Operator: Matthew Kassing, operating as Everywhere Auto Care.
Privacy contact: Matthew Kassing at everywhereautorepair@gmail.com or 480-818-6699.
What this notice covers
This notice covers the current private Everywhere Auto Care business app, its public service-request website, shared customer pages and authorized business staff. It is for this business's operations. An app subscription service for other businesses is not active in this release. Optional connections operate only when configured and authorized. A feature described as optional is not a claim that it is currently connected.
Information used to arrange and manage service
We use customer names, contact details, service addresses, vehicle information, service concerns, selected services, preferred visit times and notes to respond to requests and manage work. Vehicle information can include mileage, engine details, VIN and registration plate information when provided. Business-vehicle requests can include fleet details. Staff may add inspection findings, job assignments, work times, service history and photos.
Quotes, invoices and payment records can contain itemized work, amounts, dates, payment methods, provider references, refunds and associated customer or job information. Parts and expense records can include supplier references, order or invoice evidence and receipt images. Please do not place payment-card details, passwords or unrelated personal information in notes or photos.
Manual payment-fee records include processor or account references, transaction references, recorded fees and calculated net amounts, supporting evidence references, correction reasons and audit history. Financial exports can include these fields. Corrections preserve earlier history, and downloaded exports create additional copies. This manual recordkeeping is not an automatic provider fee feed.
Shared quote, agreement and service-summary pages can display the corresponding work, prices, decisions, notes and selected photos to people who possess the link. We record approval information; depending on the approval workflow, this can include the name or decision entered, the version presented, time, network address and browser information. Keep these links private.
Accounts, workforce information and communications
Staff accounts include identity, contact and role information. We use access controls to limit the records staff can view or change. Workforce tools can hold compensation arrangements, time entries, breaks and revision history for payroll preparation. These tools do not themselves establish that payroll payments or tax filings occur.
We retain outgoing message recipients, subjects, content, attachments and delivery history for business correspondence. Invoice messages can include PDF copies. Account invitations and sign-in messages also use the configured email service.
Connected services
Website hosting and inquiries. The public website uses OpenAI Sites and Cloudflare services, with D1 database storage for requests and R2 storage for uploaded photos. Requests are stored privately and transferred to the locally operated business app through an authenticated connection. Preferred times remain requests until an advisor confirms an appointment. The browser may send a request copy through FormSubmit for notification to everywhereautorepair@gmail.com. The website currently discloses FormSubmit's 30-day submission retention. Photos are not included in that FormSubmit copy. Website and app records can exist separately.
Gmail sending. When an owner configures Gmail, the app uses an owner-provided app password to send email through Gmail over an encrypted connection. The current implementation sends mail; it does not implement Gmail OAuth or an inbox-reading feature. This describes app behavior, not a restriction on the credential's possible permissions. The app stores the app password encrypted separately from ordinary records. Gmail and message recipients retain their own copies under their own practices.
Squarespace. App registration and activation are pending. The implemented connection is designed to request transaction-read permission and access while the owner is offline. When authorized, connection verification accesses site information and transaction responses, and stores site and verification information with encrypted access credentials. The current connection does not import those transaction responses into the app ledger; automatic receipt synchronization and native Squarespace Pay Link creation are not available in this integration. Existing Squarespace website or domain payment links are separate from this pending app connection.
Other optional providers. If enabled, Square can provide hosted checkout and payment reconciliation, with the app retaining payment, order, refund and merchant references. Square and Squarespace are different services. QuickBooks currently provides a connection and company-verification foundation; accounting synchronization is disabled, although the authorization requests accounting permission. Optional Google address search receives entered address-search text, Google Maps receives a destination when directions are opened, and NHTSA vehicle decoding receives the supplied VIN. The app's PayPal work is limited to an isolated sandbox test; it is not a production customer-payment flow in this release.
Storage, logs and protection
The business app runs on a locally operated Windows computer and stores server records and photos in a SQLite database. Tailscale provides private network access and a restricted public gateway for selected customer and integration routes. We maintain local backups of the business application's server data. Provider credentials receive separate encryption; ordinary database contents are not automatically encrypted by that credential mechanism. Authorized server administrators can access stored business information. We do not describe this system as end-to-end encrypted.
Browsers can retain unfinished drafts and recovery information. Signing out does not necessarily erase those local copies. Operations and error logs may include request, browser or troubleshooting information and may contain information entered into the app. The website separately counts call and text clicks in aggregate and uses temporary, salted daily network-address hashes for spam limits; its click counters do not contain quote details or raw network addresses.
Retention, disconnecting and requests
The current app does not apply one automatic deletion period to all service records, photos, message histories and logs. Backup rotation is separate from customer-record retention. Deleting a current photo or record can leave copies in summaries, sent emails, provider systems, browser storage or backups. Some removals preserve void or audit history.
Disconnecting Gmail or Squarespace removes the app's local connection, but does not automatically revoke the provider-side authorization or delete existing records and backups. Owners can revoke the relevant app password or app access in the provider account. QuickBooks disconnect attempts provider revocation and can remain pending if that step fails. Removing a website connection does not erase earlier requests or photos.
Contact Matthew Kassing using the details above to request access, correction or deletion and identify the relevant service or account. We review each request individually, establish which records belong to it, and explain what can be provided, corrected or removed and which copies or records remain. A request does not itself erase records or provider copies. This process does not promise immediate deletion, a fixed response time or a complete self-service export.
Changes
We keep a dated version of this notice on the website and provide notice of material changes through the website or available business contact channels.
