Skip to content

Privacy

Last updated 20 September 2026

Draft: not yet reviewed by a lawyer

This page describes how the software works today in plain language. It is not a substitute for legal advice. The operator of this service should have it reviewed and completed (company name, address, governing law) before relying on it.

This explains what Willy Auto Quote collects, why, and who else is involved.

What we store

Account: your name, email address and a scrambled (hashed) version of your password. We cannot read your password.

Shop records you enter: customers (names, phone, email, address, notes), vehicles (including VINs), quotes, parts, labor times, settings and team members.

An audit log of changes made in your shop (who did what, and when). It cannot be edited from inside the app.

When a customer answers a quote through their private link: the name they typed, the time, their network (IP) address and their browser's user-agent text, saved with their answer as evidence of approval.

To slow down password guessing we keep a counter of failed sign-ins and password-reset requests, keyed by a one-way hash of the email or address rather than the value itself.

Cookies

We use only the cookies needed to keep you signed in and to return you to the page you came from. We do not use advertising or analytics cookies, and the pages contain no third-party tracking scripts.

Who else handles data

Payments: if you subscribe, Stripe processes your payment. Card details go to Stripe, not to our servers, and we keep only identifiers such as a customer and subscription reference.

Email and text messages: if the operator has switched on message delivery, the recipient's address or phone number and the message text are passed to the email or SMS provider so it can be delivered. If it is not switched on, nothing is sent and no data goes to those providers.

VIN lookup: when you decode a VIN, the VIN is sent to the US NHTSA vPIC service, which returns the vehicle details.

We do not sell your data, and shops cannot see each other's records: the database itself enforces the separation.

Keeping data safe

Passwords are hashed. Sign-in locks after repeated failures. Password-reset and customer-approval links are long random tokens: only a fingerprint of each is stored, and they expire.

No system is perfectly secure, and some protections (such as two-factor sign-in) are not available yet.

Keeping and deleting data

Your shop's records stay while your account exists. You can export customers, parts and labor times as CSV at any time. To ask for your account or personal data to be deleted or corrected, contact us using the details on the contact page. Some records, such as the audit log, may be kept for a period so the history stays trustworthy.

Your customers' data

Your shop decides what to record about its own customers and is responsible for having the right to record it. We handle that data only to provide the service to your shop.

Questions? See the contact page.