Service VIN — Legal
Privacy Policy
This Privacy Policy explains what information Service VIN collects, how we use and protect it, and the choices you have. It includes dedicated sections on the Google user data we access when you connect Google, on our first-party-only product analytics and the cookies it sets, on how we honour Do Not Track and Global Privacy Control, on where in the world your data is actually stored, and on your rights under Quebec's Law 25.
Last updated: August 3, 2026
1. Who we are
Service VIN is an all-in-one operations platform for auto detailing, paint protection film (PPF), vinyl wrap, window tint, and ceramic coating studios. We provide quoting, online bookings, scheduling, invoicing, customer records, and optional integrations with third-party services.
The Service is owned and operated by Obsidian Auto Inc., a corporation carrying on business as Service VIN with its registered office at 168 MacEwan Ridge Close NW, Calgary, Alberta T3K 3J4, Canada. In this policy, “Service VIN,” “we,” “us,” and “our” mean Obsidian Auto Inc.. Obsidian Auto Inc. is the organization accountable for the personal information described in this policy.
This policy applies to our website and web application (together, the “Service”), reachable at servicevin.com. If you have any questions, contact us at [email protected].
2. Information we collect
We collect the following categories of information:
- Account information. When you create an account or are invited to a shop, we collect your name, email address, and — if you sign in with Google — your Google profile name and picture. We store an authentication record but never your Google password.
- Business & customer data you enter. Information you add to run your shop: customers, vehicles, quotes, bookings, invoices, inventory, messages, and notes. You are responsible for the data you enter about your own customers.
- Google user data. If you choose to connect a Google account, we access only the specific data described in Section 3 below.
- Usage & device data. Basic technical data such as IP address, browser type, and pages viewed, used to keep the Service secure and reliable. Section 9 sets out exhaustively what our product analytics collects, which cookies we set, and what never enters analytics; Section 10 explains how we honour Do Not Track and Global Privacy Control.
- Payments. If you subscribe or accept payments, billing is handled by our payment processor (Stripe). We do not store full card numbers on our servers.
3. How we access and use Google user data
Connecting Google to Service VIN is always optionaland initiated by you. We request the narrowest set of scopes needed for each feature, and we only access Google data after you grant consent on Google’s own permission screen. You can disconnect at any time (see Section 8). Below is exactly what we request and why.
a. Sign in with Google
Scopes: openid email (and basic profile)
What we access: your email address, and your basic Google profile (name and profile picture).
Why: to authenticate you and create or sign you in to your Service VIN account, and to label your account with your name and email. We do not use these details for advertising.
b. Google Calendar
Scopes: https://www.googleapis.com/auth/calendar.events and https://www.googleapis.com/auth/calendar.calendarlist.readonly
What we access: the events on the Google Calendar you choose to connect, and — read-only — the names of the calendars on your account so you can pick which one to sync. The read-only calendar list is the narrowest scope Google offers for that picker; it does not let us read the contents of your other calendars.
Why:to keep your shop’s schedule and Google Calendar in sync. When a job is booked, moved, or cancelled in Service VIN, we create, update, or delete the matching calendar event (with the vehicle, service, and bay); and we read events so the calendar and the booking board stay consistent. We access calendar data only to power these scheduling features that are visible in the app.
c. Google Business Profile
Scope: https://www.googleapis.com/auth/business.manage
What we access: your Google Business Profile location(s) and their reviews.
Why: to help you collect and manage reviews. When a job is marked complete, Service VIN can time a review request to your Google Business Profile, and it pulls new reviews back into the app so you can read and reply to them without leaving Service VIN. We access Business Profile data only to power these review-management features that are visible in the app.
d. Google Ads
Scopes (direct connection only): https://www.googleapis.com/auth/adwords and https://www.googleapis.com/auth/datamanager
How this connection is made: this connection is brokered by Zernio, a third-party advertising-API provider — you authorize Zernio, and Service VIN reads and writes your Google Ads account through it. Service VIN itself does not hold your Google Ads credentials, and the two permissions listed above are not requested on the Service VIN consent screen; our own application covering them remains under review by Google and is used only on deployments that connect Google Ads directly. Everything below describes the data involved either way.
