Skip to content

Legal

Privacy Policy

Last updated September 29, 2026

These terms are pending attorney review and may be updated.

This policy describes what Shop Bots collects to run Shop Bots, a subscription back office for collision repair shops, and what we do with it. The Terms of Service govern use of the product.

1. Who we are

Shop Bots operates Shop Bots at getshopbots.com. Questions about this policy go to hello@getshopbots.com.

2. Information we collect

We collect the following, depending on what the shop uses:

  • Account information. Email address, the sign-in method, and the person’s role on the shop (owner, manager, or staff). Passwords for Shop Bots accounts are handled by the authentication provider. We do not keep a copy of the card number; Stripe does.
  • Shop data. The profile the shop enters, such as labor rates, carriers, certifications, and how often a customer should hear from the shop.
  • Vehicle, claim, and customer information the shop types in, imports, or asks us to read from a connected portal, including estimates and repair-order details from the shop’s own CCC ONE login, and procedure text from a connected OEM or I-CAR source.
  • Email in a connected inbox. Messages read over IMAP, mail forwarded to the shop’s Shop Bots address, and the drafts staff prepare from them. Shop Bots does not send those messages.
  • Documents the shop uploads to the knowledge library or the document library. Files are stored in Supabase Storage.
  • Usage and billing. Token counts for AI calls, whether a bot is inside its included allowance, subscription status, and invoices. Overage, when configured, is billed through Stripe.

We also keep operational logs needed to run and secure the service, such as sign-in events and error records. We do not run a separate advertising profile on shop staff or on a shop’s customers.

3. How we use it

We use this information to:

  • create and secure the shop’s account and staff seats
  • draft replies, follow-ups, and answers the shop asked for
  • read a portal or mailbox the shop connected, and store that read for the shop
  • search documents the shop uploaded, for that shop’s own bots
  • bill the setup fee, the monthly bot fees, and configured usage overage
  • send service email, such as an invite or a sign-in link
  • investigate abuse, keep shops isolated, and answer a support request

4. We do not sell it

We do not sell personal information. We do not share it for advertising. We do not use one shop’s information to train an AI model on behalf of another shop. Text is sent to xAI so it can write the draft that shop requested.

5. Companies that process it

These companies process information so we can run Shop Bots. They are not allowed to use it for their own marketing of your shop.

ProviderRole
SupabaseDatabase, authentication, and file storage. Shop data is hosted in the United States.
VercelApplication hosting.
xAIAI processing for drafts the shop requests.
StripePayments, invoices, and the billing portal.
ResendDelivery of staff email, such as invites, and receipt of mail sent to the shop’s Shop Bots address.

A portal, a mailbox provider, or Google processes information under its own terms when the shop chooses to connect it. If a hosted browser is turned on to read a portal, that browser sees the pages needed for the read. The default reader runs on our worker.

We may also disclose information if the law requires it, or to protect the service, a shop, or someone’s safety.

6. Security

Portal passwords and mailbox app passwords are encrypted before they are stored. The app does not show a stored secret again. Each shop’s rows are isolated in the database so another shop cannot read them. Platform staff can see a shop’s data when supporting that shop.

No method of storage or transmission is perfect.

7. Retention and deletion

We keep shop data while the account is open and as needed to provide the service. Disconnecting a portal or mailbox removes that connection’s stored secret. Email hello@getshopbots.com to ask us to delete a shop account and the customer data in it. We will delete it within a reasonable time after we confirm the request is from the shop.

We may keep invoices, payment records, and security logs for as long as we need them for tax, billing disputes, or legal duties. Copies in backups are overwritten on the normal backup cycle.

8. Shops and their customers

Information about a shop’s customers, vehicle owners, and insurance contacts belongs to the shop’s relationship with those people. The shop decides why that information is collected and is the controller of it. Shop Bots processes it on the shop’s instructions to provide the service.

The shop is responsible for having a right to give us that information, and for any notice the shop owes its own customers. A person who wants a copy or a correction of a repair record should start with the shop. If someone contacts us about a shop’s customer, we will refer the request to that shop unless the law requires us to respond ourselves.

9. United States only

Shop Bots is offered to businesses in the United States. We do not offer it for use in other countries, and this policy is written for the United States. Shop data is stored with Supabase in the United States. The application is hosted on Vercel. We do not represent that the service meets privacy laws outside the United States.

10. Children

Shop Bots is a business service. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, email hello@getshopbots.com and we will delete it.

11. Changes

We may update this policy. When we do, we will change the “Last updated” date. For a material change, we will also give notice by email or in the product. The new policy applies from the date it is posted, unless the notice says otherwise.

12. Contact