Privacy Policy

Effective Date: January 1, 2025

Version: 1.1

Last Updated: December 30, 2025

Table of Contents

1. Introduction & Contact Information

Welcome to CollisionOS, a cloud-based shop management system designed specifically for auto body repair shops in British Columbia. We are committed to protecting your privacy and handling your personal information responsibly and transparently.

CollisionOS is operated as a sole proprietorship based in Vancouver, British Columbia, Canada. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information in compliance with:

By using CollisionOS, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree with our practices, please do not use our services.

2. Roles & Responsibilities

Understanding who controls your data and who processes it is important for privacy compliance:

2.1 Your Shop (Data Controller / Organization)

As the auto body shop using CollisionOS, you are the data controller (or "organization" under PIPEDA/BC PIPA). This means:

2.2 CollisionOS (Service Provider / Processor)

CollisionOS acts as a service provider (or "processor") on your behalf. This means:

Example: When you enter a customer's name, phone number, and vehicle VIN into a repair order, you (the shop) decided to collect that information and are responsible for obtaining the customer's consent. CollisionOS simply provides the software and cloud storage to help you manage that data securely.

2.3 Why This Matters

This distinction is important because:

3. What Information We Collect

We collect various types of information to provide and improve our cloud-based shop management services. Here's what we collect and why:

3.1 User Account Information

When you create an account or authenticate with CollisionOS, we collect:

3.2 Shop Business Information

To provide shop management functionality, we collect and store:

3.3 Customer Personal Information

As part of your repair order management, you may enter customer information including:

Example: When a customer brings in a 2018 Honda Civic for repairs after an accident, you would enter their contact information, ICBC claim number, and vehicle details into CollisionOS to create the repair order.

3.4 ICBC-Specific Data

For shops working with ICBC (Insurance Corporation of British Columbia) claims, we process:

3.5 Repair & Financial Data

To manage your shop operations, we store:

3.6 Technical & Usage Data

To improve our service and ensure security, we automatically collect:

4. How We Use Your Information

4.1 Primary Purposes

We use your personal information to provide and improve our cloud-based shop management services:

Example: When you import a Mitchell XML estimate file for a repair, we process the customer data, vehicle information, parts list, and labor operations to create a repair order in your system. This data syncs to the cloud so your technicians can access it from the shop floor on their tablets.

4.2 Secondary Purposes (Optional)

With your consent, we also use your information for purposes beyond what is strictly necessary to provide the service:

To opt out of optional analytics and product improvement: Email privacy@collisionos.ca or use browser privacy settings to block analytics cookies. Opting out will not affect core service functionality.

4.3 Purposes That Are Necessary for Service Delivery

The following uses of your information are necessary to provide CollisionOS and cannot be opted out of while using the service:

4.4 Legal Basis for Processing (PIPEDA Compliance)

We process your personal information based on:

5. Data Storage & Security

5.1 Cloud Storage

Your data is stored using industry-leading cloud infrastructure:

Important: Customer operational data is stored in Toronto, Canada via Google Firebase/Firestore. Authentication data (login emails, IP addresses) is processed in the United States via Firebase Authentication. See Section 7 below for complete cross-border transfer details.

5.2 Local Storage

For offline access and improved performance, we also store data locally on your devices:

You control local data: You can clear browser localStorage, uninstall the desktop app, or delete backup files at any time. This does not affect your cloud-stored data.

5.3 Security Measures

We implement multiple layers of security to protect your information:

5.4 Data Breach Notification

In the unlikely event of a data breach involving your personal information, we will:

6. Data Sharing & Third-Party Services

We do not sell, rent, or trade your personal information. However, we work with trusted third-party service providers to deliver and improve CollisionOS. Here's who has access to your data and why:

6.1 Google/Firebase (Cloud Infrastructure)

CollisionOS uses multiple Firebase services, each with different data processing locations:

Firebase Firestore (Database) - Canada:

Firebase Authentication - United States:

Firebase Hosting (CDN) - Global:

Privacy policy - Google Privacy Policy

6.2 Google Analytics (Usage Analytics)

6.3 Stripe (Payment Processing)

6.4 Mitchell Connect (Estimate Import)

6.5 What We DO NOT Do

To be absolutely clear:

7. Cross-Border Data Transfer & Infrastructure Access

Important Notice: Customer operational data is stored in Toronto, Canada via Google Firebase/Firestore. Some service data (authentication, CDN request metadata) may be processed outside Canada.