What we access: the Google Ads account you choose to connect — its campaigns, ad groups, keywords, ads, budgets, targeting and performance statistics, and the conversion actions used to measure results. We also send data to that account: conversions for jobs you booked and invoices you were paid for, and — only where you switch it on — customer lists built from contacts who consented to marketing.
Why: so your advertising can be managed and measured where the rest of your shop already lives. We read campaigns and their statistics to show what each one costs and earns against your real invoices; we create and manage campaigns you have reviewed and approved in the app; and we send booked jobs and invoiced revenue back as conversions so Google can optimize toward work you were actually paid for rather than form fills. Every change to a live campaign is either made by you or, if you explicitly switch on automatic optimization for that campaign, made within the limits you set.
Customer lists: when you enable audience sync, we send Google a hashed (irreversibly scrambled) form of the email address or phone number of customers who consented to marketing — never plain contact details, and never anyone who did not consent or who opted out. Google uses it to match existing customers so you can exclude them from prospecting ads or reach them for win-back. You can switch this off at any time, and doing so stops all further uploads.
We access Google Ads data only to power these advertising features that are visible in the app. We never use it for our own advertising, never combine one shop’s account data with another’s, and never sell it.
What we do not do: we do not use Google user data for advertising; we do not sell it; and we do not use it to train generalized artificial-intelligence or machine-learning models.
4. Google API Services User Data Policy — Limited Use
Service VIN’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In keeping with those requirements, we specifically confirm that we:
- limit our use of Google user data to providing or improving the user-facing features described above that are prominent in the Service VIN interface;
- do not transfer or sell Google user data to third parties such as advertising platforms, data brokers, or information resellers;
- do not use or transfer Google user data for serving ads, including retargeting, personalized, or interest-based advertising; and
- do not allow humans to read Google user data unless we first obtain your explicit consent to read specific data, it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, or the data has been aggregated and anonymized for internal operations; and
- do not use, transfer, or sell Google user data — raw, aggregated, or derived — to develop, train, or improve any generalized or foundational artificial-intelligence or machine-learning model, whether ours or a third party's.
Where AI is involved. Service VIN uses third-party AI providers for specific in-product features, always through their commercial APIs under terms that do not permit training on the inputs or outputs we send. Anthropic (Claude) powers in-app drafting and summaries. OpenAI and Google (Gemini and Imagen) are used only to generate marketing and service imagery — never for customer messages, call transcripts, or Google user data.
The only Google user data that can reach an AI provider is Google Business Profile review text, and only at the moment you use the in-app draft a reply or summarize reviews features. Google Calendar event content is never sent to any AI provider. Every provider, and what each one processes, is listed on our subprocessor page.
5. How we store and protect your data
- Encryption in transit and at rest. All traffic to the Service is served over HTTPS/TLS. Data is stored in managed, access-controlled databases.
- OAuth tokens. The access and refresh tokens Google issues when you connect an account are encrypted before they are stored, and are used only to make the API calls needed for the features you enabled.
- Access controls.Access to production data is limited to authorized personnel and is governed by per-shop isolation, so one shop cannot see another shop’s data.
6. How we share information
We do not sell your personal information or Google user data. We share information only in these limited cases:
- Service providers (sub-processors) who process data on our behalf under contract and only as needed to run the Service — for example: Supabase (application database and authentication), Stripe (payments), Twilio (calls and messaging), Resend (email), and, where configured, PostHog (product analytics) and Sentry (error monitoring). These providers are not permitted to use your data for their own purposes. The current, itemized list is published on our security page.
- Within your shop.Data you enter is visible to the members of your own shop’s workspace according to their roles.
- Legal and safety. When required to comply with applicable law, enforce our terms, or protect the rights, safety, and security of our users and the public.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this policy.
7. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. When you disconnect a Google integration, we stop accessing that Google account and delete or render unusable the stored OAuth tokens for it. When you delete your account, we delete or anonymize your personal information within a reasonable period, except where we must retain certain records to comply with legal obligations, resolve disputes, or enforce our agreements.
