Privacy Policy
Last updated: October 21, 2025
Plain‑English upfront: We respect your privacy. We only collect what we need to run our services, we don’t sell your data, and you’re in control of your information.
This Privacy Policy explains how CrankySoftware LLC ("CrankySoftware", "we", "us", or "our") collects, uses, shares, and safeguards information in connection with our websites, mobile/desktop applications, and related services, including CrankyGarage (collectively, the "Services").
⚖️ Not legal advice. This policy is a working draft intended to help describe your practices. Laws differ by location and can change. Please have counsel review before publication.
1) Who we are & how to contact us
- Controller: CrankySoftware LLC, Seattle, Washington, USA
- Contact: privacy@crankysoftware.com
- Data Protection Representative (EEA/UK, if applicable): Not appointed at this time.
- DPO (if designated): Not designated.
Questions/requests about this Policy or your data rights can be sent to the contact above.
2) What we collect
We collect information in three main ways: (A) you provide it to us; (B) it’s collected automatically; (C) it comes from third parties you connect. Examples below are tailored for CrankyGarage.
2.A Information you provide
- Account profile: name, display name, email, password/hash, locale.
- Authentication via external identity: identifiers and claims from Google, Apple, Microsoft, or other IdPs you choose to use (e.g., subject ID, display name, avatar URL, issuer and issuerAssignedId, and any consented claims such as email).
- Vehicle data: VINs, make/model/year, engine details, odometer entries, tire pressure readings, maintenance/service logs, parts and costs, tags/notes, photos, and user‑generated content.
- Uploaded documents & media: receipts, manuals, PDFs, images, videos, and other files you add to your vault/knowledge base. (Typical size limits may apply.)
- Support & correspondence: messages you send via forms or email, and related metadata.
- Payment/subscriptions: If you purchase a plan, we receive transaction metadata from our payment processors (e.g., plan type, status, masked card info or platform order ID). We do not store full card numbers.
2.B Information collected automatically
- Device & app: device model, OS version, app version, language, time zone.
- Log & diagnostics: IP address, timestamps, error/crash logs, performance telemetry.
- Usage analytics: feature usage, screens viewed, approximate city/country, and referral sources. (You can opt out where settings allow.)
- Notification schedules (no remote push): cadence/cron definitions stored in your account to trigger local device reminders; we do not store device push tokens.
2.C Information from third parties (you connect)
- External Identity Providers (Google/Apple/Microsoft/etc.).
- OBD2/TPMS & peripheral devices you pair in‑app (via Bluetooth or similar). We process readings you choose to record.
- App stores & payment platforms (Apple App Store, Google Play, Stripe, etc.): subscription status and purchase records for entitlement management.
- Document/AI processing services: if you enable features that analyze your uploaded files (e.g., “AskYourPDF”), we may send file content/metadata to that processor to provide the feature.
Your choices: Connecting external sources is optional. You can disconnect them in settings. If you do, some features may stop working.
3) Why we use your information (purposes & legal bases)
We use your information to:
- Provide and maintain the Services (create accounts, log you in, store and sync your vehicle data, decode VINs, calculate stats, show your history).
- Process transactions & manage subscriptions (entitlements, receipts, invoices, fraud prevention).
- Connect to external identity providers you choose (federated sign‑in, claims mapping).
- Diagnostics, security & safety (error logs, auditing, abuse detection, protecting accounts and Services).
- Communications (service updates, critical notices, support replies; optional marketing with your consent/opt‑in where required).
- Research & improvement (analytics, A/B tests, anonymized/aggregated insights).
- Comply with laws and enforce our terms, or respond to lawful requests.
Legal bases (GDPR/UK GDPR): contract; legitimate interests.
Legal bases: contract; legal obligation; legitimate interests.
Legal bases: contract; consent; legitimate interests.
Legal bases: legitimate interests; legal obligation.
Legal bases: contract; legitimate interests; consent (marketing where required).
Legal bases: legitimate interests; consent where required.
Legal bases: legal obligation; legitimate interests.
We do not use your personal data for automated decision‑making that produces legal or similarly significant effects without human involvement.
4) Cookies & similar technologies
Our web properties and apps may use cookies, local storage, and SDKs to remember settings, keep you signed in, measure usage, and deliver features. Where required, we obtain your consent and provide controls. You can manage preferences in our cookie banner (web) and in‑app settings.
5) Disclosures & third‑party processors
We share personal data only as needed to run the Services. We do not sell your personal information.
Categories of recipients include:
- Hosting & storage: cloud infrastructure providers used to host our apps, databases, and files.
- Identity & authentication: services that enable federated sign‑in and manage tokens/claims.
- Payments & subscriptions: app stores and (if enabled) payment processors to validate purchases and entitlements.
- Diagnostics & analytics: tools that capture crashes, performance, and telemetry to keep the Services reliable.
- Email communications: providers used to send essential account or support emails (marketing only with consent).
- Professional advisors & legal: auditors, accountants, or authorities when required by law.
We bind processors by contract to process data only under our instructions and with appropriate security measures. Where we transfer data internationally, we use safeguards such as Standard Contractual Clauses.
6) International transfers
We operate globally. If we transfer your data outside your region (e.g., from the EEA/UK to the United States), we use appropriate safeguards—such as Standard Contractual Clauses and technical/organizational measures—to protect your information.
7) Data retention
We keep personal data only as long as necessary for the purposes described or as required by law. Typical retention periods:
- Account data: for the life of your account, then deleted or anonymized within 45 days after closure; limited backups may persist for 30 days.
