Skip to content

Privacy policy

Effective August 28, 2026

Torqix is shop management software. This policy explains what information Torqix handles for repair shops and their customers, why it is handled, which service providers may process it, and how deletion and messaging choices work.

1. Who is responsible

Torqix is operated by Torqix LLC, located at 4828 NE 103rd Ave, Portland, Oregon 97220. Questions or privacy requests may be sent to bayani@torqix.net.

A repair shop controls the customer and vehicle information it enters into Torqix. Torqix processes that information to provide the service to the shop. Torqix controls information used to operate its own accounts, website, security, and support.

2. Information we handle

  • Shop and account information. Business and team contact details, authentication records, permissions, settings, support requests, and subscription or service records.
  • Shop operating data. Customer names and contact details, vehicles, repair orders, appointments, estimates, approvals, inspection media, invoices, recorded payments, messages, call records, and related work history supplied by a shop or its customer.
  • Communications and AI content. The contents and metadata of calls, texts, emails, transcripts, prompts, drafts, and responses when a shop uses those features.
  • Security and operational data. Login activity, audit records, device and browser information, network addresses, delivery events, and error or performance records needed to secure and operate the service.
  • Public work-request data. Information a person submits to a shop through its public request form, plus limited anti-abuse forensics such as IP address and user-agent.

3. How we use information

  • Provide, secure, troubleshoot, and support Torqix and the customer-facing pages a shop enables.
  • Process repair work, communications, approvals, reminders, status updates, and other shop workflows.
  • Route calls, texts, and emails and create transcripts, speech, or AI-assisted drafts when selected.
  • Prevent abuse, investigate failures, keep audit evidence, and comply with lawful obligations.

We do not sell personal information or use a shop’s customer list as Torqix’s own marketing list.

5. Service providers and subprocessors

Depending on the live feature and deployment configuration, Torqix uses the following companies to deliver the service:

  • Vercel for application hosting.
  • Neon for the PostgreSQL database.
  • Twilio or Telnyx for SMS carriage, when a shop connects its existing provider account and number.
  • Resend for email delivery and receipt.
  • DeepSeek for AI text generation.
  • Google Gemini or Anthropic as alternative AI text providers selected in deployment configuration.
  • Twilio and ElevenLabs have credential checks and protocol adapters for the voice path. No shop voice line is activated today, so Torqix is not sending shop calls through that path.

Message or AI content may be processed by the provider configured for the feature. A provider that is not configured does not receive the content merely because it appears in this list. No shop call content is sent through the unactivated voice path today.

Torqix is operated from the United States and its primary database is hosted in the United States. Some providers may process content in other countries as part of delivering their service; in particular, content sent to an AI text provider is processed wherever that provider operates, and DeepSeek is a company based outside the United States. AI model selection is deployment configuration; there is no model picker in the shop app today.

6. Cookies

Torqix uses only first-party cookies that operate the product: a session cookie that keeps a signed-in user signed in, a “remember this device” cookie that lets a person skip the second authentication factor on a device they chose to trust, and short-lived operational cookies used during sign-in and one-time credential display. Torqix does not use advertising cookies, analytics cookies, or third-party trackers, on the marketing site or in the product.

7. Security and tenant isolation

Every tenant-owned database row carries the shop organization’s identifier. PostgreSQL row-level security and the tenant-scoped database client both enforce that one organization cannot query another organization’s rows. Vendor credentials stored by Torqix are sealed using AES-256-GCM authenticated encryption before they are written to the database.

No system can promise perfect security. Shop owners should assign only the access their team needs, protect their credentials, and notify bayani@torqix.net about suspected unauthorized use.

8. Retention and deletion

  • IP address and user-agent forensics collected with a public work request are deleted after 90 days. The request itself remains in the shop’s lead workflow until handled under the shop’s instructions.
  • Records deleted through the product enter a 30-day trash window and can be restored during that time. After 30 days they can no longer be restored and become eligible for permanent purge. Permanent purge is protected by an explicit deployment gate and may drain in capped nightly batches; until that safeguard is enabled for a deployment, expired records are inaccessible through the product but may remain stored.
  • Some evidence must outlive the record it describes. In particular, the append-only SMS consent trail is designed to preserve opt-in and opt-out evidence even after the related customer or phone row is purged, and security and audit records are kept for as long as they are needed as evidence of what happened.

9. Legal disclosures and incidents

Torqix may disclose information when it reasonably believes disclosure is required by law — for example in response to a subpoena, court order, or other lawful demand — or is necessary to protect the safety, rights, or property of Torqix, its shops, or the public. Where the law allows, we will notify the affected shop of a demand for its data before responding.

If we determine that a security incident has affected personal information we hold, we will notify affected shops without unreasonable delay and as required by applicable law, and will share what we know about what was affected and what we are doing about it.

10. Children

Torqix is business software for repair shops and is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child’s information has been provided to Torqix, contact bayani@torqix.net and we will delete it.

11. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, and to know how it is shared. Torqix does not sell personal information and does not share it for cross-context behavioral advertising, so there is nothing to opt out of on that front.

For most information in Torqix, the repair shop you did business with is the controller and Torqix processes it on the shop’s instructions — so requests about a shop’s records are typically fulfilled through that shop, and we will help the shop do so. For information Torqix controls (such as a shop owner’s own account), send requests to bayani@torqix.net. We will not treat anyone differently for exercising a privacy right.

12. Access, correction, and deletion requests

A shop controls the customer records it placed in Torqix and can correct, export, trash, or restore them using the product. A customer asking about a shop’s records should contact that shop first. If the request comes to Torqix, we may need to verify the request and coordinate with the controlling shop.

Send requests to bayani@torqix.net.

13. Changes to this policy

We will update the effective date when this policy changes. Material changes will be communicated through the service or another appropriate channel. The related terms of service also apply.

This page was prepared with automated assistance and has not yet been reviewed by counsel.