8. Your choices and controls
- Disconnect Google. In Service VIN, go to Settings → Integrations and disconnect Google Calendar or Google Business Profile at any time. This revokes our access and removes the stored tokens for that connection.
- Revoke at Google.You can also review and revoke Service VIN’s access directly from your Google Account at myaccount.google.com/permissions.
- Opt out of analytics. Turn on Do Not Track or Global Privacy Control in your browser or privacy extension and we will not measure your visit or set an analytics cookie — see Section 10. You can also delete the
sv_aidandsv_attrcookies from your browser at any time; nothing in the Service depends on them. - Access, correct, or delete. You may request access to, correction of, or deletion of your personal information by emailing [email protected]. Depending on where you live, you may have additional rights under laws such as PIPEDA (Canada), Quebec’s Law 25 (see Section 14, which adds portability, de-indexation and automated-decision rights), or the GDPR (EU/UK).
9. Cookies and product analytics
This section describes our analytics architecture in deliberate detail, so that you can check it rather than take it on trust. If you spot a discrepancy between what is described here and what you observe, tell us at [email protected] and we will correct it.
Cookies we set. We use a small number of first-party cookies. We do not use advertising cookies, and no third party sets a cookie through our site.
- Essential cookies. Keep you signed in, protect forms against cross-site request forgery, and remember interface preferences such as light or dark theme. The Service does not work without these.
sv_aid— anonymous analytics identifier. A randomly generated identifier (a UUID) that lets us count a visit as one visit across several pages instead of several unrelated hits. It contains no name, email, or other information about you — it is a random number and nothing else. Lifetime 90 days. Set asHttpOnly,Secure,SameSite=Lax, so it is not readable by scripts and is not sent on cross-site requests.sv_attr— first-touch attribution. Records how you first arrived, so we can tell which of our marketing efforts actually work. It stores only a fixed allowlist of values: the campaign parametersutm_source,utm_medium,utm_campaign,utm_term,utm_content, plusgclidandrefif present, together with the host name only of the site that referred you and the path only of the page you landed on. It never stores a full referring URL and never stores a query string. It is first-touch: once set it is never overwritten, so later visits do not rewrite the record. Lifetime 90 days, and the sameHttpOnly/Secure/SameSite=Laxsettings.
Both analytics cookies are set only by our own server, only when analytics is switched on, and only when you have not signalled a tracking preference (see Section 10). You can delete them at any time in your browser, and blocking them does not break anything.
How the analytics work — and what does not happen.Our analytics deliberately avoid the usual arrangement, in which your browser loads a vendor’s script and reports directly to that vendor. Instead:
- No third-party script and no vendor SDK for the product funnel.We do not load a script from another company’s servers to measure the six-step funnel described below, and your browser never contacts that provider directly.
- Our hosting provider’s own measurement, disclosed separately. We do run Vercel Web Analytics and Vercel Speed Insights, which are features of the platform that hosts this site. These do load a small vendor-written script — served from our own domain, not a third-party one — and report to Vercel. They set no cookiesand do not track you between days or across other websites: Vercel counts a visitor using a hash derived from the request that is reset every 24 hours. We configure them so the only address they ever report is a redacted route template, never a full URL and never a query string; a customer’s share link is reported as
/p/quote/[token], with the token removed before it leaves the browser. If you send a Do Not Track or Global Privacy Control signal, neither script is loaded at all. - First-party transport only. A very small piece of our own code posts a short, fixed set of fields to an endpoint on our own domain. Our server then forwards a sanitized event to our analytics provider. Because the forward happens server-side, we control exactly what leaves, byte for byte.
- No vendor autocapture. Nothing scrapes your clicks, your keystrokes, the text on the page, or the contents of forms. We record only the specific events listed below.
- No cross-site tracking and no advertising. The identifier is first-party and cannot follow you to another site. We do not build advertising profiles, we do not sell analytics data, and we do not share it with ad networks or data brokers.
