Privacy policy
Updated October 4, 2026.
Fly Intake helps repair shops record vehicle arrivals, photos, documents, and work orders. This policy describes how the app handles information entered into it.
Information we store
We store your account name, email, Google account identifier, shop memberships, vehicle details, owner contact information, photos, documents, audio, repair notes, and work orders. When the shop owner authorizes Google Drive storage, we store their refresh token on the server to maintain the connection. Staff sign-in requests identity information only. Passwords, if used, are stored as hashes.
Google account and Drive access
Google sign-in verifies your identity. The app requests permission to create and manage only the Google Drive files it creates or you explicitly make accessible to it. All team uploads are copied into the shop owner’s Google Drive, under FLYINTAKE_VEHICLES, when syncing. Staff Google accounts are used only for authentication. We use Google data to provide the app’s login and file-storage features; we do not sell it or use it for advertising.
Fly Intake’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use information
We use information to provide accounts, save and organize repair records, sync files you choose to Google Drive, create requested work-order drafts, and support and protect the service. Only collect customer information needed for your repair work.
Who can access repair records
Members of the same shop can access its repair records and uploaded files. Other shops cannot access those records through the app. Shop owners and administrators control membership. The platform administrator manages shop creation and owner assignments. Service operators may access stored data as needed to operate, support, and maintain the service.
Service providers
The app runs on Render. Google processes sign-in and Drive storage. If you request an audio-generated work order, audio and the saved technician work order and notes are sent to Google Gemini when Gemini is configured, or to OpenAI when OpenAI is configured, for transcription and drafting. A ready preliminary photo assessment may also be included as context. Recorded activity notes are also sent to the configured provider for transcription and saved in the vehicle history; this flow does not generate a work order. Larger Gemini recordings use temporary Google API file uploads; deletion is requested after processing. We do not send your Google Drive account contents to the AI providers. Browser VIN lookup sends the VIN to the US National Highway Traffic Safety Administration’s vPIC service.
Arrival photo assessment
When Gemini is configured, saving all four vehicle corner photos starts a preliminary condition assessment. The newest corner images are resized and sent to Google Gemini; staff can also request analysis of a partial set. The app stores the observations and source-photo references privately with the repair. The assessment does not authorize repairs or replace technician inspection. Original photos remain saved and follow the shop's Drive and backup settings.
VIN photos and voice entry
When you choose printed VIN recognition, a resized photo is sent to Google Gemini. The original VIN label photo is saved as a private repair attachment and copied to the shop owner’s Google Drive when connected. Live VIN speech and keyboard dictation use the device/browser speech provider, which may process audio under its own terms. This voice-entry flow does not save an audio attachment. VIN lookup sends the entered VIN to NHTSA.
Customer SMS, emails, and repair links
When shop staff sends a welcome message, repair update, reply, or review request, we send the selected customer phone number or email address and message content to Pingram. We store texting consent, outgoing and incoming message content, delivery events, errors, and opt-outs with the shop's conversation history. Signed Pingram webhooks provide customer replies and delivery failures. Failed destinations are blocked from further app sends until contact details are corrected. Pingram processes messages under its own terms and privacy policy.
Welcome messages include a private link showing the shop, vehicle make/model/year, and current repair status. Anyone with the link can view that limited page; keep it private. It does not expose phone numbers, email addresses, VINs, internal notes, work orders, or attachments. Review short links redirect only to the shop's Google review page. Reply STOP to opt out of SMS through Pingram; contact the shop to update your communication preferences.
Optional recovery backups
When enabled by the service operator, repair records, timestamped history, uploaded files, and analysis attempts and responses are copied to private Cloudflare R2 storage for recovery, quality checks, and future extraction. Cloudflare processes these backups as a storage service provider. Backups are separate from Google Drive copies and public customer repair pages; customer links do not provide access to backups.
The service operator manages backup retention and removal. Removing an app record or a Drive copy does not automatically remove a recovery backup. Include backups when requesting record deletion from the service operator.
Retention and account controls
Records and original uploads are retained on the app server until removed by the service operator. Drive copies remain in the user’s Google Drive until removed there. Deleting a file from Drive does not delete the app’s stored original. You can revoke Google access in your Google account’s connected-app settings. Revoking access stops future Drive access but does not automatically erase existing app records or Drive copies.
To request account or record removal, contact your shop administrator. For service-level privacy or deletion requests, contact [email protected]. Do not post private repair information or credentials in public messages.
Security
We use account access controls and password hashing to help protect records. No storage or transmission method is completely secure. Protect your login and connected Google account, use trusted devices, and contact the service operator if you suspect unauthorized access.
Optional app usage analytics
When enabled by the service operator, PostHog receives generic actions performed by signed-in staff, such as opening a screen, creating an intake, changing a repair status, or saving an attachment. Events use a random identifier that lasts only for the current page. They do not include account or shop identifiers, customer contacts, VINs, filenames, repair notes, transcripts, media, page URLs, or referrers. Automatic interaction capture, session replay, person profiles, and location enrichment are disabled. Public customer status pages and sign-in pages do not send analytics. Browser Do Not Track is respected.
Browser storage
The app uses session cookies for login and browser storage for emergency unsaved drafts. The server database is the authoritative record store. Use a trusted device when handling customer information.
Changes to this policy
We may update this policy as the service changes. The date above identifies the latest version. Contact the service operator with questions about how your information is handled.