Legal

Privacy Policy

Last updated · May 18, 2026|Effective · May 18, 2026

On this page
  1. Who We Are
  2. Scope
  3. Information We Collect
  4. How We Use Information
  5. Legal Basis for Processing (GDPR)
  6. Sub-Processors
  7. International Data Transfers
  8. Data Retention
  9. Your Rights
  10. Cookies and Tracking
  11. Children's Privacy
  12. Security
  13. Data Breach Notification
  14. Third-Party Services and Links
  15. Do Not Track
  16. Changes to This Policy
  17. Contact Us

This Privacy Policy explains how Novex Solutions LLC (“Novex,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the Get Repair platform — our web-based repair shop management software, marketing website, and related services (collectively, the “Service”).

We act in two distinct capacities:

  • As a data controller for information about our direct customers (the repair businesses that subscribe to Get Repair) and visitors to our marketing website.
  • As a data processor for the end-customer information that subscribing businesses (“Organizations”) upload to, store in, or generate within the Service.

Who We Are

Novex Solutions LLC is a Delaware-registered limited liability company.

If you are located in the European Economic Area (EEA) or United Kingdom, you may contact us at the address above regarding any GDPR-related matter.

Scope

This Privacy Policy applies to:

  • Visitors to our marketing website
  • Account holders and authorized users of Get Repair (Organization owners, managers, technicians, front-desk staff, and other invited team members)
  • End customers of subscribing Organizations whose information is uploaded to or generated within the Service

It does not apply to third-party websites, applications, or services that integrate with Get Repair. Those services are governed by their own privacy policies.

Information We Collect

Information You Provide Directly

Account and Organization Information

  • Name, email address, phone number
  • Business name, address, tax IDs, business type
  • Payment method details (processed and stored by Square — we do not store full card numbers; see “Payment Information” below)
  • Login credentials (passwords are hashed and salted; we never see plaintext)
  • Profile photos, signatures, branding assets

Communications

  • Support requests, feedback, and any correspondence you send us
  • Survey responses and product research participation

Information Uploaded or Generated Within the Service (Customer Data)

When subscribing Organizations use Get Repair, they upload or create data about their own end customers and operations. This may include:

  • End-customer names, email addresses, phone numbers, postal addresses
  • Device information: make, model, serial numbers, IMEI, condition notes, photos
  • Repair tickets, estimates, invoices, work history
  • Inventory and purchase order records
  • Point-of-sale transaction history
  • Internal notes, attachments, and uploaded files
  • Custom intake form submissions

The subscribing Organization is the controller of this Customer Data. Novex processes it on their behalf in accordance with our agreement with the Organization and this Privacy Policy.

Information Collected Automatically

  • Usage data: pages viewed, features used, clicks, session duration, referring URLs
  • Device and connection data: IP address, browser type and version, operating system, device identifiers, language preferences
  • Log data: API requests, error logs, timestamps, performance metrics
  • Cookies and similar technologies: see “Cookies and Tracking” below

Payment Information

Payments are processed by our payment partner, Square. When you enter payment card details, they are transmitted directly to Square and tokenized. Novex stores only non-sensitive references (tokens, last four digits, card brand, expiration). We never store full payment card numbers or CVV codes. Square is PCI-DSS Level 1 certified.

How We Use Information

We use information for the following purposes:

  • Provide the Service — authenticate users, deliver features, sync data across devices, render reports, generate invoices, process payments
  • Account management — onboarding, billing, subscription renewals, support
  • Communication — transactional emails (receipts, password resets, system notifications) and, where permitted, product updates
  • Improve the Service — analyze usage patterns, debug issues, develop new features, conduct internal research
  • Security and fraud prevention — detect abuse, prevent unauthorized access, investigate suspicious activity, enforce our Terms of Service
  • Legal compliance — comply with laws, respond to lawful requests, exercise or defend legal claims

We do not sell personal information, and we do not use Customer Data to train artificial intelligence or machine learning models that benefit other customers or third parties. Vector embeddings generated via OpenAI for in-app semantic search are scoped to the originating Organization and are not used to train OpenAI’s foundation models (per our agreement with OpenAI’s API terms).

Sub-Processors

We engage trusted third parties to help us operate the Service. Each sub-processor is bound by contractual obligations consistent with this Privacy Policy and applicable law (including, where relevant, Standard Contractual Clauses).

Sub-ProcessorPurposeRegion
SupabaseDatabase, authentication, and file/image storageUS / EU
VercelApplication hosting and edge deliveryGlobal (US primary)
SquarePayment processingUS
ResendTransactional email deliveryUS
OpenAIVector embeddings for in-app semantic searchUS

An up-to-date list of sub-processors is maintained at /privacy#sub-processors. We will provide reasonable advance notice of new sub-processors to Organizations who have subscribed to such notifications.

International Data Transfers

Novex is based in the United States. If you access the Service from outside the US, your information may be transferred to, stored in, and processed in the US or other countries where our sub-processors operate.

For transfers of personal data from the EEA, UK, or Switzerland to the US or other non-adequate jurisdictions, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Addendum where applicable
  • Supplementary safeguards such as encryption in transit and at rest, access controls, and contractual restrictions on sub-processors

EU and UK-based Organizations may request a copy of the relevant transfer mechanisms by contacting privacy@getrepair.co.