What we actually collect. The analytics record is limited to:
- the six product milestones we measure — a site visit, a signup, a shop being created, the first quote sent, the first payment taken, and a subscription starting;
- the route of the page (for example
/pricing) — never the query string, never a full URL, and never a part of the address that identifies a record or opens a document. A customer’s share link is recorded as/p/quote/[token], with the token removed before it leaves the browser and again on our server; - the first-touch attribution values described above;
- coarse technical context, and this is the complete list of it for our own first-party record: your browser’s language setting (for example
en-CA), your screen width and height rounded down to the nearest 320 pixels, and — where our network provider supplies it — a country, nothing more precise. Our own record does not include your user-agent string, browser name, device model or operating system. Vercel Web Analytics, described above, does derive a browser name and version, an operating system name and version, and a device class (phone, tablet, desktop) from your request, and Vercel Speed Insights additionally records page-loading timings — how quickly the largest element appeared, how much the layout shifted, how fast the page responded to your first interaction — against the route template, never against a full URL; - for signed-in activity, the internal account or organization identifier (a UUID) so a funnel can be followed end to end. To make the funnel work we do link the anonymous visit identifier described below to that organization UUID at the moment an account is created, which is what lets us see that a visit became a signup. Neither value is a name, an email or anything a stranger could resolve to you, but we would rather say plainly that they are joined than let you infer they never are. If your browser sends a do-not-track signal no anonymous identifier is ever issued, so there is nothing to join.
Your customers’ personal information never enters analytics. Names, email addresses, phone numbers, postal addresses, VINs, licence plates, vehicle records, quote and invoice contents, message bodies, and customer records of any kind are excluded by design. So are full URLs with query strings, request bodies, cookies, and authorization headers. When we forward an event to our analytics provider we explicitly instruct it to discard the IP address and to perform no geographic lookup, so your raw IP address is not stored in the analytics system. That instruction is specific to PostHog and we cannot make it of Vercel: Vercel Web Analytics derives its 24-hour visitor hash, and a country, from the incoming request, which includes your IP address. Your IP is not retained by that feature, but it is processed to produce those two values, and we would rather state the distinction than let the sentence above imply more than it should.
Who processes it. There are two, and they are separate. Our hosting provider Vercel processes the Web Analytics and Speed Insights data described above, as a feature of the platform that already serves every request to this site. Our product-funnel analytics processor is PostHog. We chose it because we need to follow a six-step funnel in which several steps happen on our servers rather than in a browser, which simple pageview tools cannot do without us building an identity layer ourselves. PostHog processes this data only on our instructions, as our service provider. By default we send it to PostHog’s European Union region — see Section 12 for what that means and why.
When analytics is off entirely.The analytics layer is configuration-gated, and off unless it is switched on deliberately. When it is not switched on, the measurement component never runs, no beacon is sent, neither cookie is set, no row is written to our own records, and no request goes to the product-funnel provider. It is not merely disabled — it is absent. There is a second, narrower switch for that provider: we can run the whole measurement layer on our own database with no analytics provider configured at all, in which case nothing leaves our systems. Vercel Web Analytics and Speed Insights are governed by their own, independent switch in our hosting provider’s settings; turning the product funnel off does not turn those off, and turning those off does not turn the product funnel off. Both, however, stop for anyone sending a Do Not Track or Global Privacy Control signal.
We also keep ordinary server logs for security and reliability, which may include IP addresses and request paths. Those are operational records, separate from analytics, and are not forwarded to our analytics provider.
10. Do Not Track and Global Privacy Control
We honour Do Not Track and Global Privacy Control. If your browser or extension sends a DNT: 1 header, a Sec-GPC: 1 header, or exposes the equivalent setting to the page, we do not measure your visit.
Many sites publish a Do Not Track section that says the signal is ignored because there is no agreed standard. We do not do that. In concrete terms, when we see the signal:
- No beacon is sent. Our client-side code checks for the signal before doing anything and stops. No network request is made, not even to our own domain.
- No cookie is set. Neither
sv_aidnorsv_attris created, so there is nothing to delete afterwards. - The server drops it too. If a request carrying the signal reaches our collection endpoint anyway, the server discards the event and sets no cookie. Honouring the signal does not depend on the browser side working correctly.