- Vehicle logs (odometer, tire pressure, service history): until you delete them or your account is closed.
- Uploaded documents/media: until you delete them or your account is closed; processing artifacts (e.g., previews, embeddings) may be purged within 14 days after deletion.
- Subscription/transaction records: retained for 7 years to meet accounting/tax obligations.
- Diagnostics & logs: 90 days, unless extended for security investigations.
We may anonymize data for statistical reporting; anonymized data is not reasonably re‑identifiable and may be retained longer.
8) Security
We employ administrative, technical, and physical safeguards appropriate to the nature of the data:
- Encryption in transit (TLS 1.2+) and at rest for hosted storage.
- Access controls & least privilege, audit logging, and key management.
- Secure development practices, dependency management, and vulnerability remediation.
- Multi‑factor authentication for internal/admin access where feasible.
No method of transmission or storage is 100% secure; if we learn of a breach, we will notify you and regulators as required by law.
9) Your rights & choices
Depending on your region, you may have rights to access, correct, delete, restrict or object to processing, port your data, and withdraw consent (where processing is based on consent). We will not discriminate against you for exercising your rights.
How to exercise: Email us at privacy@crankysoftware.com or use in‑app tools (export/delete). We may need to verify your identity.
Marketing preferences: You can unsubscribe via links in emails or adjust in‑app settings. Push notifications can be controlled in your device OS and app settings.
10) Region‑specific notices
10.A California (CPRA)
- We do not sell or share your personal information for cross‑context behavioral advertising.
- We use categories of personal information as described in Sections 2–5 for the business purposes listed in Section 3.
- You may request access, correction, or deletion, and limit the use/disclosure of sensitive personal information (where applicable).
- Authorized agents may make requests on your behalf subject to verification.
10.B EEA/UK (GDPR)
- Controller: CrankySoftware LLC.
- Legal bases: see Section 3.
- Complaints: You can lodge a complaint with your local supervisory authority; we welcome the chance to resolve concerns first.
10.C Brazil (LGPD), Canada (PIPEDA), Australia & others
We honor applicable local rights and transparency requirements. Contact us to exercise your rights.
11) Children’s privacy
Our Services are not directed to children under 13. If you are in the EEA/UK, additional age thresholds may apply (typically under 16). We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us to request deletion.
12) App‑specific details (CrankyGarage)
Device permissions (you can allow/deny in your OS/app settings):
- Camera/Photos/Files: capture and attach vehicle photos/documents.
- Bluetooth: connect to OBD2/TPMS or other peripherals you choose.
- Location (optional): attach location context to logs or features you enable.
- Notifications: local on‑device reminders (no remote push).
OBD2/TPMS data: We record only the readings/events you save or configure (e.g., tire pressures, diagnostic trouble codes). Continuous background collection is off unless you explicitly enable it.
VIN decoding: VINs you submit are processed to return make/model/year and related info; decoded results become part of your vehicle record.
Uploaded documents: Please upload only files related to your vehicle(s). Typical size limits apply (e.g., between 1 MB and 500 MB per file). After verification/processing, you can query or search your documents in‑app.
AI/document features: If you enable AI‑powered analysis of your documents, content may be sent to selected processors to generate summaries or search indexes. We restrict processors’ use of your data to providing the requested feature and prohibit use for their own model training unless you opt in.
13) Your controls
In the app and/or account portal you can:
- View, edit, export, or delete your vehicle data and documents
- Disconnect identity providers and peripherals
- Manage notifications and marketing preferences
- Download a copy of your data (where available)
- Close your account
14) Changes to this Policy
We may update this Policy to reflect changes in our Services or legal requirements. We’ll post the new version and update the “Last updated” date above. Material changes will be communicated via email or in‑app notice. Your continued use after the effective date signifies acceptance.
15) Data map (appendix)
This appendix helps map what we collect to purposes, bases, and retention.
| Category | Examples | Purpose(s) | Legal basis | Typical retention |
|---|---|---|---|---|
| Account | name, email, password/hash, locale | provide account, security, support | contract; legitimate interests | account life + 45 days |
| Auth (social) | subject ID, issuer, issuerAssignedId, email (if consented) | sign‑in, account linking, fraud prevention | contract; consent; legitimate interests | account life |
| Vehicle | VIN, model/year, odometer, tires, service logs, photos | core features, history, reminders | contract; legitimate interests | until deleted/account closed |
| Documents | PDFs, receipts, manuals, images | storage, search, AI features | contract; legitimate interests; consent | until deleted/account closed |
| Telemetry | device, IP, logs, crash reports | diagnostics, security | legitimate interests | 90 days |
| Payments | subscription status, order ID | entitlements, billing, tax | contract; legal obligation | 7 years |
16) Third‑party technologies we use (concise list)
We currently use (or plan to use) these technologies to provide the Services:
- Hosting & storage: Microsoft Azure (cloud infrastructure).
- Identity & authentication: Microsoft Entra External ID (Azure AD B2C); Google Sign‑In; Sign in with Apple; Facebook Login (not enabled).
- Payments & subscriptions: Apple App Store; Google Play Billing; Stripe (planned).
- Diagnostics & analytics: Sentry (crash/error/performance); Azure Application Insights (telemetry).
- Email (if enabled): a reputable email provider (e.g., SendGrid or Mailjet).
- Document/AI (optional feature): AskYourPDF for user‑initiated document analysis.
- Notifications: local on‑device reminders only (no remote push).
We may update this list as vendors or features change.
Effective date: This Policy becomes effective on October 21, 2025.