are not responsible for the privacy practices of those third parties. Review their policies before providing them with information.
Do Not Track
Some browsers transmit “Do Not Track” signals. Because there is no industry consensus on how to interpret these signals, we do not currently respond to them. We do honor Global Privacy Control signals as described above.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last Updated” date at the top of this Policy
- Notify Organization owners by email and/or in-product notice at least 30 days before the changes take effect (for material changes)
- Post the prior version in our archive for reference
Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
Contact Us
For privacy questions, rights requests, or concerns:
- Email: privacy@getrepair.co
- Mail: Novex Solutions LLC, 1111B S Governors Ave STE 26220, Dover, DE 19904
For EEA / UK users, you also have the right to lodge a complaint with your local data protection authority.
Questions about this policy?
We’re happy to clarify. Drop us a line and the right person on our team will get back to you.
Email privacy teamNovex Solutions LLC · 1111B S Governors Ave STE 26220, Dover, DE 19904