Data Retention

We retain personal data only as long as needed for the purposes described in this Policy:

  • Account data: for the duration of your subscription, plus up to 12 months after termination for accounting, dispute resolution, and legal compliance
  • Customer Data uploaded by Organizations: for the duration of the Organization’s subscription. After termination, Organizations have 30 days to export data, after which it is deleted from active systems within 30 days and from backups within 90 days
  • Billing and tax records: retained for the period required by applicable law (typically 7 years in the US)
  • Logs and security data: typically retained for 12 months
  • Marketing data: retained until you unsubscribe or object

You or your Organization may request earlier deletion by contacting privacy@getrepair.co, subject to legal retention obligations.

Your Rights

Rights Under GDPR (EEA / UK Users)

Under Articles 12–22 of the GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure (“right to be forgotten”) — request deletion, subject to legal retention obligations
  • Restriction — request that we limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests or direct marketing
  • Withdraw consent — where processing is based on consent
  • Not be subject to automated decision-making that produces legal or similarly significant effects (we do not currently conduct such processing)
  • Lodge a complaint with your local supervisory authority

If you are an end customer of a subscribing Organization, please direct your request to that Organization first, as they are the controller of your data. We will assist them in responding.

Rights Under CCPA / CPRA (California Residents)

If you are a California resident, you have the right to:

  • Know what categories and specific pieces of personal information we have collected, used, disclosed, or sold about you in the prior 12 months
  • Delete personal information we have collected from you, subject to exceptions
  • Correct inaccurate personal information
  • Opt out of the “sale” or “sharing” of personal information (Novex does not sell or share personal information as those terms are defined under California law)
  • Limit use of sensitive personal information (we do not use sensitive personal information for purposes that trigger this right)
  • Non-discrimination for exercising any of these rights

To exercise your rights, email privacy@getrepair.co. We will verify your identity before fulfilling requests. You may designate an authorized agent to make requests on your behalf, subject to verification.

Notice of Financial Incentives: We do not offer financial incentives in exchange for personal information.

Shine the Light: California Civil Code Section 1798.83 does not apply because we do not disclose personal information to third parties for their direct marketing purposes.

How to Exercise Your Rights

Email privacy@getrepair.co with the subject line “Privacy Rights Request.” Include:

  • Your full name and the email associated with your account (or the Organization name if you are an end customer)
  • A description of the right you wish to exercise
  • Sufficient detail to verify your identity

We will respond within 30 days (GDPR) or 45 days (CCPA), with extensions where permitted.

Cookies and Tracking

We use cookies and similar technologies to:

  • Strictly necessary — authenticate sessions, remember preferences, secure the Service
  • Functional — remember settings such as language and last-visited store
  • Analytics — understand aggregate usage patterns (we do not use cookies for cross-site behavioral advertising)

You can control non-essential cookies via the cookie banner presented on first visit or by adjusting your browser settings. Disabling strictly necessary cookies will impair core functionality.

We honor Global Privacy Control (GPC) signals where applicable.

Children's Privacy

The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from anyone under the age of 16 (or under 13 in jurisdictions where that lower threshold applies). If you believe we have collected information from a minor, contact privacy@getrepair.co and we will delete it.

Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control with least-privilege defaults
  • Row-Level Security in our database
  • Multi-factor authentication for administrative access
  • Continuous monitoring, logging, and intrusion detection
  • Regular security reviews, dependency scanning, and patching
  • Background checks and security training for personnel with access to production systems

No system is perfectly secure. You are responsible for maintaining the confidentiality of your account credentials and notifying us promptly of any suspected unauthorized access.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will:

  • Notify affected Organizations without undue delay and, where feasible, within 72 hours of becoming aware of the breach (consistent with GDPR Art. 33)
  • Provide information sufficient for Organizations to meet their own notification obligations
  • Notify affected individuals directly where Novex is the controller and notification is required by law
  • Cooperate with regulators and law enforcement as required

Third-Party Services and Links

The Service may contain links to third-party websites or integrate with third-party services (for example, payment processors, accounting tools, or shipping providers chosen by the Organization). We are not responsible for the privacy practices of those third parties. Review their policies before providing them with information.

Do Not Track

Some browsers transmit “Do Not Track” signals. Because there is no industry consensus on how to interpret these signals, we do not currently respond to them. We do honor Global Privacy Control signals as described above.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this Policy
  • Notify Organization owners by email and/or in-product notice at least 30 days before the changes take effect (for material changes)
  • Post the prior version in our archive for reference

Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

Contact Us

For privacy questions, rights requests, or concerns:

  • Email: privacy@getrepair.co
  • Mail: Novex Solutions LLC, 1111B S Governors Ave STE 26220, Dover, DE 19904

For EEA / UK users, you also have the right to lodge a complaint with your local data protection authority.

Questions about this policy?

We’re happy to clarify. Drop us a line and the right person on our team will get back to you.

Email privacy team

Novex Solutions LLC · 1111B S Governors Ave STE 26220, Dover, DE 19904