MechAxis Privacy Policy

How MechAxis handles personal information as the provider of the workshop management platform. Written for Australian workshops and the Australian Privacy Principles.

Who this policy is for

This policy covers MechAxis — the software Australian workshops use to run bookings, job cards, inspections, quotes, invoicing, payments and customer communication.

If you are a vehicle owner looking for how your mechanic handles your details, this is not the document you want. Each workshop publishes its own privacy notice naming the workshop as the business that holds your records; ask them for the link, or find it on the booking form or the invoice they sent you. This policy explains only the layer underneath — how MechAxis stores and protects those records on the workshop’s behalf.

The two kinds of information we handle

The distinction matters, because our obligations differ.

1. Your account information. When a workshop subscribes, we collect information about the people who use the product — name, email address, phone number, the role assigned to them, authentication and multi-factor records, subscription and billing details, support correspondence, and records of how the product is used. We are directly responsible for this information.

2. Workshop records held on your behalf. The customer, vehicle, job, inspection, quote, invoice, payment and message records a workshop creates belong to that workshop. We store and process them so the workshop can run its business. We do not decide what goes into them, we do not use them for our own marketing, and we do not sell them or share them with other workshops.

How we collect it

Directly from you when you create an account, subscribe, contact support or make a sales enquiry. From your use of the product, including sign-in events and reliability and performance measurements. From your customers, when they use a booking link, QR intake form, quote approval page or invoice portal that your workshop has shared with them. And from our payment processor, which confirms subscription status without giving us your card number.

Why we use it

To provide and support the product; to authenticate users and protect accounts; to take subscription payments; to send you service, billing and security notices; to investigate faults and abuse; to measure reliability and improve the product; and to meet our legal and record-keeping obligations.

We do not sell personal information, and we do not use the customer records your workshop stores for advertising or profiling.

Who we share it with

Only the providers that make the product work, each limited by contract to the service they perform for us:

  • Database and authentication hosting
  • Application hosting and content delivery
  • Email delivery and SMS delivery, for the messages your workshop sends
  • Payment processing, for subscriptions and customer payments
  • Product analytics, session replay on our marketing pages, error reporting and performance monitoring
  • Accounting integrations you choose to connect, such as Xero

We may also disclose information where the law requires it, or to protect our rights or the safety of others.

Where your information is stored

Some providers store and process information outside Australia. Australian privacy law permits this, and it does not reduce our accountability: if an overseas provider mishandles information we disclosed to it, we are treated as having breached the Australian Privacy Principles ourselves. We take reasonable steps to see that these providers protect information to the standard the APPs require.

Information is likely to be handled in:

  • Japan — the database holding workshop records, including customer, vehicle, job and invoice data.
  • United States — application hosting, email, payment processing and product analytics.

SMS is the exception. Text messages your workshop sends, and replies from its customers, are handled by an Australian provider and stay onshore.

We do not claim Australian data residency. If that matters to your business, tell us before you subscribe so we can be clear about what we can and cannot offer.

Product analytics

We use PostHog, Google Analytics and Vercel Speed Insights to understand how the platform is used, measure reliability and diagnose errors. This may include page routes, device and browser details, performance measurements, account identifiers and high-level actions such as signing in, creating a workshop or starting checkout.

PostHog is configured not to record session replays, form contents, page text, customer notes or document contents. Identifiers contained in private page routes are removed before analytics events are sent. Analytics never receives your customers’ records.

We also use Microsoft Clarity on our public marketing pages — the home page, pricing, articles and tools — where it records how visitors scroll and click so we can see which pages explain the product badly. This does involve session replay, so we have confined it to those pages.

Clarity is not loaded in the workshop console, on a quote or invoice link, on a QR intake form, on an unsubscribe page, or on the sign-in screen. It is stopped, not merely idle, if you move from a marketing page into any of them. It therefore never observes a workshop’s records or a customer’s details, and never sees the single-use links that open a quote or invoice.

How we protect it

Each workshop’s data is isolated at the database layer by row-level security scoped to that organisation, so one workshop cannot query another’s records — this is enforced by the database, not only by the interface. Information is encrypted in transit and at rest. Access within a workshop is role-based, and accounts can be protected with multi-factor authentication.

MechAxis staff do not have standing access to your workshop. Entering a workshop requires an explicit, time-limited session with a stated reason, which is recorded in that workshop’s audit history and enforced by the database.

We never store full card numbers. Card details are entered directly with our payment processor and never reach our systems.

How long we keep it

We keep information while your account is active, and afterwards for the period reasonably needed for account closure, backups, dispute handling, security, and tax and accounting obligations. For financial records we keep seven years, which is longer than the five the ATO generally requires.

You can ask us to export or delete your workshop’s data, subject to identity verification, technical feasibility, the rights of others and any legal requirement to retain it. Backup copies may persist until they are overwritten in the ordinary cycle. Records of communication consent are kept as evidence of that consent, separately from the current preference.

Access, correction and complaints

You can ask what personal information we hold about you, ask us to correct it, or raise a complaint about how we have handled it. Email hello@mechaxis.com.au and we will respond within a reasonable period.

If you are a vehicle owner asking about your own records, contact the workshop that serviced your vehicle — those records are theirs, and they can act on them immediately. We will help a workshop respond to any request it receives.

If we cannot resolve a complaint to your satisfaction, you can refer it to the Office of the Australian Information Commissioner at oaic.gov.au.

Data breaches

If a breach occurs that is likely to result in serious harm, we will assess it and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we will tell affected workshops what happened and what we are doing about it.

Changes to this policy

We may update this policy as the product changes. Material changes will be communicated to subscribing workshops. The version published here is the current one.

Contact us

Questions about this policy or the MechAxis platform: hello@mechaxis.com.au. Questions about how a particular workshop handles your information should go to that workshop.