7.1 Data Storage and Processing Locations

Different types of data are processed in different locations:

7.2 Potential Cross-Border Access

While your data is stored in Canada, there may be limited circumstances where it could be accessed from other jurisdictions:

Key Point: Unlike storing data in US data centers, keeping data in Canada provides stronger privacy protections under Canadian law. However, because Google is a US-based company, the US CLOUD Act could theoretically apply to data requests, though such requests for Canadian-stored data would be subject to additional legal scrutiny and bilateral agreements.

7.3 PIPEDA Compliance & Accountability

Under PIPEDA, organizations must obtain consent for cross-border transfers and use contractual or other safeguards to provide a comparable level of protection. We comply by:

7.4 Your Acknowledgment

By using CollisionOS, you acknowledge and understand that:

7.5 Data Residency Configuration

We store your operational data in Google Firebase/Firestore's Toronto, Canada data center. Your data is configured to remain within Canada. If our regional configuration changes, this policy will be updated with at least 30 days advance notice.

8. ICBC Data Handling

Critical Disclaimer: CollisionOS is NOT affiliated with, endorsed by, or an official partner of ICBC (Insurance Corporation of British Columbia). We are an independent software tool used by auto body shops. We have no formal relationship with ICBC.

8.1 What ICBC-Related Data We Process

Many BC auto body shops work with ICBC claims. When you use CollisionOS for ICBC repairs, we process:

Example: When you import a Mitchell estimate for an ICBC claim, the XML file contains the ICBC claim number (like "CW71973-3-A"), customer contact information, vehicle VIN, and approved repair procedures. We parse this data to create the repair order in your system.

8.2 ICBC Compliance Tools

CollisionOS includes ICBC compliance reference tools that help you check repair orders against common ICBC guidelines. Important information about these tools:

Best practice: Use the compliance tools as a quick reference, but always confirm procedures with the official ICBC MDP Portal at mdp.partners.icbc.com before completing repairs.

8.3 Your Responsibilities as a Shop Owner

When you use CollisionOS to process ICBC claim data, you are responsible for:

8.4 No ICBC Data Sharing

We want to be crystal clear:

You remain solely responsible for any ICBC reporting requirements that apply to your shop.

8.5 Not an ICBC Vendor

CollisionOS itself is not an ICBC-approved vendor or partner. We are a software tool that shops can use. Whether or not your shop is an approved ICBC vendor is between you and ICBC, not related to your use of our software.

9. Your Privacy Rights (PIPEDA & BC PIPA)

Under Canadian privacy laws (PIPEDA and BC PIPA), you have important rights regarding your personal information. Here's what you can do:

9.1 Right to Access Your Information

You have the right to request and receive a copy of all personal information we hold about you.

How to exercise:

9.2 Right to Correction

You have the right to request correction of inaccurate or incomplete personal information.

How to exercise:

9.3 Right to Deletion

You have the right to request deletion of your personal information. We provide self-service tools to delete customer data directly from the application.

Customer Data vs Business Records:

  • Customer personal data (names, emails, phone numbers) - Can be deleted or anonymized upon request using our Data Privacy tools in Settings
  • Your business financial records (invoice amounts, tax calculations) - You should retain these for 6 years per CRA requirements for your own tax compliance

Note: CRA record retention requirements apply to your business financial records, not to customer personal information. You can delete customer PII at any time.

What you can delete immediately:

How to delete customer data: Go to Settings → Privacy Rights → Manage Customer Data / Deletion. You can search for customer data and delete or anonymize it directly.