- Nothing is forwarded. No event derived from that request is sent to PostHog.
One honest exception, stated plainly.Certain product milestones about a shop’s own account — that an account was created, that a first quote was sent, that a subscription started — are recorded in our own database even when the signal is present. That is first-party operational data about the running of the account, of the same nature as the account record itself, and it is not cross-site tracking. Those records are not forwarded to PostHog when the originating request carried a Do Not Track or Global Privacy Control signal.
The limit of a browser signal. Two of those milestones — a first payment and a subscription starting — are triggered by our payment provider calling our servers, not by anyone using a browser, so there is no Do Not Track header on the request to honour. When analytics is configured, those two are forwarded (an organization UUID and the plan name — no amount, no customer, no card data). If you would like your account excluded from analytics entirely rather than per-request, email us at [email protected] and we will suppress it at the account level.
11. Error monitoring
To find and fix crashes, we may send error reports to Sentry, an error-monitoring service acting as our processor. An error report contains the error message, the stack trace, the application version, the environment name, the route or component where the failure occurred, the HTTP method, and the request route — reduced to a template in the same way as analytics, so /p/invoice/[token] is reported with the token removed.
We deliberately built a minimal, hand-written integration rather than installing the vendor’s standard library, because the standard library captures request headers, cookies, and IP addresses by default. Ours sends no request headers at all — not even the user-agent string, which we removed for this reason. Error reports do notinclude request bodies, cookies, authorization headers or session tokens, your customers’ personal information, or raw IP addresses.
Error reporting is configuration-gated in the same way as analytics: if it is not configured, the monitoring code does nothing and no report leaves the application. Stack traces can occasionally contain a fragment of data that happens to be in scope at the moment of a failure; if you believe an error report captured something it should not have, contact us at [email protected] and we will purge it.
12. Where your data is processed (cross-border transfers)
Service VIN is a Canadian business, operated by Obsidian Auto Inc. from Calgary, Alberta, and is subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and — where we serve customers there — to Quebec’s Law 25. Under both, an organization may use service providers in other countries, but it remains accountable for the information and must be transparent about where the information goes and that it will be subject to the laws of that country. This section is that disclosure.
Say the important part first: your data is stored in the United States, not in Canada. We are a Canadian company, but our production database, authentication and file storage run in AWS us-east-1(Northern Virginia, United States), and our application servers run in our hosting provider’s default US East region. We do not currently offer a Canadian data-residency option, and we would rather tell you that plainly than let “Canadian company” imply Canadian storage.
Specifically:
- Application data — your account, customers, quotes, bookings, invoices, and messages — is held by our database and authentication provider (Supabase) in AWS us-east-1, United States, and served by our hosting provider (Vercel) from its default United States region.
- Payments are processed by Stripe; calls and text messages by Twilio; transactional email by Resend. Each of these is a United States company and may process the relevant data in the United States.
- Product analytics (see Section 9) are forwarded to PostHog. By default we send analytics events to PostHog’s European Unionregion, hosted in the EU. We chose the EU region deliberately: it is the strictest-jurisdiction option available to us, and it keeps our analytics posture defensible in every market we sell into without re-architecting later. The region is a configuration setting, and we may move analytics processing to PostHog’s United States region if latency or cost warrants it — if we do, we will update this policy and the subprocessor list. Analytics events contain no customer personal information and no IP address (Section 9 lists the fields exhaustively).
- Error reports (see Section 11) go to Sentry, which may process them in the United States or the European Union depending on the region configured.
Information stored in another country may be accessible to the courts, law enforcement, and national-security authorities of that country under its laws. We reduce the exposure by limiting what is sent in the first place — analytics and error monitoring in particular are engineered so that customer personal information does not leave the application at all — and by contracting with each provider to process data only on our instructions.
Before we add a provider that processes outside Quebec, we assess it: what personal information it would receive, the sensitivity of that information, the purpose, the protections it commits to contractually, and the legal regime it operates under. We engage a provider only where that assessment supports adequate protection, and only under a written agreement limiting it to our instructions. The current outcome of that exercise is the itemized list published at /security/subprocessors, which names each provider, what it receives, and where it runs.
