Legal
Security
These are the measures we operate to keep driver and garage data safe. Review this page before publishing and remove anything you do not yet do — only publish measures that are actually in place. We hold no third-party certifications and make no compliance claims beyond what is stated here.
Access control
- Accounts are protected by email sign-in or Google/Apple sign-in handled by our authentication provider; we never see or store your password.
- Database row-level security means each driver can only read and write their own profile, vehicles and bookings, and each garage only its own listing and bookings.
- Internal privileged database helpers are kept out of the public API surface and are not callable by visitors or signed-in users.
- Administrative access is limited to the people who need it to run the service.
Data in transit and at rest
- All traffic between your browser and FastFix is served over HTTPS/TLS.
- Data is stored with our managed hosting and database provider, which encrypts data at rest and takes automated backups.
- Card details are captured on our payment provider's hosted checkout; FastFix servers never receive or store full card numbers.
Data minimisation
- Garages receive only the details needed to complete the job: your name, contact details, vehicle and chosen service.
- Location is used at the moment of searching and is not stored against your account.
- Retention limits are published in the privacy policy and data is deleted or anonymised when they expire.
Operational practices
- Changes are reviewed before release and dependencies are scanned for known vulnerabilities.
- Application errors and suspicious activity are logged and monitored.
- Providers we rely on are chosen for their own security posture and are bound by written data processing terms.
- We assess new features for privacy impact before launching them.
If something goes wrong
- We investigate suspected incidents immediately and contain them as a priority.
- Where a personal data breach is likely to present a risk, we notify the relevant supervisory authority within 72 hours and affected users without undue delay.
- Affected users are told what happened, what data was involved and what to do next.
Report a vulnerability
If you believe you have found a security issue, email [security@yourdomain.com] with steps to reproduce. Please give us a reasonable period to fix the issue before disclosing it, and do not access or modify other people's data while testing. We will acknowledge your report within 5 working days.
Related: privacy policy and subprocessors.