Legal

Security

These are the measures we operate to keep driver and garage data safe. Review this page before publishing and remove anything you do not yet do — only publish measures that are actually in place. We hold no third-party certifications and make no compliance claims beyond what is stated here.

Access control

  • Accounts are protected by email sign-in or Google/Apple sign-in handled by our authentication provider; we never see or store your password.
  • Database row-level security means each driver can only read and write their own profile, vehicles and bookings, and each garage only its own listing and bookings.
  • Internal privileged database helpers are kept out of the public API surface and are not callable by visitors or signed-in users.
  • Administrative access is limited to the people who need it to run the service.

Data in transit and at rest

  • All traffic between your browser and FastFix is served over HTTPS/TLS.
  • Data is stored with our managed hosting and database provider, which encrypts data at rest and takes automated backups.
  • Card details are captured on our payment provider's hosted checkout; FastFix servers never receive or store full card numbers.

Data minimisation

  • Garages receive only the details needed to complete the job: your name, contact details, vehicle and chosen service.
  • Location is used at the moment of searching and is not stored against your account.
  • Retention limits are published in the privacy policy and data is deleted or anonymised when they expire.

Operational practices

  • Changes are reviewed before release and dependencies are scanned for known vulnerabilities.
  • Application errors and suspicious activity are logged and monitored.
  • Providers we rely on are chosen for their own security posture and are bound by written data processing terms.
  • We assess new features for privacy impact before launching them.

If something goes wrong

  • We investigate suspected incidents immediately and contain them as a priority.
  • Where a personal data breach is likely to present a risk, we notify the relevant supervisory authority within 72 hours and affected users without undue delay.
  • Affected users are told what happened, what data was involved and what to do next.

Report a vulnerability

If you believe you have found a security issue, email [security@yourdomain.com] with steps to reproduce. Please give us a reasonable period to fix the issue before disclosing it, and do not access or modify other people's data while testing. We will acknowledge your report within 5 working days.

Related: privacy policy and subprocessors.