9.4 Right to Withdraw Consent

You can withdraw your consent to our collection, use, or disclosure of your personal information at any time, subject to legal or contractual restrictions.

How to withdraw consent:

Consequences of withdrawal: If you withdraw consent, you will no longer be able to use CollisionOS. Your account will be moved to read-only mode, and you will only be able to view and export your existing data.

9.5 Right to Data Portability

You have the right to receive your personal information in a structured, commonly used, machine-readable format.

How we provide portability:

9.6 Right to Object/Complain

If you believe we are not handling your personal information in compliance with PIPEDA or BC PIPA, you have the right to complain.

Step 1 - Contact us first:

Step 2 - Contact the Privacy Commissioner:

If you are not satisfied with our response, you can file a complaint with:

Office of the Privacy Commissioner of Canada

Website: www.priv.gc.ca

Toll-free: 1-800-282-1376

TTY: 1-800-053-7382

Email: info@priv.gc.ca

9.7 No Fee for Access Requests

We do not charge a fee for access requests or exercising your privacy rights, unless your request is clearly unfounded, repetitive, or excessive. In such cases, we may charge a reasonable administrative fee or refuse the request.

10. Cookies & Tracking Technologies

CollisionOS uses cookies and similar technologies to provide functionality and improve your experience. Here's what we use and why:

10.1 Essential Cookies

These cookies are necessary for the service to function and cannot be disabled:

10.2 LocalStorage

We use browser localStorage (not cookies) extensively for:

You control localStorage: You can clear localStorage through your browser settings (typically under "Clear browsing data" > "Cookies and site data"). This will not delete your cloud-stored data, but you will lose offline cached data and preferences.

10.3 Google Analytics

We use Google Analytics to understand how users interact with CollisionOS:

How to opt out:

10.4 Firebase Analytics

Firebase provides app performance monitoring and crash reporting:

10.5 No Third-Party Advertising

We do NOT use:

CollisionOS is ad-free and funded by subscriptions only.

11. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations.

11.1 Active Accounts

While your account is active (trial or paid subscription):

11.2 Expired or Canceled Accounts

When your trial expires or subscription is canceled:

11.3 Retention Periods by Data Type

We retain different types of data for different periods:

Customer Personal Data (deletable anytime):

Your Business Financial Records (your responsibility):

System Logs (90 days - 1 year):

Important Clarification: CRA record retention requirements apply to your business records for your tax purposes. Customer personal information (names, emails, phones) is not required by CRA and can be deleted upon request under PIPEDA privacy regulations.

11.4 Self-Service Deletion

You can delete customer data at any time:

11.5 Legal Holds

In certain circumstances, we may need to retain data longer:

We will notify you if your data is subject to a legal hold.

12. Children's Privacy

CollisionOS is a business management tool designed for commercial auto body shops. Our service is restricted to users 18 years of age or older.

If you believe a minor has created an account: Please contact us immediately at privacy@collisionos.ca so we can take appropriate action.

13. Changes to Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations.

13.1 How We Notify You

When we make changes, we will:

13.2 Material Changes

For significant changes (such as changes to data sharing practices, retention periods, or your rights), we will:

13.3 Acceptance

Continued use of CollisionOS after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated policy, you should stop using the service and contact us to close your account.

13.4 Version History

We maintain a version history of our Privacy Policy. You can request previous versions by emailing privacy@collisionos.ca.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Privacy Officer

Email: privacy@collisionos.ca

Support Email: support@collisionos.ca

Business Address: Vancouver, British Columbia, Canada

What to include in your message:

Response time: We will acknowledge your inquiry within 3 business days and provide a substantive response within 30 days.

Office of the Privacy Commissioner of Canada

If you are not satisfied with our response to your privacy concern, you have the right to contact:

Website: www.priv.gc.ca

Toll-free: 1-800-282-1376

Email: info@priv.gc.ca


CollisionOS Privacy Policy v1.1

Effective Date: January 1, 2025 | Last Updated: December 30, 2025

Return to CollisionOS | Terms of Service