Privacy Policy
Last updated: 7 September 2026
1. Introduction
RepairFlow ("we", "our", "the app") is a repair shop management application developed by RepairFlow. This policy explains how we handle data when you use our iOS application.
This policy was substantially revised on 7 September 2026 following a review of the application's actual data flows. Earlier versions stated that no data left your device by default, that cloud sync used a self-hosted server, and that the app collected no device or usage information. Those statements were not accurate, and the sections below replace them.
2. Data Stored On Your Device
RepairFlow is local-first. The following is created and stored on your iPhone or iPad using Core Data (SQLite):
- Customer Information — Names, phone numbers, email addresses, and physical addresses you enter for your repair customers.
- Job & Repair Records — Device details (make, model, IMEI/serial number), repair descriptions, status, and cost estimates.
- Invoice & Payment Records — Invoice amounts, payment methods, transaction references, and timestamps.
- Photos & Attachments — Device intake photos and repair documentation captured via the camera.
- Business Settings — Your shop name, address, logo, VAT number, and payment provider configuration.
3. Data Sent To Us Automatically
The following is sent to servers we operate without any action on your part. It is the only data collected automatically.
- Installation record — When the app launches it registers the installation with our server. This includes a randomly generated installation identifier, the app version, Apple's signed app receipt with the original purchase date, and three yes/no flags indicating whether an admin PIN, a sync token and an encryption key exist on the device. The flags record whether these features are configured; they never contain the PIN, the token or the key.
We use this to identify legitimate existing customers, to understand what the service costs us to run, and to detect abuse. It is not used for advertising and is not shared with data brokers.
4. Data Sent To Us Only If You Enable A Feature
- Cloud Sync (not available in the current version) — Syncing shop data between devices is switched off and cannot be turned on. Where it was used in an earlier version, customer records, jobs, invoices, payment records, appointments, technician details and job photos were transmitted to and stored on our servers, hosted on Railway. Earlier versions of this policy described this as a "self-hosted sync server". That was incorrect: the sync service is operated by us. We also record the volume of data transferred, so we can understand running costs.
- Crash reporting (off by default) — If you enable it, crash reports are sent to our servers. These contain the error and stack trace, your device model, iOS version, app version and build number, and a randomly generated device identifier. They do not contain your customer records.
- Customer messages (not sent to us) — When you message a customer from a job or an invoice, RepairFlow writes the text and hands it to your iPhone's own Messages, WhatsApp or Mail app, where you send it yourself from your own number or address. The message and the customer's number never reach our servers. RepairFlow does not provide an SMS service, and texts are not part of your subscription — your own mobile plan carries them. Earlier versions of this policy described an "SMS relay" that passed messages through our server to an Android gateway device. The app has no such feature.
- Website Enquiries (off until you connect a website) — If you connect your website, enquiries people submit are sent to and stored on our servers so they can reach your app: the name, phone number, email address, device and description they type in. If you use the conversation feature, the messages exchanged between you and that person are stored on our servers too. This is data about your customers and prospective customers, collected from them directly rather than entered by you — see section 4a.
4a. Enquiries From Your Website — Your Customers' Data
Website Enquiries is different from every other feature here, because the person whose data we receive is not you and has never used our app. They fill in a form on your website.
For that data, you are the data controller and we are your processor: it is collected for you, held on your instructions, and we do not use it for anything except delivering it to you and keeping the conversation you have through it. We do not sell it, and we do not use it for advertising or to train anything.
Because that person cannot see this policy inside an app they do not have, the collection notice appears on the enquiry form and on the conversation page itself. If you host the form on your own site rather than using ours, giving that notice is your responsibility.
Enquiry conversations use a private link rather than an account. That link is stored hashed, expires, and stops working as soon as a new one is issued.
5. Payment Providers
Card payments are processed by the provider you choose. RepairFlow does not process payments itself and never receives your card numbers. Each provider operates its own service under its own privacy policy, and each collects data directly from your device when in use:
- Stripe (including Tap to Pay on iPhone) — processes payment information, and collects device location and product interaction data for payment compliance and fraud prevention. Subject to Stripe's Privacy Policy.
- Zettle by PayPal — processes payment information, and collects name, email address, device identifiers, product interaction and usage data, and precise location, including through PayPal's fraud-prevention component bundled with the Zettle SDK. Zettle states these are used for app functionality, analytics, personalisation and its own advertising purposes. Subject to Zettle's Privacy Policy.
- Square — payment is completed in the Square Point of Sale app under your own Square account. Subject to Square's Privacy Policy.
Where money settles is determined by the account you connect. RepairFlow does not take a share of your payments.
6. Location
RepairFlow itself does not use your location. The payment SDKs above require it: Stripe and Zettle collect device location — precise location in Zettle's case — to meet card payment regulations and to prevent fraud. This applies only while you are using card payment features. iOS will ask your permission before any location is accessed.
7. Advertising & Tracking
RepairFlow does not track you. We include no advertising SDKs and no analytics SDKs of our own, we do not build advertising profiles, and we do not sell, share or transfer your data to any third party for advertising or marketing purposes. No data is linked with data from other companies for tracking purposes.
Some data described in section 5 is collected by payment providers under their own policies, and Zettle lists advertising and personalisation among its own purposes for data it collects. That collection is theirs, applies only when you use their payment service, and is governed by their privacy policy rather than this one.
8. Camera, Bluetooth & Local Network
The camera is used to scan serial numbers and IMEI barcodes and to take repair photos. Bluetooth is used to connect to card readers. Local network access is used to link a companion device for terminal mode. These permissions are optional and the app functions without them.
Serial and IMEI lookups are performed against a device database held on your phone. Nothing is sent to us or to any lookup provider.
9. Data Retention & Deletion
Data on your device remains until you delete it. You can delete individual records or use the full data wipe option in Settings, and uninstalling the app removes all local data.
Data sent to our servers by an earlier version through Cloud Sync, and anything sent through crash reporting, is not removed by uninstalling. To have it deleted, contact us at the address below and we will remove it.
Website enquiries. An enquiry and its whole conversation are deleted permanently when you delete the enquiry in the app — that is the option to use if someone asks you to remove their data, and it cannot be undone. Binning an enquiry as spam is deliberately not the same thing: it stops it notifying you but keeps it recoverable, in case it turns out to be a real customer.
Enquiries you have dealt with, binned or converted are deleted automatically after 365 days. Enquiries nobody has answered are never deleted automatically — an unanswered enquiry is late, not stale, and losing it would mean losing a real customer.
10. Children's Privacy
RepairFlow is a business tool and is not intended for use by children under 13. We do not knowingly collect data from children.
11. Changes To This Policy
We may update this policy from time to time. Material changes will be communicated through the app or on this page.
12. Contact
If you have questions about this privacy policy, or wish to request deletion of data held on our servers, contact us at support@myrepairflow.com.