13. Security, DPA and subprocessors
Our current list of subprocessors — the specific companies that process data on our behalf, what each one does, and where it is located — is published and kept current on our subprocessor page, alongside our security practices and our Data Processing Agreement for customers who need one on file.
If you require a countersigned DPA, or a copy of the current subprocessor list in a form you can attach to your own records, email [email protected].
14. Quebec (Law 25)
Service VIN is offered to businesses located in Quebec. If you are in Quebec, or the individuals whose information you put into Service VIN are in Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25 applies to that information, and this section sets out how we meet it. Everything else in this policy applies to you as well; this section adds to it rather than replacing it.
Person responsible for the protection of personal information. Law 25 requires us to designate one and to publish the title and contact information. At Obsidian Auto Inc., that role is held by the President, reachable at [email protected] or by mail at 168 MacEwan Ridge Close NW, Calgary, Alberta T3K 3J4, Canada. Write to either to exercise any right below, or to complain about how we handled your information.
Your rights under Law 25. In addition to the access and correction rights in Section 8, if you are in Quebec you may:
- Ask what we hold, and why. You may ask for the personal information we hold about you, the categories of people inside our organization who have access to it, how long we keep it, and where it is held. We answer within 30 days.
- Have it corrected. You may require us to correct information that is inaccurate, incomplete or ambiguous, and to delete information collected without legal authority.
- Withdraw consent. You may withdraw consent to a use or disclosure at any time. Where that consent is what makes a feature work, withdrawing it turns the feature off rather than degrading it silently.
- Take your data with you (portability). You may ask for the computerized personal information you provided to us in a structured, commonly used technological format, or ask us to send it to another organization where doing so is feasible.
- De-indexation and cessation of dissemination. You may require us to stop disseminating your personal information, or to de-index a link giving access to it, where the dissemination contravenes the law or a court order — or where it causes you serious injury to reputation or privacy that clearly outweighs the public interest in the information, and stopping it does not exceed what is necessary to prevent that injury.
- Be told about automated decisions. If we ever make a decision about you based exclusively on automated processing, we will tell you at the time and, on request, explain the personal information used, the reasons and principal factors behind the decision, and your right to have it reviewed by a person. We do not make such decisions today: the AI features in Service VIN draft and suggest, and a person at the shop decides.
Technology that can identify, locate or profile you. Our product analytics set a first-party identifier so we can count one visit as one visit — described exhaustively in Section 9. We do not use it for cross-site tracking, profiling or advertising. Those functions are deactivated the moment you signal a preference: turn on Do Not Track or Global Privacy Control and no identifier is issued and no beacon is sent, as described in Section 10. You can also delete the sv_aid and sv_attr cookies at any time, and nothing in the Service depends on them.
Confidentiality incidents. We keep a register of confidentiality incidents involving personal information. Where an incident presents a risk of serious injury, we notify the Commission d’accès à l’information and the people concerned with reasonable promptness, and we notify affected shops so they can meet their own obligations to their customers. Our contractual breach-notification commitment to customers is 72 hours, set out in our Data Processing Agreement.
Processing outside Quebec. Your data is stored in the United States, not in Canada — see Section 12, which names each provider, what it receives, where it runs, and the assessment we carry out before engaging one. It is repeated here because Law 25 expects that fact to be plain rather than merely discoverable.
If we do not resolve it.If you are not satisfied with how we handled your request or your complaint, you may bring it to the Commission d’accès à l’information du Québec, which supervises the application of Law 25.
Language. This policy and our Terms of Service are published in English. If you would prefer them in French, email [email protected] and we will provide a French version of both documents before you are asked to agree to them. Your rights are identical in either language.
15. Children's privacy
The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect personal information from children.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app or by email. Your continued use of the Service after an update means you accept the revised policy.
17. Contact us
If you have questions or requests regarding this Privacy Policy or your data, contact us at [email protected]. You can also review our Terms of Service and our security practices, DPA and subprocessor list.